Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
file.exe

Overview

General Information

Sample name:file.exe
Analysis ID:1546019
MD5:ab7d13fd2200b07c2bc9fe3b3f7cc837
SHA1:22943e1fbf9c32a3bb716a002de1a8e598bbf169
SHA256:17b7ba466ce248a1f9a337d4e6a7ab092a6bb2608246c08a348b525c8e3a9311
Tags:exeuser-Bitsight
Infos:

Detection

CredGrabber, Meduza Stealer
Score:92
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Suricata IDS alerts for network traffic
Yara detected CredGrabber
Yara detected Meduza Stealer
AI detected suspicious sample
Found many strings related to Crypto-Wallets (likely being stolen)
Tries to harvest and steal Bitcoin Wallet information
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to dynamically determine API calls
Contains functionality to launch a program with higher privileges
Contains functionality to query locales information (e.g. system language)
Contains functionality to record screenshots
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Enables debug privileges
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May check the online IP address of the machine
Queries the volume information (name, serial number etc) of a device
Queries time zone information
Suricata IDS alerts with low severity for network traffic
Terminates after testing mutex exists (may check infected machine status)
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • file.exe (PID: 3812 cmdline: "C:\Users\user\Desktop\file.exe" MD5: AB7D13FD2200B07C2BC9FE3B3F7CC837)
  • cleanup
{"C2 url": "109.172.94.66", "grabber_max_size": 4194304, "anti_vm": true, "anti_dbg": true, "self_destruct": false, "extensions": ".txt", "build_name": "Ipa", "links": "", "port": 15666}
SourceRuleDescriptionAuthorStrings
00000000.00000002.1323368752.000002674DF30000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_MeduzaStealerYara detected Meduza StealerJoe Security
    00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_MeduzaStealerYara detected Meduza StealerJoe Security
      Process Memory Space: file.exe PID: 3812JoeSecurity_MeduzaStealerYara detected Meduza StealerJoe Security
        Process Memory Space: file.exe PID: 3812JoeSecurity_CredGrabberYara detected CredGrabberJoe Security
          SourceRuleDescriptionAuthorStrings
          0.2.file.exe.2674e120000.0.unpackJoeSecurity_MeduzaStealerYara detected Meduza StealerJoe Security
            0.2.file.exe.2674e120000.0.raw.unpackJoeSecurity_MeduzaStealerYara detected Meduza StealerJoe Security
              No Sigma rule has matched
              TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
              2024-10-31T11:34:30.219355+010020229301A Network Trojan was detected52.149.20.212443192.168.2.749733TCP
              2024-10-31T11:35:10.399790+010020229301A Network Trojan was detected52.149.20.212443192.168.2.754363TCP
              TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
              2024-10-31T11:34:15.039636+010020494411A Network Trojan was detected192.168.2.749699109.172.94.6615666TCP
              TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
              2024-10-31T11:34:15.039636+010020508061A Network Trojan was detected192.168.2.749699109.172.94.6615666TCP
              2024-10-31T11:34:15.045286+010020508061A Network Trojan was detected192.168.2.749699109.172.94.6615666TCP
              TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
              2024-10-31T11:34:15.039636+010020508071A Network Trojan was detected192.168.2.749699109.172.94.6615666TCP
              2024-10-31T11:34:15.045286+010020508071A Network Trojan was detected192.168.2.749699109.172.94.6615666TCP

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: 0.2.file.exe.2674e120000.0.raw.unpackMalware Configuration Extractor: Meduza Stealer {"C2 url": "109.172.94.66", "grabber_max_size": 4194304, "anti_vm": true, "anti_dbg": true, "self_destruct": false, "extensions": ".txt", "build_name": "Ipa", "links": "", "port": 15666}
              Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E193430 CryptUnprotectData,LocalFree,0_2_000002674E193430
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E157F90 CryptUnprotectData,LocalFree,0_2_000002674E157F90
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E193730 CryptProtectData,LocalFree,0_2_000002674E193730
              Source: unknownHTTPS traffic detected: 104.26.13.205:443 -> 192.168.2.7:49700 version: TLS 1.2
              Source: file.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1DB78C FindClose,FindFirstFileExW,GetLastError,0_2_000002674E1DB78C
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1DB83C GetFileAttributesExW,GetLastError,FindFirstFileW,GetLastError,FindClose,__std_fs_open_handle,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,CloseHandle,CloseHandle,0_2_000002674E1DB83C
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1A24F0 GetLogicalDriveStringsW,0_2_000002674E1A24F0
              Source: C:\Users\user\Desktop\file.exeFile opened: D:\sources\migration\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: D:\sources\replacementmanifests\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: D:\sources\migration\wtr\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: D:\sources\replacementmanifests\microsoft-activedirectory-webservices\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: D:\sources\replacementmanifests\microsoft-client-license-platform-service-migration\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: D:\sources\replacementmanifests\hwvid-migration-2\Jump to behavior

              Networking

              barindex
              Source: Network trafficSuricata IDS: 2049441 - Severity 1 - ET MALWARE Win32/Unknown Grabber Base64 Data Exfiltration Attempt : 192.168.2.7:49699 -> 109.172.94.66:15666
              Source: Network trafficSuricata IDS: 2050806 - Severity 1 - ET MALWARE [ANY.RUN] Meduza Stealer Exfiltration M2 : 192.168.2.7:49699 -> 109.172.94.66:15666
              Source: global trafficTCP traffic: 192.168.2.7:49699 -> 109.172.94.66:15666
              Source: global trafficHTTP traffic detected: GET / HTTP/1.1Accept: text/html; text/plain; */*Host: api.ipify.orgCache-Control: no-cache
              Source: Joe Sandbox ViewIP Address: 104.26.13.205 104.26.13.205
              Source: Joe Sandbox ViewIP Address: 104.26.13.205 104.26.13.205
              Source: Joe Sandbox ViewASN Name: SUMTEL-AS-RIPEMoscowRussiaRU SUMTEL-AS-RIPEMoscowRussiaRU
              Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
              Source: unknownDNS query: name: api.ipify.org
              Source: unknownDNS query: name: api.ipify.org
              Source: Network trafficSuricata IDS: 2050807 - Severity 1 - ET MALWARE [ANY.RUN] Possible Meduza Stealer Exfiltration (TCP) : 192.168.2.7:49699 -> 109.172.94.66:15666
              Source: Network trafficSuricata IDS: 2022930 - Severity 1 - ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow : 52.149.20.212:443 -> 192.168.2.7:49733
              Source: Network trafficSuricata IDS: 2022930 - Severity 1 - ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow : 52.149.20.212:443 -> 192.168.2.7:54363
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: unknownTCP traffic detected without corresponding DNS query: 109.172.94.66
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1A0420 InternetOpenA,InternetOpenUrlA,HttpQueryInfoW,HttpQueryInfoW,InternetQueryDataAvailable,InternetReadFile,InternetQueryDataAvailable,InternetCloseHandle,Concurrency::cancel_current_task,0_2_000002674E1A0420
              Source: global trafficHTTP traffic detected: GET / HTTP/1.1Accept: text/html; text/plain; */*Host: api.ipify.orgCache-Control: no-cache
              Source: global trafficDNS traffic detected: DNS query: api.ipify.org
              Source: file.exe, 00000000.00000002.1323248860.000002674C6DF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.v
              Source: file.exe, 00000000.00000002.1323368752.000002674DF30000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.ipify.org
              Source: file.exe, 00000000.00000002.1323368752.000002674DF30000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.ipify.org/
              Source: file.exe, 00000000.00000002.1323368752.000002674DF30000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.ipify.org/=
              Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
              Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
              Source: unknownHTTPS traffic detected: 104.26.13.205:443 -> 192.168.2.7:49700 version: TLS 1.2
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1A0CE0 GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetDC,GetDeviceCaps,GetDeviceCaps,CreateCompatibleDC,CreateCompatibleBitmap,SelectObject,BitBlt,SHCreateMemStream,SelectObject,DeleteDC,ReleaseDC,DeleteObject,EnterCriticalSection,LeaveCriticalSection,IStream_Size,IStream_Reset,IStream_Read,SelectObject,DeleteDC,ReleaseDC,DeleteObject,0_2_000002674E1A0CE0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1A5080 GetModuleHandleA,GetProcAddress,OpenProcess,NtQuerySystemInformation,NtQuerySystemInformation,GetCurrentProcess,NtQueryObject,GetFinalPathNameByHandleA,CloseHandle,CloseHandle,0_2_000002674E1A5080
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1A57C0 RtlAcquirePebLock,NtAllocateVirtualMemory,lstrcpyW,lstrcatW,NtAllocateVirtualMemory,lstrcpyW,RtlInitUnicodeString,RtlInitUnicodeString,LdrEnumerateLoadedModules,RtlReleasePebLock,CoInitializeEx,lstrcpyW,lstrcatW,CoGetObject,lstrcpyW,lstrcatW,CoGetObject,CoUninitialize,0_2_000002674E1A57C0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1F66C0 NtQuerySystemInformation,0_2_000002674E1F66C0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1F66D0 NtAllocateVirtualMemory,0_2_000002674E1F66D0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1F66F0 NtQueryObject,0_2_000002674E1F66F0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1A04200_2_000002674E1A0420
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1AA1900_2_000002674E1AA190
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1A31C00_2_000002674E1A31C0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1643200_2_000002674E164320
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E15EF900_2_000002674E15EF90
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E19A0500_2_000002674E19A050
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E150EE00_2_000002674E150EE0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E19FBE00_2_000002674E19FBE0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1A7C280_2_000002674E1A7C28
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1A0CE00_2_000002674E1A0CE0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E15CD100_2_000002674E15CD10
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1A19A00_2_000002674E1A19A0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1BE9940_2_000002674E1BE994
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E182B500_2_000002674E182B50
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1A27A00_2_000002674E1A27A0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1DB83C0_2_000002674E1DB83C
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E15D8600_2_000002674E15D860
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E15E8F00_2_000002674E15E8F0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1C25B40_2_000002674E1C25B4
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1515D00_2_000002674E1515D0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1A86100_2_000002674E1A8610
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1B83D00_2_000002674E1B83D0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1B640C0_2_000002674E1B640C
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1264800_2_000002674E126480
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1914700_2_000002674E191470
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E18E5700_2_000002674E18E570
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E17B1C00_2_000002674E17B1C0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1DE1A80_2_000002674E1DE1A8
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1581E00_2_000002674E1581E0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1CB2300_2_000002674E1CB230
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1772300_2_000002674E177230
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E15C2300_2_000002674E15C230
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E18E2500_2_000002674E18E250
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1993300_2_000002674E199330
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1F63680_2_000002674E1F6368
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E189FA00_2_000002674E189FA0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E19BFA00_2_000002674E19BFA0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1B9FA40_2_000002674E1B9FA4
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1270100_2_000002674E127010
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E15205E0_2_000002674E15205E
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1700B90_2_000002674E1700B9
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1260C00_2_000002674E1260C0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1B41000_2_000002674E1B4100
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E15B1100_2_000002674E15B110
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1F61400_2_000002674E1F6140
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E19E1430_2_000002674E19E143
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1C013C0_2_000002674E1C013C
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1F61600_2_000002674E1F6160
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E19E1530_2_000002674E19E153
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1F61680_2_000002674E1F6168
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1B5DC40_2_000002674E1B5DC4
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1C2DB80_2_000002674E1C2DB8
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E193E100_2_000002674E193E10
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E16CE500_2_000002674E16CE50
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E185F100_2_000002674E185F10
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E18DF300_2_000002674E18DF30
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1C0BBC0_2_000002674E1C0BBC
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1B5BDC0_2_000002674E1B5BDC
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E18DC000_2_000002674E18DC00
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E151C000_2_000002674E151C00
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E197BF00_2_000002674E197BF0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E17CC5D0_2_000002674E17CC5D
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E191C500_2_000002674E191C50
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1B6CA40_2_000002674E1B6CA4
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E159D690_2_000002674E159D69
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1B59F40_2_000002674E1B59F4
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1C9A740_2_000002674E1C9A74
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1BFABC0_2_000002674E1BFABC
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1A5B100_2_000002674E1A5B10
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1917A00_2_000002674E1917A0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1B679C0_2_000002674E1B679C
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1A57C00_2_000002674E1A57C0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1477B00_2_000002674E1477B0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1C28300_2_000002674E1C2830
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E18E8A00_2_000002674E18E8A0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E18D9000_2_000002674E18D900
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1269000_2_000002674E126900
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1BF60C0_2_000002674E1BF60C
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1966500_2_000002674E196650
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1906900_2_000002674E190690
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E16E6D90_2_000002674E16E6D9
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1497600_2_000002674E149760
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1E274C0_2_000002674E1E274C
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1467700_2_000002674E146770
              Source: C:\Users\user\Desktop\file.exeCode function: String function: 000002674E152030 appears 46 times
              Source: C:\Users\user\Desktop\file.exeCode function: String function: 000002674E14D7E0 appears 50 times
              Source: C:\Users\user\Desktop\file.exeCode function: String function: 000002674E156CA0 appears 41 times
              Source: classification engineClassification label: mal92.troj.spyw.winEXE@1/0@1/2
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1A6F60 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,CloseHandle,0_2_000002674E1A6F60
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E15E8F0 CreateToolhelp32Snapshot,Process32FirstW,Process32NextW,CloseHandle,0_2_000002674E15E8F0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E190885 CoCreateInstance,0_2_000002674E190885
              Source: C:\Users\user\Desktop\file.exeMutant created: \Sessions\1\BaseNamedObjects\Mmm-A33C734061CA11EE8C18806E6F6E6963E617C0C4
              Source: file.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
              Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: apphelp.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: mscoree.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: wininet.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: rstrtmgr.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: ncrypt.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: ntasn1.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: mswsock.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: windows.storage.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: wldp.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: iertutil.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: profapi.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: kernel.appcore.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: winhttp.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: iphlpapi.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: winnsi.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: urlmon.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: srvcli.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: netutils.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: dnsapi.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: rasadhlp.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: fwpuclnt.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: schannel.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: mskeyprotect.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: msasn1.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: dpapi.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: cryptsp.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: rsaenh.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: cryptbase.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: gpapi.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: ncryptsslp.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: uxtheme.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: windowscodecs.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: vaultcli.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeSection loaded: wintypes.dllJump to behavior
              Source: C:\Users\user\Desktop\file.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32Jump to behavior
              Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
              Source: file.exeStatic PE information: Image base 0x140000000 > 0x60000000
              Source: file.exeStatic file information: File size 2640384 > 1048576
              Source: file.exeStatic PE information: Raw size of .rdata is bigger than: 0x100000 < 0x247600
              Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
              Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
              Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
              Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
              Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
              Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
              Source: file.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
              Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
              Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
              Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
              Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
              Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
              Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E15D860 LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,0_2_000002674E15D860
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E19F8C0 push rsp; ret 0_2_000002674E19F8C1
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E19F8C4 push rsp; ret 0_2_000002674E19F8C5
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E19F8B8 push rsp; ret 0_2_000002674E19F8B9
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E19F8BC push rsp; ret 0_2_000002674E19F8BD
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E19F8B4 push rsp; ret 0_2_000002674E19F8B5
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E19F8C8 push rsp; ret 0_2_000002674E19F8C9
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E19F8CC push rsp; ret 0_2_000002674E19F8CD
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E197910 ExitProcess,OpenMutexA,ExitProcess,CreateMutexA,CreateMutexExA,ExitProcess,ReleaseMutex,CloseHandle,0_2_000002674E197910
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1DB78C FindClose,FindFirstFileExW,GetLastError,0_2_000002674E1DB78C
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1DB83C GetFileAttributesExW,GetLastError,FindFirstFileW,GetLastError,FindClose,__std_fs_open_handle,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,GetFileInformationByHandleEx,GetLastError,CloseHandle,CloseHandle,CloseHandle,0_2_000002674E1DB83C
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1A24F0 GetLogicalDriveStringsW,0_2_000002674E1A24F0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1B86B8 VirtualQuery,GetSystemInfo,VirtualAlloc,VirtualProtect,0_2_000002674E1B86B8
              Source: C:\Users\user\Desktop\file.exeFile opened: D:\sources\migration\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: D:\sources\replacementmanifests\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: D:\sources\migration\wtr\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: D:\sources\replacementmanifests\microsoft-activedirectory-webservices\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: D:\sources\replacementmanifests\microsoft-client-license-platform-service-migration\Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: D:\sources\replacementmanifests\hwvid-migration-2\Jump to behavior
              Source: file.exe, 00000000.00000002.1323368752.000002674DF30000.00000004.00000020.00020000.00000000.sdmp, file.exe, 00000000.00000002.1323193385.000002674C6D2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
              Source: C:\Users\user\Desktop\file.exeAPI call chain: ExitProcess graph end nodegraph_0-63117
              Source: C:\Users\user\Desktop\file.exeAPI call chain: ExitProcess graph end nodegraph_0-63112
              Source: C:\Users\user\Desktop\file.exeProcess information queried: ProcessInformationJump to behavior
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1A57C0 RtlAcquirePebLock,NtAllocateVirtualMemory,lstrcpyW,lstrcatW,NtAllocateVirtualMemory,lstrcpyW,RtlInitUnicodeString,RtlInitUnicodeString,LdrEnumerateLoadedModules,RtlReleasePebLock,CoInitializeEx,lstrcpyW,lstrcatW,CoGetObject,lstrcpyW,lstrcatW,CoGetObject,CoUninitialize,0_2_000002674E1A57C0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1B0D38 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_000002674E1B0D38
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1DD7B0 GetLastError,IsDebuggerPresent,OutputDebugStringW,0_2_000002674E1DD7B0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E15D860 LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,0_2_000002674E15D860
              Source: C:\Users\user\Desktop\file.exeProcess token adjusted: DebugJump to behavior
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1F62E0 SetUnhandledExceptionFilter,0_2_000002674E1F62E0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1B0D38 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_000002674E1B0D38
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E196650 ShellExecuteW,0_2_000002674E196650
              Source: C:\Users\user\Desktop\file.exeCode function: GetLocaleInfoW,0_2_000002674E1F6398
              Source: C:\Users\user\Desktop\file.exeCode function: GetLocaleInfoEx,FormatMessageA,0_2_000002674E1DB400
              Source: C:\Users\user\Desktop\file.exeCode function: GetLocaleInfoW,0_2_000002674E1BD53C
              Source: C:\Users\user\Desktop\file.exeCode function: TranslateName,TranslateName,GetACP,IsValidCodePage,GetLocaleInfoW,0_2_000002674E1C8364
              Source: C:\Users\user\Desktop\file.exeCode function: EnumSystemLocalesW,0_2_000002674E1BCFF8
              Source: C:\Users\user\Desktop\file.exeCode function: EnumSystemLocalesW,GetUserDefaultLCID,ProcessCodePage,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,0_2_000002674E1C8D98
              Source: C:\Users\user\Desktop\file.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,0_2_000002674E1C8BBC
              Source: C:\Users\user\Desktop\file.exeCode function: EnumSystemLocalesW,0_2_000002674E1C86B0
              Source: C:\Users\user\Desktop\file.exeCode function: EnumSystemLocalesW,0_2_000002674E1C8780
              Source: C:\Users\user\Desktop\file.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\Desktop\file.exeQueries volume information: C:\ VolumeInformationJump to behavior
              Source: C:\Users\user\Desktop\file.exeKey value queried: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\TimeZoneInformation TimeZoneKeyNameJump to behavior
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1CF11C GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_000002674E1CF11C
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1A12C0 GetUserNameW,0_2_000002674E1A12C0
              Source: C:\Users\user\Desktop\file.exeCode function: 0_2_000002674E1A27A0 GetTimeZoneInformation,0_2_000002674E1A27A0

              Stealing of Sensitive Information

              barindex
              Source: Yara matchFile source: Process Memory Space: file.exe PID: 3812, type: MEMORYSTR
              Source: Yara matchFile source: 0.2.file.exe.2674e120000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 0.2.file.exe.2674e120000.0.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 00000000.00000002.1323368752.000002674DF30000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: file.exe PID: 3812, type: MEMORYSTR
              Source: file.exe, 00000000.00000002.1323368752.000002674DF30000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Electrum\wallets
              Source: file.exe, 00000000.00000002.1323368752.000002674DF30000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: ElectronCash\wallets
              Source: file.exe, 00000000.00000002.1323368752.000002674DF30000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: com.liberty.jaxx\IndexedDB\file__0.indexeddb.leveldb
              Source: file.exe, 00000000.00000002.1323368752.000002674DF30000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Exodus\exodus.wallet
              Source: file.exe, 00000000.00000002.1323368752.000002674DF30000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Ethereum\keystore
              Source: file.exe, 00000000.00000002.1323368752.000002674DF30000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: Ethereum\keystore
              Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\monero-project\monero-coreJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\key4.dbJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data For AccountJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Network\CookiesJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web DataJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\MANIFEST-000001Jump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\cookies.sqliteJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\places.sqliteJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\HistoryJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.logJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\HistoryJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fu7wner3.default-release\prefs.jsJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\CURRENTJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOCKJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOG.oldJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\CookiesJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extension CookiesJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\LOGJump to behavior
              Source: C:\Users\user\Desktop\file.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login DataJump to behavior
              Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior

              Remote Access Functionality

              barindex
              Source: Yara matchFile source: Process Memory Space: file.exe PID: 3812, type: MEMORYSTR
              Source: Yara matchFile source: 0.2.file.exe.2674e120000.0.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 0.2.file.exe.2674e120000.0.raw.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: 00000000.00000002.1323368752.000002674DF30000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
              Source: Yara matchFile source: Process Memory Space: file.exe PID: 3812, type: MEMORYSTR
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
              Native API
              1
              DLL Side-Loading
              1
              Exploitation for Privilege Escalation
              1
              Access Token Manipulation
              1
              OS Credential Dumping
              12
              System Time Discovery
              Remote Services1
              Screen Capture
              21
              Encrypted Channel
              Exfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
              Access Token Manipulation
              1
              Deobfuscate/Decode Files or Information
              LSASS Memory21
              Security Software Discovery
              Remote Desktop Protocol1
              Email Collection
              1
              Non-Standard Port
              Exfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
              DLL Side-Loading
              2
              Obfuscated Files or Information
              Security Account Manager2
              Process Discovery
              SMB/Windows Admin Shares1
              Archive Collected Data
              2
              Ingress Tool Transfer
              Automated ExfiltrationData Encrypted for Impact
              Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
              DLL Side-Loading
              NTDS1
              Account Discovery
              Distributed Component Object Model2
              Data from Local System
              2
              Non-Application Layer Protocol
              Traffic DuplicationData Destruction
              Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA Secrets1
              System Owner/User Discovery
              SSHKeylogging3
              Application Layer Protocol
              Scheduled TransferData Encrypted for Impact
              Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC ScriptsSteganographyCached Domain Credentials1
              System Network Configuration Discovery
              VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
              DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup ItemsCompile After DeliveryDCSync3
              File and Directory Discovery
              Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
              Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/JobIndicator Removal from ToolsProc Filesystem24
              System Information Discovery
              Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement

              This section contains all screenshots as thumbnails, including those not shown in the slideshow.


              windows-stand
              SourceDetectionScannerLabelLink
              file.exe11%ReversingLabs
              No Antivirus matches
              No Antivirus matches
              No Antivirus matches
              SourceDetectionScannerLabelLink
              https://api.ipify.org/0%URL Reputationsafe
              https://api.ipify.org0%URL Reputationsafe
              http://crl.v0%URL Reputationsafe
              NameIPActiveMaliciousAntivirus DetectionReputation
              api.ipify.org
              104.26.13.205
              truefalse
                unknown
                NameMaliciousAntivirus DetectionReputation
                https://api.ipify.org/false
                • URL Reputation: safe
                unknown
                NameSourceMaliciousAntivirus DetectionReputation
                https://api.ipify.orgfile.exe, 00000000.00000002.1323368752.000002674DF30000.00000004.00000020.00020000.00000000.sdmpfalse
                • URL Reputation: safe
                unknown
                http://crl.vfile.exe, 00000000.00000002.1323248860.000002674C6DF000.00000004.00000020.00020000.00000000.sdmpfalse
                • URL Reputation: safe
                unknown
                https://api.ipify.org/=file.exe, 00000000.00000002.1323368752.000002674DF30000.00000004.00000020.00020000.00000000.sdmpfalse
                  unknown
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  109.172.94.66
                  unknownRussian Federation
                  41691SUMTEL-AS-RIPEMoscowRussiaRUtrue
                  104.26.13.205
                  api.ipify.orgUnited States
                  13335CLOUDFLARENETUSfalse
                  Joe Sandbox version:41.0.0 Charoite
                  Analysis ID:1546019
                  Start date and time:2024-10-31 11:33:14 +01:00
                  Joe Sandbox product:CloudBasic
                  Overall analysis duration:0h 4m 34s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:default.jbs
                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                  Number of analysed new started processes analysed:14
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • HCA enabled
                  • EGA enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Sample name:file.exe
                  Detection:MAL
                  Classification:mal92.troj.spyw.winEXE@1/0@1/2
                  EGA Information:
                  • Successful, ratio: 100%
                  HCA Information:
                  • Successful, ratio: 95%
                  • Number of executed functions: 68
                  • Number of non-executed functions: 123
                  Cookbook Comments:
                  • Found application associated with file extension: .exe
                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
                  • Excluded domains from analysis (whitelisted): otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, time.windows.com, fe3cr.delivery.mp.microsoft.com
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size exceeded maximum capacity and may have missing network information.
                  • Report size getting too big, too many NtOpenKeyEx calls found.
                  • Report size getting too big, too many NtQueryValueKey calls found.
                  • VT rate limit hit for: file.exe
                  No simulations
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  109.172.94.66file.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                    104.26.13.205file.exeGet hashmaliciousUnknownBrowse
                    • api.ipify.org/
                    file.exeGet hashmaliciousLummaC, PrivateLoader, Stealc, VidarBrowse
                    • api.ipify.org/
                    file.exeGet hashmaliciousLummaC, PrivateLoader, Stealc, VidarBrowse
                    • api.ipify.org/
                    file.exeGet hashmaliciousRDPWrap ToolBrowse
                    • api.ipify.org/
                    Prismifyr-Install.exeGet hashmaliciousNode StealerBrowse
                    • api.ipify.org/
                    file.exeGet hashmaliciousLummaC, PrivateLoader, Stealc, VidarBrowse
                    • api.ipify.org/
                    file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, VidarBrowse
                    • api.ipify.org/
                    file.exeGet hashmaliciousUnknownBrowse
                    • api.ipify.org/
                    file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, Stealc, VidarBrowse
                    • api.ipify.org/
                    file.exeGet hashmaliciousLummaC, RDPWrap Tool, LummaC Stealer, VidarBrowse
                    • api.ipify.org/
                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                    api.ipify.orgProforma Invoice.scr.exeGet hashmaliciousAgentTeslaBrowse
                    • 104.26.13.205
                    file.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                    • 104.26.12.205
                    #Uad6c#Ub9e4 #Uc8fc#Ubb38 658749 #Ubc0f 658752..exeGet hashmaliciousAgentTeslaBrowse
                    • 172.67.74.152
                    Quotation.exeGet hashmaliciousAgentTesla, GuLoaderBrowse
                    • 172.67.74.152
                    https://www.canva.com/design/DAGVD7_HMvQ/PFkDB3TDx6Ru4nNALhSqqQ/view?utm_content=DAGVD7_HMvQ&utm_campaign=designshare&utm_medium=link&utm_source=editorGet hashmaliciousUnknownBrowse
                    • 104.26.13.205
                    phish_alert_sp2_2.0.0.0.emlGet hashmaliciousHTMLPhisherBrowse
                    • 104.26.12.205
                    https://schiller.life/Get hashmaliciousHTMLPhisherBrowse
                    • 104.26.12.205
                    SecuriteInfo.com.Win32.PWSX-gen.31738.17793.exeGet hashmaliciousAgentTeslaBrowse
                    • 104.26.12.205
                    Biocon-In-Service Agreement.pdfGet hashmaliciousEvilProxy, HTMLPhisherBrowse
                    • 104.26.13.205
                    skuld3.exeGet hashmaliciousSkuld StealerBrowse
                    • 104.26.13.205
                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                    CLOUDFLARENETUSfile.exeGet hashmaliciousLummaCBrowse
                    • 188.114.96.3
                    https://flaviarc.com/vrecord%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20/Get hashmaliciousHTMLPhisherBrowse
                    • 104.18.3.157
                    Eprdtdrqbr.exeGet hashmaliciousSnake KeyloggerBrowse
                    • 188.114.96.3
                    N#U00b0 DE PEDIDO DE ABARROTES DE NOVIEMBRE 2024.exeGet hashmaliciousSnake KeyloggerBrowse
                    • 188.114.96.3
                    HT9324-25 1x40HC LDHFCLDEHAM29656 MRSU5087674.exeGet hashmaliciousFormBookBrowse
                    • 172.67.177.220
                    Proforma Invoice.scr.exeGet hashmaliciousAgentTeslaBrowse
                    • 104.26.13.205
                    24602711 Inv_Or.exeGet hashmaliciousPureLog Stealer, Snake KeyloggerBrowse
                    • 188.114.96.3
                    http://www.thearchiterra.gr/Get hashmaliciousUnknownBrowse
                    • 104.17.25.14
                    MP2318GJ-P 18000pcs.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                    • 188.114.97.3
                    hesaphareketi-01.exeGet hashmaliciousMassLogger RATBrowse
                    • 188.114.96.3
                    SUMTEL-AS-RIPEMoscowRussiaRUfile.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                    • 109.172.94.66
                    sh4.elfGet hashmaliciousUnknownBrowse
                    • 87.117.138.145
                    yakuza.i686.elfGet hashmaliciousUnknownBrowse
                    • 178.130.55.72
                    la.bot.arm5.elfGet hashmaliciousUnknownBrowse
                    • 109.172.60.44
                    BwqqVoHR71.exeGet hashmaliciousGO BackdoorBrowse
                    • 109.172.88.38
                    antispam_connect1.exeGet hashmaliciousGO BackdoorBrowse
                    • 109.172.88.38
                    na.elfGet hashmaliciousMirai, MoobotBrowse
                    • 89.221.206.246
                    wa_3rd_party_host_32.exeGet hashmaliciousGO BackdoorBrowse
                    • 109.172.88.38
                    uyTCVR3mBl.elfGet hashmaliciousUnknownBrowse
                    • 89.221.225.163
                    mtTw7o41OC.exeGet hashmaliciousFormBook, PureLog StealerBrowse
                    • 109.172.114.38
                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                    37f463bf4616ecd445d4a1937da06e19Contrato.exeGet hashmaliciousDarkCloudBrowse
                    • 104.26.13.205
                    file.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                    • 104.26.13.205
                    Quotation.exeGet hashmaliciousAgentTesla, GuLoaderBrowse
                    • 104.26.13.205
                    SecuriteInfo.com.BackDoor.AgentTeslaNET.20.28177.5145.exeGet hashmaliciousDarkCloudBrowse
                    • 104.26.13.205
                    nOrden_de_Compra___0001245.vbsGet hashmaliciousRemcos, GuLoaderBrowse
                    • 104.26.13.205
                    Ky4J8k89A7.exeGet hashmaliciousStealc, Vidar, XmrigBrowse
                    • 104.26.13.205
                    b4s45TboUL.exeGet hashmaliciousStealc, VidarBrowse
                    • 104.26.13.205
                    rCommercialoffer_Technicaloffer_pdf.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                    • 104.26.13.205
                    Justificante de pago.exeGet hashmaliciousFormBook, GuLoaderBrowse
                    • 104.26.13.205
                    rPO-000172483.exeGet hashmaliciousFormBook, GuLoaderBrowse
                    • 104.26.13.205
                    No context
                    No created / dropped files found
                    File type:PE32+ executable (GUI) x86-64, for MS Windows
                    Entropy (8bit):3.8333396760309246
                    TrID:
                    • Win64 Executable GUI (202006/5) 92.65%
                    • Win64 Executable (generic) (12005/4) 5.51%
                    • Generic Win/DOS Executable (2004/3) 0.92%
                    • DOS Executable Generic (2002/1) 0.92%
                    • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                    File name:file.exe
                    File size:2'640'384 bytes
                    MD5:ab7d13fd2200b07c2bc9fe3b3f7cc837
                    SHA1:22943e1fbf9c32a3bb716a002de1a8e598bbf169
                    SHA256:17b7ba466ce248a1f9a337d4e6a7ab092a6bb2608246c08a348b525c8e3a9311
                    SHA512:b0927525d1a4001eff195632511b63094d69511d57456e6be8c201c9d67383a41e9aae775c352e25ff62d41ab8a7e65ac329f83ec70ba74fc6183005aa9ab1eb
                    SSDEEP:24576:yCzGVH7Och0lhSMXlkixcVptzXRYPWVvg3VWprEuOAQm9os:yMGVbo0ixYpBBSlW6lo
                    TLSH:7BC50149B7A144F9F5278274C8A60A89D73338150B919BDF07BCC6A52F277D0AE39F81
                    File Content Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......T`b..............S..........................G...[y......[y......[y......(.......X...4...[y..............[.......[.......[......
                    Icon Hash:00928e8e8686b000
                    Entrypoint:0x14002e630
                    Entrypoint Section:.text
                    Digitally signed:false
                    Imagebase:0x140000000
                    Subsystem:windows gui
                    Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
                    DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                    Time Stamp:0x6720F953 [Tue Oct 29 15:03:47 2024 UTC]
                    TLS Callbacks:
                    CLR (.Net) Version:
                    OS Version Major:6
                    OS Version Minor:0
                    File Version Major:6
                    File Version Minor:0
                    Subsystem Version Major:6
                    Subsystem Version Minor:0
                    Import Hash:cdd1173aeabddc45e0cd98174340d979
                    Instruction
                    dec eax
                    sub esp, 28h
                    call 00007F5CD4BFBA2Ch
                    dec eax
                    add esp, 28h
                    jmp 00007F5CD4BFAE9Fh
                    int3
                    int3
                    dec eax
                    sub esp, 28h
                    dec ebp
                    mov eax, dword ptr [ecx+38h]
                    dec eax
                    mov ecx, edx
                    dec ecx
                    mov edx, ecx
                    call 00007F5CD4BFB032h
                    mov eax, 00000001h
                    dec eax
                    add esp, 28h
                    ret
                    int3
                    int3
                    int3
                    inc eax
                    push ebx
                    inc ebp
                    mov ebx, dword ptr [eax]
                    dec eax
                    mov ebx, edx
                    inc ecx
                    and ebx, FFFFFFF8h
                    dec esp
                    mov ecx, ecx
                    inc ecx
                    test byte ptr [eax], 00000004h
                    dec esp
                    mov edx, ecx
                    je 00007F5CD4BFB035h
                    inc ecx
                    mov eax, dword ptr [eax+08h]
                    dec ebp
                    arpl word ptr [eax+04h], dx
                    neg eax
                    dec esp
                    add edx, ecx
                    dec eax
                    arpl ax, cx
                    dec esp
                    and edx, ecx
                    dec ecx
                    arpl bx, ax
                    dec edx
                    mov edx, dword ptr [eax+edx]
                    dec eax
                    mov eax, dword ptr [ebx+10h]
                    mov ecx, dword ptr [eax+08h]
                    dec eax
                    mov eax, dword ptr [ebx+08h]
                    test byte ptr [ecx+eax+03h], 0000000Fh
                    je 00007F5CD4BFB02Dh
                    movzx eax, byte ptr [ecx+eax+03h]
                    and eax, FFFFFFF0h
                    dec esp
                    add ecx, eax
                    dec esp
                    xor ecx, edx
                    dec ecx
                    mov ecx, ecx
                    pop ebx
                    jmp 00007F5CD4BFAA66h
                    int3
                    inc eax
                    push ebx
                    dec eax
                    sub esp, 20h
                    dec eax
                    mov ebx, ecx
                    xor ecx, ecx
                    call dword ptr [0000BA2Fh]
                    dec eax
                    mov ecx, ebx
                    call dword ptr [0000BA1Eh]
                    call dword ptr [0000B990h]
                    dec eax
                    mov ecx, eax
                    mov edx, C0000409h
                    dec eax
                    add esp, 20h
                    pop ebx
                    dec eax
                    jmp dword ptr [0000BA14h]
                    dec eax
                    mov dword ptr [esp+00h], ecx
                    Programming Language:
                    • [IMP] VS2008 build 21022
                    NameVirtual AddressVirtual Size Is in Section
                    IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                    IMAGE_DIRECTORY_ENTRY_IMPORT0x280a540x8c.rdata
                    IMAGE_DIRECTORY_ENTRY_RESOURCE0x2880000x1e0.rsrc
                    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x2850000x2d60.pdata
                    IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                    IMAGE_DIRECTORY_ENTRY_BASERELOC0x2890000x94c.reloc
                    IMAGE_DIRECTORY_ENTRY_DEBUG0x27b7700x38.rdata
                    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                    IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x27b6300x140.rdata
                    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                    IMAGE_DIRECTORY_ENTRY_IAT0x3a0000x380.rdata
                    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                    NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                    .text0x10000x380940x3820065d4d1be0a6460869c5daa444f92d6dbFalse0.5292011762249443data6.552788904475446IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                    .rdata0x3a0000x2475fa0x247600861bbf3cac86f1e435d75059f1187ac3unknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                    .data0x2820000x28fc0x14005bf55c038fe49f9015242be39b0a96b3False0.1732421875data2.7583982019216005IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                    .pdata0x2850000x2d600x2e00c1e2097dc4b053bedb9c6a0caf752774False0.47834578804347827data5.561374968025357IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                    .rsrc0x2880000x1e00x2007b8b3bec2298c35473239c5eb059fcf0False0.52734375data4.7122981932940915IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                    .reloc0x2890000x94c0xa00353bd694c00da43465a9149102e7e2b9False0.488671875data5.259760371222032IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                    NameRVASizeTypeLanguageCountryZLIB Complexity
                    RT_MANIFEST0x2880600x17dXML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.5931758530183727
                    DLLImport
                    ntdll.dllRtlImageDirectoryEntryToData, RtlLeaveCriticalSection, RtlEnterCriticalSection, RtlCompareMemory, NtProtectVirtualMemory, RtlImageNtHeader, NtQueryVirtualMemory, RtlGetNtVersionNumbers
                    KERNEL32.dllLocalFree, FreeEnvironmentStringsW, GetEnvironmentStringsW, VirtualFree, VirtualAlloc, GetModuleHandleW, LoadLibraryA, WriteFile, CreateFileW, CloseHandle, GetProcAddress, GetCurrentProcess, FlushInstructionCache, VirtualQuery, WriteProcessMemory, EnterCriticalSection, GetModuleFileNameW, LeaveCriticalSection, GetModuleHandleA, MultiByteToWideChar, ExitProcess, WideCharToMultiByte, GetLastError, SetLastError, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, IsDebuggerPresent, UnhandledExceptionFilter, SetUnhandledExceptionFilter, TerminateProcess, IsProcessorFeaturePresent, GetCommandLineA, GetCommandLineW, HeapAlloc, HeapFree, GetCurrentThreadId, DeleteCriticalSection, GetStdHandle, GetStartupInfoW, RaiseException, HeapReAlloc, HeapSize, GetProcessHeap, FlsAlloc, FlsGetValue, FlsSetValue, FlsFree, InitializeCriticalSectionAndSpinCount, GetSystemTimeAsFileTime, FreeLibrary, LoadLibraryExW, LCMapStringW, GetLocaleInfoW, IsValidLocale, GetUserDefaultLCID, EnumSystemLocalesW, IsValidCodePage, GetACP, GetOEMCP, GetCPInfo, GetStringTypeW, GetModuleHandleExW, SetFilePointerEx, SetStdHandle, FlushFileBuffers, GetConsoleOutputCP, GetConsoleMode, WriteConsoleW, QueryPerformanceCounter, GetCurrentProcessId, InitializeSListHead, RtlUnwindEx, RtlPcToFileHeader, EncodePointer, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, DecodePointer, FindNextFileW, FindFirstFileExW, FindClose, GetFileType, InitializeCriticalSectionEx
                    USER32.dllLoadAcceleratorsW, LoadAcceleratorsA
                    ADVAPI32.dllOpenProcessToken, GetTokenInformation
                    OLEAUT32.dllSafeArrayAccessData, SafeArrayCreateVector, SafeArrayCreate, SafeArrayUnaccessData, SafeArrayPutElement, SysFreeString, SafeArrayDestroy, SysAllocString
                    mscoree.dllCLRCreateInstance
                    Language of compilation systemCountry where language is spokenMap
                    EnglishUnited States
                    TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                    2024-10-31T11:34:15.039636+01002049441ET MALWARE Win32/Unknown Grabber Base64 Data Exfiltration Attempt1192.168.2.749699109.172.94.6615666TCP
                    2024-10-31T11:34:15.039636+01002050806ET MALWARE [ANY.RUN] Meduza Stealer Exfiltration M21192.168.2.749699109.172.94.6615666TCP
                    2024-10-31T11:34:15.039636+01002050807ET MALWARE [ANY.RUN] Possible Meduza Stealer Exfiltration (TCP)1192.168.2.749699109.172.94.6615666TCP
                    2024-10-31T11:34:15.045286+01002050806ET MALWARE [ANY.RUN] Meduza Stealer Exfiltration M21192.168.2.749699109.172.94.6615666TCP
                    2024-10-31T11:34:15.045286+01002050807ET MALWARE [ANY.RUN] Possible Meduza Stealer Exfiltration (TCP)1192.168.2.749699109.172.94.6615666TCP
                    2024-10-31T11:34:30.219355+01002022930ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow152.149.20.212443192.168.2.749733TCP
                    2024-10-31T11:35:10.399790+01002022930ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow152.149.20.212443192.168.2.754363TCP
                    TimestampSource PortDest PortSource IPDest IP
                    Oct 31, 2024 11:34:11.847124100 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:11.852081060 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:11.852209091 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:12.410936117 CET49700443192.168.2.7104.26.13.205
                    Oct 31, 2024 11:34:12.410979986 CET44349700104.26.13.205192.168.2.7
                    Oct 31, 2024 11:34:12.411071062 CET49700443192.168.2.7104.26.13.205
                    Oct 31, 2024 11:34:12.413826942 CET49700443192.168.2.7104.26.13.205
                    Oct 31, 2024 11:34:12.413841009 CET44349700104.26.13.205192.168.2.7
                    Oct 31, 2024 11:34:13.033571005 CET44349700104.26.13.205192.168.2.7
                    Oct 31, 2024 11:34:13.033679962 CET49700443192.168.2.7104.26.13.205
                    Oct 31, 2024 11:34:13.159813881 CET49700443192.168.2.7104.26.13.205
                    Oct 31, 2024 11:34:13.159843922 CET44349700104.26.13.205192.168.2.7
                    Oct 31, 2024 11:34:13.160382032 CET44349700104.26.13.205192.168.2.7
                    Oct 31, 2024 11:34:13.160444975 CET49700443192.168.2.7104.26.13.205
                    Oct 31, 2024 11:34:13.165626049 CET49700443192.168.2.7104.26.13.205
                    Oct 31, 2024 11:34:13.211329937 CET44349700104.26.13.205192.168.2.7
                    Oct 31, 2024 11:34:13.340480089 CET44349700104.26.13.205192.168.2.7
                    Oct 31, 2024 11:34:13.340588093 CET49700443192.168.2.7104.26.13.205
                    Oct 31, 2024 11:34:13.340614080 CET44349700104.26.13.205192.168.2.7
                    Oct 31, 2024 11:34:13.340631962 CET44349700104.26.13.205192.168.2.7
                    Oct 31, 2024 11:34:13.340672016 CET49700443192.168.2.7104.26.13.205
                    Oct 31, 2024 11:34:13.340696096 CET49700443192.168.2.7104.26.13.205
                    Oct 31, 2024 11:34:13.585604906 CET49700443192.168.2.7104.26.13.205
                    Oct 31, 2024 11:34:13.585627079 CET44349700104.26.13.205192.168.2.7
                    Oct 31, 2024 11:34:15.039635897 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.045193911 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.045209885 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.045219898 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.045224905 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.045285940 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.045295000 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.045305967 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.045315981 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.045320988 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.045351028 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.045377970 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.050432920 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.050519943 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.050582886 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.050594091 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.050602913 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.050637960 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.050666094 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.050687075 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.050698042 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.050707102 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.050715923 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.050738096 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.050767899 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.050832033 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.050843000 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.050889015 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.050982952 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.050992012 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.051001072 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.051059008 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.055949926 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.056071043 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.056096077 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.056104898 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.056163073 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.056230068 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.056238890 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.056291103 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.056365967 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.056375980 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.056427956 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.056530952 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.056541920 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.056550980 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.056588888 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.056611061 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.061399937 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.061466932 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.061546087 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.061599016 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.061691999 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.061744928 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.061821938 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.061830997 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.061841965 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.061851025 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.061877012 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.061897039 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.061938047 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.061948061 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.061956882 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.061965942 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.061990023 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.062016964 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.062115908 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.062130928 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.062140942 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.062150002 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.062160015 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.062166929 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.062169075 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.062184095 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.062203884 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.062227011 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.062319040 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.062329054 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.062336922 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.062345028 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.062370062 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.062390089 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.066937923 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.066947937 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067023993 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.067063093 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067073107 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067111015 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.067131042 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.067220926 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067230940 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067239046 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067248106 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067276955 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.067296982 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.067359924 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067368984 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067416906 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.067466021 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067475080 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067483902 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067492962 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067501068 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067509890 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067517996 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.067538977 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.067549944 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.067584991 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067595005 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067599058 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067601919 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067646980 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.067671061 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.067722082 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067732096 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067739964 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067749023 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067759991 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067784071 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.067802906 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.067853928 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067862988 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067872047 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.067904949 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.067920923 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.068003893 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.068012953 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.068064928 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.072335005 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.072391033 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.072470903 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.072480917 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.072525978 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.072611094 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.072621107 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.072628975 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.072670937 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.072738886 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.072747946 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.072756052 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.072765112 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.072773933 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.072794914 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.072815895 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.072829008 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.072877884 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.072887897 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.072932959 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.073043108 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.073051929 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.073060989 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.073101997 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.073111057 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.073122025 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.073129892 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.073138952 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.073148012 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.073165894 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.073168993 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.073175907 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.073185921 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.073194981 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.073195934 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.073205948 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.073220015 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.073223114 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.073239088 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.073251963 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.073260069 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.073268890 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.073278904 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.073288918 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.073298931 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.073303938 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.073307991 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.073313951 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.073318005 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.073327065 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.073345900 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.073378086 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.077815056 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.077867031 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.077949047 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.077959061 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.077966928 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.077975035 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.078008890 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.078033924 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.078084946 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.078150988 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.078224897 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.078236103 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.078244925 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.078254938 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.078263044 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.078269958 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.078289032 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.078311920 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.078342915 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.078363895 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.078372955 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.078385115 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.078421116 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.078690052 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.078700066 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.078747034 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.078788042 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.078798056 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.078805923 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.078814983 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.078840017 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.078850985 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.078917027 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.078927040 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.078936100 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.078943968 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.078970909 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.078991890 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.079050064 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.079060078 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.079070091 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.079106092 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.079168081 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.079179049 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.079186916 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.079195023 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.079204082 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.079212904 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.079226017 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.079253912 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.079289913 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.079301119 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.079308987 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.079328060 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.079344988 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.079365015 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.079473019 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.079483032 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.079540968 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.083421946 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.083466053 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.083479881 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.083481073 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.083493948 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.083506107 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.083518982 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.083559036 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.083590031 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.083604097 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.083646059 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.083708048 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.083720922 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.083733082 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.083745956 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.083766937 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.083781958 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.083791971 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.083848953 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.083862066 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.083905935 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.083937883 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.084063053 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.084084034 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.084096909 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.084124088 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.084142923 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.084147930 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.084157944 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.084171057 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.084208965 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.084290028 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.084305048 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.084316969 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.084358931 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.084384918 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.084424019 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.084438086 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.084469080 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.084484100 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.084578991 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.084593058 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.084604025 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.084615946 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.084640026 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.084667921 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.084702015 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.084714890 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.084727049 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.084752083 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.084774017 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.084819078 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.084830999 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.084845066 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.084856033 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.084856987 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.084891081 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.084907055 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.084971905 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.084985971 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.084997892 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.085010052 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.085017920 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.085024118 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.085026979 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.085052013 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.085071087 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.085093021 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.085105896 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.085118055 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.085134983 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.085144043 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.085163116 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.085248947 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.085309982 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.088964939 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.089024067 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.089095116 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.089109898 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.089122057 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.089169979 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.089210987 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.089224100 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.089236021 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.089246988 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.089266062 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.089278936 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.089315891 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.089349031 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.089363098 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.089375973 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.089387894 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.089405060 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.089421988 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.089452982 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.089476109 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.089489937 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.089512110 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.089536905 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.089554071 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.089632988 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.089646101 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.089679956 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.089698076 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.089777946 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.089790106 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.089802980 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.089816093 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.089831114 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.089850903 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.089864016 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.089874983 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.089886904 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.089900017 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.089911938 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.089915037 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.089929104 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.089953899 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.090023994 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.090039015 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.090070009 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.090081930 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.090096951 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.090217113 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.090245008 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.090255976 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.090269089 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.090280056 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.090296984 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.090312004 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.090363979 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.090377092 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.090388060 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.090399981 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.090416908 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.090425968 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.090455055 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.090466976 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.090480089 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.090491056 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.090502977 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.090517044 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.090548992 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.090575933 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.090598106 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.090611935 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.090624094 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.090635061 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.090636015 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.090648890 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.090652943 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.090662003 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.090679884 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.090714931 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.090898037 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.090948105 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.094685078 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.094739914 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.094811916 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.094830036 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.094841957 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.094875097 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.094892979 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.094928980 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.094942093 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.094954967 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.094966888 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.094986916 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.095001936 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.095076084 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095088959 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095102072 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095122099 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.095133066 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.095215082 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095262051 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.095346928 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095360994 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095371962 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095385075 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095396042 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095407963 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095408916 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.095422029 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.095429897 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.095432997 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095447063 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095451117 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.095458984 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095469952 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095474005 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.095484018 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095485926 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.095496893 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095504045 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.095520020 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.095531940 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.095541954 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095555067 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095566034 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095581055 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095594883 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095602036 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.095607996 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095613956 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.095622063 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.095660925 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.095679045 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095691919 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095702887 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095730066 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.095740080 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.095822096 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095834017 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095844984 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095856905 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095879078 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.095894098 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.095982075 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.095993996 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.096021891 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.096034050 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.096091986 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.096112967 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.096126080 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.096133947 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.096137047 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.096149921 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.096160889 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.096189976 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.096239090 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.096251965 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.096287012 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.096362114 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.096374989 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.096385956 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.096400976 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.096410990 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.096415043 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.096425056 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.096427917 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.096462011 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.096478939 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.096510887 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.096553087 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.100395918 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.100414991 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.100478888 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.100492001 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.100502968 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.100514889 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.100589037 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.100601912 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.100613117 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.100625038 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.100728035 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.100740910 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.100754023 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.100852013 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101012945 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101025105 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101036072 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101047993 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101125002 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101138115 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101150036 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101161003 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101172924 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101267099 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101279020 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101289988 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101442099 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101454020 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101465940 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101526022 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101537943 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101548910 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101561069 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101574898 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101586103 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101629972 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101641893 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101651907 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101664066 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101675987 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101691008 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101742029 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101753950 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101768017 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101779938 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101792097 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101804018 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101869106 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101881981 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101892948 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101905107 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101917028 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101928949 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.101999044 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.102010965 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.102020979 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.102031946 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.102154016 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.105685949 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.105783939 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.107641935 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.110042095 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.111006021 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111022949 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111047029 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111058950 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111063957 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.111083031 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111095905 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111100912 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.111129045 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.111136913 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111171961 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111176014 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.111211061 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.111294031 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111341953 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111387014 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.111443043 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111475945 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111521006 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.111577988 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111591101 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111624002 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111625910 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.111641884 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111654043 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111666918 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111679077 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.111706018 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.111715078 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.111771107 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111783981 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111805916 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111818075 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111824036 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.111840010 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.111860037 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111864090 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.111874104 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111901999 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.111903906 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111916065 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.111927032 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.111946106 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.111962080 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.111998081 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.112010956 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.112046003 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.112046957 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.112061024 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.112104893 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.112395048 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.112407923 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.112445116 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.112792969 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.114007950 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.155837059 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.155991077 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.156079054 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.156096935 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.164391994 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.164625883 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.164722919 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.164752960 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.169691086 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.169709921 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.169742107 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.169758081 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.169770002 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.169780970 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.169785976 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.169794083 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.169816017 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.169820070 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.169828892 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.169842005 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.169846058 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.169873953 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.176300049 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.176587105 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.176659107 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.176675081 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.181595087 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.181615114 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.181638956 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.181652069 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.181654930 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.181665897 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.181673050 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.181674004 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.181688070 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.181701899 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.181703091 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.181711912 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.181730986 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.181754112 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.181767941 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.181780100 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.181802988 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.181802988 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.181818008 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.181819916 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.181843042 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.181862116 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.181870937 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.181884050 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.181915998 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.181922913 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.181930065 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.181961060 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.181965113 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.181974888 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182008028 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182010889 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.182022095 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182053089 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182061911 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.182097912 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.182100058 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182147026 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.182152987 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182164907 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182204962 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.182284117 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182296991 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182320118 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182332993 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182334900 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.182364941 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.182373047 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.182383060 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182395935 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182441950 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.182449102 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182461977 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182488918 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182497025 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.182512045 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182534933 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.182538986 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182552099 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182554007 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.182579041 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.182585001 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182585955 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.182627916 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.182652950 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182665110 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182676077 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182697058 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182704926 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.182708979 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182749033 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182749987 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.182761908 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182790995 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182796955 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.182805061 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182837963 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.182857990 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182871103 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182893991 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182905912 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182917118 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.182940006 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182945967 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.182952881 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182985067 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.182987928 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.183001041 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.183024883 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.183033943 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.183069944 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.183079004 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.183092117 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.183125019 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.183151960 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.183163881 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.183175087 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.183195114 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.183196068 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.183208942 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.183212042 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.183237076 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.183238983 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.183248997 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.183279037 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.183290958 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.183341980 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.183388948 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.186511993 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.186562061 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.186687946 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.186702967 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.186727047 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.186737061 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.186742067 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.186747074 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.186757088 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.186768055 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.186774969 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.186783075 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.186795950 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.186808109 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.186820030 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.186832905 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.186878920 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.186886072 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.186903000 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.186923027 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.186935902 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.186942101 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.186965942 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.186969042 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.186975002 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.186983109 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187004089 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187024117 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187026978 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187046051 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187077999 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187082052 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187089920 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187123060 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187130928 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187144041 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187158108 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187174082 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187181950 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187202930 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187242985 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187256098 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187267065 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187284946 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187289953 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187298059 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187309027 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187320948 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187329054 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187376022 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187388897 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187423944 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187432051 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187437057 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187470913 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187474966 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187488079 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187515974 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187517881 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187525034 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187529087 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187556028 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187566042 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187592983 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187606096 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187618971 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187630892 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187639952 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187658072 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187674046 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187680960 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187688112 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187711000 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187735081 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187747955 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187752008 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187788010 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187798977 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187810898 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187824965 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187835932 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187849998 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187874079 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187874079 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187886953 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187922001 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187922955 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187937021 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187964916 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187973022 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.187978983 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.187993050 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.188040972 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.188047886 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.188060045 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.188088894 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.188100100 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.188110113 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.188133001 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.188138008 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.188160896 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.188170910 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.188173056 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.188196898 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.188208103 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.188215971 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.188227892 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.188247919 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.188265085 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.188285112 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.188302994 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.188344955 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.188360929 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.188374043 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.188409090 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.188414097 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.188427925 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.188452959 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.188463926 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.188545942 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.188559055 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.188596964 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.191517115 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.191555023 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.191571951 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.191592932 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.191601992 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.191637039 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.191679001 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.191699028 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.191719055 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.191726923 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.191768885 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.191855907 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.191869020 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.191879034 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.191893101 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.191905975 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.191921949 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.191941977 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.191960096 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.191972971 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.191992998 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.192017078 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.192028999 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.192033052 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.192044973 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.192065954 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.192082882 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.192095041 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.192106962 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.192116022 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.192132950 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.192142963 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.192184925 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.192198992 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.192212105 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.192233086 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.192234993 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.192265034 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.192271948 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.192284107 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.192296028 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.192332983 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.192367077 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.192379951 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.192415953 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.192452908 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.192466021 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.192480087 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.192502022 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.192507982 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.192524910 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.192547083 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.192553997 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.192562103 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.192590952 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.192598104 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.192610979 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.192624092 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.192663908 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.192667007 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.192679882 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.192717075 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.235836029 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.236013889 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.236093044 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.236126900 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.283813000 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.283997059 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.284075975 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.284097910 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.320897102 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.321068048 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.321141958 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.321167946 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.326220989 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.326291084 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.367875099 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.368115902 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.368210077 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.368236065 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.414114952 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.414279938 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.414360046 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.414378881 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.419346094 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.419365883 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.419390917 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.419404030 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.419414997 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.419418097 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.419428110 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.419437885 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.419452906 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.419465065 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.419490099 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.419512033 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.459896088 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.460055113 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.460134029 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.460160971 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.498370886 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.498523951 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.498598099 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.498620987 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.503473997 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503492117 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503514051 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503525019 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503535986 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503547907 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503571033 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503577948 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.503582001 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503593922 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503614902 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503622055 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.503628969 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503648996 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503659964 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503674030 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.503690958 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.503703117 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503715038 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503725052 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503737926 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503747940 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503767967 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.503781080 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503792048 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503810883 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503820896 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503829956 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.503845930 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503866911 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.503880024 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.503880978 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503937006 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503947973 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503961086 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.503978014 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.503989935 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.504002094 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.504010916 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.504024029 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.504030943 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.504055977 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.504065990 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.504070044 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.504077911 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.504090071 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.504106045 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.504142046 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.504189968 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.504203081 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.504214048 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.504225969 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.504236937 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.504256964 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.504262924 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.504273891 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.504282951 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.504323006 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.504339933 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.504350901 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.504369020 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.504407883 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.504427910 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.547811985 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.547985077 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.548058033 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.548090935 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.575341940 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.575504065 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.575576067 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.575609922 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.580507994 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.580543995 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.580590963 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.580593109 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.580606937 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.580630064 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.580641985 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.580650091 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.580677986 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.580683947 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.580696106 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.580698013 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.580719948 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.580733061 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.580737114 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.580765963 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.580769062 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.580784082 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.580806017 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.580816984 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.580820084 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.580836058 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.580852032 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.580858946 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.580887079 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.580903053 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.580909967 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.580941916 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.580951929 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.580971956 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.580988884 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.580998898 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581022024 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.581062078 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.581072092 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581084013 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581129074 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.581139088 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581161022 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581182957 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.581257105 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.581279039 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581293106 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581307888 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581337929 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.581379890 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.581394911 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581408024 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581418991 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581439972 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581439972 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.581454039 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581482887 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.581527948 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581538916 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.581543922 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581588030 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.581598043 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581612110 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581648111 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581655025 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.581711054 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.581743956 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581757069 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581768990 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581783056 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581794977 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581801891 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.581844091 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.581845999 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581921101 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581933022 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581954956 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581964016 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.581970930 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581984997 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.581985950 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.581998110 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.582004070 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.582009077 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582046032 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.582093954 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582106113 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582118034 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582145929 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.582175016 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582217932 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582247019 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582252979 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.582293987 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.582335949 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582349062 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582359076 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582392931 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.582415104 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582427979 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582444906 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.582458019 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582465887 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.582499981 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.582531929 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582545042 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582556963 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582572937 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582581997 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.582586050 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582602978 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.582623005 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582629919 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.582688093 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582700968 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582712889 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582715988 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.582731962 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.582767010 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.582792044 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582876921 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582890034 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582895994 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.582926989 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.582932949 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582945108 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.582982063 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.583010912 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.583024025 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.583034992 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.583049059 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.583060980 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.583076954 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.583106041 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.583159924 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.583173037 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.583184004 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.583206892 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.583226919 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.623859882 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.624015093 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.624085903 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.624121904 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.653225899 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.653417110 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.653489113 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.653518915 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.658453941 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.658495903 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.658515930 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.658519983 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.658535004 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.658549070 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.658549070 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.658575058 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.658592939 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.658595085 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.658618927 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.658631086 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.658663034 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.658683062 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.658688068 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.658713102 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.658742905 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.658761978 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.658773899 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.658811092 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.658819914 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.658890009 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.658936024 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.658977985 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.658992052 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659004927 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659025908 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.659048080 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.659065008 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659128904 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659142017 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659156084 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659168005 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659178019 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.659212112 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.659223080 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.659250975 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659265041 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659322023 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.659332037 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659384966 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.659390926 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659404993 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659425974 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659446955 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659451008 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.659460068 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659466028 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.659476042 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659507036 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.659554958 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.659559965 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659575939 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659590006 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659598112 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.659615993 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.659621000 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659636021 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659636021 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.659648895 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659698009 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.659748077 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659761906 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659792900 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659797907 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.659837008 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.659851074 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659866095 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659888029 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659904003 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.659929037 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659938097 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.659944057 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659972906 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.659980059 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.659987926 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.660021067 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.660024881 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660038948 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660053968 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660079956 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.660093069 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.660103083 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660115957 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660161972 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.660233974 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660307884 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660321951 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660336018 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660356045 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.660381079 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.660382032 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660396099 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660425901 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660429955 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.660479069 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.660485029 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660499096 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660510063 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660533905 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.660554886 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.660582066 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660594940 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660620928 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660630941 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.660672903 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.660703897 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660717964 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660728931 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660749912 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660763979 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.660763979 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660806894 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660809040 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.660820007 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.660866976 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660868883 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.660881996 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660896063 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660918951 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.660934925 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.660949945 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660963058 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.660995007 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.661010027 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.661036968 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.661039114 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.661053896 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.661091089 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.661125898 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.661144972 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.661156893 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.661199093 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.661222935 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.661237001 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.661250114 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.661262989 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.661278009 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.661292076 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.661303043 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.661305904 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.661319971 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.661335945 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.661361933 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.661374092 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.663501978 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.663551092 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.663562059 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.663602114 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.663604021 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.663636923 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.663642883 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.663691998 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.663749933 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.663759947 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.663803101 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.663815975 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.663845062 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.663849115 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.663860083 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.663899899 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.664000988 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.664084911 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.664127111 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.664128065 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.664150953 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.664206982 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.664330959 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.664341927 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.664387941 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.664390087 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.664427042 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.664436102 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.664462090 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.664474964 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.664503098 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.664520979 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.664549112 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.664599895 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.664664030 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.664701939 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.664753914 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.664787054 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.664838076 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.664841890 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.664891958 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.664978981 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.664999008 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.665028095 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.665051937 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.665184021 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.665237904 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.665313959 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.665359974 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.665385962 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.665430069 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.665452957 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.665507078 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.665538073 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.665577888 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.665586948 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.665616989 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.665631056 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.665661097 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.665831089 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.665869951 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.665873051 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.665918112 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.665927887 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.666003942 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.666006088 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.666052103 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.666141987 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.666162968 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.666189909 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.666204929 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.666210890 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.666224957 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.666270018 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.666323900 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.666376114 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.666444063 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.666455984 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.666500092 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.668391943 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.668447018 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.668457031 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.668499947 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.668595076 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.668608904 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.668653011 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.668664932 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.668704033 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.668719053 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.668749094 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.668752909 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.668761969 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.668808937 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.668821096 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.668869019 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.668925047 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.668939114 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.668967962 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.668983936 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.669019938 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.669075012 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.669099092 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.669128895 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.669174910 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.669241905 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.669290066 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.669295073 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.669332981 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.669339895 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.669378042 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.669390917 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.669418097 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.669435024 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.669481993 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.669595003 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.669656038 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.669722080 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.669744015 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.669816017 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.669845104 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.669913054 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.669939995 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.669951916 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.669961929 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.669974089 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.670018911 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.670063972 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.670115948 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.670161009 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.670264006 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.670286894 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.670301914 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.670334101 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.670351982 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.670378923 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.670417070 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.670420885 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.670428991 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.670470953 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.670511007 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.670552969 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.670557022 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.670598030 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.670676947 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.670722961 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.670850992 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.670896053 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.670912027 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.670922041 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.670970917 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.671009064 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.671061039 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.671066046 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.671114922 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.671142101 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.671150923 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.671189070 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.671257019 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.671303988 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.671375036 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.671392918 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.671401024 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.671422005 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.671449900 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.673281908 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.673352003 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.673365116 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.673403025 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.673511028 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.673525095 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.673577070 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.673629045 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.673644066 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.673682928 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.673718929 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.673738003 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.673748970 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.673768997 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.673794985 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.673804045 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.673847914 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.673861027 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.673918962 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.673970938 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.673988104 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.674031973 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.674045086 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.674067020 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.674072981 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.674118996 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.674170017 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.674185038 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.674220085 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.674243927 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.674288988 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.674355984 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.674462080 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.674465895 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.674489975 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.674513102 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.674537897 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.674555063 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.674576044 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.674602985 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.674622059 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.674665928 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.674710035 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.674724102 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.674748898 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.674834967 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.674879074 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.675148010 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.675210953 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.675219059 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.675270081 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.675333977 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.675379992 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.675405025 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.675425053 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.675436974 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.675456047 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.675456047 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.675476074 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.675498009 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.675528049 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.675542116 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.675582886 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.675601006 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.675671101 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.675793886 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.675837040 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.675843954 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.675889015 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.675894976 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.675939083 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.675976992 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.675990105 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.676039934 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.676095009 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.676107883 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.676155090 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.676176071 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.676217079 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.676250935 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.676309109 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.676352024 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.678360939 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.678415060 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.678481102 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.678555012 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.678560972 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.678605080 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.678699017 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.678742886 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.678778887 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.678833008 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.679096937 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.679171085 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.679172993 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.679214001 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.679258108 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.679291964 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.679302931 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.679337978 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.679413080 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.679464102 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.679588079 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.679641962 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.679688931 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.679740906 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.679769993 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.679848909 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.679861069 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.679893970 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.679905891 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.679924965 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.679970026 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.680037975 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.680087090 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.680190086 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.680236101 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.680320024 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.680382013 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.680407047 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.680430889 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.680453062 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.680465937 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.680506945 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.680535078 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.680577993 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.680691957 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.680738926 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.680774927 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.680788040 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.680835009 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.680890083 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.680937052 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.681006908 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.681138039 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.681163073 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.681210041 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.681246996 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.681260109 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.681287050 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.681298018 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.681307077 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.681329012 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.681339025 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.681349039 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.681375027 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.681416035 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.681468964 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.681474924 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.681550026 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.681591988 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.681605101 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.681615114 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.681629896 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.681643963 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.681644917 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.681657076 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.681687117 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.681688070 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.681710005 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.681751966 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.683244944 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.683336973 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.683368921 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.683413029 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.683453083 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.683537960 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.683561087 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.683608055 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.683645010 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.683691025 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.684005022 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.684056997 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.684112072 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.684125900 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.684174061 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.684184074 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.684236050 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.684245110 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.684284925 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.684322119 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.684348106 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.684412003 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.684444904 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.684489965 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.684489965 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.684533119 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.684559107 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.684571981 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.684593916 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.684607983 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.684618950 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.684642076 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.684659958 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.684689999 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.684736013 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.684765100 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.684797049 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.684840918 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.684889078 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.684901953 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.684930086 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.684948921 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.684950113 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.684982061 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.684992075 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.685038090 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.685085058 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.685139894 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.685153961 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.685164928 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.685197115 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.685216904 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.685287952 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.685333014 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.685354948 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.685399055 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.685401917 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.685448885 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.685477018 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.685504913 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.685527086 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.685554981 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.686094999 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.686161041 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.687125921 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.687251091 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.688088894 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.688152075 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.688709974 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.688734055 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.688745975 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.688757896 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.688766003 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.688771009 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.688785076 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.688791990 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.688797951 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.688802958 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.688823938 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.688836098 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.688836098 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.688851118 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.688863039 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.688863993 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.688879013 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.688891888 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.688904047 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.688905001 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.688918114 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.688920021 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.688930988 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.688944101 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.688950062 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.688957930 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.688973904 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.688975096 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.688993931 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.688994884 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.689008951 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.689022064 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.689037085 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.689038038 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.689062119 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.689086914 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.689457893 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.689474106 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.689511061 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.689528942 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.689587116 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.689599991 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.689632893 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.689644098 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.689717054 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.689730883 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.689749002 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.689784050 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.689943075 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.689986944 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.690083981 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.690098047 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.690125942 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.690138102 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.690145016 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.690149069 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.690161943 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.690174103 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.690179110 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.690186024 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.690200090 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.690201998 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.690212965 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.690226078 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.690237999 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.690241098 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.690258026 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.690259933 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.690278053 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.690280914 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.690294027 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.690304995 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.690308094 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.690320015 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.690334082 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.690346003 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.690372944 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.690534115 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.690546989 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.690568924 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.690581083 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.690591097 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.690628052 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.690653086 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.690665960 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.690709114 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.691087961 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.691145897 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.692142010 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.692198038 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.693089962 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.693147898 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.694395065 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.694446087 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.694461107 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.694477081 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.694513083 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.694535971 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.694539070 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.694578886 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.694590092 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.694591045 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.694611073 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.694643021 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.694653988 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.694665909 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.694700003 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.695285082 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.695297003 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.695339918 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.695729971 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.695782900 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.696088076 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.696145058 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.696777105 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.696892023 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.697110891 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.697175980 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.697468996 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.697483063 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.697530985 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.697778940 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.697834015 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.697871923 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.697884083 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.697895050 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.697905064 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.697912931 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.697915077 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.697923899 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.697942019 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.697947025 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.697953939 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.697966099 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.697977066 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.697987080 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.697997093 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.698007107 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.698018074 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.698019028 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.698029041 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.698040962 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.698050976 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.698052883 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.698064089 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.698075056 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.698076010 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.698086023 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.698097944 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.698106050 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.698107958 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.698117018 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.698118925 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.698131084 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.698141098 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.698143005 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.698151112 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.698163033 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.698172092 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.698174000 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.698183060 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.698187113 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.698198080 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.698210001 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.698211908 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.698225975 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.698236942 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.698237896 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.698249102 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.698256969 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.698261976 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.698273897 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.698302031 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.698900938 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.698945999 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.701170921 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.701225042 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.701287031 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.701302052 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.701313972 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.701359987 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.701704025 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.701716900 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.701728106 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.701757908 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.701776028 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.702491999 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.702550888 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.702564001 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.702614069 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.703025103 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.703038931 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.703079939 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.704874039 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.704893112 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.704906940 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.704919100 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.704947948 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.704967022 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.704984903 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.704998970 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.705010891 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.705049992 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.705487013 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.705537081 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.706075907 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706093073 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706104994 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706116915 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706129074 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.706130028 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706142902 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706155062 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706163883 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.706177950 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706186056 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.706193924 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706207037 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706228971 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.706248999 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.706444025 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706456900 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706468105 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706489086 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706499100 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.706501961 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706515074 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706516027 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.706527948 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706533909 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.706541061 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706552982 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706563950 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.706566095 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706579924 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706588984 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.706593037 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706607103 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706612110 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.706619978 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706631899 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706634045 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.706645012 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706656933 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706669092 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706669092 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.706681013 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706685066 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.706692934 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706706047 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.706715107 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.706738949 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.706760883 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.707537889 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.707571983 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.707585096 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.707597017 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.707608938 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.707623005 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.707629919 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.707659960 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.707663059 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.707674026 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.707691908 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.707699060 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.707712889 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.707727909 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.707739115 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.707750082 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.707765102 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.708933115 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.708952904 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.708965063 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.708990097 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.709007978 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.709501028 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.709517956 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.709563017 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.710870981 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.710923910 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.711036921 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.711050034 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.711086988 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.711174965 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.711188078 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.711210012 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.711232901 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.711235046 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.711250067 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.711271048 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.711283922 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.711286068 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.711322069 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.712968111 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.712986946 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.713000059 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.713011026 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.713022947 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.713038921 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.713038921 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.713053942 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.713066101 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.713071108 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.713078976 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.713099003 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.713124990 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.713516951 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.713572025 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.713776112 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.713790894 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.713803053 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.713814020 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.713825941 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.713838100 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.713845015 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.713856936 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.713861942 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.713871002 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.713896990 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.713898897 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.713920116 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.713926077 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.713932991 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.713947058 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.713952065 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.713960886 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.713973045 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.713975906 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.713989973 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.714003086 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.714009047 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.714026928 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.714046955 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.714050055 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.714062929 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.714075089 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.714097023 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.714127064 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.714509010 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.714524031 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.714534044 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.714545965 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.714557886 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.714569092 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.714570999 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.714582920 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.714584112 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.714601994 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.714627028 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.714955091 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.714968920 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.714978933 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.714989901 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.715002060 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.715013027 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.715025902 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.715027094 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.715050936 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.715070009 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.715078115 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.715091944 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.715102911 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.715115070 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.715126038 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.715133905 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.715137959 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.715156078 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.715163946 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.715188980 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.715229034 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.715241909 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.715260983 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.715280056 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.715300083 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.715866089 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.715895891 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.715918064 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.715934992 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.716516018 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.716567993 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.717318058 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.717331886 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.717344046 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.717356920 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.717369080 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.717371941 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.717381954 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.717397928 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.717425108 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.717962027 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.717977047 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.717989922 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.718003035 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.718003035 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.718015909 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.718024015 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.718061924 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.718898058 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.718946934 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.718946934 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.718996048 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.718997002 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.719012976 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.719043970 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.719065905 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.720029116 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.720082998 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.720134020 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.720148087 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.720160007 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.720171928 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.720187902 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.720205069 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.720231056 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.720235109 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.720268011 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.720283031 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.720314026 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.720316887 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.720355988 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.720369101 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.720372915 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.720387936 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.720411062 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.720429897 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.720443010 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.720482111 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.720494032 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.720505953 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.720562935 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.720575094 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.720581055 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.720592022 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.720596075 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.720633984 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.720650911 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.720664024 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.720685005 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.720711946 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.720721960 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.721035957 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.721049070 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.721060991 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.721081972 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.721100092 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.721601009 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.721615076 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.721626997 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.721667051 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.721889973 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.721946955 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.722122908 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.722174883 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.722244024 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.722266912 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.722279072 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.722290039 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.722295046 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.722316027 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.722335100 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.722395897 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.722537994 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.722723007 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.722737074 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.722773075 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.722868919 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.722882986 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.722893953 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.722907066 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.722920895 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.722920895 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.722934008 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.722934961 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.722953081 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.722969055 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.722984076 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.723037958 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.723051071 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.723063946 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.723076105 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.723088980 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.723104000 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.723130941 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.723212004 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.723258972 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.723829985 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.723843098 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.723854065 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.723866940 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.723877907 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.723890066 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.723912001 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.723948956 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.724184036 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.724196911 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.724245071 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.724322081 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.724334002 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.724345922 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.724389076 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.724628925 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.724642038 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.724653006 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.724682093 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.724781036 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.724793911 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.724832058 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.724946976 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.725002050 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.725421906 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.725472927 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.725584030 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.725642920 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.725723028 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.725735903 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.725771904 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.725883961 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.725898027 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.725935936 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.726030111 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.726042032 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.726075888 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.726099014 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.726159096 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.726172924 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.726229906 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.767879963 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.772073984 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.772141933 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.772186041 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.772223949 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.772245884 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.819890976 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.820099115 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.820154905 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.820199966 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.820245028 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.820261955 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.867908001 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.872147083 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.872230053 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.872293949 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.872338057 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.872356892 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.919899940 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.923093081 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.923163891 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.923219919 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.923285961 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.923316002 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.923316956 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.928225040 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.928402901 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.928431034 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.928488970 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.928570986 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.928582907 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.928606033 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.928617001 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.928648949 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.928669930 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.928757906 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.928826094 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.928931952 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.928977013 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.929061890 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.929070950 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.929091930 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.929142952 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.929178953 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.929223061 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.929282904 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.929383039 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.929394960 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.929442883 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.929451942 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.929481030 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.929552078 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.929584026 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.929595947 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.929649115 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.929672956 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.929685116 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.929717064 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.929728031 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.929740906 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.929768085 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.929850101 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.929862022 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.929867029 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.929877043 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.929887056 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.929898977 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.929913998 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.929918051 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.929934978 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.929943085 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.929955006 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.929955959 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.929972887 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.929974079 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.929989100 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.929996014 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.930031061 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.933480024 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933538914 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933561087 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933571100 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933578014 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933583021 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933588028 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933592081 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933597088 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933612108 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933620930 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933634996 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.933649063 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933651924 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.933660984 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933671951 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933679104 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.933703899 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.933707952 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933715105 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.933721066 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933733940 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933747053 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933768988 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.933789968 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.933795929 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933808088 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933818102 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933830023 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933839083 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933847904 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.933859110 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933870077 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933876038 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933878899 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.933898926 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933909893 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933917999 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.933918953 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.933921099 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933940887 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933945894 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.933953047 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933967113 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.933990955 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.933991909 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934005022 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934015989 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934046030 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934056044 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934067011 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934067965 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934081078 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934092045 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934113979 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934129000 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934190035 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934202909 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934211969 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934222937 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934235096 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934242964 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934247017 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934256077 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934259892 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934287071 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934309959 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934323072 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934334040 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934343100 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934355974 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934366941 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934367895 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934366941 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934403896 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934403896 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934417009 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934441090 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934452057 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934462070 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934494019 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934494019 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934508085 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934514999 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934529066 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934549093 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934554100 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934561014 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934565067 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934571981 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934591055 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934595108 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934607029 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934607983 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934643984 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934643984 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934761047 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934773922 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934783936 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934796095 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934806108 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934813976 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934818983 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934824944 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934825897 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934837103 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934848070 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934855938 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934858084 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934870958 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934879065 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934890985 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934895992 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934902906 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934915066 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934938908 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934938908 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934958935 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.934962034 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934976101 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934988022 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.934999943 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935014963 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.935019016 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935033083 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935043097 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.935055017 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935077906 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.935097933 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935110092 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935118914 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.935121059 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935137033 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935147047 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.935148001 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935169935 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935184956 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.935209990 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.935286045 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935297966 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935328007 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935338974 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935343981 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935347080 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.935367107 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935370922 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.935400963 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935404062 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.935414076 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935419083 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.935452938 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935461044 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.935466051 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935477018 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935497046 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.935523033 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.935703039 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935715914 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935726881 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935736895 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935750008 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935760975 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935770988 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935781002 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935781002 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.935794115 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935796022 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.935806036 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935807943 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.935826063 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.935839891 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.935868979 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935875893 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.935920954 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.935934067 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935945988 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935955048 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.935983896 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.935997963 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.936022997 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936034918 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936052084 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936074018 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.936094046 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.936135054 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936147928 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936158895 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936197042 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.936203957 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936216116 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.936219931 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936232090 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936256886 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936268091 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936274052 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936274052 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.936286926 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936297894 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936311960 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.936320066 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936331987 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936347008 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.936372042 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.936408043 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936419010 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936428070 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936460972 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.936475039 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.936578035 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936589956 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936602116 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936614037 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936624050 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936630964 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.936647892 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.936647892 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936664104 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936672926 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.936674118 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936708927 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.936719894 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.936726093 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936764956 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936775923 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936785936 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.936815023 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.936908007 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.938533068 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.938601971 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.938602924 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.938640118 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.938653946 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.938689947 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.938693047 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.938731909 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.938889980 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.938904047 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.938915014 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.938939095 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.938962936 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.938967943 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.938967943 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.938976049 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.938978910 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.938992023 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939004898 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939008951 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.939028978 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939043999 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.939043999 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.939064026 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939066887 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.939096928 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939110994 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939124107 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939136982 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939148903 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939152956 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.939163923 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.939172983 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939189911 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.939204931 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939212084 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.939219952 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939232111 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939261913 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939264059 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.939294100 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.939307928 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.939356089 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939394951 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939416885 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939428091 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939435959 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.939441919 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939457893 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.939475060 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.939485073 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939498901 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939502954 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.939505100 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939537048 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939579010 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939615965 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939631939 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.939682007 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.939774036 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939788103 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939800024 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939811945 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939825058 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939832926 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.939837933 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939860106 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.939861059 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939873934 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939886093 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.939887047 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939903021 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939908028 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.939918041 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939924955 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.939930916 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.939970016 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.939970016 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.940016031 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940063953 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940076113 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940078020 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.940088987 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940104961 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940119028 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940133095 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.940133095 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.940133095 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.940148115 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940160990 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940171957 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.940176010 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940190077 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940213919 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.940239906 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940295935 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940295935 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.940311909 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940356970 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.940376997 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940391064 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940402031 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940445900 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.940460920 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.940460920 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940474987 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940510035 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.940530062 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.940666914 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940680981 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940692902 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940726042 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.940745115 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940752983 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.940778017 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940789938 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940800905 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940813065 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940824032 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.940824032 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940824032 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.940838099 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940851927 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940851927 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.940860033 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.940906048 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.940915108 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940927029 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940937996 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940949917 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940960884 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940964937 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.940973043 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940985918 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.940998077 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.940998077 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.941008091 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941020012 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941030979 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.941031933 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941055059 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941063881 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.941067934 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941086054 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.941097021 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.941113949 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941126108 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941145897 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941159964 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.941191912 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.941222906 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941236019 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941274881 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941287041 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941306114 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941310883 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.941328049 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941332102 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.941365957 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941371918 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.941394091 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941421986 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.941555977 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941560984 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.941570044 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941581011 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941592932 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941602945 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.941617012 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941629887 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941636086 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.941642046 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941654921 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941677094 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.941677094 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.941677094 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.941720963 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941730022 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.941735029 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941756010 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941768885 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941781044 CET1566649699109.172.94.66192.168.2.7
                    Oct 31, 2024 11:34:15.941785097 CET4969915666192.168.2.7109.172.94.66
                    Oct 31, 2024 11:34:15.941793919 CET1566649699109.172.94.66192.168.2.7
                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                    Oct 31, 2024 11:34:12.397808075 CET192.168.2.71.1.1.10x5dd3Standard query (0)api.ipify.orgA (IP address)IN (0x0001)false
                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                    Oct 31, 2024 11:34:12.405399084 CET1.1.1.1192.168.2.70x5dd3No error (0)api.ipify.org104.26.13.205A (IP address)IN (0x0001)false
                    Oct 31, 2024 11:34:12.405399084 CET1.1.1.1192.168.2.70x5dd3No error (0)api.ipify.org172.67.74.152A (IP address)IN (0x0001)false
                    Oct 31, 2024 11:34:12.405399084 CET1.1.1.1192.168.2.70x5dd3No error (0)api.ipify.org104.26.12.205A (IP address)IN (0x0001)false
                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                    0192.168.2.749700104.26.13.2054433812C:\Users\user\Desktop\file.exe
                    TimestampBytes transferredDirectionData
                    2024-10-31 10:34:13 UTC100OUTGET / HTTP/1.1
                    Accept: text/html; text/plain; */*
                    Host: api.ipify.org
                    Cache-Control: no-cache
                    2024-10-31 10:34:13 UTC399INHTTP/1.1 200 OK
                    Date: Thu, 31 Oct 2024 10:34:13 GMT
                    Content-Type: text/plain
                    Content-Length: 14
                    Connection: close
                    Vary: Origin
                    cf-cache-status: DYNAMIC
                    Server: cloudflare
                    CF-RAY: 8db2fdc8b8c6e542-DFW
                    server-timing: cfL4;desc="?proto=TCP&rtt=1218&sent=5&recv=6&lost=0&retrans=0&sent_bytes=2817&recv_bytes=738&delivery_rate=2419381&cwnd=251&unsent_bytes=0&cid=c9a8c099fee1ba1b&ts=321&x=0"
                    2024-10-31 10:34:13 UTC14INData Raw: 31 37 33 2e 32 35 34 2e 32 35 30 2e 37 37
                    Data Ascii: 173.254.250.77


                    Click to jump to process

                    Click to jump to process

                    Click to dive into process behavior distribution

                    Target ID:0
                    Start time:06:34:10
                    Start date:31/10/2024
                    Path:C:\Users\user\Desktop\file.exe
                    Wow64 process (32bit):false
                    Commandline:"C:\Users\user\Desktop\file.exe"
                    Imagebase:0x7ff67e140000
                    File size:2'640'384 bytes
                    MD5 hash:AB7D13FD2200B07C2BC9FE3B3F7CC837
                    Has elevated privileges:true
                    Has administrator privileges:true
                    Programmed in:C, C++ or other language
                    Yara matches:
                    • Rule: JoeSecurity_MeduzaStealer, Description: Yara detected Meduza Stealer, Source: 00000000.00000002.1323368752.000002674DF30000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                    • Rule: JoeSecurity_MeduzaStealer, Description: Yara detected Meduza Stealer, Source: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                    Reputation:low
                    Has exited:true

                    Reset < >

                      Execution Graph

                      Execution Coverage:6.9%
                      Dynamic/Decrypted Code Coverage:100%
                      Signature Coverage:29.9%
                      Total number of Nodes:2000
                      Total number of Limit Nodes:123
                      execution_graph 61958 2674e1a7f01 61959 2674e1a7f2c 61958->61959 61972 2674e1a7f17 61958->61972 61960 2674e1a7f35 61959->61960 61961 2674e1a80fc 61959->61961 61968 2674e1a7f96 memcpy_s 61960->61968 61977 2674e1679e0 61960->61977 61962 2674e1a8169 61961->61962 61967 2674e1a7bd0 3 API calls 61961->61967 61964 2674e1a7bd0 3 API calls 61962->61964 61964->61972 61965 2674e1a84bb 61966 2674e1a808e 61970 2674e1a7bd0 3 API calls 61966->61970 61967->61961 61968->61966 61973 2674e1a7bd0 61968->61973 61970->61972 61989 2674e1ce010 61972->61989 61974 2674e1a7bfd 61973->61974 61975 2674e1ce010 _Strcoll 3 API calls 61974->61975 61976 2674e1a84bb 61975->61976 61976->61968 61978 2674e167a0e 61977->61978 61979 2674e167b72 61977->61979 61982 2674e167a78 61978->61982 61983 2674e167aa4 61978->61983 62005 2674e14d720 45 API calls 61979->62005 61981 2674e167b77 62006 2674e14d660 45 API calls 2 library calls 61981->62006 61982->61981 61984 2674e167a85 61982->61984 61985 2674e1ce2d0 std::_Facet_Register 45 API calls 61983->61985 61988 2674e167a8d ISource memcpy_s _Strxfrm 61983->61988 61996 2674e1ce2d0 61984->61996 61985->61988 61988->61968 61990 2674e1ce019 61989->61990 61991 2674e1ce024 61990->61991 61992 2674e1ce694 IsProcessorFeaturePresent 61990->61992 61991->61965 61993 2674e1ce6ac 61992->61993 62018 2674e1ce888 RtlCaptureContext RtlLookupFunctionEntry capture_previous_context 61993->62018 61995 2674e1ce6bf 61995->61965 61998 2674e1ce2db 61996->61998 61997 2674e1ce2f4 61997->61988 61998->61997 62001 2674e1ce2fa 61998->62001 62007 2674e1c936c 61998->62007 62000 2674e1ce305 62011 2674e14d660 45 API calls 2 library calls 62000->62011 62001->62000 62010 2674e1cf0f0 RtlPcToFileHeader RaiseException Concurrency::cancel_current_task std::bad_alloc::bad_alloc 62001->62010 62004 2674e1ce30b 62006->61988 62012 2674e1c93a8 62007->62012 62010->62000 62011->62004 62017 2674e1bba3c EnterCriticalSection 62012->62017 62018->61995 62019 2674e19ad20 62020 2674e19ad50 62019->62020 62025 2674e1db83c 62020->62025 62023 2674e1ce010 _Strcoll 3 API calls 62024 2674e19ada6 62023->62024 62026 2674e1db87e 62025->62026 62027 2674e1db887 __std_fs_get_current_path 62026->62027 62029 2674e1db999 62026->62029 62032 2674e1db8df GetFileAttributesExW 62026->62032 62028 2674e1ce010 _Strcoll 3 API calls 62027->62028 62030 2674e19ad69 62028->62030 62057 2674e1dbc10 CreateFileW __std_fs_get_current_path 62029->62057 62030->62023 62034 2674e1db8f3 __std_fs_get_current_path 62032->62034 62035 2674e1db944 62032->62035 62033 2674e1db9bc 62036 2674e1db9f1 GetFileInformationByHandleEx 62033->62036 62037 2674e1dba8f 62033->62037 62048 2674e1db9c2 _invalid_parameter_noinfo 62033->62048 62034->62027 62038 2674e1db902 FindFirstFileW 62034->62038 62035->62027 62035->62029 62039 2674e1dba31 62036->62039 62045 2674e1dba0b _invalid_parameter_noinfo __std_fs_get_current_path 62036->62045 62040 2674e1dbaaa GetFileInformationByHandleEx 62037->62040 62037->62048 62038->62027 62041 2674e1db921 FindClose 62038->62041 62039->62037 62043 2674e1dba52 GetFileInformationByHandleEx 62039->62043 62047 2674e1dbac0 _invalid_parameter_noinfo __std_fs_get_current_path 62040->62047 62040->62048 62041->62035 62042 2674e1dbb51 62058 2674e1cb5c4 42 API calls 2 library calls 62042->62058 62043->62037 62049 2674e1dba6e _invalid_parameter_noinfo __std_fs_get_current_path 62043->62049 62051 2674e1dbb62 62045->62051 62054 2674e1db9db 62045->62054 62046 2674e1dbb56 62059 2674e1cb5c4 42 API calls 2 library calls 62046->62059 62052 2674e1dbb5c 62047->62052 62047->62054 62048->62027 62048->62042 62048->62054 62049->62046 62049->62054 62061 2674e1cb5c4 42 API calls 2 library calls 62051->62061 62060 2674e1cb5c4 42 API calls 2 library calls 62052->62060 62054->62027 62057->62033 62062 2674e1a2b20 62063 2674e1a2b32 ISource 62062->62063 62065 2674e1a2c4b _Strxfrm 62063->62065 62068 2674e1a317d 62063->62068 62071 2674e195ef0 45 API calls 5 library calls 62063->62071 62067 2674e1a2cdd ISource 62065->62067 62072 2674e167870 62065->62072 62067->62068 62069 2674e1ce010 _Strcoll 3 API calls 62067->62069 62070 2674e1a3161 62069->62070 62071->62065 62073 2674e1679c3 62072->62073 62074 2674e16789f 62072->62074 62084 2674e14d720 45 API calls 62073->62084 62076 2674e1678fc 62074->62076 62077 2674e167928 62074->62077 62078 2674e1679c8 62076->62078 62079 2674e167909 62076->62079 62081 2674e1ce2d0 std::_Facet_Register 45 API calls 62077->62081 62083 2674e167911 ISource _Strxfrm 62077->62083 62085 2674e14d660 45 API calls 2 library calls 62078->62085 62080 2674e1ce2d0 std::_Facet_Register 45 API calls 62079->62080 62080->62083 62081->62083 62083->62067 62085->62083 62086 2674e1634a6 62087 2674e1634ab ISource 62086->62087 62088 2674e1ce010 _Strcoll 3 API calls 62087->62088 62089 2674e1634bf 62088->62089 62090 2674e1a8197 62091 2674e1a81a1 62090->62091 62096 2674e1a8610 62091->62096 62094 2674e1ce010 _Strcoll 3 API calls 62095 2674e1a84bb 62094->62095 62097 2674e1a864f 62096->62097 62104 2674e1a81b0 62096->62104 62099 2674e1a88cf 62097->62099 62103 2674e1a884e 62097->62103 62105 2674e17b080 43 API calls 62097->62105 62106 2674e17b0e0 IsProcessorFeaturePresent RtlCaptureContext RtlLookupFunctionEntry _Strcoll 62099->62106 62101 2674e1d11d8 RtlPcToFileHeader RaiseException Concurrency::cancel_current_task 62101->62103 62102 2674e166710 45 API calls 62102->62103 62103->62101 62103->62102 62103->62104 62104->62094 62105->62097 62106->62103 62107 2674e163181 62108 2674e1634dd 62107->62108 62109 2674e163194 62107->62109 62127 2674e160a00 45 API calls ISource 62108->62127 62121 2674e163bd0 62109->62121 62112 2674e1634e8 62122 2674e163c61 62121->62122 62124 2674e163c04 62121->62124 62129 2674e14d660 45 API calls 2 library calls 62122->62129 62128 2674e167e80 IsProcessorFeaturePresent RtlCaptureContext RtlLookupFunctionEntry _Strcoll 62124->62128 62126 2674e163c87 62127->62112 62128->62122 62129->62126 62130 2674e1aacfe 62135 2674e1ab670 62130->62135 62133 2674e1ce010 _Strcoll 3 API calls 62134 2674e1aad3b 62133->62134 62136 2674e1ab68e 62135->62136 62137 2674e1ab6c1 62136->62137 62141 2674e18c620 45 API calls 4 library calls 62136->62141 62142 2674e1abf90 62137->62142 62140 2674e1aad06 62140->62133 62141->62137 62143 2674e1abfb3 62142->62143 62146 2674e1abfad 62142->62146 62145 2674e1abfca 62143->62145 62159 2674e173290 62143->62159 62144 2674e1ac037 62144->62140 62145->62146 62148 2674e1ac064 62145->62148 62146->62144 62178 2674e18c620 45 API calls 4 library calls 62146->62178 62179 2674e14eb40 45 API calls 62148->62179 62150 2674e1ac0a6 62180 2674e1d11d8 62150->62180 62152 2674e1ac0b7 62153 2674e167870 45 API calls 62152->62153 62157 2674e1ac0e5 62152->62157 62153->62157 62154 2674e1ac190 62154->62140 62155 2674e1abf90 45 API calls 62155->62157 62156 2674e167870 45 API calls 62156->62157 62157->62154 62157->62155 62157->62156 62160 2674e1732cd 62159->62160 62162 2674e173363 62160->62162 62163 2674e173341 62160->62163 62168 2674e1732dd ISource 62160->62168 62161 2674e1ce010 _Strcoll 3 API calls 62164 2674e17350f 62161->62164 62166 2674e1afa64 42 API calls 62162->62166 62185 2674e1afa64 62163->62185 62164->62145 62170 2674e173391 _Strxfrm 62166->62170 62167 2674e167870 45 API calls 62167->62170 62168->62161 62169 2674e1734b1 62169->62168 62171 2674e173597 62169->62171 62170->62167 62170->62169 62174 2674e1afa64 42 API calls 62170->62174 62176 2674e173547 62170->62176 62172 2674e1735c4 62171->62172 62177 2674e173290 45 API calls 62171->62177 62172->62145 62173 2674e1735db 62173->62145 62174->62170 62176->62169 62204 2674e1b0544 42 API calls 3 library calls 62176->62204 62177->62173 62178->62144 62179->62150 62181 2674e1d1214 RtlPcToFileHeader 62180->62181 62182 2674e1d11f7 62180->62182 62183 2674e1d122c 62181->62183 62184 2674e1d123b RaiseException 62181->62184 62182->62181 62183->62184 62184->62152 62186 2674e1afa80 62185->62186 62187 2674e1afa9e 62185->62187 62207 2674e1b54cc 7 API calls _Strcoll 62186->62207 62205 2674e1afd4c EnterCriticalSection 62187->62205 62191 2674e1afa85 62208 2674e1b1008 42 API calls _invalid_parameter_noinfo 62191->62208 62196 2674e1afa90 _local_unwind 62196->62168 62204->62176 62206 2674e1f6208 62205->62206 62207->62191 62208->62196 62209 2674e1a1f1b RegOpenKeyExA 62210 2674e1a1f45 RegQueryValueExA 62209->62210 62211 2674e1a1f84 ISource 62209->62211 62210->62211 62212 2674e1a2014 RegCloseKey 62211->62212 62213 2674e1a201a 62211->62213 62212->62213 62215 2674e1ce010 _Strcoll 3 API calls 62213->62215 62216 2674e1a202d 62215->62216 62217 2674e157981 62223 2674e14f6c0 62217->62223 62219 2674e1579b4 FindNextFileW 62220 2674e1579d2 62219->62220 62221 2674e1ce010 _Strcoll 3 API calls 62220->62221 62222 2674e1579f9 62221->62222 62224 2674e14f6d8 ISource 62223->62224 62224->62219 62225 2674e19b210 62226 2674e19b28b 62225->62226 62283 2674e14f5f0 62226->62283 62228 2674e19b2b0 ISource 62230 2674e19b7b3 62228->62230 62286 2674e150680 62228->62286 62361 2674e14eb40 45 API calls 62230->62361 62231 2674e19b319 memcpy_s 62232 2674e19b662 62231->62232 62292 2674e1a8c00 62231->62292 62232->62230 62267 2674e19b463 ISource 62232->62267 62274 2674e19b871 62232->62274 62235 2674e1ce010 _Strcoll 3 API calls 62239 2674e19b745 62235->62239 62240 2674e19b609 62360 2674e1738d0 43 API calls 62240->62360 62241 2674e19b3a7 62305 2674e1a8fb0 62241->62305 62242 2674e19b7e5 62245 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62242->62245 62246 2674e19b7f6 62245->62246 62362 2674e14eb40 45 API calls 62246->62362 62247 2674e19b3d9 62249 2674e19b3f6 62247->62249 62250 2674e19b479 62247->62250 62249->62230 62253 2674e19b428 62249->62253 62323 2674e1a7710 62250->62323 62252 2674e19b81f 62255 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62252->62255 62312 2674e1a7550 62253->62312 62254 2674e19b48d 62258 2674e19b4a4 62254->62258 62259 2674e19b527 62254->62259 62262 2674e19b833 62255->62262 62257 2674e19b435 62322 2674e172ab0 43 API calls 62257->62322 62258->62246 62261 2674e19b4d6 62258->62261 62260 2674e1a7710 45 API calls 62259->62260 62264 2674e19b53b 62260->62264 62265 2674e1a7550 46 API calls 62261->62265 62363 2674e14eb40 45 API calls 62262->62363 62268 2674e1a7710 45 API calls 62264->62268 62269 2674e19b4e3 62265->62269 62267->62235 62271 2674e19b54a 62268->62271 62334 2674e172ab0 43 API calls 62269->62334 62270 2674e19b85d 62272 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62270->62272 62335 2674e185d00 62271->62335 62272->62274 62364 2674e14feb0 45 API calls Concurrency::cancel_current_task 62274->62364 62275 2674e19b55a 62275->62262 62277 2674e19b58d 62275->62277 62278 2674e1a7550 46 API calls 62277->62278 62279 2674e19b59a 62278->62279 62346 2674e161e70 62279->62346 62281 2674e19b5aa 62359 2674e172ab0 43 API calls 62281->62359 62365 2674e156f20 62283->62365 62285 2674e14f612 62285->62228 62287 2674e1506b1 62286->62287 62288 2674e1db83c 49 API calls 62287->62288 62289 2674e1506cd 62288->62289 62290 2674e1ce010 _Strcoll 3 API calls 62289->62290 62291 2674e150752 62290->62291 62291->62231 62293 2674e1a8c26 62292->62293 62380 2674e163950 62293->62380 62299 2674e19b397 62299->62240 62299->62241 62300 2674e1a8cea 62300->62299 62407 2674e14eb40 45 API calls 62300->62407 62302 2674e1a8d88 62303 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62302->62303 62304 2674e1a8d99 62303->62304 62686 2674e1628d0 62305->62686 62307 2674e1a8fe6 62696 2674e1ac350 62307->62696 62311 2674e1a9055 62311->62247 62315 2674e1a7562 62312->62315 63044 2674e174130 62312->63044 62314 2674e1a7590 62314->62257 62315->62314 63050 2674e14eb40 45 API calls 62315->63050 62317 2674e1a75d6 62318 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62317->62318 62319 2674e1a75e7 62318->62319 62320 2674e1a7617 62319->62320 63051 2674e1b0410 8 API calls 3 library calls 62319->63051 62320->62257 62322->62267 62328 2674e1a772f 62323->62328 62333 2674e1a77ae 62323->62333 62325 2674e1a776a 62325->62254 62327 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62329 2674e1a77ec 62327->62329 62328->62325 63063 2674e1a9830 45 API calls 3 library calls 62328->63063 62331 2674e1a779d 62332 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62331->62332 62332->62333 63064 2674e166710 62333->63064 62334->62267 62336 2674e185d3d 62335->62336 62337 2674e185d7e 62335->62337 62338 2674e185d5c 62336->62338 63073 2674e163610 62336->63073 62340 2674e166710 45 API calls 62337->62340 62338->62275 62341 2674e185db1 62340->62341 62342 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62341->62342 62345 2674e185dc2 62342->62345 62343 2674e185df6 62343->62275 62345->62343 63079 2674e1db76c 43 API calls __std_fs_directory_iterator_open 62345->63079 62347 2674e161e9e 62346->62347 62348 2674e161ec2 62347->62348 62351 2674e161f3b 62347->62351 62352 2674e161f14 62347->62352 62358 2674e161f25 62347->62358 62348->62281 62350 2674e161f7b 63082 2674e14d660 45 API calls 2 library calls 62350->63082 62353 2674e161f2d _Strxfrm 62351->62353 62355 2674e1ce2d0 std::_Facet_Register 45 API calls 62351->62355 62352->62350 62356 2674e1ce2d0 std::_Facet_Register 45 API calls 62352->62356 62353->62281 62355->62353 62356->62358 62357 2674e161f81 62358->62353 63081 2674e14d720 45 API calls 62358->63081 62359->62267 62360->62232 62361->62242 62362->62252 62363->62270 62366 2674e156f4e 62365->62366 62367 2674e156f72 62366->62367 62371 2674e156fff 62366->62371 62372 2674e156f9a 62366->62372 62373 2674e157043 62366->62373 62377 2674e156fe9 62366->62377 62367->62285 62375 2674e156ff1 _Strxfrm 62371->62375 62376 2674e1ce2d0 std::_Facet_Register 45 API calls 62371->62376 62374 2674e1ce2d0 std::_Facet_Register 45 API calls 62372->62374 62372->62377 62379 2674e14d720 45 API calls 62373->62379 62374->62377 62375->62285 62376->62375 62377->62375 62378 2674e14d660 45 API calls 2 library calls 62377->62378 62378->62373 62381 2674e1ce2d0 std::_Facet_Register 45 API calls 62380->62381 62382 2674e1639b0 62381->62382 62408 2674e1dc5ac 62382->62408 62384 2674e1639c0 62417 2674e163e30 62384->62417 62387 2674e163a50 62388 2674e163a5d 62387->62388 62432 2674e1dc878 EnterCriticalSection GetProcAddress std::_Lockit::_Lockit 62387->62432 62395 2674e1744f0 62388->62395 62390 2674e163a78 62433 2674e14eb40 45 API calls 62390->62433 62392 2674e163ab8 62393 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62392->62393 62394 2674e163ac9 62393->62394 62445 2674e163560 62395->62445 62398 2674e197470 62399 2674e197524 62398->62399 62400 2674e197495 62398->62400 62399->62300 62450 2674e1dcae8 62400->62450 62404 2674e1974bb 62459 2674e175a10 61 API calls 4 library calls 62404->62459 62406 2674e1974e1 62406->62300 62407->62302 62434 2674e1dbf4c 62408->62434 62410 2674e1dc5ce 62416 2674e1dc612 _Strxfrm 62410->62416 62438 2674e1dc7a4 45 API calls std::_Facet_Register 62410->62438 62412 2674e1dc5e6 62439 2674e1dc7d4 43 API calls std::locale::_Setgloballocale 62412->62439 62414 2674e1dc5f1 62414->62416 62440 2674e1b0410 8 API calls 3 library calls 62414->62440 62416->62384 62416->62416 62418 2674e1dbf4c std::_Lockit::_Lockit 2 API calls 62417->62418 62419 2674e163e60 62418->62419 62420 2674e1dbf4c std::_Lockit::_Lockit 2 API calls 62419->62420 62422 2674e163e85 62419->62422 62420->62422 62421 2674e163efd 62423 2674e1ce010 _Strcoll 3 API calls 62421->62423 62422->62421 62442 2674e14e7e0 62 API calls 8 library calls 62422->62442 62424 2674e1639f5 62423->62424 62424->62387 62424->62390 62426 2674e163f0f 62427 2674e163f15 62426->62427 62428 2674e163f76 62426->62428 62443 2674e1dc56c 45 API calls std::_Facet_Register 62427->62443 62444 2674e14e320 45 API calls 2 library calls 62428->62444 62431 2674e163f7b 62432->62388 62433->62392 62435 2674e1dbf60 62434->62435 62436 2674e1dbf5b 62434->62436 62435->62410 62441 2674e1bbaac EnterCriticalSection GetProcAddress std::_Locinfo::_Locinfo_ctor 62436->62441 62438->62412 62439->62414 62440->62416 62442->62426 62443->62421 62444->62431 62446 2674e1ce2d0 std::_Facet_Register 45 API calls 62445->62446 62447 2674e163581 62446->62447 62448 2674e1dc5ac 48 API calls 62447->62448 62449 2674e163591 62448->62449 62449->62398 62452 2674e1dcb2a 62450->62452 62453 2674e1974a5 62452->62453 62460 2674e1de1a0 62452->62460 62453->62399 62458 2674e174030 42 API calls _Strcoll 62453->62458 62456 2674e1dcb77 62456->62453 62480 2674e1af980 62456->62480 62458->62404 62459->62406 62462 2674e1de0cc 62460->62462 62461 2674e1de0f2 62500 2674e1b54cc 7 API calls _Strcoll 62461->62500 62462->62461 62464 2674e1de125 62462->62464 62466 2674e1de12b 62464->62466 62467 2674e1de138 62464->62467 62465 2674e1de0f7 62501 2674e1b1008 42 API calls _invalid_parameter_noinfo 62465->62501 62502 2674e1b54cc 7 API calls _Strcoll 62466->62502 62488 2674e1bcbc4 62467->62488 62469 2674e1dcb5d 62469->62453 62479 2674e1b0be4 42 API calls _invalid_parameter_noinfo 62469->62479 62479->62456 62481 2674e1af9b0 62480->62481 62631 2674e1af860 62481->62631 62483 2674e1af9c9 62484 2674e1af9ee 62483->62484 62641 2674e1aefc8 42 API calls 3 library calls 62483->62641 62487 2674e1afa03 62484->62487 62642 2674e1aefc8 42 API calls 3 library calls 62484->62642 62487->62453 62505 2674e1bba3c EnterCriticalSection 62488->62505 62500->62465 62501->62469 62502->62469 62632 2674e1af8a9 62631->62632 62633 2674e1af87b 62631->62633 62635 2674e1afd4c _fread_nolock EnterCriticalSection 62632->62635 62640 2674e1af89b 62632->62640 62657 2674e1b0f38 42 API calls _invalid_parameter_noinfo 62633->62657 62636 2674e1af8bf 62635->62636 62643 2674e1af8dc 62636->62643 62638 2674e1af8cb 62658 2674e1afd58 LeaveCriticalSection 62638->62658 62640->62483 62641->62484 62642->62487 62644 2674e1af8f7 62643->62644 62645 2674e1af91c 62643->62645 62669 2674e1b0f38 42 API calls _invalid_parameter_noinfo 62644->62669 62647 2674e1af917 62645->62647 62659 2674e1af690 62645->62659 62647->62638 62655 2674e1af94a 62655->62647 62677 2674e1bc8e4 62655->62677 62657->62640 62660 2674e1af6b5 62659->62660 62664 2674e1af6e6 62659->62664 62661 2674e1b8f94 _fread_nolock 42 API calls 62660->62661 62660->62664 62662 2674e1af6d6 62661->62662 62682 2674e1bc4ac 42 API calls 2 library calls 62662->62682 62665 2674e1bcd24 62664->62665 62666 2674e1af938 62665->62666 62667 2674e1bcd37 62665->62667 62670 2674e1b8f94 62666->62670 62667->62666 62668 2674e1bc8e4 __free_lconv_mon 7 API calls 62667->62668 62668->62666 62669->62647 62671 2674e1b8f9d 62670->62671 62675 2674e1af940 62670->62675 62683 2674e1b54cc 7 API calls _Strcoll 62671->62683 62673 2674e1b8fa2 62684 2674e1b1008 42 API calls _invalid_parameter_noinfo 62673->62684 62676 2674e1bc998 43 API calls _invalid_parameter_noinfo 62675->62676 62676->62655 62678 2674e1bc91a 62677->62678 62679 2674e1bc8e9 HeapFree 62677->62679 62678->62647 62679->62678 62680 2674e1bc904 __free_lconv_mon __std_fs_get_current_path 62679->62680 62685 2674e1b54cc 7 API calls _Strcoll 62680->62685 62682->62664 62683->62673 62684->62675 62685->62678 62687 2674e162a26 62686->62687 62688 2674e162903 62686->62688 62687->62688 62689 2674e162a33 62687->62689 62690 2674e1ce010 _Strcoll 3 API calls 62688->62690 62759 2674e1672c0 45 API calls 3 library calls 62689->62759 62691 2674e162932 62690->62691 62691->62307 62693 2674e162a54 62694 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62693->62694 62695 2674e162a65 62694->62695 62697 2674e1ac3a4 62696->62697 62760 2674e1b53c4 62697->62760 62701 2674e1ac4af 62783 2674e199020 62701->62783 62704 2674e1ce010 _Strcoll 3 API calls 62705 2674e1a9049 62704->62705 62706 2674e1aa190 62705->62706 62707 2674e1aa4ad 62706->62707 62710 2674e1aa1d7 memcpy_s 62706->62710 62845 2674e1adad0 62707->62845 62903 2674e186760 45 API calls 62710->62903 62711 2674e1aaa20 45 API calls 62716 2674e1aa4ec 62711->62716 62713 2674e1aa227 62904 2674e1acc30 46 API calls 2 library calls 62713->62904 62715 2674e1aa5f0 ISource 62718 2674e1628d0 45 API calls 62715->62718 62726 2674e1aa6b4 62715->62726 62731 2674e1aa793 62715->62731 62752 2674e1aa7ea 62715->62752 62716->62715 62719 2674e1868c0 46 API calls 62716->62719 62717 2674e1aa237 62722 2674e1aaa20 45 API calls 62717->62722 62718->62726 62723 2674e1aa535 62719->62723 62720 2674e1ce010 _Strcoll 3 API calls 62724 2674e1aa744 62720->62724 62721 2674e1aa414 ISource 62721->62720 62730 2674e1aa243 62722->62730 62725 2674e189fa0 46 API calls 62723->62725 62724->62311 62727 2674e1aa55b 62725->62727 62726->62721 62726->62731 62732 2674e186e40 46 API calls 62727->62732 62728 2674e1aa441 62728->62721 62735 2674e1628d0 45 API calls 62728->62735 62729 2674e1aa3f9 62733 2674e1628d0 45 API calls 62729->62733 62757 2674e1aa3d8 ISource 62730->62757 62905 2674e1868c0 62730->62905 62992 2674e185930 43 API calls 62731->62992 62739 2674e1aa56a ISource 62732->62739 62733->62721 62735->62721 62737 2674e1aa28f 62913 2674e189fa0 62737->62913 62738 2674e1aa7ab 62742 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62738->62742 62745 2674e1cffe8 __std_exception_destroy 8 API calls 62739->62745 62739->62752 62755 2674e1aa7bb 62739->62755 62742->62755 62743 2674e1aa7da 62747 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62743->62747 62744 2674e1aa2b5 62981 2674e186e40 62744->62981 62746 2674e1aa5e2 62745->62746 62749 2674e1cffe8 __std_exception_destroy 8 API calls 62746->62749 62747->62752 62749->62715 62751 2674e1aa2da ISource 62751->62755 62988 2674e1cffe8 62751->62988 62993 2674e185930 43 API calls 62755->62993 62756 2674e1cffe8 __std_exception_destroy 8 API calls 62758 2674e1aa353 ISource 62756->62758 62757->62728 62757->62729 62758->62755 62758->62757 62759->62693 62790 2674e1b956c 62760->62790 62765 2674e1aaa20 62766 2674e1aaa43 62765->62766 62770 2674e1aaa90 62765->62770 62767 2674e1abf90 45 API calls 62766->62767 62769 2674e1aaa48 62767->62769 62768 2674e1abf90 45 API calls 62768->62770 62769->62770 62771 2674e1abf90 45 API calls 62769->62771 62770->62768 62781 2674e1aaae3 62770->62781 62772 2674e1aaa57 62771->62772 62773 2674e1aaa6d 62772->62773 62774 2674e1abf90 45 API calls 62772->62774 62775 2674e1ce010 _Strcoll 3 API calls 62773->62775 62777 2674e1aaa66 62774->62777 62778 2674e1aaa8a 62775->62778 62776 2674e1aabe8 62779 2674e1ce010 _Strcoll 3 API calls 62776->62779 62777->62770 62777->62773 62778->62701 62780 2674e1aad3b 62779->62780 62780->62701 62781->62776 62782 2674e1abf90 45 API calls 62781->62782 62782->62781 62784 2674e199057 62783->62784 62785 2674e19902e 62783->62785 62784->62704 62785->62784 62844 2674e14eb40 45 API calls 62785->62844 62787 2674e19908e 62788 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62787->62788 62789 2674e19909f 62788->62789 62791 2674e1b9581 __std_fs_get_current_path 62790->62791 62792 2674e1b9590 FlsGetValue 62791->62792 62793 2674e1b95ad FlsSetValue 62791->62793 62794 2674e1b95a7 62792->62794 62798 2674e1b959d _invalid_parameter_noinfo 62792->62798 62795 2674e1b95bf 62793->62795 62793->62798 62794->62793 62834 2674e1bcf4c 62795->62834 62804 2674e1b53cd 62798->62804 62841 2674e1b8f3c 42 API calls __std_fs_directory_iterator_open 62798->62841 62799 2674e1b95ec FlsSetValue 62802 2674e1b960a 62799->62802 62803 2674e1b95f8 FlsSetValue 62799->62803 62800 2674e1b95dc FlsSetValue 62801 2674e1b95e5 62800->62801 62805 2674e1bc8e4 __free_lconv_mon 7 API calls 62801->62805 62840 2674e1b931c 7 API calls _Getctype 62802->62840 62803->62801 62830 2674e1bb7f4 62804->62830 62805->62798 62808 2674e1b9612 62812 2674e1bc8e4 __free_lconv_mon 7 API calls 62808->62812 62812->62798 62831 2674e1ac48a 62830->62831 62832 2674e1bb809 62830->62832 62831->62765 62832->62831 62843 2674e1c5328 42 API calls 3 library calls 62832->62843 62838 2674e1bcf5d wcsftime 62834->62838 62835 2674e1bcfae 62842 2674e1b54cc 7 API calls _Strcoll 62835->62842 62837 2674e1b95ce 62837->62799 62837->62800 62838->62835 62838->62837 62839 2674e1c936c std::_Facet_Register 2 API calls 62838->62839 62839->62838 62840->62808 62842->62837 62843->62831 62844->62787 62846 2674e1adb4e 62845->62846 62847 2674e1868c0 46 API calls 62846->62847 62848 2674e1ae71f 62847->62848 62849 2674e189fa0 46 API calls 62848->62849 62850 2674e1ae745 62849->62850 62851 2674e186e40 46 API calls 62850->62851 62852 2674e1ae755 62851->62852 62853 2674e1ae760 62852->62853 62854 2674e1ae7c8 62852->62854 62994 2674e150a50 62853->62994 62999 2674e185930 43 API calls 62854->62999 62856 2674e1ae7d4 62858 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62856->62858 62859 2674e1ae7e4 62858->62859 63000 2674e185930 43 API calls 62859->63000 62861 2674e1ae7f1 62862 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62861->62862 62863 2674e1ae801 62862->62863 63001 2674e185930 43 API calls 62863->63001 62865 2674e1ae774 62868 2674e1ce010 _Strcoll 3 API calls 62865->62868 62866 2674e1ae80e 62867 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62866->62867 62869 2674e1ae81e 62867->62869 62870 2674e1aa4e0 62868->62870 63002 2674e18bd10 43 API calls 62869->63002 62870->62711 62872 2674e1ae82b 62873 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62872->62873 62874 2674e1ae83b 62873->62874 63003 2674e185930 43 API calls 62874->63003 62876 2674e1ae848 62877 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62876->62877 62878 2674e1ae858 62877->62878 63004 2674e185930 43 API calls 62878->63004 62880 2674e1ae865 62881 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62880->62881 62882 2674e1ae875 62881->62882 63005 2674e185930 43 API calls 62882->63005 62884 2674e1ae882 62885 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62884->62885 62886 2674e1ae892 62885->62886 63006 2674e185930 43 API calls 62886->63006 62888 2674e1ae89f 62889 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62888->62889 62890 2674e1ae8af 62889->62890 63007 2674e185930 43 API calls 62890->63007 62892 2674e1ae8bc 62893 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62892->62893 62894 2674e1ae8cc 62893->62894 63008 2674e185930 43 API calls 62894->63008 62896 2674e1ae8d9 62897 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62896->62897 62898 2674e1ae8e9 62897->62898 63009 2674e185930 43 API calls 62898->63009 62900 2674e1ae8f6 62901 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62900->62901 62902 2674e1ae906 62901->62902 62903->62713 62904->62717 62907 2674e18690c 62905->62907 62906 2674e18699d ISource 62908 2674e186e40 46 API calls 62906->62908 62912 2674e186b23 ISource 62906->62912 62907->62906 62909 2674e167870 45 API calls 62907->62909 62910 2674e186a69 62908->62910 62909->62906 62911 2674e167870 45 API calls 62910->62911 62910->62912 62911->62912 62912->62737 62914 2674e189fff 62913->62914 63010 2674e17b5c0 11 API calls 2 library calls 62914->63010 62916 2674e18a016 63011 2674e150780 62916->63011 62918 2674e18a04e ISource 62924 2674e18a28f 62918->62924 63023 2674e1cff58 62918->63023 62921 2674e18a253 ISource 62922 2674e1ce010 _Strcoll 3 API calls 62921->62922 62923 2674e18a278 62922->62923 62923->62744 62925 2674e1868c0 46 API calls 62924->62925 62926 2674e18aeff 62925->62926 62927 2674e189fa0 46 API calls 62926->62927 62928 2674e18af25 62927->62928 62929 2674e186e40 46 API calls 62928->62929 62930 2674e18af35 62929->62930 62931 2674e18af40 62930->62931 62932 2674e18afa8 62930->62932 62936 2674e150a50 8 API calls 62931->62936 63029 2674e185930 43 API calls 62932->63029 62934 2674e18afb4 62935 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62934->62935 62937 2674e18afc4 62935->62937 62938 2674e18af54 62936->62938 63030 2674e185930 43 API calls 62937->63030 62947 2674e1ce010 _Strcoll 3 API calls 62938->62947 62940 2674e18afd1 62941 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62940->62941 62942 2674e18afe1 62941->62942 63031 2674e185930 43 API calls 62942->63031 62944 2674e18afee 62945 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62944->62945 62946 2674e18affe 62945->62946 63032 2674e18bd10 43 API calls 62946->63032 62950 2674e18af89 62947->62950 62949 2674e18b00b 62951 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62949->62951 62950->62744 62952 2674e18b01b 62951->62952 63033 2674e185930 43 API calls 62952->63033 62954 2674e18b028 62955 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62954->62955 62956 2674e18b038 62955->62956 63034 2674e185930 43 API calls 62956->63034 62958 2674e18b045 62959 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62958->62959 62960 2674e18b055 62959->62960 63035 2674e185930 43 API calls 62960->63035 62962 2674e18b062 62963 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62962->62963 62964 2674e18b072 62963->62964 63036 2674e185930 43 API calls 62964->63036 62966 2674e18b07f 62967 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62966->62967 62968 2674e18b08f 62967->62968 63037 2674e185930 43 API calls 62968->63037 62970 2674e18b09c 62971 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62970->62971 62972 2674e18b0ac 62971->62972 63038 2674e185930 43 API calls 62972->63038 62974 2674e18b0b9 62975 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62974->62975 62976 2674e18b0c9 62975->62976 63039 2674e185930 43 API calls 62976->63039 62978 2674e18b0d6 62979 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 62978->62979 62980 2674e18b0e6 62979->62980 62982 2674e186f37 62981->62982 62987 2674e186e96 62981->62987 62983 2674e1ce010 _Strcoll 3 API calls 62982->62983 62984 2674e186f47 62983->62984 62984->62731 62984->62751 62986 2674e167870 45 API calls 62986->62987 62987->62982 62987->62986 63042 2674e17b080 43 API calls 62987->63042 62989 2674e1aa345 62988->62989 62990 2674e1cfff7 62988->62990 62989->62756 63043 2674e1b0410 8 API calls 3 library calls 62990->63043 62992->62738 62993->62743 62995 2674e1cffe8 __std_exception_destroy 8 API calls 62994->62995 62996 2674e150a7e 62995->62996 62997 2674e1cffe8 __std_exception_destroy 8 API calls 62996->62997 62998 2674e150a8b 62997->62998 62998->62865 62999->62856 63000->62861 63001->62866 63002->62872 63003->62876 63004->62880 63005->62884 63006->62888 63007->62892 63008->62896 63009->62900 63010->62916 63012 2674e1507bb 63011->63012 63013 2674e167870 45 API calls 63012->63013 63014 2674e1508f0 63012->63014 63013->63014 63015 2674e150993 ISource 63014->63015 63017 2674e1509cc 63014->63017 63016 2674e1ce010 _Strcoll 3 API calls 63015->63016 63018 2674e1509b8 63016->63018 63019 2674e1cffe8 __std_exception_destroy 8 API calls 63017->63019 63018->62918 63020 2674e150a15 63019->63020 63021 2674e1cffe8 __std_exception_destroy 8 API calls 63020->63021 63022 2674e150a22 ISource 63021->63022 63022->62918 63024 2674e1cff79 63023->63024 63028 2674e18a1ff 63023->63028 63025 2674e1cffae 63024->63025 63024->63028 63040 2674e1b8330 42 API calls 2 library calls 63024->63040 63041 2674e1b0410 8 API calls 3 library calls 63025->63041 63028->62921 63028->62924 63029->62934 63030->62940 63031->62944 63032->62949 63033->62954 63034->62958 63035->62962 63036->62966 63037->62970 63038->62974 63039->62978 63040->63025 63041->63028 63042->62987 63043->62989 63045 2674e17419b 63044->63045 63046 2674e17414f 63044->63046 63045->62315 63052 2674e173f40 63046->63052 63048 2674e174184 63049 2674e1af980 43 API calls 63048->63049 63049->63045 63050->62317 63051->62319 63053 2674e173f63 63052->63053 63054 2674e174012 63052->63054 63053->63054 63060 2674e173f6d 63053->63060 63055 2674e1ce010 _Strcoll 3 API calls 63054->63055 63056 2674e174021 63055->63056 63056->63048 63057 2674e1ce010 _Strcoll 3 API calls 63058 2674e173fce 63057->63058 63058->63048 63059 2674e173fb1 63059->63057 63060->63059 63062 2674e1b00c0 42 API calls _invalid_parameter_noinfo 63060->63062 63062->63059 63063->62331 63065 2674e166767 63064->63065 63066 2674e150780 45 API calls 63065->63066 63067 2674e1667a3 ISource 63066->63067 63068 2674e1cff58 __std_exception_copy 43 API calls 63067->63068 63070 2674e166972 63067->63070 63069 2674e1668f2 ISource 63068->63069 63069->63070 63071 2674e1ce010 _Strcoll 3 API calls 63069->63071 63072 2674e166964 63071->63072 63072->62327 63074 2674e16365a 63073->63074 63080 2674e14d720 45 API calls 63074->63080 63079->62345 63082->62357 63083 2674e16366d 63084 2674e163679 63083->63084 63085 2674e1636b8 63084->63085 63086 2674e1636e4 63084->63086 63088 2674e1ce2d0 std::_Facet_Register 45 API calls 63085->63088 63094 2674e163765 63085->63094 63087 2674e1ce2d0 std::_Facet_Register 45 API calls 63086->63087 63092 2674e1636cd _Strxfrm 63086->63092 63087->63092 63088->63092 63090 2674e16376b 63090->63090 63091 2674e16373b ISource 63092->63091 63095 2674e14d720 45 API calls 63092->63095 63096 2674e14d660 45 API calls 2 library calls 63094->63096 63096->63090 63097 2674e197910 63162 2674e19a880 GetCurrentProcess OpenProcessToken 63097->63162 63100 2674e197934 63644 2674e19ac70 46 API calls 2 library calls 63100->63644 63101 2674e19795e 63167 2674e1a6f60 GetCurrentProcess OpenProcessToken 63101->63167 63105 2674e19793e 63645 2674e1a5b10 73 API calls _Strcoll 63105->63645 63106 2674e1a6f60 8 API calls 63108 2674e197976 63106->63108 63175 2674e1a31c0 63108->63175 63109 2674e197947 63112 2674e197952 ExitProcess 63109->63112 63111 2674e197980 63318 2674e198360 63111->63318 63112->63101 63114 2674e197a07 ISource 63115 2674e197a45 OpenMutexA 63114->63115 63120 2674e197bd7 63114->63120 63116 2674e197a8a CreateMutexA 63115->63116 63117 2674e197a7e ExitProcess 63115->63117 63118 2674e197aba 63116->63118 63117->63116 63322 2674e19adb0 63118->63322 63122 2674e197acf 63350 2674e15d860 LoadLibraryA 63122->63350 63123 2674e197ac3 ExitProcess 63123->63122 63141 2674e197b0b 63542 2674e198590 63141->63542 63163 2674e19a8d6 GetTokenInformation 63162->63163 63164 2674e19a90e 63162->63164 63163->63164 63165 2674e1ce010 _Strcoll 3 API calls 63164->63165 63166 2674e197930 63165->63166 63166->63100 63166->63101 63168 2674e1a6fc5 LookupPrivilegeValueW 63167->63168 63169 2674e1a6fe3 63167->63169 63168->63169 63170 2674e1a6feb AdjustTokenPrivileges 63168->63170 63171 2674e1a703f 63169->63171 63172 2674e1a7033 CloseHandle 63169->63172 63170->63169 63173 2674e1ce010 _Strcoll 3 API calls 63171->63173 63172->63171 63174 2674e19796a 63173->63174 63174->63106 63648 2674e1a1d70 GetCurrentHwProfileW 63175->63648 63179 2674e1a32c9 63180 2674e1a3313 63179->63180 63797 2674e1af298 44 API calls 63179->63797 63670 2674e1a8ab0 63180->63670 63183 2674e1a3323 63187 2674e1a339e ISource _Strxfrm 63183->63187 63188 2674e1a3374 63183->63188 63798 2674e1b8030 63183->63798 63185 2674e1a3475 ISource 63189 2674e1ce010 _Strcoll 3 API calls 63185->63189 63186 2674e1b8030 42 API calls 63186->63188 63187->63185 63190 2674e1a34bb 63187->63190 63188->63186 63188->63187 63191 2674e1a349a 63189->63191 63682 2674e1a16b0 63190->63682 63191->63111 63202 2674e1a31c0 135 API calls 63203 2674e1a3560 63202->63203 63724 2674e1a1130 63203->63724 63205 2674e1a356d 63728 2674e174580 63205->63728 63207 2674e1a359a 63736 2674e160e50 63207->63736 63209 2674e1a35f3 63210 2674e160e50 45 API calls 63209->63210 63211 2674e1a3643 63210->63211 63212 2674e174580 45 API calls 63211->63212 63213 2674e1a36a5 63212->63213 63214 2674e160e50 45 API calls 63213->63214 63215 2674e1a3703 63214->63215 63216 2674e160e50 45 API calls 63215->63216 63217 2674e1a3753 63216->63217 63218 2674e174580 45 API calls 63217->63218 63219 2674e1a37bb 63218->63219 63220 2674e160e50 45 API calls 63219->63220 63221 2674e1a3819 63220->63221 63222 2674e160e50 45 API calls 63221->63222 63223 2674e1a3869 63222->63223 63224 2674e174580 45 API calls 63223->63224 63225 2674e1a38be 63224->63225 63226 2674e160e50 45 API calls 63225->63226 63227 2674e1a3905 63226->63227 63228 2674e160e50 45 API calls 63227->63228 63229 2674e1a3941 63228->63229 63230 2674e1a396b GlobalMemoryStatusEx 63229->63230 63231 2674e1a399b 63230->63231 63232 2674e160e50 45 API calls 63231->63232 63233 2674e1a3a46 63232->63233 63234 2674e160e50 45 API calls 63233->63234 63235 2674e1a3a96 63234->63235 63236 2674e174580 45 API calls 63235->63236 63237 2674e1a3aec 63236->63237 63238 2674e160e50 45 API calls 63237->63238 63239 2674e1a3b48 63238->63239 63240 2674e160e50 45 API calls 63239->63240 63241 2674e1a3b9a 63240->63241 63242 2674e174580 45 API calls 63241->63242 63243 2674e1a3bec 63242->63243 63244 2674e160e50 45 API calls 63243->63244 63245 2674e1a3c4b 63244->63245 63246 2674e160e50 45 API calls 63245->63246 63247 2674e1a3d1a 63246->63247 63750 2674e1a0ce0 12 API calls 63247->63750 63253 2674e1a3d95 63254 2674e160e50 45 API calls 63253->63254 63255 2674e1a3dee 63254->63255 63256 2674e160e50 45 API calls 63255->63256 63257 2674e1a3eaa ISource 63256->63257 63266 2674e1a4e1d 63257->63266 63785 2674e1a0b10 GetDesktopWindow GetWindowRect 63257->63785 63319 2674e198382 63318->63319 63319->63319 63320 2674e186f60 46 API calls 63319->63320 63321 2674e198396 63320->63321 63321->63114 64126 2674e1a0a50 GetUserGeoID GetGeoInfoA 63322->64126 63325 2674e174580 45 API calls 63326 2674e19ae16 63325->63326 63327 2674e160e50 45 API calls 63326->63327 63328 2674e19ae5c 63327->63328 63329 2674e160e50 45 API calls 63328->63329 63330 2674e19ae98 63329->63330 63331 2674e19aec2 WSAStartup 63330->63331 63332 2674e19aedc socket 63331->63332 63345 2674e19b04f ISource 63331->63345 63333 2674e19af02 htons 63332->63333 63334 2674e19b049 WSACleanup 63332->63334 63335 2674e19b0ef 63333->63335 63344 2674e19af35 _Strxfrm 63333->63344 63334->63345 64136 2674e199f00 SHGetKnownFolderPath 63335->64136 63337 2674e1ce010 _Strcoll 3 API calls 63338 2674e197abf 63337->63338 63338->63122 63338->63123 63339 2674e1b8030 42 API calls 63339->63344 63340 2674e19b100 ISource 63341 2674e19b1f3 63340->63341 63342 2674e199f00 47 API calls 63340->63342 63342->63345 63344->63339 63346 2674e19affc inet_pton connect 63344->63346 63348 2674e19b03c closesocket 63344->63348 64132 2674e1ac280 63344->64132 63345->63337 63345->63341 63346->63344 63347 2674e19b0cd 63346->63347 63347->63335 63349 2674e163610 45 API calls 63347->63349 63348->63334 63349->63335 63351 2674e15d956 6 API calls 63350->63351 63352 2674e15e800 __crtLCMapStringW 63350->63352 63351->63352 63361 2674e15dd15 ISource 63351->63361 63353 2674e1ce010 _Strcoll 3 API calls 63352->63353 63354 2674e15e83d 63353->63354 63370 2674e15e8f0 CreateToolhelp32Snapshot 63354->63370 63355 2674e193180 45 API calls 63355->63361 63356 2674e164320 45 API calls 63356->63361 63357 2674e1645f0 45 API calls 63357->63361 63358 2674e160e50 45 API calls 63358->63361 63359 2674e165910 45 API calls 63359->63361 63360 2674e1ce2d0 45 API calls std::_Facet_Register 63360->63361 63361->63352 63361->63355 63361->63356 63361->63357 63361->63358 63361->63359 63361->63360 63363 2674e15e8b5 63361->63363 63364 2674e1628d0 45 API calls 63361->63364 63366 2674e15e85e 63361->63366 64144 2674e17a720 45 API calls std::_Facet_Register 63361->64144 64145 2674e16bb00 45 API calls 2 library calls 63361->64145 63364->63361 63367 2674e166710 45 API calls 63366->63367 63368 2674e15e8a2 63367->63368 63369 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 63368->63369 63369->63363 63371 2674e15e955 memcpy_s 63370->63371 63372 2674e160300 63 API calls 63371->63372 63373 2674e15e961 63372->63373 63374 2674e15e96c Process32FirstW 63373->63374 63375 2674e15eb84 63373->63375 63384 2674e15e980 ISource 63374->63384 63376 2674e160220 45 API calls 63375->63376 63377 2674e15eb97 63376->63377 63379 2674e164320 45 API calls 63377->63379 63381 2674e15ed72 ISource _invalid_parameter_noinfo 63377->63381 63378 2674e193180 45 API calls 63378->63384 63380 2674e15ebd5 63379->63380 63383 2674e1645f0 45 API calls 63380->63383 63386 2674e1ce010 _Strcoll 3 API calls 63381->63386 63392 2674e15ee84 63381->63392 63382 2674e16afc0 45 API calls 63382->63384 63388 2674e15ebe9 63383->63388 63384->63375 63384->63378 63384->63382 63385 2674e165630 45 API calls 63384->63385 63384->63392 63394 2674e168db0 45 API calls 63384->63394 63395 2674e15eb5f Process32NextW 63384->63395 64146 2674e163c90 63384->64146 63385->63384 63387 2674e15ee63 63386->63387 63396 2674e15ef90 63387->63396 63389 2674e160e50 45 API calls 63388->63389 63390 2674e15ecbb 63389->63390 63393 2674e160e50 45 API calls 63390->63393 63393->63381 63394->63384 63395->63384 63397 2674e15efe4 memcpy_s 63396->63397 63398 2674e160300 63 API calls 63397->63398 63399 2674e15eff0 63398->63399 64150 2674e1a21e0 63399->64150 63401 2674e15f727 63402 2674e1a21e0 48 API calls 63401->63402 63423 2674e15f74d ISource 63402->63423 63403 2674e15f90c 63404 2674e160220 45 API calls 63403->63404 63405 2674e15f92b 63404->63405 63409 2674e164320 45 API calls 63405->63409 63420 2674e15fae2 ISource 63405->63420 63406 2674e16afc0 45 API calls 63406->63423 63407 2674e165630 45 API calls 63415 2674e15f57a ISource 63407->63415 63408 2674e163c90 62 API calls 63408->63415 63411 2674e15f969 63409->63411 63410 2674e16afc0 45 API calls 63410->63415 63412 2674e1645f0 45 API calls 63411->63412 63416 2674e15f97f 63412->63416 63413 2674e168db0 45 API calls 63413->63415 63414 2674e163c90 62 API calls 63414->63423 63415->63401 63415->63407 63415->63408 63415->63410 63415->63413 63418 2674e15fd59 63415->63418 63421 2674e160e50 45 API calls 63416->63421 63417 2674e165630 45 API calls 63417->63423 63419 2674e168db0 45 API calls 63419->63423 63420->63418 63422 2674e1ce010 _Strcoll 3 API calls 63420->63422 63425 2674e15fa2c 63421->63425 63424 2674e15fd38 63422->63424 63423->63403 63423->63406 63423->63414 63423->63417 63423->63418 63423->63419 63427 2674e15fda0 63424->63427 63426 2674e160e50 45 API calls 63425->63426 63426->63420 64163 2674e1a55f0 63427->64163 63429 2674e15fdf6 memcpy_s 63430 2674e160300 63 API calls 63429->63430 63446 2674e15fe11 ISource _Strxfrm 63430->63446 63431 2674e15ff22 63432 2674e160220 45 API calls 63431->63432 63433 2674e15ff2f 63432->63433 63435 2674e164320 45 API calls 63433->63435 63449 2674e160102 ISource 63433->63449 63436 2674e15ff5f 63435->63436 63438 2674e1645f0 45 API calls 63436->63438 63442 2674e15ff76 63438->63442 63439 2674e163c90 62 API calls 63439->63446 63440 2674e1ce010 _Strcoll 3 API calls 63441 2674e1601e5 63440->63441 63450 2674e15cd10 CredEnumerateA 63441->63450 63444 2674e160e50 45 API calls 63442->63444 63443 2674e168db0 45 API calls 63443->63446 63447 2674e16004b 63444->63447 63445 2674e160206 63446->63431 63446->63439 63446->63443 63446->63445 64171 2674e193290 45 API calls 2 library calls 63446->64171 64172 2674e16afc0 63446->64172 63448 2674e160e50 45 API calls 63447->63448 63448->63449 63449->63440 63449->63445 63451 2674e15d78a 63450->63451 63460 2674e15cd80 ISource 63450->63460 63452 2674e1ce010 _Strcoll 3 API calls 63451->63452 63454 2674e15d799 63452->63454 63453 2674e15d77d CredFree 63453->63451 63469 2674e182590 63454->63469 63455 2674e1ce2d0 45 API calls std::_Facet_Register 63455->63460 63456 2674e164320 45 API calls 63456->63460 63457 2674e1645f0 45 API calls 63457->63460 63458 2674e160e50 45 API calls 63458->63460 63459 2674e165910 45 API calls 63459->63460 63460->63453 63460->63455 63460->63456 63460->63457 63460->63458 63460->63459 63462 2674e15d7ba 63460->63462 63463 2674e15d80b ISource 63460->63463 63464 2674e1628d0 45 API calls 63460->63464 64190 2674e17a720 45 API calls std::_Facet_Register 63460->64190 64191 2674e16bb00 45 API calls 2 library calls 63460->64191 63466 2674e166710 45 API calls 63462->63466 63464->63460 63467 2674e15d7f8 63466->63467 63468 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 63467->63468 63468->63463 63470 2674e1828af 63469->63470 63476 2674e1825e5 ISource 63469->63476 63471 2674e1ce010 _Strcoll 3 API calls 63470->63471 63472 2674e1828bb 63471->63472 63481 2674e185270 63472->63481 63473 2674e150680 49 API calls 63473->63476 63475 2674e14f5f0 45 API calls 63475->63476 63476->63470 63476->63473 63476->63475 63477 2674e182905 63476->63477 63478 2674e1828dc 63476->63478 63480 2674e1828f0 63476->63480 64192 2674e14feb0 45 API calls Concurrency::cancel_current_task 63478->64192 64193 2674e14feb0 45 API calls Concurrency::cancel_current_task 63480->64193 63482 2674e18558f 63481->63482 63490 2674e1852c5 ISource 63481->63490 63483 2674e1ce010 _Strcoll 3 API calls 63482->63483 63484 2674e18559b 63483->63484 63493 2674e152f30 63484->63493 63485 2674e150680 49 API calls 63485->63490 63486 2674e1855d0 64195 2674e14feb0 45 API calls Concurrency::cancel_current_task 63486->64195 63488 2674e14f5f0 45 API calls 63488->63490 63489 2674e1855e5 63490->63482 63490->63485 63490->63486 63490->63488 63490->63489 63491 2674e1855bc 63490->63491 64194 2674e14feb0 45 API calls Concurrency::cancel_current_task 63491->64194 64196 2674e150ee0 63493->64196 63496 2674e152f63 63500 2674e153032 ISource 63496->63500 63506 2674e153234 63496->63506 64206 2674e152130 109 API calls 2 library calls 63496->64206 63499 2674e15323f 63502 2674e14ecf0 2 API calls 63499->63502 63500->63506 64201 2674e1515d0 63500->64201 63501 2674e1ce010 _Strcoll 3 API calls 63503 2674e15321b 63501->63503 63505 2674e153245 63502->63505 63510 2674e15b110 63503->63510 63504 2674e15308c 63504->63499 63509 2674e1531e9 ISource 63504->63509 64207 2674e152130 109 API calls 2 library calls 63504->64207 64208 2674e14ecf0 63506->64208 63508 2674e1531b5 63508->63506 63508->63509 63509->63501 63511 2674e15c162 63510->63511 63540 2674e15b16c ISource 63510->63540 63512 2674e1ce010 _Strcoll 3 API calls 63511->63512 63513 2674e15c171 63512->63513 63513->63141 63514 2674e15c1b1 64326 2674e14feb0 45 API calls Concurrency::cancel_current_task 63514->64326 63518 2674e14f5f0 45 API calls 63518->63540 63520 2674e150680 49 API calls 63520->63540 63521 2674e15c197 64325 2674e14feb0 45 API calls Concurrency::cancel_current_task 63521->64325 63524 2674e15c1cc 63528 2674e14ecf0 2 API calls 63524->63528 63525 2674e15c208 64327 2674e14fe40 63525->64327 63526 2674e15c21e 63527 2674e164320 45 API calls 63527->63540 63528->63525 63530 2674e1628d0 45 API calls 63530->63540 63531 2674e1645f0 45 API calls 63531->63540 63533 2674e161e70 45 API calls 63533->63540 63534 2674e160e50 45 API calls 63534->63540 63539 2674e174580 45 API calls 63539->63540 63540->63511 63540->63514 63540->63518 63540->63520 63540->63521 63540->63524 63540->63525 63540->63526 63540->63527 63540->63530 63540->63531 63540->63533 63540->63534 63540->63539 64212 2674e19b890 63540->64212 64268 2674e165440 63540->64268 64273 2674e193430 CryptUnprotectData 63540->64273 64281 2674e164160 63540->64281 64292 2674e19a950 63540->64292 64299 2674e162b20 45 API calls 3 library calls 63540->64299 64300 2674e14f2f0 63540->64300 64304 2674e14f180 63540->64304 64315 2674e160d70 45 API calls 2 library calls 63540->64315 64316 2674e150340 63540->64316 63543 2674e1985d7 memcpy_s 63542->63543 63544 2674e160300 63 API calls 63543->63544 63545 2674e1985e0 63544->63545 63547 2674e198605 63545->63547 64630 2674e198840 63545->64630 63548 2674e160220 45 API calls 63547->63548 63549 2674e198612 63548->63549 63550 2674e164320 45 API calls 63549->63550 63552 2674e198735 ISource 63549->63552 63551 2674e198644 63550->63551 63553 2674e1645f0 45 API calls 63551->63553 63554 2674e1ce010 _Strcoll 3 API calls 63552->63554 63556 2674e198829 63552->63556 63557 2674e19865c 63553->63557 63555 2674e197b1d 63554->63555 63559 2674e15c230 63555->63559 63558 2674e160e50 45 API calls 63557->63558 63558->63552 63560 2674e15c380 63559->63560 63561 2674e156f20 45 API calls 63560->63561 63562 2674e15c3bd ISource 63561->63562 63563 2674e150680 49 API calls 63562->63563 63566 2674e15ccc8 63562->63566 63571 2674e15c43b 63563->63571 63565 2674e15cc56 ISource 63567 2674e1ce010 _Strcoll 3 API calls 63565->63567 63568 2674e14fe40 45 API calls 63566->63568 63570 2674e15cc82 63567->63570 63582 2674e15cce4 63568->63582 63569 2674e15cca8 64647 2674e14feb0 45 API calls Concurrency::cancel_current_task 63569->64647 63589 2674e157b20 63570->63589 63572 2674e164160 50 API calls 63571->63572 63577 2674e15cafd ISource 63571->63577 63587 2674e15c54d ISource _Strcoll 63571->63587 63572->63587 63573 2674e19a950 103 API calls 63573->63587 63574 2674e150340 47 API calls 63574->63587 63576 2674e14f2f0 45 API calls 63576->63587 63577->63565 63577->63569 63579 2674e15cd08 63577->63579 63580 2674e14f180 45 API calls 63580->63587 63581 2674e164320 45 API calls 63581->63587 63584 2674e14ecf0 2 API calls 63582->63584 63583 2674e1645f0 45 API calls 63583->63587 63584->63579 63585 2674e174580 45 API calls 63585->63587 63586 2674e160e50 45 API calls 63586->63587 63587->63566 63587->63569 63587->63573 63587->63574 63587->63576 63587->63577 63587->63580 63587->63581 63587->63582 63587->63583 63587->63585 63587->63586 64644 2674e14f3d0 45 API calls 63587->64644 64645 2674e162b20 45 API calls 3 library calls 63587->64645 64646 2674e160d70 45 API calls 2 library calls 63587->64646 63591 2674e157b75 63589->63591 63594 2674e157bd2 63589->63594 63644->63105 63645->63109 63649 2674e1a1db8 63648->63649 63652 2674e1a1e18 63648->63652 63807 2674e193180 63649->63807 63651 2674e1a1dc7 63651->63652 63816 2674e1af298 44 API calls 63651->63816 63653 2674e1ce010 _Strcoll 3 API calls 63652->63653 63654 2674e1a1e90 63653->63654 63656 2674e1a1400 63654->63656 63833 2674e19aa40 63656->63833 63658 2674e1a1448 GetVolumeInformationW 63661 2674e1a14a7 ISource memcpy_s 63658->63661 63660 2674e1a14f6 63663 2674e1ce010 _Strcoll 3 API calls 63660->63663 63661->63660 63662 2674e1a15cc 63661->63662 63844 2674e193a00 63 API calls 63661->63844 63664 2674e1a15b3 63663->63664 63664->63179 63666 2674e1a1532 63845 2674e193b40 62 API calls 2 library calls 63666->63845 63668 2674e1a1559 63846 2674e160220 63668->63846 63673 2674e1a8af9 63670->63673 63681 2674e1a8b79 63670->63681 63672 2674e1a8bf8 63862 2674e14d660 45 API calls 2 library calls 63672->63862 63676 2674e1a8b7e _Strxfrm 63673->63676 63677 2674e1a8b64 63673->63677 63678 2674e1a8b8c 63673->63678 63675 2674e1a8bfe 63676->63183 63677->63672 63679 2674e1ce2d0 std::_Facet_Register 45 API calls 63677->63679 63678->63676 63680 2674e1ce2d0 std::_Facet_Register 45 API calls 63678->63680 63679->63681 63680->63676 63681->63676 63861 2674e14d720 45 API calls 63681->63861 63683 2674e1a1709 memcpy_s 63682->63683 63684 2674e1ce2d0 std::_Facet_Register 45 API calls 63683->63684 63685 2674e1a176e 63684->63685 63863 2674e169960 63685->63863 63687 2674e1a17b1 EnumDisplayDevicesW 63690 2674e1a184c 63687->63690 63691 2674e1a17ae ISource 63687->63691 63688 2674e193180 45 API calls 63688->63691 63692 2674e1ce010 _Strcoll 3 API calls 63690->63692 63691->63687 63691->63688 63694 2674e1a198e 63691->63694 63873 2674e1a9340 45 API calls 2 library calls 63691->63873 63693 2674e1a196d 63692->63693 63695 2674e1a15e0 RegGetValueA 63693->63695 63696 2674e1a165b 63695->63696 63697 2674e1ce010 _Strcoll 3 API calls 63696->63697 63698 2674e1a169d 63697->63698 63699 2674e1a19a0 63698->63699 63700 2674e1a1a24 ISource 63699->63700 63701 2674e1a1d58 63700->63701 63875 2674e1dd070 GetNativeSystemInfo 63700->63875 63703 2674e1a1b08 63876 2674e186f60 63703->63876 63705 2674e1a1b9d ISource 63705->63701 63706 2674e1ce010 _Strcoll 3 API calls 63705->63706 63707 2674e1a1d40 63706->63707 63708 2674e1a12c0 63707->63708 63882 2674e1cf000 63708->63882 63711 2674e1a130f 63713 2674e193180 45 API calls 63711->63713 63712 2674e1a131c 63714 2674e1ce010 _Strcoll 3 API calls 63712->63714 63713->63712 63715 2674e1a134e 63714->63715 63716 2674e1a1360 63715->63716 63717 2674e1cf000 _Strcoll 63716->63717 63718 2674e1a1370 GetComputerNameW 63717->63718 63719 2674e1a13af 63718->63719 63720 2674e1a13bc 63718->63720 63721 2674e193180 45 API calls 63719->63721 63722 2674e1ce010 _Strcoll 3 API calls 63720->63722 63721->63720 63723 2674e1a13ee 63722->63723 63723->63202 63725 2674e1a1230 63724->63725 63884 2674e1a0420 63725->63884 63727 2674e1a1254 ISource 63727->63205 63729 2674e1745b3 63728->63729 63730 2674e1ce2d0 std::_Facet_Register 45 API calls 63729->63730 63731 2674e1745c8 63730->63731 63732 2674e161e70 45 API calls 63731->63732 63733 2674e1745e5 63732->63733 63734 2674e1ce010 _Strcoll 3 API calls 63733->63734 63735 2674e1745fe 63734->63735 63735->63207 63737 2674e160e87 63736->63737 63738 2674e160e8f 63736->63738 63927 2674e166ad0 45 API calls 2 library calls 63737->63927 63742 2674e160f24 63738->63742 63917 2674e166990 63738->63917 63741 2674e160ead 63741->63742 63743 2674e160ee0 ISource 63741->63743 63745 2674e166710 45 API calls 63742->63745 63744 2674e1ce010 _Strcoll 3 API calls 63743->63744 63746 2674e160f0f 63744->63746 63747 2674e160f59 63745->63747 63746->63209 63748 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 63747->63748 63749 2674e160f6a 63748->63749 63751 2674e1a0e30 SelectObject DeleteDC ReleaseDC DeleteObject 63750->63751 63752 2674e1a0e98 63750->63752 63753 2674e1a0e90 63751->63753 63929 2674e1999b0 63752->63929 63757 2674e1ce010 _Strcoll 3 API calls 63753->63757 63755 2674e1a0f45 EnterCriticalSection LeaveCriticalSection 63937 2674e199b40 GetObjectW 63755->63937 63760 2674e1a1105 63757->63760 63774 2674e164320 63760->63774 63762 2674e1a0fd8 63763 2674e1a1025 IStream_Read 63762->63763 63766 2674e1a0fca memcpy_s 63762->63766 63964 2674e1ac940 63762->63964 63765 2674e1a103a memcpy_s 63763->63765 63976 2674e160300 63765->63976 63766->63763 64064 2674e161cc0 63774->64064 63776 2674e16438a 63777 2674e161cc0 45 API calls 63776->63777 63778 2674e16449d 63777->63778 63779 2674e1645f0 63778->63779 63780 2674e164634 63779->63780 63781 2674e1ce2d0 std::_Facet_Register 45 API calls 63780->63781 63782 2674e164649 63781->63782 63783 2674e1ce010 _Strcoll 3 API calls 63782->63783 63784 2674e16469d 63783->63784 63784->63253 63786 2674e1a0b6a 63785->63786 63797->63179 63799 2674e1b806a 63798->63799 63804 2674e1b8049 63798->63804 63800 2674e1b956c _Getctype 42 API calls 63799->63800 63801 2674e1b806f 63800->63801 63802 2674e1bb7f4 _Getctype 42 API calls 63801->63802 63803 2674e1b8088 63802->63803 63803->63804 64125 2674e1bf168 42 API calls 3 library calls 63803->64125 63804->63183 63806 2674e1b80be 63806->63183 63808 2674e1931ce 63807->63808 63814 2674e1931af ISource 63807->63814 63808->63808 63817 2674e156ca0 63808->63817 63809 2674e1ce010 _Strcoll 3 API calls 63810 2674e19326e 63809->63810 63810->63651 63812 2674e1931f7 63830 2674e193290 45 API calls 2 library calls 63812->63830 63814->63809 63815 2674e19327c 63814->63815 63816->63651 63819 2674e156cc6 63817->63819 63826 2674e156dc1 63817->63826 63818 2674e156cd9 _Strxfrm 63818->63812 63819->63818 63821 2674e156d13 63819->63821 63822 2674e156dbc 63819->63822 63824 2674e156d75 63819->63824 63821->63822 63825 2674e156d5a 63821->63825 63831 2674e14d660 45 API calls 2 library calls 63822->63831 63828 2674e1ce2d0 std::_Facet_Register 45 API calls 63824->63828 63829 2674e156d62 _Strxfrm 63824->63829 63827 2674e1ce2d0 std::_Facet_Register 45 API calls 63825->63827 63832 2674e14d720 45 API calls 63826->63832 63827->63829 63828->63829 63829->63812 63830->63814 63831->63826 63850 2674e161a20 63833->63850 63836 2674e19aa9f 63839 2674e19ab4b 63836->63839 63856 2674e1db800 GetCurrentDirectoryW 63836->63856 63858 2674e1676b0 45 API calls 4 library calls 63836->63858 63841 2674e156ca0 45 API calls 63839->63841 63843 2674e19abbf 63839->63843 63840 2674e19ac6c 63841->63843 63842 2674e19ac28 ISource 63842->63658 63843->63842 63859 2674e14fd30 45 API calls 2 library calls 63843->63859 63844->63666 63845->63668 63847 2674e160268 63846->63847 63848 2674e1602d9 63847->63848 63849 2674e163610 45 API calls 63847->63849 63848->63660 63849->63848 63851 2674e161a35 63850->63851 63852 2674e161a50 63850->63852 63851->63836 63853 2674e161a62 63852->63853 63860 2674e1676b0 45 API calls 4 library calls 63852->63860 63853->63836 63855 2674e161aa3 63855->63836 63857 2674e1db812 __std_fs_get_current_path 63856->63857 63857->63836 63858->63836 63859->63840 63860->63855 63862->63675 63864 2674e16998c 63863->63864 63872 2674e1699c7 ISource 63863->63872 63865 2674e169a92 63864->63865 63867 2674e1699de 63864->63867 63868 2674e1699b5 63864->63868 63874 2674e14d660 45 API calls 2 library calls 63865->63874 63871 2674e1ce2d0 std::_Facet_Register 45 API calls 63867->63871 63867->63872 63868->63865 63869 2674e1699c2 63868->63869 63870 2674e1ce2d0 std::_Facet_Register 45 API calls 63869->63870 63870->63872 63871->63872 63872->63691 63873->63691 63874->63872 63875->63703 63877 2674e187025 63876->63877 63880 2674e186f90 _Strxfrm 63876->63880 63881 2674e18b130 46 API calls 4 library calls 63877->63881 63879 2674e18703a 63879->63705 63880->63705 63881->63879 63883 2674e1a12d0 GetUserNameW 63882->63883 63883->63711 63883->63712 63885 2674e1a0482 63884->63885 63886 2674e1a0640 InternetOpenA 63884->63886 63914 2674e1ce1c0 EnterCriticalSection LeaveCriticalSection 63885->63914 63887 2674e1a0687 InternetOpenUrlA 63886->63887 63894 2674e1a0664 63886->63894 63891 2674e1a06fa HttpQueryInfoW 63887->63891 63887->63894 63890 2674e1ce010 _Strcoll 3 API calls 63892 2674e1a0a20 63890->63892 63893 2674e1a0757 HttpQueryInfoW 63891->63893 63891->63894 63892->63727 63896 2674e1a07d4 InternetQueryDataAvailable 63893->63896 63897 2674e1a07ad 63893->63897 63894->63890 63899 2674e1a09be InternetCloseHandle 63896->63899 63912 2674e1a07ef 63896->63912 63915 2674e1b5310 42 API calls 2 library calls 63897->63915 63899->63894 63900 2674e1a07bc 63900->63896 63903 2674e1a088c InternetReadFile 63904 2674e1a0978 63903->63904 63909 2674e1a0841 ISource memcpy_s _Strxfrm 63903->63909 63904->63899 63907 2674e1a09ad ISource 63904->63907 63911 2674e1a0a3b 63904->63911 63905 2674e1ce2d0 std::_Facet_Register 45 API calls 63905->63909 63907->63899 63908 2674e1ce2d0 std::_Facet_Register 45 API calls 63908->63912 63909->63903 63909->63904 63909->63905 63909->63911 63909->63912 63913 2674e1a0954 InternetQueryDataAvailable 63909->63913 63910 2674e1a0a46 63916 2674e14d660 45 API calls 2 library calls 63911->63916 63912->63899 63912->63903 63912->63908 63912->63909 63912->63911 63913->63899 63913->63909 63915->63900 63916->63910 63918 2674e1669b6 63917->63918 63919 2674e1669fc 63918->63919 63920 2674e166ac1 63918->63920 63926 2674e166a6d 63918->63926 63922 2674e1ce2d0 std::_Facet_Register 45 API calls 63919->63922 63928 2674e14d740 45 API calls 63920->63928 63924 2674e166a18 63922->63924 63925 2674e1628d0 45 API calls 63924->63925 63925->63926 63926->63741 63927->63738 63930 2674e1999d0 63929->63930 63936 2674e199a2f 63929->63936 64006 2674e1ce1c0 EnterCriticalSection LeaveCriticalSection 63930->64006 63936->63755 63938 2674e199b84 63937->63938 63939 2674e1ce010 _Strcoll 3 API calls 63938->63939 63940 2674e199c1e 63939->63940 63941 2674e199c30 63940->63941 63942 2674e1999b0 11 API calls 63941->63942 63943 2674e199c64 63942->63943 63944 2674e199cac 63943->63944 63945 2674e199c6d EnterCriticalSection 63943->63945 63949 2674e1ce010 _Strcoll 3 API calls 63944->63949 63946 2674e199cd0 LeaveCriticalSection GdipGetImageEncodersSize 63945->63946 63947 2674e199c7e GdiplusStartup 63945->63947 63946->63944 63950 2674e199cec 63946->63950 63947->63946 63948 2674e199ca2 LeaveCriticalSection 63947->63948 63948->63944 63951 2674e199cbd IStream_Size IStream_Reset 63949->63951 63953 2674e199d08 _Strcoll 63950->63953 64007 2674e199740 IsProcessorFeaturePresent RtlCaptureContext RtlLookupFunctionEntry _Strcoll 63950->64007 63951->63762 63951->63766 63954 2674e199d6d GdipGetImageEncoders 63953->63954 63955 2674e199d63 63953->63955 63954->63955 63956 2674e199d84 63954->63956 63955->63944 64008 2674e1b0410 8 API calls 3 library calls 63955->64008 63956->63955 63958 2674e199e72 GdipCreateBitmapFromHBITMAP GdipSaveImageToStream 63956->63958 63959 2674e199e07 GdipCreateBitmapFromScan0 GdipSaveImageToStream 63956->63959 63961 2674e199e62 GdipDisposeImage 63958->63961 63962 2674e199eca GdipDisposeImage 63958->63962 63960 2674e199e70 63959->63960 63959->63961 63960->63962 63961->63955 63962->63955 63965 2674e1ac96c 63964->63965 63974 2674e1ac99f memcpy_s _Strxfrm 63964->63974 63966 2674e1ac98b 63965->63966 63969 2674e1ac9e6 63965->63969 63968 2674e1aca94 63966->63968 63970 2674e1ce2d0 std::_Facet_Register 45 API calls 63966->63970 64010 2674e14d660 45 API calls 2 library calls 63968->64010 63972 2674e1ce2d0 std::_Facet_Register 45 API calls 63969->63972 63969->63974 63970->63974 63972->63974 63973 2674e1aca9a 63975 2674e1aca5a ISource 63974->63975 64009 2674e160a00 45 API calls ISource 63974->64009 63975->63766 63977 2674e163950 63 API calls 63976->63977 63978 2674e1603a3 63977->63978 64011 2674e162dd0 63978->64011 64007->63953 64008->63955 64009->63968 64010->63973 64012 2674e163560 48 API calls 64011->64012 64013 2674e16041a 64012->64013 64065 2674e161cd5 64064->64065 64066 2674e161ceb 64064->64066 64065->63776 64067 2674e1679e0 45 API calls 64066->64067 64069 2674e161d05 memcpy_s 64066->64069 64068 2674e161d51 64067->64068 64068->63776 64069->63776 64125->63806 64127 2674e161cc0 45 API calls 64126->64127 64128 2674e1a0ac1 GetGeoInfoA 64127->64128 64130 2674e161cc0 45 API calls 64128->64130 64131 2674e19adf3 64130->64131 64131->63325 64133 2674e1ac2a1 64132->64133 64134 2674e1b8030 42 API calls 64133->64134 64135 2674e1ac2e9 _Strxfrm 64133->64135 64134->64133 64135->63344 64137 2674e19a015 CoTaskMemFree 64136->64137 64139 2674e199f67 64136->64139 64138 2674e1ce010 _Strcoll 3 API calls 64137->64138 64140 2674e19a030 64138->64140 64139->64139 64141 2674e156ca0 45 API calls 64139->64141 64140->63340 64142 2674e199f99 ISource 64141->64142 64142->64137 64143 2674e19a042 64142->64143 64144->63361 64145->63361 64147 2674e163cb4 64146->64147 64148 2674e163e30 62 API calls 64147->64148 64149 2674e163cc6 64148->64149 64149->63384 64151 2674e1a2254 RegOpenKeyExA 64150->64151 64152 2674e1a249b 64151->64152 64156 2674e1a2277 64151->64156 64154 2674e1a24a4 RegCloseKey 64152->64154 64155 2674e1a24aa 64152->64155 64153 2674e1a2284 RegEnumKeyExA 64153->64156 64154->64155 64157 2674e1ce010 _Strcoll 3 API calls 64155->64157 64156->64152 64156->64153 64159 2674e1a24dd 64156->64159 64158 2674e1a24bc 64157->64158 64158->63415 64162 2674e14d720 45 API calls 64159->64162 64164 2674e1a5616 ISource wcsftime 64163->64164 64167 2674e1a5708 wcsftime 64164->64167 64168 2674e1a5735 64164->64168 64186 2674e1a91f0 45 API calls 3 library calls 64164->64186 64187 2674e1ac520 45 API calls 3 library calls 64164->64187 64167->63429 64169 2674e1a5773 RtlInitUnicodeString RtlInitUnicodeString 64168->64169 64170 2674e1a57a4 64168->64170 64169->63429 64170->63429 64171->63446 64173 2674e16affd 64172->64173 64175 2674e16b032 64173->64175 64176 2674e168db0 45 API calls 64173->64176 64174 2674e16b066 64177 2674e16b1dd 64174->64177 64178 2674e16b21c 64174->64178 64175->64174 64185 2674e1617e0 45 API calls 64175->64185 64176->64175 64179 2674e16b1ee 64177->64179 64188 2674e169890 45 API calls 2 library calls 64177->64188 64189 2674e14eb40 45 API calls 64178->64189 64179->63446 64182 2674e16b260 64183 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 64182->64183 64184 2674e16b271 64183->64184 64185->64174 64186->64164 64187->64164 64188->64179 64189->64182 64190->63460 64191->63460 64198 2674e1511f0 ISource 64196->64198 64197 2674e1ce010 _Strcoll 3 API calls 64199 2674e1513c4 64197->64199 64198->64197 64200 2674e1514f9 64198->64200 64199->63496 64200->63496 64202 2674e1518e0 ISource 64201->64202 64203 2674e1ce010 _Strcoll 3 API calls 64202->64203 64204 2674e151be9 64202->64204 64205 2674e151ab4 64203->64205 64205->63504 64206->63500 64207->63508 64209 2674e14ed0d 64208->64209 64210 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 64209->64210 64211 2674e14ed1e 64210->64211 64213 2674e19b90b 64212->64213 64214 2674e14f5f0 45 API calls 64213->64214 64215 2674e19b930 ISource 64214->64215 64216 2674e150680 49 API calls 64215->64216 64222 2674e19be33 64215->64222 64218 2674e19b999 memcpy_s 64216->64218 64217 2674e19bce2 64217->64222 64257 2674e19bef1 64217->64257 64261 2674e19bae3 ISource 64217->64261 64218->64217 64223 2674e1a8c00 75 API calls 64218->64223 64221 2674e1ce010 _Strcoll 3 API calls 64224 2674e19bdc5 64221->64224 64337 2674e14eb40 45 API calls 64222->64337 64226 2674e19ba17 64223->64226 64224->63540 64230 2674e1a8fb0 46 API calls 64226->64230 64267 2674e19bc67 64226->64267 64227 2674e19be65 64228 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 64227->64228 64231 2674e19be76 64228->64231 64232 2674e19ba59 64230->64232 64338 2674e14eb40 45 API calls 64231->64338 64234 2674e19ba76 64232->64234 64235 2674e19baf9 64232->64235 64234->64222 64238 2674e19baa8 64234->64238 64236 2674e1a7710 45 API calls 64235->64236 64239 2674e19bb0d 64236->64239 64237 2674e19be9f 64240 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 64237->64240 64241 2674e1a7550 46 API calls 64238->64241 64243 2674e19bb24 64239->64243 64244 2674e19bba7 64239->64244 64248 2674e19beb3 64240->64248 64242 2674e19bab5 64241->64242 64333 2674e172ab0 43 API calls 64242->64333 64243->64231 64247 2674e19bb56 64243->64247 64246 2674e1a7710 45 API calls 64244->64246 64249 2674e19bbbb 64246->64249 64250 2674e1a7550 46 API calls 64247->64250 64339 2674e14eb40 45 API calls 64248->64339 64253 2674e1a7710 45 API calls 64249->64253 64254 2674e19bb63 64250->64254 64252 2674e19bedd 64255 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 64252->64255 64256 2674e19bbca 64253->64256 64334 2674e172ab0 43 API calls 64254->64334 64255->64257 64258 2674e185d00 46 API calls 64256->64258 64340 2674e14feb0 45 API calls Concurrency::cancel_current_task 64257->64340 64260 2674e19bbda 64258->64260 64260->64248 64262 2674e1a7550 46 API calls 64260->64262 64261->64221 64263 2674e19bc1a 64262->64263 64264 2674e161e70 45 API calls 64263->64264 64265 2674e19bc2a 64264->64265 64335 2674e172ab0 43 API calls 64265->64335 64267->64261 64336 2674e1738d0 43 API calls 64267->64336 64269 2674e161cc0 45 API calls 64268->64269 64270 2674e165498 _Strxfrm 64269->64270 64271 2674e161cc0 45 API calls 64270->64271 64272 2674e1655d9 64271->64272 64272->63540 64274 2674e193496 64273->64274 64275 2674e19355c 64273->64275 64277 2674e1934bd memcpy_s _Strxfrm 64274->64277 64279 2674e1679e0 45 API calls 64274->64279 64276 2674e1ce010 _Strcoll 3 API calls 64275->64276 64278 2674e193576 64276->64278 64280 2674e193516 LocalFree 64277->64280 64278->63540 64279->64277 64280->64275 64282 2674e156f20 45 API calls 64281->64282 64283 2674e1641ac 64282->64283 64341 2674e14ff10 64283->64341 64287 2674e1ce2d0 std::_Facet_Register 45 API calls 64289 2674e16420f 64287->64289 64288 2674e1642de 64290 2674e1ce010 _Strcoll 3 API calls 64288->64290 64350 2674e1db76c 43 API calls __std_fs_directory_iterator_open 64289->64350 64291 2674e1642fa 64290->64291 64291->63540 64362 2674e19a050 64292->64362 64295 2674e164320 45 API calls 64296 2674e19a9aa 64295->64296 64297 2674e1ce010 _Strcoll 3 API calls 64296->64297 64298 2674e19aa2d 64297->64298 64298->63540 64299->63540 64303 2674e14f310 64300->64303 64301 2674e156ca0 45 API calls 64302 2674e14f39a 64301->64302 64302->63540 64303->64301 64305 2674e14f1b0 64304->64305 64618 2674e1db4ec 64305->64618 64307 2674e14f247 64307->63540 64308 2674e14f1bc __std_fs_convert_wide_to_narrow 64308->64307 64309 2674e14f294 64308->64309 64311 2674e161cc0 45 API calls 64308->64311 64622 2674e14edc0 RtlPcToFileHeader RaiseException Concurrency::cancel_current_task 64309->64622 64313 2674e14f220 __std_fs_convert_wide_to_narrow 64311->64313 64313->64307 64621 2674e14edc0 RtlPcToFileHeader RaiseException Concurrency::cancel_current_task 64313->64621 64315->63540 64318 2674e150370 64316->64318 64317 2674e1db74c 2 API calls 64317->64318 64318->64317 64319 2674e15043e 64318->64319 64321 2674e1503ab 64318->64321 64628 2674e14fd30 45 API calls 2 library calls 64319->64628 64320 2674e1ce010 _Strcoll 3 API calls 64323 2674e150429 64320->64323 64321->64320 64323->63540 64324 2674e15044c 64328 2674e14fe59 64327->64328 64629 2674e14f7f0 45 API calls ISource 64328->64629 64330 2674e14fe90 64331 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 64330->64331 64332 2674e14fea1 64331->64332 64333->64261 64334->64261 64335->64267 64336->64217 64337->64227 64338->64237 64339->64252 64342 2674e14ff33 64341->64342 64343 2674e156ca0 45 API calls 64342->64343 64347 2674e15005b 64342->64347 64344 2674e14ff8f ISource 64343->64344 64345 2674e150096 64344->64345 64351 2674e1db78c 64344->64351 64347->64287 64347->64289 64349 2674e150028 64349->64347 64358 2674e1db74c FindNextFileW 64349->64358 64350->64288 64352 2674e1db7aa FindClose 64351->64352 64353 2674e1db7b7 FindFirstFileExW 64351->64353 64352->64353 64354 2674e1db7f8 64352->64354 64355 2674e1db7de __std_fs_get_current_path 64353->64355 64361 2674e1cb5c4 42 API calls 2 library calls 64354->64361 64355->64349 64359 2674e1db761 GetLastError 64358->64359 64360 2674e1db75a 64358->64360 64360->64349 64363 2674e150680 49 API calls 64362->64363 64364 2674e19a0a1 64363->64364 64365 2674e19a78e 64364->64365 64369 2674e19a0dd memcpy_s 64364->64369 64366 2674e19a7cc 64365->64366 64412 2674e19a73e 64365->64412 64455 2674e14feb0 45 API calls Concurrency::cancel_current_task 64366->64455 64368 2674e1ce010 _Strcoll 3 API calls 64370 2674e19a7b0 64368->64370 64371 2674e1a8c00 75 API calls 64369->64371 64369->64412 64370->64295 64370->64296 64372 2674e19a108 64371->64372 64373 2674e19a144 64372->64373 64374 2674e19a589 64372->64374 64449 2674e1a4e80 22 API calls 2 library calls 64373->64449 64419 2674e176ac0 64374->64419 64380 2674e19a7e2 64456 2674e14eb40 45 API calls 64380->64456 64381 2674e19a156 64450 2674e1a5080 55 API calls 6 library calls 64381->64450 64383 2674e19a5b7 64390 2674e176ac0 61 API calls 64383->64390 64385 2674e19a167 64387 2674e19a26a GetFileSize 64385->64387 64388 2674e19a17a 64385->64388 64386 2674e19a80e 64389 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 64386->64389 64393 2674e19a2ab 64387->64393 64397 2674e19a286 memcpy_s 64387->64397 64388->64380 64391 2674e19a1c1 ISource 64388->64391 64402 2674e19a81f 64389->64402 64392 2674e19a5f0 64390->64392 64451 2674e1738d0 43 API calls 64391->64451 64438 2674e1a8da0 64392->64438 64393->64397 64398 2674e1679e0 45 API calls 64393->64398 64396 2674e19a310 SetFilePointer 64399 2674e19a357 _fread_nolock 64396->64399 64397->64396 64398->64396 64413 2674e19a48b 64399->64413 64415 2674e19a35f 64399->64415 64400 2674e19a219 64400->64412 64457 2674e14eb40 45 API calls 64402->64457 64409 2674e19a4e0 ISource 64453 2674e1738d0 43 API calls 64409->64453 64410 2674e19a3e2 ISource 64452 2674e1738d0 43 API calls 64410->64452 64411 2674e19a864 64417 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 64411->64417 64412->64368 64413->64380 64413->64409 64415->64380 64415->64410 64418 2674e19a875 64417->64418 64420 2674e176b1d 64419->64420 64422 2674e176c02 64419->64422 64458 2674e177340 64420->64458 64506 2674e14eb40 45 API calls 64422->64506 64423 2674e176b42 64427 2674e176b79 64423->64427 64496 2674e172eb0 64423->64496 64425 2674e176bcf 64434 2674e1769e0 64425->64434 64426 2674e176c44 64428 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 64426->64428 64427->64425 64507 2674e14eb40 45 API calls 64427->64507 64428->64427 64430 2674e176c9d 64431 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 64430->64431 64432 2674e176cb1 64431->64432 64435 2674e176a10 64434->64435 64436 2674e177340 61 API calls 64435->64436 64437 2674e176a1f 64436->64437 64437->64383 64439 2674e1a8df8 64438->64439 64440 2674e1a8e16 64438->64440 64439->64440 64448 2674e173290 45 API calls 64439->64448 64441 2674e1a8ed6 64440->64441 64601 2674e1aea20 64440->64601 64448->64440 64449->64381 64450->64385 64451->64400 64452->64400 64453->64400 64456->64386 64457->64411 64459 2674e177380 64458->64459 64463 2674e17735d 64458->64463 64461 2674e17738e 64459->64461 64462 2674e168db0 45 API calls 64459->64462 64460 2674e17737a 64460->64423 64461->64423 64462->64461 64463->64460 64508 2674e14eb40 45 API calls 64463->64508 64465 2674e1773e3 64466 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 64465->64466 64471 2674e1773f4 ISource 64466->64471 64467 2674e177555 64467->64423 64469 2674e17773d 64511 2674e1764b0 61 API calls 7 library calls 64469->64511 64471->64467 64509 2674e1764b0 61 API calls 7 library calls 64471->64509 64473 2674e17775c 64512 2674e16d350 45 API calls _Strcoll 64473->64512 64474 2674e17770a 64474->64469 64475 2674e1777e6 64474->64475 64510 2674e16d350 45 API calls _Strcoll 64474->64510 64477 2674e177811 64475->64477 64515 2674e176330 45 API calls 2 library calls 64475->64515 64485 2674e17783a ISource 64477->64485 64516 2674e175ec0 61 API calls 2 library calls 64477->64516 64480 2674e1777b3 64493 2674e1777e0 64480->64493 64514 2674e175ec0 61 API calls 2 library calls 64480->64514 64481 2674e177775 64481->64480 64481->64485 64481->64493 64513 2674e176330 45 API calls 2 library calls 64481->64513 64483 2674e17793a 64484 2674e177972 64483->64484 64484->64485 64488 2674e1ce010 _Strcoll 3 API calls 64485->64488 64489 2674e177a73 64485->64489 64491 2674e177a58 64488->64491 64491->64423 64492 2674e16d350 45 API calls 64492->64493 64493->64483 64493->64485 64493->64492 64494 2674e176330 45 API calls 64493->64494 64517 2674e175ec0 61 API calls 2 library calls 64493->64517 64494->64493 64497 2674e172ee3 64496->64497 64498 2674e172f3b 64497->64498 64499 2674e173f40 42 API calls 64497->64499 64500 2674e1ce010 _Strcoll 3 API calls 64498->64500 64501 2674e172f06 64499->64501 64502 2674e172fa9 64500->64502 64501->64498 64503 2674e172f26 64501->64503 64520 2674e1b0b4c 64501->64520 64502->64427 64503->64498 64528 2674e1b0164 64503->64528 64506->64426 64507->64430 64508->64465 64509->64474 64510->64474 64511->64473 64512->64481 64513->64480 64514->64493 64515->64477 64516->64485 64517->64493 64521 2674e1b0b7c 64520->64521 64537 2674e1b08fc 64521->64537 64524 2674e1b0bba 64529 2674e1b0178 64528->64529 64530 2674e1b018d 64528->64530 64571 2674e1b54cc 7 API calls _Strcoll 64529->64571 64530->64529 64532 2674e1b0192 64530->64532 64563 2674e1be2bc 64532->64563 64533 2674e1b017d 64572 2674e1b1008 42 API calls _invalid_parameter_noinfo 64533->64572 64536 2674e1b0188 64536->64498 64538 2674e1b0966 64537->64538 64539 2674e1b0926 64537->64539 64538->64539 64541 2674e1b096b 64538->64541 64556 2674e1b0f38 42 API calls _invalid_parameter_noinfo 64539->64556 64542 2674e1afd4c _fread_nolock EnterCriticalSection 64541->64542 64544 2674e1b0970 64542->64544 64543 2674e1b094d 64543->64524 64548 2674e1aefc8 42 API calls 3 library calls 64543->64548 64550 2674e1b0a74 64544->64550 64548->64524 64556->64543 64564 2674e1be2ec 64563->64564 64573 2674e1bddd0 64564->64573 64571->64533 64572->64536 64623 2674e1c60b8 64618->64623 64620 2674e1db4f5 __std_fs_code_page 64620->64308 64624 2674e1b956c _Getctype 42 API calls 64623->64624 64625 2674e1c60c1 64624->64625 64626 2674e1bb7f4 _Getctype 42 API calls 64625->64626 64627 2674e1c60da 64626->64627 64627->64620 64628->64324 64629->64330 64631 2674e198874 64630->64631 64632 2674e198877 RegOpenKeyExA 64630->64632 64631->64632 64633 2674e1988a3 RegCloseKey 64632->64633 64638 2674e1988a9 64632->64638 64633->64638 64634 2674e198924 64635 2674e1ce010 _Strcoll 3 API calls 64634->64635 64636 2674e19893b 64635->64636 64636->63545 64638->64634 64639 2674e1988d7 64638->64639 64643 2674e198950 68 API calls 3 library calls 64638->64643 64640 2674e1a21e0 48 API calls 64639->64640 64641 2674e1988fa 64640->64641 64641->64634 64642 2674e198840 71 API calls 64641->64642 64642->64641 64643->64638 64644->63587 64645->63587 64646->63587 64918 2674e182b50 64919 2674e150680 49 API calls 64918->64919 64920 2674e182bb0 64919->64920 64921 2674e150680 49 API calls 64920->64921 64922 2674e183440 64921->64922 64923 2674e14f2f0 45 API calls 64922->64923 64933 2674e18385c ISource 64922->64933 64925 2674e183479 64923->64925 64924 2674e1ce010 _Strcoll 3 API calls 64926 2674e183887 64924->64926 64927 2674e14f180 45 API calls 64925->64927 64928 2674e183486 64927->64928 64979 2674e185970 64928->64979 64931 2674e19a950 103 API calls 64932 2674e183553 64931->64932 64932->64933 64934 2674e1838a3 64932->64934 64933->64924 64935 2674e166710 45 API calls 64934->64935 64936 2674e1838e1 64935->64936 64937 2674e1d11d8 Concurrency::cancel_current_task 2 API calls 64936->64937 64938 2674e1838f4 64937->64938 64939 2674e14fe40 45 API calls 64938->64939 64940 2674e183904 64939->64940 64941 2674e14fe40 45 API calls 64940->64941 64942 2674e183916 64941->64942 64943 2674e14fe40 45 API calls 64942->64943 64944 2674e183926 64943->64944 64945 2674e14fe40 45 API calls 64944->64945 64946 2674e18394e 64945->64946 64947 2674e14ecf0 2 API calls 64946->64947 64948 2674e183960 64947->64948 64949 2674e14fe40 45 API calls 64948->64949 64950 2674e183976 64949->64950 64951 2674e14ecf0 2 API calls 64950->64951 64952 2674e183988 64951->64952 64953 2674e14f2f0 45 API calls 64952->64953 64954 2674e1839da 64953->64954 64955 2674e14f180 45 API calls 64954->64955 64956 2674e1839eb 64955->64956 64957 2674e14f5f0 45 API calls 64956->64957 64958 2674e183ee5 64957->64958 64959 2674e156f20 45 API calls 64958->64959 64960 2674e1840ee 64959->64960 64961 2674e19a050 103 API calls 64960->64961 64962 2674e184120 64961->64962 64983 2674e162140 63 API calls 4 library calls 64962->64983 64964 2674e1843ed 64984 2674e1663a0 45 API calls 3 library calls 64964->64984 64966 2674e184429 64975 2674e184e19 64966->64975 64985 2674e1505e0 52 API calls _Strcoll 64966->64985 64968 2674e184445 64969 2674e184f36 64968->64969 64968->64975 64970 2674e14ecf0 2 API calls 64969->64970 64971 2674e184f3b 64970->64971 64986 2674e14feb0 45 API calls Concurrency::cancel_current_task 64971->64986 64976 2674e1ce010 _Strcoll 3 API calls 64975->64976 64978 2674e184f07 64976->64978 64980 2674e185996 64979->64980 64981 2674e186f60 46 API calls 64980->64981 64982 2674e183499 64981->64982 64982->64931 64983->64964 64984->64966 64985->64968 64987 2674e1b9130 64988 2674e1b8f94 _fread_nolock 42 API calls 64987->64988 64990 2674e1b914f 64988->64990 64989 2674e1b918d 64991 2674e1b9156 64989->64991 64993 2674e1b91cd 64989->64993 65010 2674e1bdc84 42 API calls 2 library calls 64989->65010 64990->64989 64990->64991 65009 2674e1b90b4 42 API calls _fread_nolock 64990->65009 64998 2674e1b8fbc 64993->64998 64996 2674e1b91c1 64996->64993 65011 2674e1be360 64996->65011 64999 2674e1b8f94 _fread_nolock 42 API calls 64998->64999 65000 2674e1b8fe1 64999->65000 65001 2674e1b9081 65000->65001 65002 2674e1b8ff0 65000->65002 65025 2674e1bc4ac 42 API calls 2 library calls 65001->65025 65004 2674e1b900e 65002->65004 65007 2674e1b902c 65002->65007 65024 2674e1bc4ac 42 API calls 2 library calls 65004->65024 65006 2674e1b901c 65006->64991 65007->65006 65016 2674e1befb4 65007->65016 65009->64989 65010->64996 65012 2674e1bcf4c _Getctype 7 API calls 65011->65012 65013 2674e1be384 65012->65013 65014 2674e1bc8e4 __free_lconv_mon 7 API calls 65013->65014 65015 2674e1be38f 65014->65015 65015->64993 65017 2674e1befe4 65016->65017 65026 2674e1bede0 65017->65026 65020 2674e1bf023 65022 2674e1bf038 65020->65022 65038 2674e1aefc8 42 API calls 3 library calls 65020->65038 65022->65006 65024->65006 65025->65006 65028 2674e1bee29 65026->65028 65030 2674e1bee0d 65026->65030 65027 2674e1beeb7 65041 2674e1b0f38 42 API calls _invalid_parameter_noinfo 65027->65041 65028->65027 65031 2674e1bee61 65028->65031 65030->65020 65037 2674e1aefc8 42 API calls 3 library calls 65030->65037 65039 2674e1c4c70 EnterCriticalSection 65031->65039 65037->65020 65038->65022 65040 2674e1f6208 65039->65040 65041->65030 65042 2674e1ae056 65043 2674e1aaa20 45 API calls 65042->65043 65044 2674e1ae05e 65043->65044 65045 2674e167089 65046 2674e1670a7 65045->65046 65047 2674e1670e6 65046->65047 65048 2674e167112 65046->65048 65049 2674e16719e 65047->65049 65050 2674e1670f3 65047->65050 65053 2674e1ce2d0 std::_Facet_Register 45 API calls 65048->65053 65054 2674e1670fb ISource _Strxfrm 65048->65054 65055 2674e14d660 45 API calls 2 library calls 65049->65055 65051 2674e1ce2d0 std::_Facet_Register 45 API calls 65050->65051 65051->65054 65053->65054 65055->65054 65056 2674e1aba33 65057 2674e1ab785 65056->65057 65059 2674e1ab798 65056->65059 65058 2674e167870 45 API calls 65057->65058 65058->65059 65060 2674e1abf90 45 API calls 65059->65060 65061 2674e1ab710 65060->65061 65062 2674e1a7c28 65063 2674e1a7c4e 65062->65063 65076 2674e1a7c39 65062->65076 65064 2674e1a7c57 65063->65064 65079 2674e1a7dfb 65063->65079 65067 2674e161cc0 45 API calls 65064->65067 65080 2674e1a7cb1 65064->65080 65065 2674e1a7ea7 65069 2674e1a8610 46 API calls 65065->65069 65066 2674e1ce010 _Strcoll 3 API calls 65068 2674e1a84bb 65066->65068 65067->65080 65071 2674e1a7ec0 65069->65071 65070 2674e1a8610 46 API calls 65070->65079 65073 2674e1a7bd0 3 API calls 65071->65073 65072 2674e1a7d70 65074 2674e1a8610 46 API calls 65072->65074 65073->65076 65075 2674e1a7da2 65074->65075 65081 2674e1a7bd0 3 API calls 65075->65081 65076->65066 65077 2674e1a7bd0 3 API calls 65077->65079 65078 2674e1a8610 46 API calls 65078->65080 65079->65065 65079->65070 65079->65077 65080->65072 65080->65078 65082 2674e1a7bd0 3 API calls 65080->65082 65081->65076 65082->65080 65083 2674e1730f0 65084 2674e173107 65083->65084 65089 2674e173112 _Strxfrm 65083->65089 65085 2674e173123 _Strxfrm 65086 2674e17324d 65086->65085 65087 2674e1b0834 _fread_nolock 44 API calls 65086->65087 65087->65085 65089->65085 65089->65086 65090 2674e1b0834 65089->65090 65093 2674e1b0854 65090->65093 65094 2674e1b087e 65093->65094 65095 2674e1b084c 65093->65095 65094->65095 65096 2674e1b08ca 65094->65096 65097 2674e1b088d memcpy_s 65094->65097 65095->65089 65098 2674e1afd4c _fread_nolock EnterCriticalSection 65096->65098 65121 2674e1b54cc 7 API calls _Strcoll 65097->65121 65099 2674e1b08d2 65098->65099 65106 2674e1b05d4 65099->65106 65102 2674e1b08a2 65122 2674e1b1008 42 API calls _invalid_parameter_noinfo 65102->65122 65107 2674e1b05fb memcpy_s 65106->65107 65112 2674e1b0615 65106->65112 65108 2674e1b0605 65107->65108 65107->65112 65119 2674e1b0672 memcpy_s _Strxfrm 65107->65119 65144 2674e1b54cc 7 API calls _Strcoll 65108->65144 65110 2674e1b060a 65145 2674e1b1008 42 API calls _invalid_parameter_noinfo 65110->65145 65123 2674e1afd58 LeaveCriticalSection 65112->65123 65114 2674e1b07f3 memcpy_s 65208 2674e1b54cc 7 API calls _Strcoll 65114->65208 65115 2674e1b8f94 _fread_nolock 42 API calls 65115->65119 65119->65112 65119->65114 65119->65115 65124 2674e1bcde0 65119->65124 65146 2674e1b54cc 7 API calls _Strcoll 65119->65146 65147 2674e1b1008 42 API calls _invalid_parameter_noinfo 65119->65147 65148 2674e1be994 65119->65148 65121->65102 65122->65095 65125 2674e1bcdfd 65124->65125 65129 2674e1bce12 65124->65129 65238 2674e1b54cc 7 API calls _Strcoll 65125->65238 65127 2674e1bce02 65239 2674e1b1008 42 API calls _invalid_parameter_noinfo 65127->65239 65130 2674e1bce55 65129->65130 65131 2674e1be360 _fread_nolock 7 API calls 65129->65131 65138 2674e1bce0d 65129->65138 65132 2674e1b8f94 _fread_nolock 42 API calls 65130->65132 65131->65130 65133 2674e1bce67 65132->65133 65209 2674e1be878 65133->65209 65136 2674e1b8f94 _fread_nolock 42 API calls 65137 2674e1bce95 65136->65137 65137->65138 65139 2674e1b8f94 _fread_nolock 42 API calls 65137->65139 65138->65119 65140 2674e1bcea1 65139->65140 65140->65138 65141 2674e1b8f94 _fread_nolock 42 API calls 65140->65141 65142 2674e1bceae 65141->65142 65143 2674e1b8f94 _fread_nolock 42 API calls 65142->65143 65143->65138 65144->65110 65145->65112 65146->65119 65147->65119 65149 2674e1be9cf 65148->65149 65150 2674e1be9b7 65148->65150 65152 2674e1bedb3 65149->65152 65157 2674e1bea1e 65149->65157 65258 2674e1b54ac 7 API calls _Strcoll 65150->65258 65273 2674e1b54ac 7 API calls _Strcoll 65152->65273 65154 2674e1be9bc 65259 2674e1b54cc 7 API calls _Strcoll 65154->65259 65155 2674e1bedb8 65274 2674e1b54cc 7 API calls _Strcoll 65155->65274 65159 2674e1be9c4 65157->65159 65160 2674e1bea27 65157->65160 65164 2674e1bea55 65157->65164 65159->65119 65260 2674e1b54ac 7 API calls _Strcoll 65160->65260 65161 2674e1bea34 65275 2674e1b1008 42 API calls _invalid_parameter_noinfo 65161->65275 65163 2674e1bea2c 65261 2674e1b54cc 7 API calls _Strcoll 65163->65261 65167 2674e1bea7b 65164->65167 65168 2674e1beab8 65164->65168 65169 2674e1bea8a 65164->65169 65167->65169 65195 2674e1beaa6 65167->65195 65170 2674e1bf284 wcsftime 7 API calls 65168->65170 65262 2674e1b54ac 7 API calls _Strcoll 65169->65262 65172 2674e1beacb 65170->65172 65174 2674e1bc8e4 __free_lconv_mon 7 API calls 65172->65174 65173 2674e1bea8f 65263 2674e1b54cc 7 API calls _Strcoll 65173->65263 65177 2674e1bead5 65174->65177 65180 2674e1bc8e4 __free_lconv_mon 7 API calls 65177->65180 65179 2674e1bea96 65264 2674e1b1008 42 API calls _invalid_parameter_noinfo 65179->65264 65182 2674e1beadc 65180->65182 65184 2674e1beae4 65182->65184 65185 2674e1beaff 65182->65185 65183 2674e1bebed GetConsoleMode 65186 2674e1bec01 65183->65186 65188 2674e1bec5b _fread_nolock 65183->65188 65265 2674e1b54cc 7 API calls _Strcoll 65184->65265 65267 2674e1bf058 42 API calls 2 library calls 65185->65267 65186->65188 65190 2674e1bec0b ReadConsoleW 65186->65190 65191 2674e1bec4f 65188->65191 65194 2674e1bed79 __std_fs_get_current_path 65188->65194 65190->65191 65201 2674e1bec30 __std_fs_get_current_path 65190->65201 65197 2674e1becc2 65191->65197 65198 2674e1bece7 65191->65198 65207 2674e1beaa1 65191->65207 65192 2674e1bc8e4 __free_lconv_mon 7 API calls 65192->65159 65193 2674e1beae9 65266 2674e1b54ac 7 API calls _Strcoll 65193->65266 65200 2674e1bed84 65194->65200 65194->65201 65250 2674e1c90b8 65195->65250 65269 2674e1be5a4 42 API calls 4 library calls 65197->65269 65198->65207 65270 2674e1be3cc 42 API calls _fread_nolock 65198->65270 65271 2674e1b54cc 7 API calls _Strcoll 65200->65271 65201->65207 65268 2674e1b5440 7 API calls 2 library calls 65201->65268 65205 2674e1bed89 65272 2674e1b54ac 7 API calls _Strcoll 65205->65272 65207->65192 65208->65110 65210 2674e1be8a2 65209->65210 65211 2674e1be8ba 65209->65211 65240 2674e1b54ac 7 API calls _Strcoll 65210->65240 65213 2674e1be95c 65211->65213 65218 2674e1be8f2 65211->65218 65247 2674e1b54ac 7 API calls _Strcoll 65213->65247 65214 2674e1be8a7 65241 2674e1b54cc 7 API calls _Strcoll 65214->65241 65216 2674e1be961 65248 2674e1b54cc 7 API calls _Strcoll 65216->65248 65221 2674e1be910 65218->65221 65222 2674e1be8fb 65218->65222 65220 2674e1bce74 65220->65136 65220->65138 65223 2674e1c4c70 _fread_nolock EnterCriticalSection 65221->65223 65242 2674e1b54ac 7 API calls _Strcoll 65222->65242 65225 2674e1be917 65223->65225 65227 2674e1be942 65225->65227 65228 2674e1be92d 65225->65228 65226 2674e1be900 65243 2674e1b54cc 7 API calls _Strcoll 65226->65243 65232 2674e1be994 _fread_nolock 44 API calls 65227->65232 65244 2674e1b54cc 7 API calls _Strcoll 65228->65244 65235 2674e1be93d 65232->65235 65233 2674e1be908 65249 2674e1b1008 42 API calls _invalid_parameter_noinfo 65233->65249 65234 2674e1be932 65245 2674e1b54ac 7 API calls _Strcoll 65234->65245 65246 2674e1c4d58 LeaveCriticalSection 65235->65246 65238->65127 65239->65138 65240->65214 65241->65220 65242->65226 65243->65233 65244->65234 65245->65235 65247->65216 65248->65233 65249->65220 65251 2674e1c90c1 65250->65251 65252 2674e1c90ce 65250->65252 65276 2674e1b54cc 7 API calls _Strcoll 65251->65276 65255 2674e1bebcd 65252->65255 65277 2674e1b54cc 7 API calls _Strcoll 65252->65277 65255->65183 65255->65188 65256 2674e1c9105 65278 2674e1b1008 42 API calls _invalid_parameter_noinfo 65256->65278 65258->65154 65259->65159 65260->65163 65261->65161 65262->65173 65263->65179 65264->65207 65265->65193 65266->65207 65267->65195 65268->65207 65269->65207 65270->65207 65271->65205 65272->65207 65273->65155 65274->65161 65275->65159 65276->65255 65277->65256 65278->65255

                      Control-flow Graph

                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Object$DeleteMetricsSystem$CreateSelectStream_$CapsCompatibleCriticalDeviceReleaseSection$BitmapEnterLeaveReadResetSizeStream
                      • String ID:
                      • API String ID: 3214587331-3916222277
                      • Opcode ID: e4e63702ac4330d30596b5454e9ccec30832c3b90c2f1c900078c08ebe0bdd3a
                      • Instruction ID: d1833279775fa4a63b24420aeb80ed2bb5dc596af62f31b2541d5f1dfe04032c
                      • Opcode Fuzzy Hash: e4e63702ac4330d30596b5454e9ccec30832c3b90c2f1c900078c08ebe0bdd3a
                      • Instruction Fuzzy Hash: F9B12B72248BC086E760DB21F85839FB3B5F789BA4F508515DA8A53B69DF39C084CB80

                      Control-flow Graph

                      • Executed
                      • Not Executed
                      control_flow_graph 40 2674e1db83c-2674e1db87c 41 2674e1db891-2674e1db89a 40->41 42 2674e1db87e-2674e1db885 40->42 44 2674e1db8b6-2674e1db8b8 41->44 45 2674e1db89c-2674e1db89f 41->45 42->41 43 2674e1db887-2674e1db88c 42->43 46 2674e1dbb10-2674e1dbb36 call 2674e1ce010 43->46 48 2674e1dbb0e 44->48 49 2674e1db8be-2674e1db8c2 44->49 45->44 47 2674e1db8a1-2674e1db8a9 45->47 50 2674e1db8af-2674e1db8b2 47->50 51 2674e1db8ab-2674e1db8ad 47->51 48->46 53 2674e1db999-2674e1db9c0 call 2674e1dbc10 49->53 54 2674e1db8c8-2674e1db8cb 49->54 50->44 51->44 51->50 64 2674e1db9e2-2674e1db9eb 53->64 65 2674e1db9c2-2674e1db9cb 53->65 57 2674e1db8df-2674e1db8f1 GetFileAttributesExW 54->57 58 2674e1db8cd-2674e1db8d5 54->58 61 2674e1db8f3-2674e1db8fc call 2674e1f6168 57->61 62 2674e1db944-2674e1db953 57->62 58->57 60 2674e1db8d7-2674e1db8d9 58->60 60->53 60->57 61->46 74 2674e1db902-2674e1db914 FindFirstFileW 61->74 63 2674e1db957-2674e1db959 62->63 69 2674e1db965-2674e1db993 63->69 70 2674e1db95b-2674e1db963 63->70 67 2674e1db9f1-2674e1dba09 GetFileInformationByHandleEx 64->67 68 2674e1dba9f-2674e1dbaa8 64->68 71 2674e1db9cd-2674e1db9d5 call 2674e1f6140 65->71 72 2674e1db9db-2674e1db9dd 65->72 75 2674e1dba31-2674e1dba4a 67->75 76 2674e1dba0b-2674e1dba17 call 2674e1f6168 67->76 77 2674e1dbaaa-2674e1dbabe GetFileInformationByHandleEx 68->77 78 2674e1dbaf7-2674e1dbaf9 68->78 69->48 69->53 70->53 70->69 71->72 89 2674e1dbb51-2674e1dbb56 call 2674e1cb5c4 71->89 72->46 80 2674e1db916-2674e1db91c call 2674e1f6168 74->80 81 2674e1db921-2674e1db942 FindClose 74->81 75->68 87 2674e1dba4c-2674e1dba50 75->87 101 2674e1dba19-2674e1dba24 call 2674e1f6140 76->101 102 2674e1dba2a-2674e1dba2c 76->102 85 2674e1dbae4-2674e1dbaf4 77->85 86 2674e1dbac0-2674e1dbacc call 2674e1f6168 77->86 82 2674e1dbafb-2674e1dbaff 78->82 83 2674e1dbb37-2674e1dbb3b 78->83 80->46 81->63 82->48 91 2674e1dbb01-2674e1dbb0c call 2674e1f6140 82->91 94 2674e1dbb3d-2674e1dbb48 call 2674e1f6140 83->94 95 2674e1dbb4a-2674e1dbb4f 83->95 85->78 86->102 111 2674e1dbad2-2674e1dbadd call 2674e1f6140 86->111 96 2674e1dba52-2674e1dba6c GetFileInformationByHandleEx 87->96 97 2674e1dba98 87->97 114 2674e1dbb57-2674e1dbb5c call 2674e1cb5c4 89->114 91->48 91->89 94->89 94->95 95->46 106 2674e1dba8f-2674e1dba96 96->106 107 2674e1dba6e-2674e1dba7a call 2674e1f6168 96->107 103 2674e1dba9c 97->103 101->102 120 2674e1dbb63-2674e1dbb6b call 2674e1cb5c4 101->120 102->46 103->68 106->103 107->102 118 2674e1dba7c-2674e1dba87 call 2674e1f6140 107->118 125 2674e1dbadf 111->125 126 2674e1dbb5d-2674e1dbb62 call 2674e1cb5c4 111->126 114->126 118->114 130 2674e1dba8d 118->130 125->102 126->120 130->102
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Close$ErrorFileFindHandleLast$AttributesFirst__std_fs_open_handle
                      • String ID:
                      • API String ID: 2398595512-0
                      • Opcode ID: c43c54e3e165f8807fdec21084e482379ff19f217a5b6f75efe34dcfe3cbcfef
                      • Instruction ID: 6b8effc928f5f2cca21fbcb606fe19f57f9a4dd6b299d02bc910efd54ceecd18
                      • Opcode Fuzzy Hash: c43c54e3e165f8807fdec21084e482379ff19f217a5b6f75efe34dcfe3cbcfef
                      • Instruction Fuzzy Hash: 6991723138CA4146EAA48B25B81CF6B63B0E789BB8F544714DAB7477D4DF3AE84587C0
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Name$ComputerCurrentDevicesDisplayEnumFileGlobalMemoryModuleProfileStatusUserValuewcsftime
                      • String ID: %d-%m-%Y, %H:%M:%S$computer_name$cpu$gpu$ram$system$time$timezone$user_name
                      • API String ID: 4154315062-1182675529
                      • Opcode ID: 7ab7a56d14c3b18e0c541bfa9df40e1211505bfeffc88797f03d1f8a09a2898e
                      • Instruction ID: a28013d6cd6f3334b057767dd694ac0b8df66ff35c64199d9e8e7d2e6f0714a0
                      • Opcode Fuzzy Hash: 7ab7a56d14c3b18e0c541bfa9df40e1211505bfeffc88797f03d1f8a09a2898e
                      • Instruction Fuzzy Hash: 35037B72659BC189EB21CF34E8883EE3771F795798F409616EA9C07A99EF35C284C740

                      Control-flow Graph

                      • Executed
                      • Not Executed
                      control_flow_graph 623 2674e15d860-2674e15d950 LoadLibraryA 624 2674e15e807-2674e15e811 623->624 625 2674e15d956-2674e15dd0f GetProcAddress * 6 623->625 626 2674e15e813-2674e15e815 624->626 627 2674e15e820-2674e15e823 624->627 625->624 628 2674e15dd15-2674e15dd18 625->628 626->627 629 2674e15e82e-2674e15e85d call 2674e1ce010 627->629 630 2674e15e825-2674e15e828 call 2674e1f6160 627->630 628->624 631 2674e15dd1e-2674e15dd21 628->631 630->629 631->624 635 2674e15dd27-2674e15dd2a 631->635 635->624 637 2674e15dd30-2674e15dd33 635->637 637->624 638 2674e15dd39-2674e15dd3c 637->638 638->624 639 2674e15dd42-2674e15dd50 638->639 640 2674e15dd54-2674e15dd56 639->640 640->624 641 2674e15dd5c-2674e15dd68 640->641 641->624 642 2674e15dd6e 641->642 643 2674e15dd73-2674e15dd8e 642->643 645 2674e15e7ee-2674e15e7fa 643->645 646 2674e15dd94-2674e15ddb2 643->646 645->643 647 2674e15e800 645->647 646->645 649 2674e15ddb8-2674e15ddca 646->649 647->624 650 2674e15e7d5-2674e15e7e7 649->650 651 2674e15ddd0 649->651 650->645 652 2674e15ddd4-2674e15de25 call 2674e1ce2d0 651->652 656 2674e15de2b-2674e15de32 652->656 657 2674e15e0a4 652->657 656->657 659 2674e15de38-2674e15df2b call 2674e193180 call 2674e164320 call 2674e1645f0 656->659 660 2674e15e0a6-2674e15e0ad 657->660 685 2674e15df32-2674e15df3a 659->685 662 2674e15e0b3-2674e15e0ba 660->662 663 2674e15e324-2674e15e360 660->663 662->663 665 2674e15e0c0-2674e15e1ae call 2674e193180 call 2674e164320 call 2674e1645f0 662->665 671 2674e15e5f7-2674e15e5f9 663->671 672 2674e15e366-2674e15e374 663->672 697 2674e15e1b5-2674e15e1bd 665->697 677 2674e15e7a7-2674e15e7bd call 2674e1604b0 671->677 678 2674e15e5ff-2674e15e724 call 2674e152030 call 2674e160e50 call 2674e152030 call 2674e160e50 call 2674e163070 call 2674e1ce2d0 call 2674e17a720 671->678 675 2674e15e37a-2674e15e381 672->675 676 2674e15e5f0-2674e15e5f3 672->676 675->676 683 2674e15e387-2674e15e47c call 2674e193180 call 2674e164320 call 2674e1645f0 675->683 676->671 681 2674e15e5f5 676->681 692 2674e15e7c3-2674e15e7ce 677->692 693 2674e15ddd2 677->693 771 2674e15e726-2674e15e728 678->771 772 2674e15e730-2674e15e749 call 2674e1628d0 678->772 681->671 712 2674e15e480-2674e15e487 683->712 685->685 690 2674e15df3c-2674e15df96 call 2674e152030 call 2674e165910 call 2674e163070 685->690 720 2674e15dfc9-2674e15dff3 690->720 721 2674e15df98-2674e15dfa9 690->721 692->650 693->652 697->697 702 2674e15e1bf-2674e15e218 call 2674e152030 call 2674e165910 call 2674e163070 697->702 734 2674e15e24b-2674e15e275 702->734 735 2674e15e21a-2674e15e22b 702->735 712->712 717 2674e15e489-2674e15e4e2 call 2674e152030 call 2674e165910 call 2674e163070 712->717 781 2674e15e515-2674e15e53e 717->781 782 2674e15e4e4-2674e15e4f5 717->782 729 2674e15e02b-2674e15e051 720->729 730 2674e15dff5-2674e15e009 720->730 725 2674e15dfab-2674e15dfbe 721->725 726 2674e15dfc4 call 2674e1ce030 721->726 725->726 732 2674e15e8bc-2674e15e8c1 call 2674e1b1028 725->732 726->720 740 2674e15e089-2674e15e0a2 729->740 741 2674e15e053-2674e15e067 729->741 737 2674e15e00b-2674e15e01e 730->737 738 2674e15e024-2674e15e029 call 2674e1ce030 730->738 745 2674e15e8c2-2674e15e8c7 call 2674e1b1028 732->745 746 2674e15e2ad-2674e15e2d3 734->746 747 2674e15e277-2674e15e28b 734->747 742 2674e15e22d-2674e15e240 735->742 743 2674e15e246 call 2674e1ce030 735->743 737->738 737->745 738->729 740->660 751 2674e15e069-2674e15e07c 741->751 752 2674e15e082-2674e15e087 call 2674e1ce030 741->752 742->743 753 2674e15e8ce-2674e15e8d3 call 2674e1b1028 742->753 743->734 761 2674e15e8c8-2674e15e8cd call 2674e1b1028 745->761 762 2674e15e30b-2674e15e31d 746->762 763 2674e15e2d5-2674e15e2e9 746->763 756 2674e15e28d-2674e15e2a0 747->756 757 2674e15e2a6-2674e15e2ab call 2674e1ce030 747->757 751->752 751->761 752->740 770 2674e15e8d4-2674e15e8d9 call 2674e1b1028 753->770 756->757 756->770 757->746 761->753 762->663 774 2674e15e2eb-2674e15e2fe 763->774 775 2674e15e304-2674e15e309 call 2674e1ce030 763->775 777 2674e15e8da-2674e15e8df call 2674e1b1028 770->777 784 2674e15e72e 771->784 785 2674e15e864-2674e15e8b5 call 2674e162a90 call 2674e166640 call 2674e166710 call 2674e1d11d8 771->785 792 2674e15e74d-2674e15e759 772->792 774->775 774->777 775->762 803 2674e15e8e0-2674e15e8e5 call 2674e1b1028 777->803 793 2674e15e574-2674e15e59a 781->793 794 2674e15e540-2674e15e554 781->794 788 2674e15e4f7-2674e15e50a 782->788 789 2674e15e510 call 2674e1ce030 782->789 784->792 818 2674e15e8b6-2674e15e8bb call 2674e1b1028 785->818 788->789 788->803 789->781 798 2674e15e75b-2674e15e77e 792->798 799 2674e15e780-2674e15e78a call 2674e16bb00 792->799 801 2674e15e59c-2674e15e5b0 793->801 802 2674e15e5d0-2674e15e5e9 793->802 806 2674e15e556-2674e15e569 794->806 807 2674e15e56f call 2674e1ce030 794->807 811 2674e15e78f-2674e15e7a0 call 2674e163070 798->811 799->811 814 2674e15e5cb call 2674e1ce030 801->814 815 2674e15e5b2-2674e15e5c5 801->815 802->676 806->807 809 2674e15e85e-2674e15e863 call 2674e1b1028 806->809 807->793 809->785 811->677 814->802 815->814 815->818 818->732
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: AddressProc$Library$FreeLoad
                      • String ID: cannot use push_back() with $system$vault
                      • API String ID: 2449869053-1741236777
                      • Opcode ID: 47ffc357aac57c06b6f327d8b91be1eb1c7e7c14895f5a63de02cffcb4a7522a
                      • Instruction ID: 5e0deea1e194ef59471df7110ff35b5722b21eb8eeb61b6b4b938d7f4d4e5ce4
                      • Opcode Fuzzy Hash: 47ffc357aac57c06b6f327d8b91be1eb1c7e7c14895f5a63de02cffcb4a7522a
                      • Instruction Fuzzy Hash: 3A926F32609BC48ADB618F29E8883DE73B5F789798F104215EB9C57B99EF35C654C340

                      Control-flow Graph

                      • Executed
                      • Not Executed
                      control_flow_graph 916 2674e197910-2674e197932 call 2674e19a880 919 2674e197934-2674e19795d call 2674e19ac70 call 2674e1a5b10 call 2674e161b40 ExitProcess 916->919 920 2674e19795e-2674e197a11 call 2674e1a6f60 * 2 call 2674e1a31c0 call 2674e198360 916->920 919->920 935 2674e197a13-2674e197a25 920->935 936 2674e197a45-2674e197a7c OpenMutexA 920->936 937 2674e197a40 call 2674e1ce030 935->937 938 2674e197a27-2674e197a3a 935->938 939 2674e197a8a-2674e197ac1 CreateMutexA call 2674e191fa0 call 2674e19adb0 936->939 940 2674e197a7e-2674e197a89 ExitProcess 936->940 937->936 938->937 942 2674e197bd7-2674e197bdc call 2674e1b1028 938->942 951 2674e197acf-2674e197b32 call 2674e1a34d0 call 2674e15d860 call 2674e15e8f0 call 2674e15ef90 call 2674e15fda0 call 2674e15cd10 call 2674e182590 call 2674e185270 call 2674e152f30 call 2674e15b110 call 2674e159b30 call 2674e198590 call 2674e15c230 call 2674e157b20 call 2674e154de0 call 2674e157e10 call 2674e19fbe0 939->951 952 2674e197ac3-2674e197ace ExitProcess 939->952 940->939 948 2674e197bdd-2674e197be2 call 2674e1b1028 942->948 989 2674e197b37-2674e197b47 call 2674e196f20 951->989 952->951 993 2674e197b49-2674e197b55 ReleaseMutex call 2674e1f6140 989->993 994 2674e197b5b-2674e197b62 989->994 993->994 996 2674e197b64-2674e197b69 call 2674e197bf0 994->996 997 2674e197b6a-2674e197b76 994->997 996->997 999 2674e197ba6-2674e197bd6 call 2674e1ce010 997->999 1000 2674e197b78-2674e197b8a 997->1000 1002 2674e197ba1 call 2674e1ce030 1000->1002 1003 2674e197b8c-2674e197b9f 1000->1003 1002->999 1003->948 1003->1002
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Process$Exit$MutexOpenToken$CreateCurrentFileInformationInitializeModuleName
                      • String ID: SeDebugPrivilege$SeImpersonatePrivilege
                      • API String ID: 470559343-3768118664
                      • Opcode ID: 159e54d527fafda6f55e24249329156e0a9e935cd3bf13cb4f19f12f82537621
                      • Instruction ID: 8c023842cd3f0a8e9211952bcbc09846eb71c7e17bcdca1927390ae91dd7feec
                      • Opcode Fuzzy Hash: 159e54d527fafda6f55e24249329156e0a9e935cd3bf13cb4f19f12f82537621
                      • Instruction Fuzzy Hash: 8F61827269CA8081FA10AB68F45D3AF6271FFCA7B8F500515E6DE426D6DF2AC044C7C1

                      Control-flow Graph

                      • Executed
                      • Not Executed
                      control_flow_graph 1007 2674e1c25b4-2674e1c25ef call 2674e1c1c54 call 2674e1c1c5c call 2674e1c1cc4 1014 2674e1c25f5-2674e1c2600 call 2674e1c1c64 1007->1014 1015 2674e1c2819-2674e1c2865 call 2674e1b1058 call 2674e1c1c54 call 2674e1c1c5c call 2674e1c1cc4 1007->1015 1014->1015 1020 2674e1c2606-2674e1c2610 1014->1020 1042 2674e1c29a3-2674e1c2a11 call 2674e1b1058 call 2674e1cb124 1015->1042 1043 2674e1c286b-2674e1c2876 call 2674e1c1c64 1015->1043 1023 2674e1c2632-2674e1c2636 1020->1023 1024 2674e1c2612-2674e1c2615 1020->1024 1025 2674e1c2639-2674e1c2641 1023->1025 1027 2674e1c2618-2674e1c2623 1024->1027 1025->1025 1028 2674e1c2643-2674e1c2656 call 2674e1bf284 1025->1028 1030 2674e1c2625-2674e1c262c 1027->1030 1031 2674e1c262e-2674e1c2630 1027->1031 1037 2674e1c266e-2674e1c267a call 2674e1bc8e4 1028->1037 1038 2674e1c2658-2674e1c265a call 2674e1bc8e4 1028->1038 1030->1027 1030->1031 1031->1023 1032 2674e1c265f-2674e1c266d 1031->1032 1048 2674e1c2681-2674e1c2689 1037->1048 1038->1032 1060 2674e1c2a13-2674e1c2a1a 1042->1060 1061 2674e1c2a1f-2674e1c2a22 1042->1061 1043->1042 1052 2674e1c287c-2674e1c2887 call 2674e1c1c94 1043->1052 1048->1048 1051 2674e1c268b-2674e1c269c call 2674e1c770c 1048->1051 1051->1015 1062 2674e1c26a2-2674e1c26f8 call 2674e1d09c0 * 4 call 2674e1c24d0 1051->1062 1052->1042 1059 2674e1c288d-2674e1c2894 call 2674e1bc8e4 1052->1059 1069 2674e1c2899-2674e1c28a7 call 2674e1f6260 1059->1069 1064 2674e1c2aaf-2674e1c2ab2 1060->1064 1065 2674e1c2a24 1061->1065 1066 2674e1c2a59-2674e1c2a6c call 2674e1bf284 1061->1066 1119 2674e1c26fa-2674e1c26fe 1062->1119 1070 2674e1c2a27 call 2674e1c2830 1064->1070 1071 2674e1c2ab8-2674e1c2ac0 call 2674e1c25b4 1064->1071 1065->1070 1082 2674e1c2a6e 1066->1082 1083 2674e1c2a77-2674e1c2a92 call 2674e1cb124 1066->1083 1080 2674e1c28ad-2674e1c28b0 1069->1080 1078 2674e1c2a2c-2674e1c2a58 call 2674e1bc8e4 call 2674e1ce010 1070->1078 1071->1078 1086 2674e1c28b6-2674e1c28d7 1080->1086 1087 2674e1c2978-2674e1c29a2 call 2674e1c1c4c call 2674e1c1c3c call 2674e1c1c44 1080->1087 1088 2674e1c2a70-2674e1c2a75 call 2674e1bc8e4 1082->1088 1097 2674e1c2a94-2674e1c2a97 1083->1097 1098 2674e1c2a99-2674e1c2aab call 2674e1bc8e4 1083->1098 1092 2674e1c28e2-2674e1c28e9 1086->1092 1093 2674e1c28d9-2674e1c28df 1086->1093 1088->1065 1101 2674e1c28eb-2674e1c28f3 1092->1101 1102 2674e1c28fd 1092->1102 1093->1092 1097->1088 1098->1064 1101->1102 1109 2674e1c28f5-2674e1c28fb 1101->1109 1108 2674e1c28ff-2674e1c2973 call 2674e1d09c0 * 4 call 2674e1c60b8 call 2674e1c2ac8 * 2 1102->1108 1108->1087 1109->1108 1122 2674e1c2704-2674e1c2708 1119->1122 1123 2674e1c2700 1119->1123 1122->1119 1125 2674e1c270a-2674e1c272f call 2674e1b5310 1122->1125 1123->1122 1131 2674e1c2732-2674e1c2736 1125->1131 1132 2674e1c2745-2674e1c2749 1131->1132 1133 2674e1c2738-2674e1c2743 1131->1133 1132->1131 1133->1132 1135 2674e1c274b-2674e1c274f 1133->1135 1137 2674e1c27d0-2674e1c27d4 1135->1137 1138 2674e1c2751-2674e1c2779 call 2674e1b5310 1135->1138 1140 2674e1c27d6-2674e1c27d8 1137->1140 1141 2674e1c27db-2674e1c27e8 1137->1141 1149 2674e1c277b 1138->1149 1150 2674e1c2797-2674e1c279b 1138->1150 1140->1141 1144 2674e1c2803-2674e1c2812 call 2674e1c1c4c call 2674e1c1c3c 1141->1144 1145 2674e1c27ea-2674e1c2800 call 2674e1c24d0 1141->1145 1144->1015 1145->1144 1153 2674e1c277e-2674e1c2785 1149->1153 1150->1137 1155 2674e1c279d-2674e1c27bb call 2674e1b5310 1150->1155 1153->1150 1156 2674e1c2787-2674e1c2795 1153->1156 1161 2674e1c27c7-2674e1c27ce 1155->1161 1156->1150 1156->1153 1161->1137 1162 2674e1c27bd-2674e1c27c1 1161->1162 1162->1137 1163 2674e1c27c3 1162->1163 1163->1161
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: _get_daylight$_invalid_parameter_noinfo$ErrorFreeHeapInformationLastTimeZone
                      • String ID: Eastern Standard Time$Eastern Summer Time
                      • API String ID: 355007559-239921721
                      • Opcode ID: 78eb675e9cd755191b67956b91f2f98d36718c9094a46172317fefae4576ec3a
                      • Instruction ID: bd70ead2136ec1635c3b70e4ea95e7ac0260faa824923dc3961edfd110523841
                      • Opcode Fuzzy Hash: 78eb675e9cd755191b67956b91f2f98d36718c9094a46172317fefae4576ec3a
                      • Instruction Fuzzy Hash: 42D1F436748A5086E724DF26F48D7AB6771F7847ACF458125EE4983A85DF3AC4C1C780

                      Control-flow Graph

                      • Executed
                      • Not Executed
                      control_flow_graph 1164 2674e1a0420-2674e1a047c 1165 2674e1a0482-2674e1a0495 call 2674e1ce1c0 1164->1165 1166 2674e1a0640-2674e1a0662 InternetOpenA 1164->1166 1165->1166 1177 2674e1a049b-2674e1a060b 1165->1177 1167 2674e1a0664-2674e1a0682 1166->1167 1168 2674e1a0687-2674e1a06a0 1166->1168 1170 2674e1a0a11-2674e1a0a3a call 2674e1ce010 1167->1170 1171 2674e1a06a2 1168->1171 1172 2674e1a06a5-2674e1a06d2 InternetOpenUrlA 1168->1172 1171->1172 1175 2674e1a06d4-2674e1a06f5 1172->1175 1176 2674e1a06fa-2674e1a0725 HttpQueryInfoW 1172->1176 1179 2674e1a0a08 1175->1179 1180 2674e1a0757-2674e1a07ab HttpQueryInfoW 1176->1180 1181 2674e1a0727-2674e1a0752 1176->1181 1182 2674e1a0610-2674e1a0618 1177->1182 1179->1170 1184 2674e1a07d4-2674e1a07e9 InternetQueryDataAvailable 1180->1184 1185 2674e1a07ad-2674e1a07c1 call 2674e1b5310 1180->1185 1181->1179 1182->1182 1183 2674e1a061a-2674e1a063b call 2674e152030 call 2674e1ce614 call 2674e1ce160 1182->1183 1183->1166 1187 2674e1a07ef 1184->1187 1188 2674e1a09be-2674e1a0a04 InternetCloseHandle 1184->1188 1185->1184 1195 2674e1a07c3-2674e1a07d0 call 2674e167060 1185->1195 1193 2674e1a07f4-2674e1a07f9 1187->1193 1188->1179 1193->1188 1196 2674e1a07ff-2674e1a0819 1193->1196 1195->1184 1199 2674e1a081b-2674e1a0821 1196->1199 1200 2674e1a088c-2674e1a08a3 InternetReadFile 1196->1200 1205 2674e1a084f-2674e1a0852 call 2674e1ce2d0 1199->1205 1206 2674e1a0823-2674e1a082a 1199->1206 1203 2674e1a08a9-2674e1a08ae 1200->1203 1204 2674e1a0978-2674e1a097f 1200->1204 1203->1204 1208 2674e1a08b4-2674e1a08bf 1203->1208 1204->1188 1209 2674e1a0981-2674e1a0992 1204->1209 1212 2674e1a0857-2674e1a0887 call 2674e1d09c0 1205->1212 1210 2674e1a0a41-2674e1a0a46 call 2674e14d660 1206->1210 1211 2674e1a0830-2674e1a083b call 2674e1ce2d0 1206->1211 1214 2674e1a08c1-2674e1a08ec call 2674e1d0310 1208->1214 1215 2674e1a08ee-2674e1a0907 call 2674e167b90 1208->1215 1216 2674e1a0994-2674e1a09a7 1209->1216 1217 2674e1a09ad-2674e1a09ba call 2674e1ce030 1209->1217 1222 2674e1a0a3b-2674e1a0a40 call 2674e1b1028 1211->1222 1231 2674e1a0841-2674e1a084d 1211->1231 1212->1200 1233 2674e1a0908-2674e1a090f 1214->1233 1215->1233 1216->1217 1216->1222 1217->1188 1222->1210 1231->1212 1234 2674e1a0911-2674e1a0922 1233->1234 1235 2674e1a0952 1233->1235 1237 2674e1a0924-2674e1a0937 1234->1237 1238 2674e1a093d-2674e1a0950 call 2674e1ce030 1234->1238 1236 2674e1a0954-2674e1a0969 InternetQueryDataAvailable 1235->1236 1236->1188 1240 2674e1a096b-2674e1a0973 1236->1240 1237->1222 1237->1238 1238->1236 1240->1193
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Internet$Query$AvailableDataHttpInfoOpen$CloseConcurrency::cancel_current_taskCriticalEnterFileHandleReadSection
                      • String ID:
                      • API String ID: 2604747929-0
                      • Opcode ID: 1cbb99dd4fe00097619a0ced69e2d148608187bcbc2ca1b834ac75fee8039cdb
                      • Instruction ID: afd8b167f39300c96ffdd9388dea0253b824f86a9365f273869c75a09bc7508f
                      • Opcode Fuzzy Hash: 1cbb99dd4fe00097619a0ced69e2d148608187bcbc2ca1b834ac75fee8039cdb
                      • Instruction Fuzzy Hash: 92027D32A28B9489F700CB65F8483AE77B4F785BA8F105215EE9D57B99DF79C080C780

                      Control-flow Graph

                      • Executed
                      • Not Executed
                      control_flow_graph 1315 2674e19a050-2674e19a0d7 call 2674e150680 1318 2674e19a78e-2674e19a790 1315->1318 1319 2674e19a0dd-2674e19a0e5 1315->1319 1320 2674e19a792-2674e19a796 1318->1320 1321 2674e19a7cc-2674e19a7e2 call 2674e14feb0 1318->1321 1319->1320 1322 2674e19a0eb-2674e19a13e call 2674e1d09c0 call 2674e1a8c00 1319->1322 1323 2674e19a79e-2674e19a7cb call 2674e1ce010 1320->1323 1331 2674e19a7e3-2674e19a7e8 call 2674e1b1028 1321->1331 1334 2674e19a144-2674e19a14c 1322->1334 1335 2674e19a589-2674e19a5c5 call 2674e176ac0 call 2674e1769e0 1322->1335 1338 2674e19a7e9-2674e19a81f call 2674e14d930 call 2674e14eb40 call 2674e1d11d8 1331->1338 1339 2674e19a151-2674e19a174 call 2674e1a4e80 call 2674e1a5080 1334->1339 1340 2674e19a14e 1334->1340 1351 2674e19a5e4-2674e19a672 call 2674e176ac0 call 2674e1a8da0 1335->1351 1352 2674e19a5c7-2674e19a5d8 call 2674e167060 1335->1352 1368 2674e19a820-2674e19a823 1338->1368 1354 2674e19a26a-2674e19a284 GetFileSize 1339->1354 1355 2674e19a17a-2674e19a190 1339->1355 1340->1339 1351->1338 1386 2674e19a678-2674e19a67c call 2674e174130 1351->1386 1361 2674e19a5dd 1352->1361 1364 2674e19a286-2674e19a2a9 1354->1364 1365 2674e19a2ab-2674e19a2c1 1354->1365 1359 2674e19a192-2674e19a1a6 1355->1359 1360 2674e19a1c6-2674e19a265 call 2674e1738d0 call 2674e1dc8f0 1355->1360 1366 2674e19a1c1 call 2674e1ce030 1359->1366 1367 2674e19a1a8-2674e19a1bb 1359->1367 1360->1323 1361->1351 1371 2674e19a310-2674e19a359 SetFilePointer call 2674e1f6190 1364->1371 1372 2674e19a2f3-2674e19a30b call 2674e1679e0 1365->1372 1373 2674e19a2c3-2674e19a2f1 call 2674e1d09c0 1365->1373 1366->1360 1367->1331 1367->1366 1378 2674e19a825-2674e19a82c 1368->1378 1379 2674e19a82e-2674e19a83f 1368->1379 1387 2674e19a35f-2674e19a3b1 1371->1387 1388 2674e19a48b-2674e19a4af 1371->1388 1372->1371 1373->1371 1384 2674e19a843-2674e19a875 call 2674e14d930 call 2674e14eb40 call 2674e1d11d8 1378->1384 1379->1384 1393 2674e19a681-2674e19a684 1386->1393 1402 2674e19a3b3-2674e19a3c7 1387->1402 1403 2674e19a3e7-2674e19a486 call 2674e1738d0 call 2674e1dc8f0 1387->1403 1400 2674e19a4b1-2674e19a4c5 1388->1400 1401 2674e19a4e5-2674e19a584 call 2674e1738d0 call 2674e1dc8f0 1388->1401 1397 2674e19a6b3-2674e19a78c call 2674e1738d0 call 2674e1dc8f0 1393->1397 1398 2674e19a686-2674e19a6ad 1393->1398 1397->1323 1398->1368 1398->1397 1406 2674e19a4e0 call 2674e1ce030 1400->1406 1407 2674e19a4c7-2674e19a4da 1400->1407 1401->1323 1409 2674e19a3e2 call 2674e1ce030 1402->1409 1410 2674e19a3c9-2674e19a3dc 1402->1410 1403->1323 1406->1401 1407->1331 1407->1406 1409->1403 1410->1331 1410->1409
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: File$PointerReadSize
                      • String ID: exists$ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set
                      • API String ID: 404940565-15404121
                      • Opcode ID: 070f574dbe00e942d553051624e6254ec65e45f4c51a1969a7e5fa42a2d304cd
                      • Instruction ID: 43d720529fa4fe00fa67221dbb3e43480225f09405ebfd610930c8948503a35d
                      • Opcode Fuzzy Hash: 070f574dbe00e942d553051624e6254ec65e45f4c51a1969a7e5fa42a2d304cd
                      • Instruction Fuzzy Hash: 6E320532254BC189EB20CF28E8883DE37B1F78575CF448626DA9D57A99EF75C684C780

                      Control-flow Graph

                      • Executed
                      • Not Executed
                      control_flow_graph 1424 2674e1be994-2674e1be9b5 1425 2674e1be9cf-2674e1be9d1 1424->1425 1426 2674e1be9b7-2674e1be9ca call 2674e1b54ac call 2674e1b54cc 1424->1426 1428 2674e1bedb3-2674e1bedc0 call 2674e1b54ac call 2674e1b54cc 1425->1428 1429 2674e1be9d7-2674e1be9de 1425->1429 1443 2674e1bedcb 1426->1443 1446 2674e1bedc6 call 2674e1b1008 1428->1446 1429->1428 1432 2674e1be9e4-2674e1bea18 1429->1432 1432->1428 1435 2674e1bea1e-2674e1bea25 1432->1435 1438 2674e1bea3f-2674e1bea42 1435->1438 1439 2674e1bea27-2674e1bea3a call 2674e1b54ac call 2674e1b54cc 1435->1439 1440 2674e1bedaf-2674e1bedb1 1438->1440 1441 2674e1bea48-2674e1bea4a 1438->1441 1439->1446 1447 2674e1bedce-2674e1beddd 1440->1447 1441->1440 1445 2674e1bea50-2674e1bea53 1441->1445 1443->1447 1445->1439 1449 2674e1bea55-2674e1bea79 1445->1449 1446->1443 1453 2674e1bea7b-2674e1bea7e 1449->1453 1454 2674e1beaae-2674e1beab6 1449->1454 1457 2674e1beaa6-2674e1beaac 1453->1457 1458 2674e1bea80-2674e1bea88 1453->1458 1455 2674e1beab8-2674e1beae2 call 2674e1bf284 call 2674e1bc8e4 * 2 1454->1455 1456 2674e1bea8a-2674e1beaa1 call 2674e1b54ac call 2674e1b54cc call 2674e1b1008 1454->1456 1485 2674e1beae4-2674e1beafa call 2674e1b54cc call 2674e1b54ac 1455->1485 1486 2674e1beaff-2674e1beb29 call 2674e1bf058 1455->1486 1489 2674e1bec3d 1456->1489 1461 2674e1beb2d-2674e1beb3e 1457->1461 1458->1456 1458->1457 1462 2674e1beb44-2674e1beb4c 1461->1462 1463 2674e1bebc5-2674e1bebcf call 2674e1c90b8 1461->1463 1462->1463 1466 2674e1beb4e-2674e1beb50 1462->1466 1476 2674e1bebd5-2674e1bebeb 1463->1476 1477 2674e1bec5b 1463->1477 1466->1463 1470 2674e1beb52-2674e1beb70 1466->1470 1470->1463 1474 2674e1beb72-2674e1beb7e 1470->1474 1474->1463 1479 2674e1beb80-2674e1beb82 1474->1479 1476->1477 1482 2674e1bebed-2674e1bebff GetConsoleMode 1476->1482 1481 2674e1bec60-2674e1bec79 call 2674e1f6190 1477->1481 1479->1463 1484 2674e1beb84-2674e1beb9c 1479->1484 1493 2674e1bec7f-2674e1bec81 1481->1493 1482->1477 1488 2674e1bec01-2674e1bec09 1482->1488 1484->1463 1491 2674e1beb9e-2674e1bebaa 1484->1491 1485->1489 1486->1461 1488->1481 1495 2674e1bec0b-2674e1bec2e ReadConsoleW 1488->1495 1490 2674e1bec40-2674e1bec4a call 2674e1bc8e4 1489->1490 1490->1447 1491->1463 1499 2674e1bebac-2674e1bebae 1491->1499 1501 2674e1bec87-2674e1bec8f 1493->1501 1502 2674e1bed79-2674e1bed82 call 2674e1f6168 1493->1502 1496 2674e1bec4f-2674e1bec59 1495->1496 1497 2674e1bec30 call 2674e1f6168 1495->1497 1508 2674e1bec9c-2674e1becb3 1496->1508 1512 2674e1bec36-2674e1bec38 call 2674e1b5440 1497->1512 1499->1463 1507 2674e1bebb0-2674e1bebc0 1499->1507 1501->1502 1510 2674e1bec95 1501->1510 1518 2674e1bed84-2674e1bed9a call 2674e1b54cc call 2674e1b54ac 1502->1518 1519 2674e1bed9f-2674e1beda2 1502->1519 1507->1463 1508->1490 1511 2674e1becb5-2674e1becc0 1508->1511 1510->1508 1515 2674e1becc2-2674e1becdb call 2674e1be5a4 1511->1515 1516 2674e1bece7-2674e1becef 1511->1516 1512->1489 1526 2674e1bece0-2674e1bece2 1515->1526 1521 2674e1becf1-2674e1bed03 1516->1521 1522 2674e1bed67-2674e1bed74 call 2674e1be3cc 1516->1522 1518->1489 1519->1512 1524 2674e1beda8-2674e1bedaa 1519->1524 1527 2674e1bed05 1521->1527 1528 2674e1bed5a-2674e1bed62 1521->1528 1522->1526 1524->1490 1526->1490 1531 2674e1bed0b-2674e1bed12 1527->1531 1528->1490 1533 2674e1bed14-2674e1bed18 1531->1533 1534 2674e1bed4f-2674e1bed54 1531->1534 1536 2674e1bed35 1533->1536 1537 2674e1bed1a-2674e1bed21 1533->1537 1534->1528 1539 2674e1bed3b-2674e1bed4b 1536->1539 1537->1536 1538 2674e1bed23-2674e1bed27 1537->1538 1538->1536 1540 2674e1bed29-2674e1bed33 1538->1540 1539->1531 1541 2674e1bed4d 1539->1541 1540->1539 1541->1528
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: _invalid_parameter_noinfo
                      • String ID:
                      • API String ID: 3215553584-0
                      • Opcode ID: dedb8fb46c5dda6867a1f8f7f3193f8991d0e0f929d9214b83268d16dff2bb5e
                      • Instruction ID: 834d90cd768b077ed922277b44a8b1d756accf54151f81db271eb36b9c4e200f
                      • Opcode Fuzzy Hash: dedb8fb46c5dda6867a1f8f7f3193f8991d0e0f929d9214b83268d16dff2bb5e
                      • Instruction Fuzzy Hash: 41C1F53225C78999E7619B21A48C3BF77B1F784BA8F451101EADA0B3D5DFBAC464C780

                      Control-flow Graph

                      • Executed
                      • Not Executed
                      control_flow_graph 1542 2674e1c2830-2674e1c2865 call 2674e1c1c54 call 2674e1c1c5c call 2674e1c1cc4 1549 2674e1c29a3-2674e1c2a11 call 2674e1b1058 call 2674e1cb124 1542->1549 1550 2674e1c286b-2674e1c2876 call 2674e1c1c64 1542->1550 1562 2674e1c2a13-2674e1c2a1a 1549->1562 1563 2674e1c2a1f-2674e1c2a22 1549->1563 1550->1549 1556 2674e1c287c-2674e1c2887 call 2674e1c1c94 1550->1556 1556->1549 1561 2674e1c288d-2674e1c28a7 call 2674e1bc8e4 call 2674e1f6260 1556->1561 1577 2674e1c28ad-2674e1c28b0 1561->1577 1565 2674e1c2aaf-2674e1c2ab2 1562->1565 1566 2674e1c2a24 1563->1566 1567 2674e1c2a59-2674e1c2a6c call 2674e1bf284 1563->1567 1569 2674e1c2a27 call 2674e1c2830 1565->1569 1570 2674e1c2ab8-2674e1c2ac0 call 2674e1c25b4 1565->1570 1566->1569 1579 2674e1c2a6e 1567->1579 1580 2674e1c2a77-2674e1c2a92 call 2674e1cb124 1567->1580 1576 2674e1c2a2c-2674e1c2a58 call 2674e1bc8e4 call 2674e1ce010 1569->1576 1570->1576 1582 2674e1c28b6-2674e1c28d7 1577->1582 1583 2674e1c2978-2674e1c29a2 call 2674e1c1c4c call 2674e1c1c3c call 2674e1c1c44 1577->1583 1584 2674e1c2a70-2674e1c2a75 call 2674e1bc8e4 1579->1584 1592 2674e1c2a94-2674e1c2a97 1580->1592 1593 2674e1c2a99-2674e1c2aab call 2674e1bc8e4 1580->1593 1587 2674e1c28e2-2674e1c28e9 1582->1587 1588 2674e1c28d9-2674e1c28df 1582->1588 1584->1566 1595 2674e1c28eb-2674e1c28f3 1587->1595 1596 2674e1c28fd 1587->1596 1588->1587 1592->1584 1593->1565 1595->1596 1602 2674e1c28f5-2674e1c28fb 1595->1602 1601 2674e1c28ff-2674e1c2973 call 2674e1d09c0 * 4 call 2674e1c60b8 call 2674e1c2ac8 * 2 1596->1601 1601->1583 1602->1601
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: _get_daylight_invalid_parameter_noinfo$ErrorFreeHeapInformationLastTimeZone
                      • String ID: Eastern Standard Time$Eastern Summer Time
                      • API String ID: 3458911817-239921721
                      • Opcode ID: 43bd24f32916a3010015ca28f009028db3fb9592cea4450c0e897acc97307f69
                      • Instruction ID: c8d2db4e48d5af5180f5fff16ff1b2a35777e6e650ef210741f473b8fb2bf724
                      • Opcode Fuzzy Hash: 43bd24f32916a3010015ca28f009028db3fb9592cea4450c0e897acc97307f69
                      • Instruction Fuzzy Hash: F151D172748A5086E720DF21F98D79B7770F7887ACF458526AB4D83A95DF3AC480C780

                      Control-flow Graph

                      • Executed
                      • Not Executed
                      control_flow_graph 1621 2674e1aa190-2674e1aa1d1 1622 2674e1aa1d7-2674e1aa201 call 2674e1d09c0 1621->1622 1623 2674e1aa4ad-2674e1aa4e7 call 2674e1adad0 call 2674e1aaa20 1621->1623 1628 2674e1aa210-2674e1aa249 call 2674e186760 call 2674e1acc30 call 2674e1aaa20 1622->1628 1629 2674e1aa203-2674e1aa20c 1622->1629 1632 2674e1aa4ec-2674e1aa4f2 1623->1632 1659 2674e1aa24f-2674e1aa2d4 call 2674e152030 call 2674e1868c0 call 2674e189fa0 call 2674e186e40 1628->1659 1660 2674e1aa3f0-2674e1aa3f7 1628->1660 1629->1628 1633 2674e1aa68f-2674e1aa693 1632->1633 1634 2674e1aa4f8-2674e1aa573 call 2674e152030 call 2674e1868c0 call 2674e189fa0 call 2674e186e40 1632->1634 1639 2674e1aa699-2674e1aa6f6 call 2674e1628d0 call 2674e163070 1633->1639 1640 2674e1aa75c-2674e1aa763 1633->1640 1688 2674e1aa579-2674e1aa581 1634->1688 1689 2674e1aa7ce-2674e1aa7ea call 2674e185930 call 2674e1d11d8 1634->1689 1642 2674e1aa735-2674e1aa75b call 2674e1ce010 1639->1642 1666 2674e1aa6f8-2674e1aa70d 1639->1666 1640->1642 1643 2674e1aa765-2674e1aa77a 1640->1643 1649 2674e1aa724-2674e1aa730 call 2674e1ce030 1643->1649 1650 2674e1aa77c-2674e1aa78f 1643->1650 1649->1642 1656 2674e1aa791 1650->1656 1657 2674e1aa799-2674e1aa79e call 2674e1b1028 1650->1657 1656->1649 1675 2674e1aa79f-2674e1aa7bb call 2674e185930 call 2674e1d11d8 1657->1675 1659->1675 1716 2674e1aa2da-2674e1aa2e2 1659->1716 1669 2674e1aa441-2674e1aa444 1660->1669 1670 2674e1aa3f9-2674e1aa43f call 2674e1628d0 1660->1670 1666->1649 1674 2674e1aa70f-2674e1aa722 1666->1674 1672 2674e1aa446-2674e1aa487 call 2674e1628d0 1669->1672 1673 2674e1aa49c-2674e1aa4a8 call 2674e186580 1669->1673 1684 2674e1aa48c-2674e1aa49b call 2674e163070 1670->1684 1672->1684 1673->1642 1674->1649 1674->1657 1707 2674e1aa7bc-2674e1aa7c1 call 2674e1b1028 1675->1707 1684->1673 1695 2674e1aa583-2674e1aa594 1688->1695 1696 2674e1aa5b4-2674e1aa5f9 call 2674e1cffe8 * 2 1688->1696 1708 2674e1aa7eb-2674e1aa7f0 call 2674e1b1028 1689->1708 1701 2674e1aa5af call 2674e1ce030 1695->1701 1702 2674e1aa596-2674e1aa5a9 1695->1702 1719 2674e1aa62d-2674e1aa648 1696->1719 1720 2674e1aa5fb-2674e1aa60d 1696->1720 1701->1696 1702->1701 1702->1708 1724 2674e1aa7c2-2674e1aa7c7 call 2674e1b1028 1707->1724 1723 2674e1aa7f1-2674e1aa7f6 call 2674e1b1028 1708->1723 1721 2674e1aa316-2674e1aa35c call 2674e1cffe8 * 2 1716->1721 1722 2674e1aa2e4-2674e1aa2f6 1716->1722 1727 2674e1aa64a-2674e1aa65c 1719->1727 1728 2674e1aa67c-2674e1aa68a 1719->1728 1725 2674e1aa60f-2674e1aa622 1720->1725 1726 2674e1aa628 call 2674e1ce030 1720->1726 1750 2674e1aa38f-2674e1aa3a9 1721->1750 1751 2674e1aa35e-2674e1aa36f 1721->1751 1729 2674e1aa311 call 2674e1ce030 1722->1729 1730 2674e1aa2f8-2674e1aa30b 1722->1730 1741 2674e1aa7c8-2674e1aa7cd call 2674e1b1028 1724->1741 1725->1723 1725->1726 1726->1719 1736 2674e1aa677 call 2674e1ce030 1727->1736 1737 2674e1aa65e-2674e1aa671 1727->1737 1728->1633 1729->1721 1730->1707 1730->1729 1736->1728 1737->1736 1743 2674e1aa793-2674e1aa798 call 2674e1b1028 1737->1743 1741->1689 1743->1657 1754 2674e1aa3dd-2674e1aa3eb 1750->1754 1755 2674e1aa3ab-2674e1aa3bd 1750->1755 1752 2674e1aa371-2674e1aa384 1751->1752 1753 2674e1aa38a call 2674e1ce030 1751->1753 1752->1724 1752->1753 1753->1750 1754->1660 1757 2674e1aa3bf-2674e1aa3d2 1755->1757 1758 2674e1aa3d8 call 2674e1ce030 1755->1758 1757->1741 1757->1758 1758->1754
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: __std_exception_destroy
                      • String ID: value
                      • API String ID: 2453523683-494360628
                      • Opcode ID: 987078f5df702c92cfcbb4711575e5ec2aceca2ad405bd377ea89f015cf24099
                      • Instruction ID: 7df936a9950a42261e0ef59b0ee39245dee3543b26c8c5844ae1e8946f924ab3
                      • Opcode Fuzzy Hash: 987078f5df702c92cfcbb4711575e5ec2aceca2ad405bd377ea89f015cf24099
                      • Instruction Fuzzy Hash: 31028072669BC085EB01CB74E48C3AF6771E7857B8F505302FA9D42ADAEF69C185C780

                      Control-flow Graph

                      • Executed
                      • Not Executed
                      control_flow_graph 1760 2674e15e8f0-2674e15e966 CreateToolhelp32Snapshot call 2674e1d09c0 call 2674e160300 1765 2674e15e96c-2674e15e97a Process32FirstW 1760->1765 1766 2674e15eb84-2674e15eba0 call 2674e160220 1760->1766 1768 2674e15e980-2674e15e982 1765->1768 1772 2674e15ede8-2674e15edfd call 2674e1f6140 1766->1772 1773 2674e15eba6-2674e15ec8c call 2674e164320 call 2674e1645f0 1766->1773 1768->1766 1769 2674e15e988-2674e15e9a0 call 2674e193180 1768->1769 1778 2674e15e9a5-2674e15e9c9 call 2674e16afc0 call 2674e165630 1769->1778 1779 2674e15e9a2 1769->1779 1781 2674e15ee2f-2674e15ee83 call 2674e15eea0 call 2674e1ce010 1772->1781 1782 2674e15edff-2674e15ee13 1772->1782 1794 2674e15ec90-2674e15ec98 1773->1794 1800 2674e15e9d0-2674e15e9f7 1778->1800 1779->1778 1785 2674e15ee2a call 2674e1ce030 1782->1785 1786 2674e15ee15-2674e15ee28 1782->1786 1785->1781 1786->1785 1790 2674e15ee84-2674e15ee89 call 2674e1b1028 1786->1790 1804 2674e15ee8a-2674e15ee8f call 2674e1b1028 1790->1804 1794->1794 1798 2674e15ec9a-2674e15ed40 call 2674e152030 call 2674e160e50 1794->1798 1815 2674e15ed45-2674e15ed4c 1798->1815 1800->1800 1803 2674e15e9f9-2674e15ea1b 1800->1803 1806 2674e15ea1d-2674e15ea35 1803->1806 1807 2674e15ea37-2674e15ea4b call 2674e16e020 1803->1807 1814 2674e15ee90-2674e15ee95 call 2674e1b1028 1804->1814 1811 2674e15ea50-2674e15ead3 call 2674e16afc0 call 2674e165630 call 2674e163c90 call 2674e168f10 call 2674e168db0 1806->1811 1807->1811 1842 2674e15eb09-2674e15eb2b 1811->1842 1843 2674e15ead5-2674e15eae9 1811->1843 1824 2674e15ee96-2674e15ee9b call 2674e1b1028 1814->1824 1815->1815 1819 2674e15ed4e-2674e15eda4 call 2674e152030 call 2674e160e50 call 2674e163070 1815->1819 1837 2674e15edd7-2674e15ede4 1819->1837 1838 2674e15eda6-2674e15edb7 1819->1838 1837->1772 1840 2674e15edb9-2674e15edcc 1838->1840 1841 2674e15edd2 call 2674e1ce030 1838->1841 1840->1824 1840->1841 1841->1837 1847 2674e15eb2d-2674e15eb3f 1842->1847 1848 2674e15eb5f-2674e15eb7f Process32NextW 1842->1848 1845 2674e15eaeb-2674e15eafe 1843->1845 1846 2674e15eb04 call 2674e1ce030 1843->1846 1845->1804 1845->1846 1846->1842 1850 2674e15eb5a call 2674e1ce030 1847->1850 1851 2674e15eb41-2674e15eb54 1847->1851 1848->1768 1850->1848 1851->1814 1851->1850
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Process32$CloseCreateFirstHandleNextSnapshotToolhelp32
                      • String ID: [PID:
                      • API String ID: 420147892-2210602247
                      • Opcode ID: 49e1bdd5f0a815328ed98b044775215af8e708dc1237a8f9b7400ba31e774226
                      • Instruction ID: 80fcc3b67147c7883bdab9faa170b260b0e38350881d67ffe68441dda93d17c6
                      • Opcode Fuzzy Hash: 49e1bdd5f0a815328ed98b044775215af8e708dc1237a8f9b7400ba31e774226
                      • Instruction Fuzzy Hash: 09E1B272658BC086EB21CF29E8883DE77B5F3857A8F504615EA9D07B99DF39C280C740
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: ProcessToken$AdjustCloseCurrentHandleLookupOpenPrivilegePrivilegesValue
                      • String ID:
                      • API String ID: 3038321057-0
                      • Opcode ID: 531cdee19d4338272bd72dea2281194fba849ceb76ba317d0e5429946739ecd1
                      • Instruction ID: 4b70ffd7c997ee1624066b6a07ad30d4be3058bf7e6e8977287ad683aa783c14
                      • Opcode Fuzzy Hash: 531cdee19d4338272bd72dea2281194fba849ceb76ba317d0e5429946739ecd1
                      • Instruction Fuzzy Hash: 85216232258B8082E720CF21F84865FB7B4F788BA4F554526EB8A47B58DF7EC541CB80
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID: cannot use push_back() with $directory_iterator::directory_iterator$exists$prefs.js$status
                      • API String ID: 0-2713369562
                      • Opcode ID: bc6167765cd887f948e6de0cafee9c8faaac96c4b35634b11dcebc054af40ea2
                      • Instruction ID: 596da1a50e3ce0141f80a885c0c12b48993b365a25a99d34e2134bff14ec6e8c
                      • Opcode Fuzzy Hash: bc6167765cd887f948e6de0cafee9c8faaac96c4b35634b11dcebc054af40ea2
                      • Instruction Fuzzy Hash: CA524732659BC485E6719B24F8893DBB3B4F7C9798F405616DACC42B5AEF39C184CB80
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: recv$Cleanupclosesocket
                      • String ID:
                      • API String ID: 146070474-0
                      • Opcode ID: 806a4a243e067ddc7ea33b02be9b806603713cc115ceef18e3d52f999a19f6ea
                      • Instruction ID: 78c0568fc6dba07616c74681e162b06d5688e2312c964cca21da5d8b9983f05b
                      • Opcode Fuzzy Hash: 806a4a243e067ddc7ea33b02be9b806603713cc115ceef18e3d52f999a19f6ea
                      • Instruction Fuzzy Hash: D612707265CBC481EA21CB25F45D3EFA372F7897A4F504612DAAD42ADADF79C084C780
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Cred$EnumerateFree
                      • String ID: cannot use push_back() with
                      • API String ID: 3403564193-4122110429
                      • Opcode ID: 7f4501be166d4e62800c9a0490ad29578926095491fce65abb76899efcbdcd5a
                      • Instruction ID: 4bb0d445339b40352c60abcc197e832c6a43ed1c1d84be50465e550172e5c7c2
                      • Opcode Fuzzy Hash: 7f4501be166d4e62800c9a0490ad29578926095491fce65abb76899efcbdcd5a
                      • Instruction Fuzzy Hash: 23625E72658BC489EB208F69E8883DE7771F3897ACF504316EAAD07A99DF75C184C740
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: InformationTimeZone
                      • String ID: [UTC
                      • API String ID: 565725191-1715286942
                      • Opcode ID: b58b7325c87ae02d2ee982d16b0f90fc9c459f7d80b1f325c0682f373bf87291
                      • Instruction ID: 3c5e494f9da2cd080d34e21500e6a009fb2f5d49744a38dbf9b9610f2671256a
                      • Opcode Fuzzy Hash: b58b7325c87ae02d2ee982d16b0f90fc9c459f7d80b1f325c0682f373bf87291
                      • Instruction Fuzzy Hash: F8910B32629FC48AD7918F29E88169EB3B5F399798F105215EECE57B19EF38C250C740
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: CryptDataFreeLocalUnprotect
                      • String ID:
                      • API String ID: 1561624719-0
                      • Opcode ID: 745b95fad6454cfba2baa49d265ae9e186c3197e9b7cc3c38aa5005324c71f1a
                      • Instruction ID: be4d40eaef690a4870da0db090bf7407f37d055f6a0c4e0b94f8e9cb96e9d1c2
                      • Opcode Fuzzy Hash: 745b95fad6454cfba2baa49d265ae9e186c3197e9b7cc3c38aa5005324c71f1a
                      • Instruction Fuzzy Hash: 7D414C32618B80CAE3208F74E4483EE37B5F75974CF054625EA8907E89DF7AD5A4C384
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: DriveLogicalStrings
                      • String ID:
                      • API String ID: 2022863570-0
                      • Opcode ID: 99e841b9d2a1402a9344bdc4a72a4f4aa518b8bacc59b2fa878c6312c5a5c892
                      • Instruction ID: 60dc318629ff5a74f7027efb934b4ca9e973750a7f79662f01f94c3cf36111a8
                      • Opcode Fuzzy Hash: 99e841b9d2a1402a9344bdc4a72a4f4aa518b8bacc59b2fa878c6312c5a5c892
                      • Instruction Fuzzy Hash: C7716F32A58B8082E710CF24F4883AEB775F7957A8F505305EB9813AA9DF79D1D1DB80
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: NameUser
                      • String ID:
                      • API String ID: 2645101109-0
                      • Opcode ID: 304db165e96ffb8f4312c8aac323597a159ec649b26c09208dc9996fa76d73a8
                      • Instruction ID: 099ad238079f8e5d494344532360e152511b94a38a51abc51201d4ee1dd62dcc
                      • Opcode Fuzzy Hash: 304db165e96ffb8f4312c8aac323597a159ec649b26c09208dc9996fa76d73a8
                      • Instruction Fuzzy Hash: B601843261878182E721CF21F84939FB3B0FB98798F440225E6CD42659DFBDC194CB84
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID: cores
                      • API String ID: 0-2370456839
                      • Opcode ID: 5f8d3312878fd7513d5439c5e54874277449181de9e6983141e79406de49ea54
                      • Instruction ID: ed4d94a8b1202f19498a395f434342704bc30766d79bec90df3e4191234a2165
                      • Opcode Fuzzy Hash: 5f8d3312878fd7513d5439c5e54874277449181de9e6983141e79406de49ea54
                      • Instruction Fuzzy Hash: FCB194B2F58B808AF700CFB8E0493ED3772A7957ACF605715DE5822A9ADF758195C380
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID: \u%04x
                      • API String ID: 0-2916071157
                      • Opcode ID: 423056e69d5645a73791192e4bdea90b748ecd25ecc214abb60e516277d7c3cf
                      • Instruction ID: de17402d2b1f3cf40086daed69d8ca66f6348b158b2bba9fc177528ac217888e
                      • Opcode Fuzzy Hash: 423056e69d5645a73791192e4bdea90b748ecd25ecc214abb60e516277d7c3cf
                      • Instruction Fuzzy Hash: CA81E23234868492EB54CB29F45C7BE6771F785B98F888422DB4E47B92DF3AC555C380
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID: ":
                      • API String ID: 0-3662656813
                      • Opcode ID: 8d0ff03ade165144a1cb16236d9c57af16f3fb6bb80c765c02794f7e906c0b96
                      • Instruction ID: 5ed4c61c9f5d970428be305ab01fd8be4fe9510d505e2661d83f1dd0073bd5b5
                      • Opcode Fuzzy Hash: 8d0ff03ade165144a1cb16236d9c57af16f3fb6bb80c765c02794f7e906c0b96
                      • Instruction Fuzzy Hash: 48910276208A8582DB20DF26E09866E7771F788FD8F459002DF4E47B65CF7AC558CB80
                      Strings
                      • ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/, xrefs: 000002674E1643A9
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID: ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
                      • API String ID: 0-1713319389
                      • Opcode ID: 9aa0667118115d02de2f98f1551d5d1aef04593037e5c7732c84333e8f847c70
                      • Instruction ID: dd14b176842534f6db795573761ac13f6370e5b6b6cfaeeb625b67c589044072
                      • Opcode Fuzzy Hash: 9aa0667118115d02de2f98f1551d5d1aef04593037e5c7732c84333e8f847c70
                      • Instruction Fuzzy Hash: AC41B17361D6E04AE702CB39941537D7FB2E366B88F1C8252DBD48774ADA2EC216CB10
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: f13c4fc0892c945449c4b0a1aa611ece94c51e5f87558ca622be0231ad3f26a8
                      • Instruction ID: 4ae0f0535df21d41fb2fa858ce53722b6a23e78d9776f0e386724de81e102c40
                      • Opcode Fuzzy Hash: f13c4fc0892c945449c4b0a1aa611ece94c51e5f87558ca622be0231ad3f26a8
                      • Instruction Fuzzy Hash: C8725E72659BC489DB308F29E8483DE73B5F3897A8F504315EA9C56B99EF39C284C740
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 85bf54d05ae5b2102e59a41a46eddd9130fbe40a36119e206e038bf8a4a2031a
                      • Instruction ID: 5b7acf84606be6db2fc774a86c2851dd90667d394b0a1b0ba98a5ffe4f1a5ca1
                      • Opcode Fuzzy Hash: 85bf54d05ae5b2102e59a41a46eddd9130fbe40a36119e206e038bf8a4a2031a
                      • Instruction Fuzzy Hash: B8F16D72619F848AEB208B69F44935E77B4F3887ACF105315EADC57B99EF38C1908B40
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: ee91e03d6bdba9ce984c20643351cb60f5c2fb637e94a0ac2dec0ed29fe7b088
                      • Instruction ID: b7a0041a371a76f15a9facf9ed512481f343129ba7fe28e7d7928901f015a1ad
                      • Opcode Fuzzy Hash: ee91e03d6bdba9ce984c20643351cb60f5c2fb637e94a0ac2dec0ed29fe7b088
                      • Instruction Fuzzy Hash: 19F15D32619F848AEB218B69E84535E77B4F3897ACF104315EEDC57B99EF78C1908B40

                      Control-flow Graph

                      • Executed
                      • Not Executed
                      control_flow_graph 132 2674e199c30-2674e199c6b call 2674e1999b0 135 2674e199cac 132->135 136 2674e199c6d-2674e199c7c EnterCriticalSection 132->136 139 2674e199cb1-2674e199ccf call 2674e1ce010 135->139 137 2674e199cd0-2674e199cea LeaveCriticalSection GdipGetImageEncodersSize 136->137 138 2674e199c7e-2674e199ca0 GdiplusStartup 136->138 137->135 142 2674e199cec-2674e199cff 137->142 138->137 140 2674e199ca2-2674e199ca6 LeaveCriticalSection 138->140 140->135 143 2674e199d01-2674e199d0a call 2674e199740 142->143 144 2674e199d3b-2674e199d49 call 2674e1b7a5c 142->144 150 2674e199d38 143->150 151 2674e199d0c-2674e199d16 143->151 152 2674e199d50-2674e199d5a 144->152 153 2674e199d4b-2674e199d4e 144->153 150->144 154 2674e199d22-2674e199d36 call 2674e1cf000 151->154 155 2674e199d18 151->155 156 2674e199d5e-2674e199d61 152->156 153->156 154->156 155->154 158 2674e199d63-2674e199d68 156->158 159 2674e199d6d-2674e199d7e GdipGetImageEncoders 156->159 160 2674e199ed8-2674e199edb 158->160 161 2674e199d84-2674e199d8d 159->161 162 2674e199ec3-2674e199ec8 159->162 166 2674e199ef4-2674e199ef6 160->166 167 2674e199edd 160->167 164 2674e199dbf 161->164 165 2674e199d8f-2674e199d9d 161->165 162->160 170 2674e199dc6-2674e199dd6 164->170 168 2674e199da0-2674e199dab 165->168 166->139 169 2674e199ee0-2674e199ef2 call 2674e1b0410 167->169 171 2674e199db8-2674e199dbd 168->171 172 2674e199dad-2674e199db2 168->172 169->166 174 2674e199dd8-2674e199de3 170->174 175 2674e199de9-2674e199e05 170->175 171->164 171->168 172->171 176 2674e199e67-2674e199e6b 172->176 174->162 174->175 178 2674e199e72-2674e199eb1 GdipCreateBitmapFromHBITMAP GdipSaveImageToStream 175->178 179 2674e199e07-2674e199e60 GdipCreateBitmapFromScan0 GdipSaveImageToStream 175->179 176->170 182 2674e199eb3 178->182 183 2674e199eca-2674e199ed7 GdipDisposeImage 178->183 180 2674e199e70 179->180 181 2674e199e62-2674e199e65 179->181 180->183 184 2674e199eb6-2674e199ebd GdipDisposeImage 181->184 182->184 183->160 184->162
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Gdip$Image$CriticalSection$DisposeEncodersLeave$BitmapCreateEnterErrorFromGdiplusInitializeLastSaveScan0SizeStartupStream
                      • String ID: &
                      • API String ID: 1703174404-3042966939
                      • Opcode ID: c8cab759edf9eae6b4a215f3f51f8edc88a07c67ac3e523ca83177caeb1bf491
                      • Instruction ID: 2ce658c488aa7070ba7d058fd410b83457e03f02fb60e260d8c0fa0e3ef6be00
                      • Opcode Fuzzy Hash: c8cab759edf9eae6b4a215f3f51f8edc88a07c67ac3e523ca83177caeb1bf491
                      • Instruction Fuzzy Hash: 91916A32244B459AEB20CF31E84C79A37B5F759BACF458515EA4947B98DF3AC981C3C0

                      Control-flow Graph

                      • Executed
                      • Not Executed
                      control_flow_graph 831 2674e19adb0-2674e19aed6 call 2674e1a0a50 call 2674e174580 call 2674e152030 call 2674e160e50 call 2674e152030 call 2674e160e50 call 2674e163070 WSAStartup 846 2674e19b04f 831->846 847 2674e19aedc-2674e19aefc socket 831->847 848 2674e19b051-2674e19b059 846->848 849 2674e19af02-2674e19af2f htons 847->849 850 2674e19b049 WSACleanup 847->850 851 2674e19b08c-2674e19b0cc call 2674e1ce010 848->851 852 2674e19b05b-2674e19b06c 848->852 853 2674e19b0f0-2674e19b124 call 2674e199f00 call 2674e161bb0 849->853 854 2674e19af35-2674e19af3d 849->854 850->846 856 2674e19b087 call 2674e1ce030 852->856 857 2674e19b06e-2674e19b081 852->857 878 2674e19b126-2674e19b13c 853->878 879 2674e19b15c-2674e19b179 call 2674e199f00 853->879 859 2674e19af3f-2674e19af46 854->859 860 2674e19af48-2674e19af56 854->860 856->851 857->856 862 2674e19b1f9-2674e19b1fe call 2674e1b1028 857->862 865 2674e19af58 859->865 860->865 866 2674e19af5b-2674e19af5e 860->866 880 2674e19b1ff-2674e19b204 call 2674e1b1028 862->880 865->866 869 2674e19af60-2674e19af6a call 2674e1b8030 866->869 870 2674e19af74-2674e19af7c 866->870 869->870 888 2674e19af6c-2674e19af72 869->888 871 2674e19af86-2674e19af8c 870->871 872 2674e19af7e-2674e19af84 870->872 876 2674e19af8e-2674e19afa5 871->876 877 2674e19afa7-2674e19afc5 871->877 872->876 882 2674e19afc7 876->882 877->882 883 2674e19afca-2674e19aff7 call 2674e1d0310 call 2674e1ac280 877->883 884 2674e19b157 call 2674e1ce030 878->884 885 2674e19b13e-2674e19b151 878->885 891 2674e19b17e-2674e19b1a6 call 2674e161bb0 879->891 882->883 900 2674e19aff9 883->900 901 2674e19affc-2674e19b029 inet_pton connect 883->901 884->879 885->880 885->884 888->869 888->870 898 2674e19b1a8-2674e19b1be 891->898 899 2674e19b1da-2674e19b1ee 891->899 902 2674e19b1c0-2674e19b1d3 898->902 903 2674e19b1d5 call 2674e1ce030 898->903 899->848 900->901 905 2674e19b02f-2674e19b036 901->905 906 2674e19b0cd-2674e19b0d7 901->906 902->903 907 2674e19b1f3-2674e19b1f8 call 2674e1b1028 902->907 903->899 905->854 910 2674e19b03c-2674e19b043 closesocket 905->910 906->853 909 2674e19b0d9-2674e19b0e2 906->909 907->862 912 2674e19b0e4 909->912 913 2674e19b0e7-2674e19b0ef call 2674e163610 909->913 910->850 912->913 913->853
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Info$CleanupStartupUserclosesocketconnecthtonsinet_ptonsocket
                      • String ID: geo$system
                      • API String ID: 213021568-2364779556
                      • Opcode ID: c2fc1ad6804c5c5f360e4f6909b4af621ec0678ef62ffb262d1181aed6f8fe8c
                      • Instruction ID: d96bd80f8a51e0364823b99b34ee8949c26174725b467a0369db0cb467c07531
                      • Opcode Fuzzy Hash: c2fc1ad6804c5c5f360e4f6909b4af621ec0678ef62ffb262d1181aed6f8fe8c
                      • Instruction Fuzzy Hash: 71C1DF72758A8185FB10CF65F44C39E7372E7497B8F404616DAA913BE9DE3AC54AC380

                      Control-flow Graph

                      • Executed
                      • Not Executed
                      control_flow_graph 1242 2674e1e2de4-2674e1e2e57 call 2674e1e29c4 1245 2674e1e2e71-2674e1e2e7b call 2674e1c4d80 1242->1245 1246 2674e1e2e59-2674e1e2e62 call 2674e1b54ac 1242->1246 1252 2674e1e2e96-2674e1e2eff CreateFileW 1245->1252 1253 2674e1e2e7d-2674e1e2e94 call 2674e1b54ac call 2674e1b54cc 1245->1253 1251 2674e1e2e65-2674e1e2e6c call 2674e1b54cc 1246->1251 1269 2674e1e31b3-2674e1e31d3 1251->1269 1254 2674e1e2f01-2674e1e2f07 1252->1254 1255 2674e1e2f7c-2674e1e2f87 GetFileType 1252->1255 1253->1251 1259 2674e1e2f49-2674e1e2f77 call 2674e1f6168 call 2674e1b5440 1254->1259 1260 2674e1e2f09-2674e1e2f0d 1254->1260 1262 2674e1e2f89-2674e1e2fc4 call 2674e1f6168 call 2674e1b5440 call 2674e1f6140 1255->1262 1263 2674e1e2fda-2674e1e2fe1 1255->1263 1259->1251 1260->1259 1265 2674e1e2f0f-2674e1e2f47 CreateFileW 1260->1265 1262->1251 1289 2674e1e2fca-2674e1e2fd5 call 2674e1b54cc 1262->1289 1267 2674e1e2fe3-2674e1e2fe7 1263->1267 1268 2674e1e2fe9-2674e1e2fec 1263->1268 1265->1255 1265->1259 1273 2674e1e2ff2-2674e1e3047 call 2674e1c4c98 1267->1273 1268->1273 1274 2674e1e2fee 1268->1274 1283 2674e1e3066-2674e1e3097 call 2674e1e274c 1273->1283 1284 2674e1e3049-2674e1e3055 call 2674e1e2bd0 1273->1284 1274->1273 1293 2674e1e309d-2674e1e30e0 1283->1293 1294 2674e1e3099-2674e1e309b 1283->1294 1284->1283 1291 2674e1e3057 1284->1291 1289->1251 1295 2674e1e3059-2674e1e3061 call 2674e1bca5c 1291->1295 1297 2674e1e3102-2674e1e310d 1293->1297 1298 2674e1e30e2-2674e1e30e6 1293->1298 1294->1295 1295->1269 1301 2674e1e3113-2674e1e3117 1297->1301 1302 2674e1e31b1 1297->1302 1298->1297 1300 2674e1e30e8-2674e1e30fd 1298->1300 1300->1297 1301->1302 1304 2674e1e311d-2674e1e3162 call 2674e1f6140 CreateFileW 1301->1304 1302->1269 1307 2674e1e3164-2674e1e3192 call 2674e1f6168 call 2674e1b5440 call 2674e1c4ec0 1304->1307 1308 2674e1e3197-2674e1e31ac 1304->1308 1307->1308 1308->1302
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: File$CreateErrorLast_invalid_parameter_noinfo$CloseHandle$Type_get_daylight
                      • String ID:
                      • API String ID: 1330151763-0
                      • Opcode ID: fdf61d42724756312793b09a47440c7f26da154d6b582e1d821e9f29e9064b4d
                      • Instruction ID: a8bd7be974ba9c29004eb68a4abf9439d68697f3fc1a0f5ef7352b72b41edb17
                      • Opcode Fuzzy Hash: fdf61d42724756312793b09a47440c7f26da154d6b582e1d821e9f29e9064b4d
                      • Instruction Fuzzy Hash: F7C1BF36768A4086EB14CF69E4986AE3771F389BACF011205EB2E9B7D5DF36C455C380

                      Control-flow Graph

                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: CriticalSection$EnterLeave$DeleteGdiplusObjectShutdown
                      • String ID:
                      • API String ID: 4268643673-0
                      • Opcode ID: be887bc960cbccda344ab6468f496d858ea158950171f96801833c93cdf224ad
                      • Instruction ID: b5807d62ebd8cd82244c5f168905c9e71b4a24a0235a5b2aaf1d7e3b3edfb966
                      • Opcode Fuzzy Hash: be887bc960cbccda344ab6468f496d858ea158950171f96801833c93cdf224ad
                      • Instruction Fuzzy Hash: 9C110632215B50C1EB109F25F84C11A73B4FB48FA8B688615DAAE066A4DF3AC896C7C0
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Value
                      • String ID: ProductName$SOFTWARE\Microsoft\Windows NT\CurrentVersion
                      • API String ID: 3702945584-1787575317
                      • Opcode ID: b1e0a8fe3c51dcceeb44e5e829cc4e22f419d79027cccbe765d0735392233611
                      • Instruction ID: d48bd5f8a5030c2ab525141ae8364f2efabd74d5492fbaf276c6e895a1cbfe34
                      • Opcode Fuzzy Hash: b1e0a8fe3c51dcceeb44e5e829cc4e22f419d79027cccbe765d0735392233611
                      • Instruction Fuzzy Hash: B0114932608B8586EB20CF21F44939FB3B4F789798F950215EB9847B59DFB9C194CB80
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Cleanupclosesocketrecv
                      • String ID:
                      • API String ID: 3447645871-0
                      • Opcode ID: a1fd8b036ec507ad2677786e8e2f05097c65768e2b4a7e4e5f93b3f25a2915ae
                      • Instruction ID: a071a9cfb26105d1890ac6de02de49fe09b36a2365b1e05bfcbed288b79c0e0c
                      • Opcode Fuzzy Hash: a1fd8b036ec507ad2677786e8e2f05097c65768e2b4a7e4e5f93b3f25a2915ae
                      • Instruction Fuzzy Hash: 0B915F72658BC081EA218B29F44D3AF6731F7897B8F504711DAAD43ADADF7AC485C780
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: CloseEnumOpen
                      • String ID:
                      • API String ID: 1332880857-0
                      • Opcode ID: 37a20a9c9e16e55d53c3a3fc0d2c691137ca469aefa22ef58f04c22457e6a31c
                      • Instruction ID: 001332d8d9cc170219218e80ace877d9e8bd3697bd4367d61244b523965a2a72
                      • Opcode Fuzzy Hash: 37a20a9c9e16e55d53c3a3fc0d2c691137ca469aefa22ef58f04c22457e6a31c
                      • Instruction Fuzzy Hash: 9E716C72758B8486FB108B69F44C3AE6771F7857B8F600606EAA913AD9DF79C0C1C780
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: EnumOpen
                      • String ID:
                      • API String ID: 3231578192-0
                      • Opcode ID: 284f26594728a5cfb21f7fab24030501096eb33afcc3a3f4b41e590617c8509e
                      • Instruction ID: b1e3b8d5c9f89945e453637c659aaa9c8d6b717ca6f6a11ed4263c0e4ad3b601
                      • Opcode Fuzzy Hash: 284f26594728a5cfb21f7fab24030501096eb33afcc3a3f4b41e590617c8509e
                      • Instruction Fuzzy Hash: 12319E32754B818AE720CFA1F848BAE7374F7487ACF200615EE9917A58DF79C192C780
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: _invalid_parameter_noinfo$_local_unwind
                      • String ID:
                      • API String ID: 1677304287-0
                      • Opcode ID: 13238feca355ad5099b8879a5aa110a70d7495b53b6978f051a829bb7d95c8e0
                      • Instruction ID: c2b3583ab5ef905c03b5440d65b3c43ecbb8abe0ef1dafd1ef937198b34722bf
                      • Opcode Fuzzy Hash: 13238feca355ad5099b8879a5aa110a70d7495b53b6978f051a829bb7d95c8e0
                      • Instruction Fuzzy Hash: 1321AD32658A4585EA54DF14F4AD3BF2371F798BA8F980521E65A4B3E2EF3AC104C380
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: CloseOpenQueryValue
                      • String ID:
                      • API String ID: 3677997916-0
                      • Opcode ID: d4b9140bfc6d9ea04eacfbff610b74c596ef884b94f6cef94036681d8c8e6d65
                      • Instruction ID: 1bfcdbec9863933c0e60c6cd8a52892952a770cdc60d7c43fbbedefc89a44cb4
                      • Opcode Fuzzy Hash: d4b9140bfc6d9ea04eacfbff610b74c596ef884b94f6cef94036681d8c8e6d65
                      • Instruction Fuzzy Hash: 31218072758B8081EA508B25F49D36FA731E7D97E8F505211EA8E42AA9DF2DC084CB80
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Info$User
                      • String ID:
                      • API String ID: 2017065092-0
                      • Opcode ID: 5e81fc33c97f2df56606f25030b080222af27e1cacd37c198a59a94de2717080
                      • Instruction ID: e72ed617c2fc22189a25b30127e6ca433fa4449cff55abf36fe565b5801d244f
                      • Opcode Fuzzy Hash: 5e81fc33c97f2df56606f25030b080222af27e1cacd37c198a59a94de2717080
                      • Instruction Fuzzy Hash: FA118832628B8087E7108F61F45875EB3A1F794B88F445628EB8503B59EF7DD5908B84
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: ProcessToken$CurrentInformationOpen
                      • String ID:
                      • API String ID: 2743777493-0
                      • Opcode ID: 79da113c3c0a76ffcf1c48350ac2c5eed2f535508000765d1fa8a3a57ddea8bb
                      • Instruction ID: 6bb0124204afa3c0a9d164563fd4ce3743a41378c0b150c1b685037b9ff3e1a9
                      • Opcode Fuzzy Hash: 79da113c3c0a76ffcf1c48350ac2c5eed2f535508000765d1fa8a3a57ddea8bb
                      • Instruction Fuzzy Hash: 91114C32618B8186EB50CF11F44834BB3B0F789B98F559126EB8A47B18CF39D555CB80
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Concurrency::cancel_current_task
                      • String ID: cannot use operator[] with a numeric argument with
                      • API String ID: 118556049-485864652
                      • Opcode ID: 9b0994f026258f43ebbce98ea956028a87141582a1d70255c3a1aaa8c98a4bc8
                      • Instruction ID: cdab77396c090509a8c3d80d7691be0b35528838510704f7c17b320c0c833094
                      • Opcode Fuzzy Hash: 9b0994f026258f43ebbce98ea956028a87141582a1d70255c3a1aaa8c98a4bc8
                      • Instruction Fuzzy Hash: 4C31D77234978456EE149B26B54C35E62A6AB04BF8F584B219FBE0B7D5DE79C081C380
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: CurrentProfile
                      • String ID: Unknown
                      • API String ID: 2104809126-1654365787
                      • Opcode ID: 2a6ee122688f5a96e0a8cc6196d85905b433c85ebbab946d33e16e82af128ba1
                      • Instruction ID: 66b1b6f1f45dca4d64149b813278cc6792a8f9439882d727db434a55039bfed9
                      • Opcode Fuzzy Hash: 2a6ee122688f5a96e0a8cc6196d85905b433c85ebbab946d33e16e82af128ba1
                      • Instruction Fuzzy Hash: 7F31AF3262CBC082E621CF25F4483ABB770F799798F545215EBC902A56DF7EC184CB80
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: FolderFreeKnownPathTask
                      • String ID:
                      • API String ID: 969438705-0
                      • Opcode ID: 9d342e6bc7984493d0823a976a2a24132e515d0a9b4175990963786efd2d540d
                      • Instruction ID: 2e45d1008981dbf69c024f5b51210fd27a0d12fc3695a28a783ea9a669c407d6
                      • Opcode Fuzzy Hash: 9d342e6bc7984493d0823a976a2a24132e515d0a9b4175990963786efd2d540d
                      • Instruction Fuzzy Hash: 04317372A18B8081E6208B25F48935FA771F7997F8F145316EAAD42A99DF7DC181CB80
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: CloseOpen
                      • String ID:
                      • API String ID: 47109696-0
                      • Opcode ID: 63935fde39ecc338d01250bcb3d3bae0183f3603a2da617671fa71598eb8f9c0
                      • Instruction ID: 6c84f4374b0e4b8bf25f46b0f39002f5b9c1ea4e67cc97d7ee90268018be6187
                      • Opcode Fuzzy Hash: 63935fde39ecc338d01250bcb3d3bae0183f3603a2da617671fa71598eb8f9c0
                      • Instruction Fuzzy Hash: AA21C931759A4085FE50DB21F84C3ABA371FB99BE8F595111FA4E43B99DF29C481CB80
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: CloseCreateCredEnumerateFirstHandleMutexProcess32ReleaseSnapshotToolhelp32recv
                      • String ID:
                      • API String ID: 420082584-0
                      • Opcode ID: 2aff061a96fa003136030da793816787c67282d0d4cc7bf931d73954cfeefc25
                      • Instruction ID: ea73783467e8a35c3d68243b26c98203b06326b8b5c1c9e06282a1021940d8ed
                      • Opcode Fuzzy Hash: 2aff061a96fa003136030da793816787c67282d0d4cc7bf931d73954cfeefc25
                      • Instruction Fuzzy Hash: 142184716DC68041F96077B8B05F3EF1272BF877BCF510911E69A411D79E1B8080C6D2
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: CloseHandleMutexReleaserecv
                      • String ID:
                      • API String ID: 2659716615-0
                      • Opcode ID: 41887f138c2950a91eb45c9b439a4017ba76a56d803172850a4683dc8199a118
                      • Instruction ID: 68e6e38a6136c106f0f98a8829603b461104e0234e5a485021304f7721e465f7
                      • Opcode Fuzzy Hash: 41887f138c2950a91eb45c9b439a4017ba76a56d803172850a4683dc8199a118
                      • Instruction Fuzzy Hash: C811A9726DC68041FA50B778F45E39F6272BF877BCF440A10DA9A412D7DE1AC080C6D1
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: ErrorFileLastPointer
                      • String ID:
                      • API String ID: 2976181284-0
                      • Opcode ID: 684c58d74d927086b1ea70340506491b7a3181aa5c9dc2c1a8c1bf280f0d3fce
                      • Instruction ID: b664f65a853264868cfdb6d7da778b314feda492d950ed7020c858528c1db9bf
                      • Opcode Fuzzy Hash: 684c58d74d927086b1ea70340506491b7a3181aa5c9dc2c1a8c1bf280f0d3fce
                      • Instruction Fuzzy Hash: 2911E371318B8085DA10CB25F44C2AA6371A744BF8F584715EEBA4B7D9DF39C05187C0
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Concurrency::cancel_current_task$std::bad_alloc::bad_alloc
                      • String ID:
                      • API String ID: 1173176844-0
                      • Opcode ID: 647c0ec3bd219342c1a3967082ea970fdc1df8bfe98e4d70f3447211def9c4af
                      • Instruction ID: 64c38cb2ef2878c3cd827e19f1209bbbd71e00c37e17346f5a3396e53f407233
                      • Opcode Fuzzy Hash: 647c0ec3bd219342c1a3967082ea970fdc1df8bfe98e4d70f3447211def9c4af
                      • Instruction Fuzzy Hash: B9E012707C910545FD6827B534AD3BB01601F49778E1C27206A36856C7AF1684D282D0
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: ErrorFreeHeapLast
                      • String ID:
                      • API String ID: 485612231-0
                      • Opcode ID: 72138e40380d5112b21707695b445e96a660da0ee9e2d4851e9dc7ca50ec71c9
                      • Instruction ID: 4293554bd65feec0b9da869096f6efb382477f9eeedd62962ac6d73597a28319
                      • Opcode Fuzzy Hash: 72138e40380d5112b21707695b445e96a660da0ee9e2d4851e9dc7ca50ec71c9
                      • Instruction Fuzzy Hash: 4BE01270B5D74156FF5867F2784E33B11B25FD87A9F04446489AB86262ED2A498442C0
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Concurrency::cancel_current_task
                      • String ID:
                      • API String ID: 118556049-0
                      • Opcode ID: 06f445c4d715db9863d0123942d7ba89de07497fb5fccb386a9ea5c6f4e75a07
                      • Instruction ID: 3c71711246c930515fabc5ebfb35b49aa83294ce46fd50a6a16ba38b76389a36
                      • Opcode Fuzzy Hash: 06f445c4d715db9863d0123942d7ba89de07497fb5fccb386a9ea5c6f4e75a07
                      • Instruction Fuzzy Hash: 52618D3234964489EE24DF1AA09C37E6771F745FB8F958A12CE6A0B7D5DE3AD4C18380
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Concurrency::cancel_current_task
                      • String ID:
                      • API String ID: 118556049-0
                      • Opcode ID: 65d87c9becc87b84f7b60218b84011864f34b5e39e3dfbbd607665c6a2404761
                      • Instruction ID: 86e1c56bae183b4bb536034b0160d83fb8b365608b282b1ec0d3d14e216d2685
                      • Opcode Fuzzy Hash: 65d87c9becc87b84f7b60218b84011864f34b5e39e3dfbbd607665c6a2404761
                      • Instruction Fuzzy Hash: C8515772348B448AEB158F29E05835E73B1F349FA8F954612DE5E473A9DF3AC481C380
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Concurrency::cancel_current_task
                      • String ID:
                      • API String ID: 118556049-0
                      • Opcode ID: f9eeb733f8a4a108af94915df536c0dc9c1f59d31989ab427aad8964bec0a731
                      • Instruction ID: 60214ffc676cdfcd68263aae3045cbd3d70c94b0b8d3cd049a72ce2151a760eb
                      • Opcode Fuzzy Hash: f9eeb733f8a4a108af94915df536c0dc9c1f59d31989ab427aad8964bec0a731
                      • Instruction Fuzzy Hash: 3541923134968446EA209F26B50C3AFA775FB44BF8F584621AFAD077D9DF3AC1418344
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: __std_fs_directory_iterator_open
                      • String ID:
                      • API String ID: 4007087469-0
                      • Opcode ID: 43e7b7ec92958d63d99828dcff5fb3f68b6e8dc1755e8ac558656ec0f0987f5b
                      • Instruction ID: a47983bc631e984ad595ee01c51a398be8ac0d0fa28a84a4621216c588127f82
                      • Opcode Fuzzy Hash: 43e7b7ec92958d63d99828dcff5fb3f68b6e8dc1755e8ac558656ec0f0987f5b
                      • Instruction Fuzzy Hash: CC41B07369874042EA209B29B54C3AF6372E7897F8F544321EE69477D5EF3AC5828780
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: InformationVolume__std_fs_get_current_path
                      • String ID:
                      • API String ID: 155845060-0
                      • Opcode ID: 17caa88a6e64e68cf8b2a5312d52c31980bee5c53dc09247b1e49657a9dce78d
                      • Instruction ID: 4f056804e93c877de74a4ca6f0a4745f5220bb811dee9400d3329ccfbc554826
                      • Opcode Fuzzy Hash: 17caa88a6e64e68cf8b2a5312d52c31980bee5c53dc09247b1e49657a9dce78d
                      • Instruction Fuzzy Hash: E151A032B58B8086E710CF78E8483AE7775F785798F504216EB8D53A99DF79C584CB80
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: _invalid_parameter_noinfo
                      • String ID:
                      • API String ID: 3215553584-0
                      • Opcode ID: 46feabfb0ec63526bfe7f4d0af9dd018a1b8cbeb56ac3d5732f810cec2e323f6
                      • Instruction ID: 35351a424e1eee991b90ee94a26180d5c1134fb359de7594af67728d47ad1d93
                      • Opcode Fuzzy Hash: 46feabfb0ec63526bfe7f4d0af9dd018a1b8cbeb56ac3d5732f810cec2e323f6
                      • Instruction Fuzzy Hash: 0D41A1326596848BEA74CB19F54C3BE77B1E794BA8F100245EBE687791CF3AD402C781
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 2016bef736a871d965ad28d601afe214608b753d0a8815541933cd2007257222
                      • Instruction ID: 5a75df9426e8a590b91d3dd81f6166366f94a12e40725c255c229a091dd1a9b8
                      • Opcode Fuzzy Hash: 2016bef736a871d965ad28d601afe214608b753d0a8815541933cd2007257222
                      • Instruction Fuzzy Hash: D231A87134964447EE24DB25F50C3AEA372EB48BF8F5846229B6D0B7D5DE79C1918380
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Concurrency::cancel_current_task
                      • String ID:
                      • API String ID: 118556049-0
                      • Opcode ID: bf54b1cc109dbce257a7005c98462d862d7f1a93d9052ce3ddfbaee0a55d3b34
                      • Instruction ID: 835cc46206d96633b78cd5a8c7db94f8bdb7e947ff985b2529cdd85328fdfcd9
                      • Opcode Fuzzy Hash: bf54b1cc109dbce257a7005c98462d862d7f1a93d9052ce3ddfbaee0a55d3b34
                      • Instruction Fuzzy Hash: 9F319572345B8481EA24DF65F14C37FA3B1E788BE8F1046259BAE17B95DF39C0418380
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Concurrency::cancel_current_task
                      • String ID:
                      • API String ID: 118556049-0
                      • Opcode ID: 3d16a0aeb39d9c52c041f65ce0578effe35c927b71fa7443a73ada3af2142184
                      • Instruction ID: 2b7265f9071063a394c0249ed9cc828625b4929481051666200403a5e7021363
                      • Opcode Fuzzy Hash: 3d16a0aeb39d9c52c041f65ce0578effe35c927b71fa7443a73ada3af2142184
                      • Instruction Fuzzy Hash: B021E632745B8446EE19EB25B50C3AA6271EB44BF8F2447219A7D437D6EF7AC4D28380
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Concurrency::cancel_current_task
                      • String ID:
                      • API String ID: 118556049-0
                      • Opcode ID: de654f582790c1b2a35a96a9886b6342dcb862ad43b9daa025dfbf981dd7dae6
                      • Instruction ID: f23dddc4ab3b6b946251b62d44b3ed2cc36facc8421d079886f00158a519831b
                      • Opcode Fuzzy Hash: de654f582790c1b2a35a96a9886b6342dcb862ad43b9daa025dfbf981dd7dae6
                      • Instruction Fuzzy Hash: DD21F47238A6844AFE19DB35F15C37E62619740FFCF440A219A7E07BD9DE6AC5828384
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: _invalid_parameter_noinfo
                      • String ID:
                      • API String ID: 3215553584-0
                      • Opcode ID: 457153a46a009ee407bab954f631945d0509b3d7eb0f1de31150085b5eb366e5
                      • Instruction ID: 3ce5aa86212bb395dc0064a9ad1c19361283408c20f4acc9f8cdb8002a765b47
                      • Opcode Fuzzy Hash: 457153a46a009ee407bab954f631945d0509b3d7eb0f1de31150085b5eb366e5
                      • Instruction Fuzzy Hash: 2F31983165860489F7916F15E88D37F36B1A784BBDF510205E9AA0B3D2DF7AC444C791
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: _invalid_parameter_noinfo
                      • String ID:
                      • API String ID: 3215553584-0
                      • Opcode ID: 2220776c349fdba2b6784378f9128c234d6ceb4fcfd5e2b10759636d1f6578db
                      • Instruction ID: e389c162189d684ed60246240b17e5b49155be8bd8031ca09ab1f338cfb9729b
                      • Opcode Fuzzy Hash: 2220776c349fdba2b6784378f9128c234d6ceb4fcfd5e2b10759636d1f6578db
                      • Instruction Fuzzy Hash: 7A11D332B4C79081EA609F11F44C7BFB2B0B784BA9F584421EA9947786DF3EC40087C2
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: _invalid_parameter_noinfo
                      • String ID:
                      • API String ID: 3215553584-0
                      • Opcode ID: 0d6c5737907d3245f73467c876848eebb3143c49d3ef4b73218378d8403eb434
                      • Instruction ID: e34fef9f7feda816b5309dfe46252419d78adf21b66348aea1c0723e1a4ef400
                      • Opcode Fuzzy Hash: 0d6c5737907d3245f73467c876848eebb3143c49d3ef4b73218378d8403eb434
                      • Instruction Fuzzy Hash: CD219632618A8087DB619F1CF45C36A77B1F794B68F544324FA69476D9DF3AC440CB40
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: send
                      • String ID:
                      • API String ID: 2809346765-0
                      • Opcode ID: c6986e2cf72187001e57c619f9179f3f533dc14f1b44f62c562c025f18a7376a
                      • Instruction ID: f983c250733c88979b84f768b9583d183f74d74a34df92459c32d5bd19e1a684
                      • Opcode Fuzzy Hash: c6986e2cf72187001e57c619f9179f3f533dc14f1b44f62c562c025f18a7376a
                      • Instruction Fuzzy Hash: 1901D631718A8481DB50CF2AF548A5AA7B1F789FE8F585134EF5D03B4CDF29C8418B84
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: FileFindNext
                      • String ID:
                      • API String ID: 2029273394-0
                      • Opcode ID: ccfa8f38ed612f4e8ddd3e6d6a05ec771484547eb56912c77a55a8e41b15c97b
                      • Instruction ID: 81e8eac61a4d48f264bfeba8a41cbaa0944bf49c1e6d44fa1abe02af5d978f9b
                      • Opcode Fuzzy Hash: ccfa8f38ed612f4e8ddd3e6d6a05ec771484547eb56912c77a55a8e41b15c97b
                      • Instruction Fuzzy Hash: A901FF3625CA8195DA70CB56F49939B6374F788BA8F444422DE8D83B59DE39C886CB40
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: _invalid_parameter_noinfo
                      • String ID:
                      • API String ID: 3215553584-0
                      • Opcode ID: 0ed47cd4b59ff69551f8e78227d8f4e38a940980cad2ee6427b640313745ffe7
                      • Instruction ID: 1fd3296331122780b72ff239540df025b365d5546c80deac5ce32bbf5c304eff
                      • Opcode Fuzzy Hash: 0ed47cd4b59ff69551f8e78227d8f4e38a940980cad2ee6427b640313745ffe7
                      • Instruction Fuzzy Hash: 4CE0923169D64589EB69ABB8B28D37E72B0AB447F8F144321AAB4462C6DE26C4904650
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: FileFindNext
                      • String ID:
                      • API String ID: 2029273394-0
                      • Opcode ID: 7c5c8b2f9f95c20798bba13689a054510256dd3270a922cf6db1b5b31cf82ad3
                      • Instruction ID: 9f4e3619a73621b472a5565cd0c2696c0b3e108732629ebead33566c1d8f7019
                      • Opcode Fuzzy Hash: 7c5c8b2f9f95c20798bba13689a054510256dd3270a922cf6db1b5b31cf82ad3
                      • Instruction Fuzzy Hash: A0C04C24F9D501C2EAD417626C8EA0311B09798B24F540410820580151DD1E85D697D1
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: InfoNativeSystem
                      • String ID:
                      • API String ID: 1721193555-0
                      • Opcode ID: ab98e528da3f92edb45ebba1ca75c218e2e96c98443ac49b096ad434246530e8
                      • Instruction ID: a4667a2b75445818d32faa59343ecfa661257397d4b610ddf6c7319a773c914e
                      • Opcode Fuzzy Hash: ab98e528da3f92edb45ebba1ca75c218e2e96c98443ac49b096ad434246530e8
                      • Instruction Fuzzy Hash: 6CB09236A188C0C7CA11FB14EC4A00A7331F798B18FD00400E38942624DE2DCA2ACE80
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: AllocHeap
                      • String ID:
                      • API String ID: 4292702814-0
                      • Opcode ID: 82cf8587b9ba114877d0bf38a3d5084c08df71825f5767c6e8ed258d5192905f
                      • Instruction ID: 9bd15c231e463a3a412de833f5ebefab23e44cfb3248f3d16ce43fca8a1a72ae
                      • Opcode Fuzzy Hash: 82cf8587b9ba114877d0bf38a3d5084c08df71825f5767c6e8ed258d5192905f
                      • Instruction Fuzzy Hash: B5F0247038964049FE245B75B40D3F752B11B88BA8F0C14B85D5AC63C2DF2EC4C082D0
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: AllocHeap
                      • String ID:
                      • API String ID: 4292702814-0
                      • Opcode ID: 1572e28e03939d407de42495dc5117ea16b091d6e57b15f942660159700d15ee
                      • Instruction ID: fd8a83001512a0c9113ea249825c35247522de8c5f2aadc2972f116add62b841
                      • Opcode Fuzzy Hash: 1572e28e03939d407de42495dc5117ea16b091d6e57b15f942660159700d15ee
                      • Instruction Fuzzy Hash: CAF0303939D20549FE546BB17D4D37721B15B9C7B8F085A609D7AC53C2DF2EC48186E0
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Concurrency::cancel_current_task
                      • String ID: "$#base$#include$*$/$No closed word$Unexpected eof$conditional not closed$key declared, but no value$key opened, but never closed$object is not closed with '}'$quote was opened but not closed.$unexpected '}'$unexpected key without object$word wasnt properly ended
                      • API String ID: 118556049-2258937249
                      • Opcode ID: c7a38751adf7bcd4ec8bde13cc5c570cbedffbdf296dfa864acab9f84c59b659
                      • Instruction ID: e968601ca1795cfad907914c6a7181b0596d9e258921544f5d02c4c626143d3b
                      • Opcode Fuzzy Hash: c7a38751adf7bcd4ec8bde13cc5c570cbedffbdf296dfa864acab9f84c59b659
                      • Instruction Fuzzy Hash: 62E27D72349BC485EB608F64E88C3EE2771F744BACF545222DA5D0BA99DF75CA85C380
                      APIs
                      • Concurrency::cancel_current_task.LIBCPMT ref: 000002674E16FCC1
                        • Part of subcall function 000002674E14D7E0: __std_exception_copy.LIBVCRUNTIME ref: 000002674E14D823
                        • Part of subcall function 000002674E1D11D8: RtlPcToFileHeader.KERNEL32 ref: 000002674E1D121C
                        • Part of subcall function 000002674E1D11D8: RaiseException.KERNEL32 ref: 000002674E1D1262
                      • Concurrency::cancel_current_task.LIBCPMT ref: 000002674E16FD82
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Concurrency::cancel_current_task$ExceptionFileHeaderRaise__std_exception_copy
                      • String ID: "$#base$#include$*$/$No closed word$Unexpected eof$conditional not closed$key declared, but no value$key opened, but never closed$object is not closed with '}'$quote was opened but not closed.$unexpected '}'$unexpected key without object$word wasnt properly ended
                      • API String ID: 145623376-2258937249
                      • Opcode ID: 617e5560431b85d2165705e9510db6f3a535c635b7fd86c397cd2d0aa2054dc2
                      • Instruction ID: 9b51448a4e34703bc39bc00b7188f0a8a255affb25bb6fe5ab48d84d32952857
                      • Opcode Fuzzy Hash: 617e5560431b85d2165705e9510db6f3a535c635b7fd86c397cd2d0aa2054dc2
                      • Instruction Fuzzy Hash: 80E28D72249AC486EB60CF34E88C3EE2771F7497ACF445612DA5D0BA99DF76C685C380
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Concurrency::cancel_current_task
                      • String ID: BOOTNXT$autorun.inf$boot.ini$boot.sdi$bootfont.bin$bootmgfw.efi$bootmgr$bootsect.bak$bootstat.dat$d3d9caps.dat$desktop.ini$gdipfontcachev1.dat$iconcache.db$indexervolumeguid$mib.bin$ntldr$ntuser.dat$ntuser.dat.log$ntuser.ini$reagent.xml$thumbs.db$winre.wim$winsipolicy.p7b$wpsettings.dat
                      • API String ID: 118556049-850610325
                      • Opcode ID: edcd2fc5b2d1d5c491b5765352a7b000dcade2125810695668c3c1cd0c070a6d
                      • Instruction ID: 596cb698db7cce5cc2c79d6ba6f9dcd95476e58cac891f6056f7a9b0af4b0127
                      • Opcode Fuzzy Hash: edcd2fc5b2d1d5c491b5765352a7b000dcade2125810695668c3c1cd0c070a6d
                      • Instruction Fuzzy Hash: 3EC1B572E64FC985E721DB34D8863EA5331F7EA39CF906302794865856EFA593C4C780
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: lstrcpy$lstrcat$AllocateInitLockMemoryObjectStringUnicodeVirtual$AcquireEnumerateFolderFreeInitializeKnownLoadedModulesPathReleaseTaskUninitialize
                      • String ID:
                      • API String ID: 1424456515-0
                      • Opcode ID: 991b0681b3cb0b811cca883475f0af3d880034819dab3a9f0d92d3b5d847a852
                      • Instruction ID: 4f8068af51080f35868db97f1e42b318ea67bcd30195713bf9735bc7c145ea6e
                      • Opcode Fuzzy Hash: 991b0681b3cb0b811cca883475f0af3d880034819dab3a9f0d92d3b5d847a852
                      • Instruction Fuzzy Hash: 11D2A936629FC48AD7A18F69E88169EB3B5F388B88F105215EECD57B18EF34C254C744
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Initialize$Security
                      • String ID: @
                      • API String ID: 119290355-2766056989
                      • Opcode ID: d3a2611dec909c8325a65b782830566092cebbe6120a51421e17bc99a6e45572
                      • Instruction ID: e78c6470157f2ab46452cdbe3212553ae3a775dfd1d6ae943d30b1c3a4df4ab4
                      • Opcode Fuzzy Hash: d3a2611dec909c8325a65b782830566092cebbe6120a51421e17bc99a6e45572
                      • Instruction Fuzzy Hash: 5DC17E72B48B808AFB10CF75E45C39E3372E789BACF005615DE5A16A99DF7AC194C384
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Concurrency::cancel_current_task
                      • String ID: #recycle$$recycle.bin$$windows.~bt$$windows.~ws$$winreagent$All users$AppData$Application Data$Boot$PerfLogs$Program Files$Program Files (x86)$ProgramData$System Volume Information$Windows$Windows.old$Windows.~bt$bootmgr$config.msi$ntldr
                      • API String ID: 118556049-2722463023
                      • Opcode ID: f0092856a2f44c3b95c7e50647ff602fc0e35287a884e110670a5cc4549e278c
                      • Instruction ID: b0bef85648b792f35cae95b6b7981c5bd1f9752a46228635e25a0a7549e446bf
                      • Opcode Fuzzy Hash: f0092856a2f44c3b95c7e50647ff602fc0e35287a884e110670a5cc4549e278c
                      • Instruction Fuzzy Hash: 7EA1B672E64FC985E720DB34D8863EA5331F7EA39CF906702794865856EFA5A2C4C780
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: _invalid_parameter_noinfo$memcpy_s$fegetenv
                      • String ID: 1#IND$1#INF$1#QNAN$1#SNAN
                      • API String ID: 808467561-2761157908
                      • Opcode ID: d9b607ac31ade7ddb84878c7754434a563a71c4121ff0c351274636517767a1e
                      • Instruction ID: 80dc55351007dee836bd9ecda3576d9a181400e631809cd4b1ecc90cb26ef58c
                      • Opcode Fuzzy Hash: d9b607ac31ade7ddb84878c7754434a563a71c4121ff0c351274636517767a1e
                      • Instruction Fuzzy Hash: 36B203726582808BE7668F64E44CBEF37B1F34479CF505216DB4697A88DF36DA81CB80
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Handle$Query$CloseInformationProcessSystem$AddressCriticalCurrentEnterFinalModuleNameObjectOpenPathProcSection
                      • String ID: File$NtDuplicateObject$ntdll.dll
                      • API String ID: 2066483518-3955674919
                      • Opcode ID: 38d65493492f6e7dd8087a2e3300eba3a870d78a46c5fdb8a1c4863bdd7da851
                      • Instruction ID: f657a2ac682c1a8dd09a8933ea41f44503921fd4b0cd5eec6451325c2361cf25
                      • Opcode Fuzzy Hash: 38d65493492f6e7dd8087a2e3300eba3a870d78a46c5fdb8a1c4863bdd7da851
                      • Instruction Fuzzy Hash: 17E1AE72B48A809AFB00DF75E45C3AE2772F745BACF404525DE5A27B99DF3AC1458380
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: CriticalEnterExecuteSectionShell
                      • String ID: .exe$.exe$abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789+=-&^%$#@!(){}[},.;'$ios_base::badbit set$ios_base::eofbit set$ios_base::failbit set$open$runas$temp_directory_path
                      • API String ID: 4038919937-3845196099
                      • Opcode ID: c7e399cc671644e4e1475da5459dac05b7e6842f13cea8b34b197d8abce8da6a
                      • Instruction ID: 3b558e888da7f6e48800c5efa522783adcb5f736224f8f401ffdd33bf8540ae7
                      • Opcode Fuzzy Hash: c7e399cc671644e4e1475da5459dac05b7e6842f13cea8b34b197d8abce8da6a
                      • Instruction Fuzzy Hash: 76327F72618B8089EB10CF24F88C39E77B2F7817ACF505616EA5D47AA9DF79C185C780
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Concurrency::cancel_current_task
                      • String ID: cannot compare iterators of different containers$cannot use push_back() with $type must be string, but is $value
                      • API String ID: 118556049-2711811579
                      • Opcode ID: 48f93b1b7774b6c92ea80d83ff522397fac04e2e2bb4faf2629b70e72dee0907
                      • Instruction ID: cc02dad4a9f72fcc250b6f8148c77ffcace3acc48ab79bfa621b2bcefe5fbc22
                      • Opcode Fuzzy Hash: 48f93b1b7774b6c92ea80d83ff522397fac04e2e2bb4faf2629b70e72dee0907
                      • Instruction Fuzzy Hash: E8636C72659BC499EB309F24E8483EE23B1F7497ACF405615DA9D4BA9ADF35C284C380
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: lstrcatlstrcpy$Object$AcquireAllocateInitializeLockMemoryUninitializeVirtual
                      • String ID:
                      • API String ID: 3636535045-0
                      • Opcode ID: 62d431a354481ccfb15ad27e92260adfbdf61f84281a700c847a0d14b703fc52
                      • Instruction ID: 978ab3f21f76c5f43a4d00cada09749103c9c6c52be7342cdc7bb4b84793caa5
                      • Opcode Fuzzy Hash: 62d431a354481ccfb15ad27e92260adfbdf61f84281a700c847a0d14b703fc52
                      • Instruction Fuzzy Hash: 7AB2883652AFC58AD7A18F69F88169AB3A4F388B84F105215FFCD57B18EF38C2548744
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID: content$directory_iterator::directory_iterator$exists$filename$status
                      • API String ID: 0-3429737954
                      • Opcode ID: 586549ad99a1701b7123dcb876a5536be7328543a59eda1aa36236f9a4aa8d39
                      • Instruction ID: 9355ebfcc0c9a5b97d34cc4e8b5d331c32fda82f9df2ea5243470df493561ecc
                      • Opcode Fuzzy Hash: 586549ad99a1701b7123dcb876a5536be7328543a59eda1aa36236f9a4aa8d39
                      • Instruction Fuzzy Hash: 5F827F32659BC089EB218F38E88C3EE2371F7857A8F455615EA4D47B99EF35C685C380
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: ErrorLastNameTranslate$CodePageValidValue
                      • String ID: utf8
                      • API String ID: 1791977518-905460609
                      • Opcode ID: b55e187aed6d809e8e73de1ec35ea0a41fa3c0b50307ddf2958949270e0425d4
                      • Instruction ID: 025697f40318c45501c428d067308f7f7bc3f7d3cc54e76419c93a232b416d60
                      • Opcode Fuzzy Hash: b55e187aed6d809e8e73de1ec35ea0a41fa3c0b50307ddf2958949270e0425d4
                      • Instruction Fuzzy Hash: B6919F7228879085FB249F21F48D3AB23B4E745BA8F448121DB8987785DF7AE592C7C0
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Value$Locale$CodeErrorInfoLastPageValid$DefaultEnumLocalesProcessSystemUser
                      • String ID:
                      • API String ID: 2591520935-0
                      • Opcode ID: 6f43a37a45385bbf7dfa6322a723e9dff443d4f39bf2271c5d7c4ac8f131f397
                      • Instruction ID: 257e78774697250c8038a45ecea549d6ebe2dafdb55e4fd1da3fcb4102b708a1
                      • Opcode Fuzzy Hash: 6f43a37a45385bbf7dfa6322a723e9dff443d4f39bf2271c5d7c4ac8f131f397
                      • Instruction Fuzzy Hash: 05718D3274475089FF50DB60E89C7EE73B1BB48B6CF4444159A4993695EF3AE485C3D0
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: __std_exception_destroy
                      • String ID: value
                      • API String ID: 2453523683-494360628
                      • Opcode ID: e2b516a9c62dac184565c8316076e1f3e75b4eb33cbc8470e56ac888791338c2
                      • Instruction ID: 458de213a3743f70e6ec0046bd9f019609c90995f31af5dd5db505aeb307d686
                      • Opcode Fuzzy Hash: e2b516a9c62dac184565c8316076e1f3e75b4eb33cbc8470e56ac888791338c2
                      • Instruction Fuzzy Hash: 2702A072668BC085EB00CB74E48C3AE6771F7857B8F505B02FA9D42ADADF69C185C781
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: ExceptionFilterUnhandled$CaptureContextDebuggerEntryFunctionLookupPresentUnwindVirtual
                      • String ID:
                      • API String ID: 1239891234-0
                      • Opcode ID: 36bcf539ff511b9f2f372bada547dc74a3fd29a2a4a08272e792b2519e980bba
                      • Instruction ID: 23fbffb795e866479799c5b77356aaec6f4f4a7064bdccf7c5b9fc9c68f59220
                      • Opcode Fuzzy Hash: 36bcf539ff511b9f2f372bada547dc74a3fd29a2a4a08272e792b2519e980bba
                      • Instruction Fuzzy Hash: 34315F36258F8086EB60CF25F8483AE73B4F7887A8F540525EA9D43B99DF39C555CB80
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID: content$directory_iterator::directory_iterator$exists$filename$files$key
                      • API String ID: 0-2980817763
                      • Opcode ID: 2c4ef3ecad0500aa6eed00e193ac1fbf3ecaf5aaf7455de47e6adcb8bc4d7ab3
                      • Instruction ID: b757438669d742e892a1ebed58a39d2eae98a76a1a2cfe6bba6607030f4b5b2e
                      • Opcode Fuzzy Hash: 2c4ef3ecad0500aa6eed00e193ac1fbf3ecaf5aaf7455de47e6adcb8bc4d7ab3
                      • Instruction Fuzzy Hash: 5EA25E72659BC089DB218F28E8883DE33B5F7857ACF505215EA9D0BB99DF75C284C740
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: memcpy_s
                      • String ID:
                      • API String ID: 1502251526-3916222277
                      • Opcode ID: d6d9011da9560f75d79d712151dba2a05f068b08906f83bba3c34db6d26f72f4
                      • Instruction ID: abeeadc055318c7300d0f99ded8ce569183c51352a33cc74482f3551e92ee1c6
                      • Opcode Fuzzy Hash: d6d9011da9560f75d79d712151dba2a05f068b08906f83bba3c34db6d26f72f4
                      • Instruction Fuzzy Hash: 74C1C2B26586858BE724CF19F08CB6FB7A5F394798F44C125DB8647B44EB39D805CB80
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: __std_fs_convert_wide_to_narrow$__std_fs_code_page
                      • String ID: !$content$filename$status$users
                      • API String ID: 3645842244-3795777748
                      • Opcode ID: 60ac7814a54a8b643bfdec3331cd5155469ff46daf70a046570bf52c7ae01c32
                      • Instruction ID: c7086e07feb53d061bd5e969c2e690664c55acbc81dc2b569217bbb54e8a9fb3
                      • Opcode Fuzzy Hash: 60ac7814a54a8b643bfdec3331cd5155469ff46daf70a046570bf52c7ae01c32
                      • Instruction Fuzzy Hash: 19B26F72655BC48ADB21DF38E8483DE2371F7857ACF405212EA9D4BA99EF75C684C380
                      APIs
                      Strings
                      • ERROR : Unable to initialize critical section in CAtlBaseModule, xrefs: 000002674E1DD833
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: DebugDebuggerErrorLastOutputPresentString
                      • String ID: ERROR : Unable to initialize critical section in CAtlBaseModule
                      • API String ID: 389471666-631824599
                      • Opcode ID: 16a569409356b0160a0f82d33effe78a83beb9a47a3a0e70dd5b5d693d8f2952
                      • Instruction ID: efad0ecbc0dd849563b74671f64ac9f2b4504fac8bfa8a94054201a9615390d5
                      • Opcode Fuzzy Hash: 16a569409356b0160a0f82d33effe78a83beb9a47a3a0e70dd5b5d693d8f2952
                      • Instruction Fuzzy Hash: 47114C32654B8197F7089B22EA5D36A33B5F784369F404129C74942A51EF3AD4B4C790
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Virtual$AllocInfoProtectQuerySystem
                      • String ID:
                      • API String ID: 3562403962-0
                      • Opcode ID: 9274b09c63967ddddcb91dd4133cd15f84ec3bcd53289bbf1f5affcb4001546f
                      • Instruction ID: 8bebcb99d734d0ddd238dff1731a90ce4c4e8677873233f0fb3550a8b45907c5
                      • Opcode Fuzzy Hash: 9274b09c63967ddddcb91dd4133cd15f84ec3bcd53289bbf1f5affcb4001546f
                      • Instruction Fuzzy Hash: 4F317E32354A809EEB10CF35E8597EA33A5F748B9CF484426DA4E8BB48DF39C645C780
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                      • String ID:
                      • API String ID: 2933794660-0
                      • Opcode ID: d8fd20b6762ae4129b3796e8a1e8986ce167c62aad8fb109aab352fc19ec2d03
                      • Instruction ID: 4a602d376b789e5017c47c5690de4d1575882f6ce6328d02cbf01682c6807fa5
                      • Opcode Fuzzy Hash: d8fd20b6762ae4129b3796e8a1e8986ce167c62aad8fb109aab352fc19ec2d03
                      • Instruction Fuzzy Hash: D7112A36B54F018AEB00CF60F8593A933B4F319768F450E21DA6E867A4DF79C19483C0
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: __std_exception_copy
                      • String ID: parse_error$value
                      • API String ID: 592178966-1739288027
                      • Opcode ID: 1d34b1375488a2bb023fe0f893e63fd44ebd2c15bad9e7ad3506a9593953888f
                      • Instruction ID: 54a5cf02cbc882a56102c958705ea6866adb62a85e2555fdb611d7b76b72fd73
                      • Opcode Fuzzy Hash: 1d34b1375488a2bb023fe0f893e63fd44ebd2c15bad9e7ad3506a9593953888f
                      • Instruction Fuzzy Hash: 6CF1B072B58A8195FB10DB74E44D3EE2332F7853ACF805702EA9D56ADAEF25C185C380
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID: content$directory_iterator::directory_iterator$exists$filename
                      • API String ID: 0-1400943384
                      • Opcode ID: 8b35b3d5587ea94a94bebcf1f1e0d333c16c49093410206e5fe1f831f9e8b02e
                      • Instruction ID: d7bb0caba57bb9755ddeacc8b60691c276ffb696ac655a339f3799f1329e4223
                      • Opcode Fuzzy Hash: 8b35b3d5587ea94a94bebcf1f1e0d333c16c49093410206e5fe1f831f9e8b02e
                      • Instruction Fuzzy Hash: 6F528072655BC489EB208F28E8483DE73B1F7897ACF515216DA9C07B99EF35C280C780
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: _get_daylight$_invalid_parameter_noinfo
                      • String ID:
                      • API String ID: 1286766494-0
                      • Opcode ID: 53678dbfd363e45a668b87caebf557c33f1b3fa57ada2052f9e6c048d45eb0ee
                      • Instruction ID: 6b0b59f1880eae23086647591b495eafc7e9004353824a60ec79d03c150f21e3
                      • Opcode Fuzzy Hash: 53678dbfd363e45a668b87caebf557c33f1b3fa57ada2052f9e6c048d45eb0ee
                      • Instruction Fuzzy Hash: 3592BF32248B9086EB358F24A45C2BF37B1F755BACF448155DB8A87B95DF3AC990C380
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: FormatInfoLocaleMessage
                      • String ID: !x-sys-default-locale
                      • API String ID: 4235545615-2729719199
                      • Opcode ID: f8e0064fd4687ebb9f26372c89aa93b1c3d5825c993d4f26b54fdbc6e52d471c
                      • Instruction ID: eeea4ebdad852200a27a8f36b135b504f073e47cf7683932887c8a7e3091eaac
                      • Opcode Fuzzy Hash: f8e0064fd4687ebb9f26372c89aa93b1c3d5825c993d4f26b54fdbc6e52d471c
                      • Instruction Fuzzy Hash: 0B01D472748B8482E751CB11F44CBAAB7B1F3887E8F444115D65A03B99CF3DC909CB80
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID: pTa4uqR6tQnDMX31uTju4CtIJm3aeKMSl0wkJ3rxGh8=$port$tMz6UdI0Pus=
                      • API String ID: 0-1882791999
                      • Opcode ID: 4edee334fbf5cf4b4df3e25979f4f240496e674528569ec0022c8f6ecb73b9ec
                      • Instruction ID: c5c2c5c5287b733e9874300b7d020b8585a162f463c488c29f032ad70cfae6b7
                      • Opcode Fuzzy Hash: 4edee334fbf5cf4b4df3e25979f4f240496e674528569ec0022c8f6ecb73b9ec
                      • Instruction Fuzzy Hash: E0727C72629FC485EA60CB24F48839FB3B5F795794F506216EACD52B99EF38C190CB40
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID: Software$exists
                      • API String ID: 0-2364128853
                      • Opcode ID: 2c7e43ceba25fa8f849f794a5ed6ea09cb62ebc729ca1fe346c9cea9114599f8
                      • Instruction ID: 34a736f02103f5554f0c4880730ed51b591544006ab88ed3759ae9e0c7733268
                      • Opcode Fuzzy Hash: 2c7e43ceba25fa8f849f794a5ed6ea09cb62ebc729ca1fe346c9cea9114599f8
                      • Instruction Fuzzy Hash: AEE28072654BC48AEB208F29E8883DE7374F789BA8F114612DB9D57B99DF35C580C380
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: __std_fs_convert_narrow_to_wide$__std_fs_code_page
                      • String ID: content$filename
                      • API String ID: 2896615418-474635906
                      • Opcode ID: 82fc525f08498d42bcd2b941c7ab55b5a5f535dd5cf2ae8d4db5d830883c1726
                      • Instruction ID: 91a66f452fc7a0977fd91be0bde1084c9c04fd10b7dc40883ace6b447d41075c
                      • Opcode Fuzzy Hash: 82fc525f08498d42bcd2b941c7ab55b5a5f535dd5cf2ae8d4db5d830883c1726
                      • Instruction Fuzzy Hash: 44C2387265DBC481DA718B14F4883DBA3B1F7C97A4F405216EADD43AA9EF39C590CB80
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: InfoLocale
                      • String ID: GetLocaleInfoEx
                      • API String ID: 2299586839-2904428671
                      • Opcode ID: 7225a06619955565ff47aed1f984b3dac7adc03be6b0bc75c8be47510ce207d3
                      • Instruction ID: b8feb055164972f7dcb743a655fb2ac32c73cd03f34f7be5c47e90086dcca730
                      • Opcode Fuzzy Hash: 7225a06619955565ff47aed1f984b3dac7adc03be6b0bc75c8be47510ce207d3
                      • Instruction Fuzzy Hash: 8101D631748B8089EB048B46F44C29BB371E788BE8F584426DF4D07B95CE39C54187C0
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: ExecuteFileModuleNameShell
                      • String ID:
                      • API String ID: 1703432166-0
                      • Opcode ID: 69a7a0bf2e3c2ea62d15ae9e710cbad767f350b7f450484520631a79c21b3666
                      • Instruction ID: 5c04d2848bd2ff5419381615779d5663e97965cf8379443fca56157f1b1558be
                      • Opcode Fuzzy Hash: 69a7a0bf2e3c2ea62d15ae9e710cbad767f350b7f450484520631a79c21b3666
                      • Instruction Fuzzy Hash: 9A122632629FC48AEB408F29E88569EB3B5F389798F105215EEDD57B58EF78C150C740
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: ExceptionRaise_clrfp
                      • String ID:
                      • API String ID: 15204871-0
                      • Opcode ID: 0d1fdd39e7615aa663790279dd2e603f564fcf233a3cabb7812fd32a0ccc1c41
                      • Instruction ID: f8763cfca1a3fe3bc0df96e9589b75983ad52fb34c706747b81eca1fae857350
                      • Opcode Fuzzy Hash: 0d1fdd39e7615aa663790279dd2e603f564fcf233a3cabb7812fd32a0ccc1c41
                      • Instruction Fuzzy Hash: F8B14A77244B848BEB15CF29D88A35D3BB0F384B9CF158911DA5D877A8CB3AD891C740
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: CryptDataFreeLocalUnprotect
                      • String ID:
                      • API String ID: 1561624719-0
                      • Opcode ID: d3f3e25cce19232a8fc63a7dde533911a37660d2a701ce24fb7f17b17b65185d
                      • Instruction ID: 72e7f63b546435180734f5e7c459165e44ab32d6e4d33343df461975d733fcb3
                      • Opcode Fuzzy Hash: d3f3e25cce19232a8fc63a7dde533911a37660d2a701ce24fb7f17b17b65185d
                      • Instruction Fuzzy Hash: 02618C73B58B809AF710DF78E45839E73B1E7587ACF008625EA8917A89DF79C1948390
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: CryptDataFreeLocalProtect
                      • String ID:
                      • API String ID: 2714945720-0
                      • Opcode ID: 4f17aac50473bc08939b1f8f49e55619b8cc9a5443be74896b8ea89f8c9b9f98
                      • Instruction ID: 53b71fe2b150cc7ff5714a4fe6085bbe84d0ad015282814e3c2af5a42b319317
                      • Opcode Fuzzy Hash: 4f17aac50473bc08939b1f8f49e55619b8cc9a5443be74896b8ea89f8c9b9f98
                      • Instruction Fuzzy Hash: ED415D32618B80CAE3208F74E4483EE37B5F75974CF040625EB8906E89DF7AD5A4C384
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: CriticalEnterSection
                      • String ID: dumps$emoji
                      • API String ID: 1904992153-2873254224
                      • Opcode ID: 4b1e15c5a11ac2e7a2a46e896d609379b33c8c6b2792195f922911b66fa10dab
                      • Instruction ID: 4c8cff397e5de065b108738af3d0a57a135c79f78f95817c90f0a55967957726
                      • Opcode Fuzzy Hash: 4b1e15c5a11ac2e7a2a46e896d609379b33c8c6b2792195f922911b66fa10dab
                      • Instruction Fuzzy Hash: 86C16C32A16F89C9E700CF39E9892DE33B1E75979CF014255AE8C26B59EF35D164C384
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID: e+000$gfff
                      • API String ID: 0-3030954782
                      • Opcode ID: 2cbc57aff2d67c5b7b5817a98a5636741370ddff258dc2e67d949cc7c9c23afe
                      • Instruction ID: 59a875374557560ef200ed8587f16019a7f631b24991ddb9e47d5b8d8ce500f1
                      • Opcode Fuzzy Hash: 2cbc57aff2d67c5b7b5817a98a5636741370ddff258dc2e67d949cc7c9c23afe
                      • Instruction Fuzzy Hash: 115157327582C44AE7248B35ED5CB6A7BA1F348BB8F489221CFA447AC5CF3AC4458740
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Concurrency::cancel_current_task
                      • String ID:
                      • API String ID: 118556049-0
                      • Opcode ID: 11887bff267953a81fc5c7707205ce55c7db93e1042c3f9384933876f0421cd2
                      • Instruction ID: bc794dbc658da8c61b68ff748bbd7bdd1d989cc6f108d6f50c5d4d7cdcdf1638
                      • Opcode Fuzzy Hash: 11887bff267953a81fc5c7707205ce55c7db93e1042c3f9384933876f0421cd2
                      • Instruction Fuzzy Hash: 9902AD72759B8085EB10CFA5E04C3AE73B1EB48BA8F548622DE9D17799DF35C991C380
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID: %
                      • API String ID: 0-2567322570
                      • Opcode ID: 31dc066f60dec5c20116c549c8edff8692e5cde31cbf9bbb8dc501f53c089c23
                      • Instruction ID: 6791b308972cdb46491f85ffcad552eff612d21f1073ac16076b91674b630fef
                      • Opcode Fuzzy Hash: 31dc066f60dec5c20116c549c8edff8692e5cde31cbf9bbb8dc501f53c089c23
                      • Instruction Fuzzy Hash: 8F122332748A808AFB25CBB5F4583EE67B2EB567ACF044125DE4917B99DF39C445C380
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Concurrency::cancel_current_task
                      • String ID:
                      • API String ID: 118556049-0
                      • Opcode ID: 5725728a7d5880c26a14869a88820e8a502357b17066dbcef380198e4c18c99c
                      • Instruction ID: dc6cbb0dfc1247a34494a007aa3d830007652dfb5f23ee27ec7affc1c493ee55
                      • Opcode Fuzzy Hash: 5725728a7d5880c26a14869a88820e8a502357b17066dbcef380198e4c18c99c
                      • Instruction Fuzzy Hash: 39A18772709B9889EB00CBA9E8883AD37B0F359B58F548516DF8D53B59DF3AC091C380
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Concurrency::cancel_current_task
                      • String ID:
                      • API String ID: 118556049-0
                      • Opcode ID: a70163d0b74f0bae0e352dcfd68d5cbc6f1094de50f1fd8400f9a81b72710518
                      • Instruction ID: dd7fef15936c7656990559fcfd4dcbeeb7227daadbd5f0f06c06249082438dfa
                      • Opcode Fuzzy Hash: a70163d0b74f0bae0e352dcfd68d5cbc6f1094de50f1fd8400f9a81b72710518
                      • Instruction Fuzzy Hash: 87A19C72709B9889EB00CBA9E8883AD37B0F359B58F548516DF8D57B55DF3AC091C381
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Concurrency::cancel_current_task
                      • String ID:
                      • API String ID: 118556049-0
                      • Opcode ID: 70af4160fee7732a81d3346de3a9ab4de8a6a07c9c07957bea0c8618dbd08fb0
                      • Instruction ID: 75576a4b51fb00de581cbe532700ad08c18846b65e17371d90e83508f9871789
                      • Opcode Fuzzy Hash: 70af4160fee7732a81d3346de3a9ab4de8a6a07c9c07957bea0c8618dbd08fb0
                      • Instruction Fuzzy Hash: DDA1AB32708B9889EB00CBA9E8883AD37B0F359B58F548516DF8D57B59DF3AC591C381
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Concurrency::cancel_current_task
                      • String ID:
                      • API String ID: 118556049-0
                      • Opcode ID: b5e0e21ec6c82c00fd5a72b22cf06e3cec2efb3b9fb948b51070eedc5c18d768
                      • Instruction ID: a4d360faf462b7f52affec2fafdcef06c69c74dc10bddf955fa46f7a4d302845
                      • Opcode Fuzzy Hash: b5e0e21ec6c82c00fd5a72b22cf06e3cec2efb3b9fb948b51070eedc5c18d768
                      • Instruction Fuzzy Hash: 59A1BA32719B9889EB00CBA9E4883AD37B4F359B58F548516DF8D57B59DF3AC091C340
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Concurrency::cancel_current_task
                      • String ID:
                      • API String ID: 118556049-0
                      • Opcode ID: aa155d2428affaad3dff09cb27702bac1ee311a87af78df446814e3db2567fb8
                      • Instruction ID: 01a1148294e318a3b30da2c6dd6cdc6a90837e63e189cacb81a6ca115405b2b0
                      • Opcode Fuzzy Hash: aa155d2428affaad3dff09cb27702bac1ee311a87af78df446814e3db2567fb8
                      • Instruction Fuzzy Hash: 36A1AB72709B9889EB00CBA9E4883AD77B4F359B98F548416CF8E57B55DF3AC091C381
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Concurrency::cancel_current_task
                      • String ID:
                      • API String ID: 118556049-0
                      • Opcode ID: 014629591955776a3e379f40fbc38e65614e09b97ba97b947780923ae4677d6c
                      • Instruction ID: 66550b14a0d5a89cdb72c2ddc8c34e22aacebd7015f77b6d3983f03485658240
                      • Opcode Fuzzy Hash: 014629591955776a3e379f40fbc38e65614e09b97ba97b947780923ae4677d6c
                      • Instruction Fuzzy Hash: AEA1BD72709B9889EB00CB69E8883AD37B0F355B58F548416DF8E57B95DF3AC095C380
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: _get_daylight_invalid_parameter_noinfo
                      • String ID:
                      • API String ID: 474895018-0
                      • Opcode ID: 478d06da54e2b3a66e66189e0c84ed42d95a5f3c443f95b055d9117d1e8d888c
                      • Instruction ID: 642eab6925046190fde4f4192bfe832acbf9ac3b8b0c04fda1d624805d8d92f7
                      • Opcode Fuzzy Hash: 478d06da54e2b3a66e66189e0c84ed42d95a5f3c443f95b055d9117d1e8d888c
                      • Instruction Fuzzy Hash: 7D610732B8C2A047FB648B6CB46C77F72E1A740778F195629FA66876D1DE66C840C7C0
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: ErrorLast$EnumLocalesSystemValue
                      • String ID:
                      • API String ID: 3029459697-0
                      • Opcode ID: 6f94e02c4e5af3f2d24d495b9659a8a16ccc68b84b60a7fb4290613ef45ef0e5
                      • Instruction ID: 815b284695741f37f2e809e060ca7a0cbcd6d5d188a834a2615538345ada5d0d
                      • Opcode Fuzzy Hash: 6f94e02c4e5af3f2d24d495b9659a8a16ccc68b84b60a7fb4290613ef45ef0e5
                      • Instruction Fuzzy Hash: 4711CD77A486448AEB148F26E0897AA7BB0F390FF8F448116D669833C0DF25DAD1C780
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID: .
                      • API String ID: 0-248832578
                      • Opcode ID: d7c440884c17b1e0119c1bf76a89def2a676133d0e6a7819e9ec44b59dc85dc0
                      • Instruction ID: fd4206eebf82c09d6fdcb085ff86bd1c0c5573db72e7cdfad8a5fecd210f929e
                      • Opcode Fuzzy Hash: d7c440884c17b1e0119c1bf76a89def2a676133d0e6a7819e9ec44b59dc85dc0
                      • Instruction Fuzzy Hash: 48C18672258B8086EB608F25E44CF6F63B2F748BB8F554221EA5953794DF76DC81C380
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: ErrorLast$EnumLocalesSystemValue
                      • String ID:
                      • API String ID: 3029459697-0
                      • Opcode ID: 23455ccc0c183205af815f8f90c949c9b5771d78cdc52d32387f6d5e086aeed2
                      • Instruction ID: 372cc65370ac075d788fb21ed9b258efba1404c3096cfda9058ed3919b1b6d45
                      • Opcode Fuzzy Hash: 23455ccc0c183205af815f8f90c949c9b5771d78cdc52d32387f6d5e086aeed2
                      • Instruction Fuzzy Hash: E001D472B483808AFB104F26F48D7AB76F1E740BB8F459222D665876C4EF7698C1C780
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: EnumLocalesSystem
                      • String ID:
                      • API String ID: 2099609381-0
                      • Opcode ID: 3ad3dc04116331610f50ea24032eab0aa5ce82721b33bdf3b2c4282bed5d3594
                      • Instruction ID: 6ce8b6a19703fb4b8149684d1daaf692056c53f42fa1c80dc03cca65650aa1ca
                      • Opcode Fuzzy Hash: 3ad3dc04116331610f50ea24032eab0aa5ce82721b33bdf3b2c4282bed5d3594
                      • Instruction Fuzzy Hash: 8FF08C72708B4083E700CB25F98D7AB7371E3887E4F058125EA9A83364CF39C5908380
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: BlanketCreateInstanceProxy
                      • String ID:
                      • API String ID: 1899829610-0
                      • Opcode ID: 2176c8afc786855b077dc832f5c45baebcf4524a083926ee920c6ccbf8625f2a
                      • Instruction ID: bfd52dfd9d48143f03510fed31eb448eb5cd214593652fb4de4a0c4bcb4857a6
                      • Opcode Fuzzy Hash: 2176c8afc786855b077dc832f5c45baebcf4524a083926ee920c6ccbf8625f2a
                      • Instruction Fuzzy Hash: A2F01C76B49B409AFB21CB70E40C2AE7772F749B1CF544216CA8A52A54DF2AC549C7C0
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID: gfffffff
                      • API String ID: 0-1523873471
                      • Opcode ID: 464dfa4c83a1cb36a3231215890441720f32f86cfff47949ad74be45281fce93
                      • Instruction ID: 1fcdce7feb57c8d62ab28b937ec89210f00c22e625bdef77f73d6c2da0b5922c
                      • Opcode Fuzzy Hash: 464dfa4c83a1cb36a3231215890441720f32f86cfff47949ad74be45281fce93
                      • Instruction Fuzzy Hash: DEA157727087C48AEB21CF2AB8087AF77A5E758BA8F058121DECA47785DE3EC445C741
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID: 0-3916222277
                      • Opcode ID: c8c0e72bc119871c5b85316c786ffb1e00813fd8e725d0fad8a77cec11a74a0d
                      • Instruction ID: b8035ed0c5c0db71948c92d876beceb445f3da7293f87f7b3e7d041b6d7e64b1
                      • Opcode Fuzzy Hash: c8c0e72bc119871c5b85316c786ffb1e00813fd8e725d0fad8a77cec11a74a0d
                      • Instruction Fuzzy Hash: 70B191B2A487448AE7658F39E45C37E3BB4E329B6CF240919CB8A47799CF36C451C781
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 6ecc5fde8d2de207e84c6efd4c763c26627f34c44f0a3e2290a945a0bf27fbe9
                      • Instruction ID: 49ae6682103b41da8ba6033bbae0d1758d6a004b9541f46505ec6d7867489ea6
                      • Opcode Fuzzy Hash: 6ecc5fde8d2de207e84c6efd4c763c26627f34c44f0a3e2290a945a0bf27fbe9
                      • Instruction Fuzzy Hash: 13A2E572919FC88AD7718F29E8412DAB7B4F799788F105315EACC26B59EF38C250CB44
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: c818c400f7f99635ff87755adcfa24266b134346301f2490f8a5ec602e6d4987
                      • Instruction ID: 92615e300a098674829492513515230f3913d289622b3a046d064462fe7f763d
                      • Opcode Fuzzy Hash: c818c400f7f99635ff87755adcfa24266b134346301f2490f8a5ec602e6d4987
                      • Instruction Fuzzy Hash: A5B24F36515FC88ED7768F29AC853DA73A8F35979CF105229EB8C5AB1DEB3083649340
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 1fd5320e4fc1fa6aa4b9814b896660084761b987e267291dce0f087101a88708
                      • Instruction ID: 5437b914b5cf55dd61a5cccd6a2b0eadbfd9db3c586e8033debed19b4d3f63f7
                      • Opcode Fuzzy Hash: 1fd5320e4fc1fa6aa4b9814b896660084761b987e267291dce0f087101a88708
                      • Instruction Fuzzy Hash: E0722A32648BC489EB718F65E8883DA77B5F349BACF505215DA9C1BB99DF39C280C740
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: ed3dbf53fc4028370182dbf3e5fe94cb6d6997e6740396f2b2d77411637f3093
                      • Instruction ID: 9f9325e609cfc9a31a1970fcd814e7734160c707d64c7c59f417e9bbac736a30
                      • Opcode Fuzzy Hash: ed3dbf53fc4028370182dbf3e5fe94cb6d6997e6740396f2b2d77411637f3093
                      • Instruction Fuzzy Hash: DF722A32648BC489EB718F65E8883DA77B5F349BACF505215DA9C1BB99DF39C280C740
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 08a5a50627158813c623d4e5cb51a4fdefe75cac5403bb3d7e85f96f2ed2cfff
                      • Instruction ID: 94ba01a18c921f81b598a1fb5f8a73393fe1472c010becf404a1ed0197812e7d
                      • Opcode Fuzzy Hash: 08a5a50627158813c623d4e5cb51a4fdefe75cac5403bb3d7e85f96f2ed2cfff
                      • Instruction Fuzzy Hash: 1C62A031DADE46CAE253CF35B85DB572374BB523E8F518703E81E67A50DF2AD4428A80
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: ce3d232bc6d3f07051b2921d649d913664c9ba3e6b849fb3c8405b5a9f64f184
                      • Instruction ID: d1f74e60f0972a9afbce1d3e07002cafc5d26a151ce11c055862548e6581fae3
                      • Opcode Fuzzy Hash: ce3d232bc6d3f07051b2921d649d913664c9ba3e6b849fb3c8405b5a9f64f184
                      • Instruction Fuzzy Hash: 8912D432619FC88AD7618F29E84129AB3B4F79D798F105315EACC57B59EF38C250CB44
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: e9d93a74443c6f8ac6cedb0670b6b61eb984213f148bfa24390be1f61368f6b0
                      • Instruction ID: 420801f898248651a87d1eeb66857ffa5616d223fe043b422510bb814d601d3f
                      • Opcode Fuzzy Hash: e9d93a74443c6f8ac6cedb0670b6b61eb984213f148bfa24390be1f61368f6b0
                      • Instruction Fuzzy Hash: D1D1C172A986448AEB688B29E05C3BF27B1E725B6CF540A06DEC5477D5CF37C846C780
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: ErrorLastNameTranslate$CodePageValidValue_invalid_parameter_noinfo
                      • String ID:
                      • API String ID: 4023145424-0
                      • Opcode ID: c5683b5ab0db41bcb1323fa95207c310c2977e7ab6ae4716e61d197a6b5daa51
                      • Instruction ID: d3bcce3fd257b8e8303a231317cbf4e75ac0836575e74af61da08626f5f7a943
                      • Opcode Fuzzy Hash: c5683b5ab0db41bcb1323fa95207c310c2977e7ab6ae4716e61d197a6b5daa51
                      • Instruction Fuzzy Hash: AEC1C53674878089EB609B62A81C3BF67B0F7947ACF404016DECA87795DF3AC545C780
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 51ef0ac578645917856e162b7255db7289b9b2fec19e44a9d134a756b0a5b295
                      • Instruction ID: eaba06014bb169d555068a7d9f029619018cdfc9a27a22a5f863e47887e975d1
                      • Opcode Fuzzy Hash: 51ef0ac578645917856e162b7255db7289b9b2fec19e44a9d134a756b0a5b295
                      • Instruction Fuzzy Hash: 6502D132A15FC88DE7228F39EC913D977B4F799798F105216EB9C2AB59EB348254C340
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 37313e4d91971378b4c4ebfe0f4fd16e6e162cfaef336df67a8eef634e769e91
                      • Instruction ID: b349d809900a7a22fda778202c7f73cf3723020649a5bac79b2a4cb646957db1
                      • Opcode Fuzzy Hash: 37313e4d91971378b4c4ebfe0f4fd16e6e162cfaef336df67a8eef634e769e91
                      • Instruction Fuzzy Hash: E1B16D72A487548EEB658F39E05C33E3BB0E329B6CF245929CA8A07395CF36C451C785
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: d891d87693f37a7620722e5036b1d6734a998c987c863807eb95cc6e9321161d
                      • Instruction ID: 0d1ecc84aac109cdf262bb58cbc40adc50b8932474fb0fa5daa5db0be60d820b
                      • Opcode Fuzzy Hash: d891d87693f37a7620722e5036b1d6734a998c987c863807eb95cc6e9321161d
                      • Instruction Fuzzy Hash: BA9182B76246808FD355CF19E440A4ABBA4F3D8B48F51E615EF8593B14E739DA06CF40
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: _invalid_parameter_noinfo
                      • String ID:
                      • API String ID: 3215553584-0
                      • Opcode ID: 3122cbdb49cd209c7d571a28d43a9570b111a50fb6fbee65f2f7a32fc1e4fc01
                      • Instruction ID: 6c19bb1d0cff7fa9b5062931b9a8d85a0897598d1495e3db3b532c770b70aa69
                      • Opcode Fuzzy Hash: 3122cbdb49cd209c7d571a28d43a9570b111a50fb6fbee65f2f7a32fc1e4fc01
                      • Instruction Fuzzy Hash: 2B819072244A508AEB64DF65E49D3BE2374F784BACF144626EEAE87B95CF35C041C780
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 1e77e51a571294c47d83fb4e19e75fd85eff00a0cc81eb461c84f405b589c283
                      • Instruction ID: b8fd784bba0835081d94155f3e2dba42861e5b117be004b16b6dacc330047930
                      • Opcode Fuzzy Hash: 1e77e51a571294c47d83fb4e19e75fd85eff00a0cc81eb461c84f405b589c283
                      • Instruction Fuzzy Hash: 49B1E232A15BC88DE7208F39E8413DEB3B4F79A798F505215EACC6AB59EB34C254C741
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: d9a79637e09c603694a07bf17c0bb50a9c478638dd2406be1bae50177a5a3912
                      • Instruction ID: 731a0e083df66ff66e8d37dd6362f5366cabce73e87e54bac2d23922b0db5f90
                      • Opcode Fuzzy Hash: d9a79637e09c603694a07bf17c0bb50a9c478638dd2406be1bae50177a5a3912
                      • Instruction Fuzzy Hash: 1181C57224C7808AE774CB19B48C36BB6A1F3857A8F544219DB9D87B99DF3EC5818B40
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 5d1609d76aae511c1edeab3b8d14fd2ffd1ccd2070ce5fc9c49f5e0c20b9161a
                      • Instruction ID: 9d916856fc6fab7f68d0b521de292e602d93254c35848d9bcf2862e79f2d16f8
                      • Opcode Fuzzy Hash: 5d1609d76aae511c1edeab3b8d14fd2ffd1ccd2070ce5fc9c49f5e0c20b9161a
                      • Instruction Fuzzy Hash: 3A61E4B2745AD883EE208F79E04D7EE6370F7547E8F458661EA5D07784DE3AD581C280
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 7fd1a8886b244ef549c759e362195161de7e5846fe9f3a2ce2d94e44a98cebc7
                      • Instruction ID: 91bcaa23ecf9530163a08a41672712d7b85b8b57f0b72445244a044db686d79c
                      • Opcode Fuzzy Hash: 7fd1a8886b244ef549c759e362195161de7e5846fe9f3a2ce2d94e44a98cebc7
                      • Instruction Fuzzy Hash: 6361EE2321E2C48FD30EDF7C589106D7F61D3A7908788469DEAC5EBB4BC504C95ACBA6
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 482e0394848c3e12cd66b979c184e45e97f38b3dba2f2b8e1e478abf0f74d34b
                      • Instruction ID: bad83a968c98f226efe8435a2ad7099c264a51a07b11872a78146dff47082bc3
                      • Opcode Fuzzy Hash: 482e0394848c3e12cd66b979c184e45e97f38b3dba2f2b8e1e478abf0f74d34b
                      • Instruction Fuzzy Hash: 425104B3B0568443DB248B49F846796F7A5FB987C5F00A126EE8D57B68EB3CD580C700
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 65988544bd8c51d46c1f2ecd44d2c2020be5c6c9d2ff497e3ff94f9df2993759
                      • Instruction ID: 2f92a295632530bd1f07ec2600be82442a608d1742040d9c58f3174e4c0097f9
                      • Opcode Fuzzy Hash: 65988544bd8c51d46c1f2ecd44d2c2020be5c6c9d2ff497e3ff94f9df2993759
                      • Instruction Fuzzy Hash: 67518C72A586508AE7688F29E15D37EB7B2E354B6CF144109DE875B799CF22CC41C7C0
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 09a4a0272fcb28be4f4c2347f47eb615663c13edcd1074745415d1c72bb9a049
                      • Instruction ID: b61173ae2a7787bc17527fb86b5f5d4784ed35fcb67517fbcbf0f4fef61cedbe
                      • Opcode Fuzzy Hash: 09a4a0272fcb28be4f4c2347f47eb615663c13edcd1074745415d1c72bb9a049
                      • Instruction Fuzzy Hash: 7E519D72A586508AE7688F28E05C33E2BB2E355B6CF640204CF8A177D9CB22CC42C7C0
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 15eac905c6263da8fcd042729b4cf6c2eac0663125a33ca76778ac8e5de10585
                      • Instruction ID: 6c260cbe513a8b878c815f7ee42b8a419547f722214d91926a54c07188bb912a
                      • Opcode Fuzzy Hash: 15eac905c6263da8fcd042729b4cf6c2eac0663125a33ca76778ac8e5de10585
                      • Instruction Fuzzy Hash: 1A515976A986508AE7289F28E19C33E27B2E355B6CF154115DE8B2B7D9CB32DC41C7C0
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: a1276585151577c5049716043ce568e71c08712838c9400709ab3047a6a4253b
                      • Instruction ID: dc8222de84fe17ce10442f753468e69570d3e34f5dc8c21eb9df4447f780f5ba
                      • Opcode Fuzzy Hash: a1276585151577c5049716043ce568e71c08712838c9400709ab3047a6a4253b
                      • Instruction Fuzzy Hash: C54106FB5CDAC44AF3924B785C7E25B3FB1A7E6E28F0D949AC780471C3A957080586C1
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: ErrorFreeHeapLast
                      • String ID:
                      • API String ID: 485612231-0
                      • Opcode ID: 893cde930e78cc51105ec5636604812294eefaa0d4abf3a70b7ba8ed9ec5214d
                      • Instruction ID: 8b989cd9d1d6a6c426b6dc5873b9171c04d8629fe95ec40da3cdc70cbb1bb7fc
                      • Opcode Fuzzy Hash: 893cde930e78cc51105ec5636604812294eefaa0d4abf3a70b7ba8ed9ec5214d
                      • Instruction Fuzzy Hash: 6E41B732714E5442EF04CF6AE91C65AB3A1A748FE8F4A9522DE0EC7B54DF3DC4828340
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 98cd094313ed2037ccc8782024778216330ac1f2612bd7d9e2e2b2ae76f12b02
                      • Instruction ID: 6a8000111db9dac228bcc61299dcaf553dcaf9b3705cd64dd4e261030beecbc4
                      • Opcode Fuzzy Hash: 98cd094313ed2037ccc8782024778216330ac1f2612bd7d9e2e2b2ae76f12b02
                      • Instruction Fuzzy Hash: 973162F758DEC40AF7921B7C9D7E25B2FB1E39AE28F4E84998784031C7AC57280596C1
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 14e20909d8fae815a2a236acf6c5cc8b831a1dabc23c65dc1f3470caa292b9f8
                      • Instruction ID: 47b7c102baa6a7594fc9d89252aa4a3a8b036c38bc90cb2fb661a018ff5d6977
                      • Opcode Fuzzy Hash: 14e20909d8fae815a2a236acf6c5cc8b831a1dabc23c65dc1f3470caa292b9f8
                      • Instruction Fuzzy Hash: F93102FB5CDAC44AF3934B785C7E24B3FB0A7E6E28F0D84968780471C7A957180586C1
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 1cc7beeee5fada05c663dfdd44f81150fdbeb992a14920ca678986335bb5f39c
                      • Instruction ID: fb22eed10572299d3cc05addffad1f8a233b015553c832517ec9a06b22efc591
                      • Opcode Fuzzy Hash: 1cc7beeee5fada05c663dfdd44f81150fdbeb992a14920ca678986335bb5f39c
                      • Instruction Fuzzy Hash: 9C31B1EB5CDAC40AF3924B785D7E35B3FB097E6E28F0D849A8780471C7A947590586C1
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 8d7b787d11b41dbc44b4748bdbefcc21f6dfd1e357da298ee2112c9f988ea8d8
                      • Instruction ID: 3e99707aff22921471661166e9b26e511e44c560f8bdcf01c2e5210b7e001ec1
                      • Opcode Fuzzy Hash: 8d7b787d11b41dbc44b4748bdbefcc21f6dfd1e357da298ee2112c9f988ea8d8
                      • Instruction Fuzzy Hash: A02130F758DEC40AF7921B7C9D7E25B2FB1E39AE28F4E84A98784031C7AC57180596C1
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 8aed357bd1e5aa7fadd1eb61ba27027061c862cb839a1155f22db4f4389644ef
                      • Instruction ID: 1f19cf8fef1548c7aad9c74d6cc121b745e2b0b0900be9a58aac69d5af530d48
                      • Opcode Fuzzy Hash: 8aed357bd1e5aa7fadd1eb61ba27027061c862cb839a1155f22db4f4389644ef
                      • Instruction Fuzzy Hash: 531136F754EAC40BF3920F785E6E24B3FB0A795E18F4D8459C784031C7AD17680596C1
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: b62692185f0952021f42339d391be37b2b68d69df015e7583d467e4b8e0e3d8f
                      • Instruction ID: 77b4834225d0ad8f24c23c54e64a4ca77c78d2e126c81db338b1b54ed89edecc
                      • Opcode Fuzzy Hash: b62692185f0952021f42339d391be37b2b68d69df015e7583d467e4b8e0e3d8f
                      • Instruction Fuzzy Hash: FA01A1E794EBC04EE3535B781C7E1093FB0A79A914B8E8597C381872C3D54A4C0983E2
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 77fbf8e923f89f056e9526ecdb34e03657dccd48feaa973093d3c497ed56ed7a
                      • Instruction ID: 50a8b8e8edbc0f4079a8ade28d8a11991279aa70de32ae00e43282b3072bf40d
                      • Opcode Fuzzy Hash: 77fbf8e923f89f056e9526ecdb34e03657dccd48feaa973093d3c497ed56ed7a
                      • Instruction Fuzzy Hash: E3D0C9EFD4DC8546F96147782CBE2C90FA1EB6B6B9F691C49A7B44229739035C0F0AC1
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 5b1fcfa14c0485fe98eea24fc35bc54b37c1f2dff9bda23e3120baaeca383856
                      • Instruction ID: 6a1d3ce7e83bc00a4c4da626c6c2e274129735229b0081f27947ab72509394b1
                      • Opcode Fuzzy Hash: 5b1fcfa14c0485fe98eea24fc35bc54b37c1f2dff9bda23e3120baaeca383856
                      • Instruction Fuzzy Hash:
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: CloseHandle$Token$Process32$InformationNextOpenProcess$ConvertCreateDuplicateErrorFirstLastSnapshotStringToolhelp32_invalid_parameter_noinfo
                      • String ID:
                      • API String ID: 1854266383-0
                      • Opcode ID: 95c02c708e2dd0fc13a943db0dc148411871edf296a3fb3e701c8bc9c21aef15
                      • Instruction ID: 86a58890c7e379096fc7c6e913260743df2e571e32ae914197fb70682fa0eeeb
                      • Opcode Fuzzy Hash: 95c02c708e2dd0fc13a943db0dc148411871edf296a3fb3e701c8bc9c21aef15
                      • Instruction Fuzzy Hash: 14813932258B8086EB50CB22F84C76BB3B5F7C9BA8F404515EE9A47B58DF7AC544C780
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Value$ErrorLast$Heap$AllocFree
                      • String ID:
                      • API String ID: 570795689-0
                      • Opcode ID: 9149da2b617047b16655290e3171b53232e19cbea25b6a6d8123559a7d664372
                      • Instruction ID: ad6f5454e56b2dddec0015b95acd2c5852b01048f1b29875ed553dafaffee781
                      • Opcode Fuzzy Hash: 9149da2b617047b16655290e3171b53232e19cbea25b6a6d8123559a7d664372
                      • Instruction Fuzzy Hash: 0441E3703CC6414AFA58A332B95D37B61764F547BCF094B25A8BA0B6D3DE2B944297C0
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID: No closed word$key declared, but no value$key opened, but never closed$object is not closed with '}'$quote was opened but not closed.$unexpected '}'$unexpected key without object$word wasnt properly ended
                      • API String ID: 0-2700065129
                      • Opcode ID: 54f9e4c533da8cc83bdbcfe6076038442e444a18dbcd0ad599e53e28fcfb47a6
                      • Instruction ID: aee29fd7a4408c4ce77142bffe307cc000ef0371fb723636ce4b006f24bea900
                      • Opcode Fuzzy Hash: 54f9e4c533da8cc83bdbcfe6076038442e444a18dbcd0ad599e53e28fcfb47a6
                      • Instruction Fuzzy Hash: 34A13E31658EC6A4EB60EF24F88C3DB7374F79036CF905512E64A0696AEF75C689C780
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Concurrency::cancel_current_task$std::_$Locinfo::_Locinfo_ctorLockitLockit::_
                      • String ID: bad locale name$false$true
                      • API String ID: 164343898-1062449267
                      • Opcode ID: f2c583cc08c2fc1c24db8880ae22343201fbab21c815b86846b4fc8c7bc58cd0
                      • Instruction ID: fac64ed7872bef99a0ea1a34b57990868196eb2e0b5dbd6766a628b91ea78001
                      • Opcode Fuzzy Hash: f2c583cc08c2fc1c24db8880ae22343201fbab21c815b86846b4fc8c7bc58cd0
                      • Instruction Fuzzy Hash: 35719B32749B408AEB11DF70F4583AE33B2EB8572CF140624DE8927AAADF39C451C784
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Session$ListProcess$CriticalCurrentEnterRegisterResourcesSectionStart
                      • String ID:
                      • API String ID: 3572076967-0
                      • Opcode ID: a35c6fe72c13dad0c03fe2dbd95fe45af4d9ce3c3bea894cf2d167248458fb9f
                      • Instruction ID: 8bf7ffe73a17819f9303f54ab2ced8d36346ed5be7b370da45c8a4c94a87e380
                      • Opcode Fuzzy Hash: a35c6fe72c13dad0c03fe2dbd95fe45af4d9ce3c3bea894cf2d167248458fb9f
                      • Instruction Fuzzy Hash: 91511C72B48A008AF710CFA5F95C7AE73B1F788768F404525DA4AA7A98DF36C905C7C0
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: _invalid_parameter_noinfo
                      • String ID: 0$f$p$p
                      • API String ID: 3215553584-1202675169
                      • Opcode ID: 52987e50f1db9deef54869d210a835d1c4791c89626e79df4bbc7dc00e5fb524
                      • Instruction ID: 4ee34a0dc7bd0dc595ff6b5d86548f215f0f9148263ab53ef7e79a52dd3a16c2
                      • Opcode Fuzzy Hash: 52987e50f1db9deef54869d210a835d1c4791c89626e79df4bbc7dc00e5fb524
                      • Instruction Fuzzy Hash: 1B12AF3264C2518AFB20AB15F05C7BB76B1F340B68F948116E7D2876C8EF3EC5848B94
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: AddressFreeLibraryProc
                      • String ID: api-ms-$ext-ms-
                      • API String ID: 3013587201-537541572
                      • Opcode ID: 11773e365cd412d7a76d792911502b683686e1c6c513d2bf19565073d050b19b
                      • Instruction ID: cbf979061db0161693288f975fd0b7145ef99732ec5503fd73929eae17ff77ef
                      • Opcode Fuzzy Hash: 11773e365cd412d7a76d792911502b683686e1c6c513d2bf19565073d050b19b
                      • Instruction Fuzzy Hash: 9C41E171359A0086FB19DB16BC0C36B63B6B745BF8F0945259D5A8B798EF3EC44583C0
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Internet$CloseFileHandleOpenRead
                      • String ID: File Downloader
                      • API String ID: 4038090926-3631955488
                      • Opcode ID: ecf15071ea5af7eb00f2f65c016d9ace3b271b52a974d1f9444f993ae54cec16
                      • Instruction ID: a77e5d671babffa407a940131666c6701c2658fa60ed48530ff25b965fa891e1
                      • Opcode Fuzzy Hash: ecf15071ea5af7eb00f2f65c016d9ace3b271b52a974d1f9444f993ae54cec16
                      • Instruction Fuzzy Hash: F7319E72258B8086EB10CF21F85879BB371F789BD8F544425EE8943B58DF7AC195CB80
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast
                      • String ID: CONOUT$
                      • API String ID: 3230265001-3130406586
                      • Opcode ID: 0dddb6de3d597d68cfacc53ab6be1cbd4af4669a405a6786b7c60127ef89aaa0
                      • Instruction ID: a54f38cea7ef6845c5a65b6f366e6da1fc5485c6c546457cd2b2bba36e42e7ac
                      • Opcode Fuzzy Hash: 0dddb6de3d597d68cfacc53ab6be1cbd4af4669a405a6786b7c60127ef89aaa0
                      • Instruction Fuzzy Hash: D0115831618A9086E7508B52F85C72BB2B0F78CFF8F044224EA5A877A4CF7AC84487C0
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: ByteCharMultiWide$CompareInfoString
                      • String ID:
                      • API String ID: 2984826149-0
                      • Opcode ID: 92bac5e0378c4bd192cc901063e9eb12bd808531ab6fa154afa5c1adc07e564a
                      • Instruction ID: d8a294ddf560f050de907b8609199213fffa57bdc36d7c9cd74f91082d1728a5
                      • Opcode Fuzzy Hash: 92bac5e0378c4bd192cc901063e9eb12bd808531ab6fa154afa5c1adc07e564a
                      • Instruction Fuzzy Hash: BAA1C27238878046FB318F25A44CBAB66B1A745BBCF4847219A7947BC5DF7AE84483C0
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: ImpersonateLoggedRevertSelfUser
                      • String ID: APPB
                      • API String ID: 1724704203-1278849820
                      • Opcode ID: 0cdcb25afdf0f537736c0c9d6cf5e32dbc2d09c82f56beca2433bdeeb49a7e2e
                      • Instruction ID: cb96efea9cf19b043940e2e0936d2ce9b70f60499a5582a7d3892c03d892a931
                      • Opcode Fuzzy Hash: 0cdcb25afdf0f537736c0c9d6cf5e32dbc2d09c82f56beca2433bdeeb49a7e2e
                      • Instruction Fuzzy Hash: 8A12A172798A8089FB009BB8E45C39E2772E7467BCF505701EA6D57ADADF76C081C380
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: ByteCharMultiStringWide
                      • String ID:
                      • API String ID: 2829165498-0
                      • Opcode ID: e031dea7b6db84cb520ba2c45569280d6f7d95c207c4d1fed0011a78314f5e9f
                      • Instruction ID: cdeca53ece8611dc980cc1b8edcc565fd78578b1cfc9ae6ac5b1082e1e85ae2e
                      • Opcode Fuzzy Hash: e031dea7b6db84cb520ba2c45569280d6f7d95c207c4d1fed0011a78314f5e9f
                      • Instruction Fuzzy Hash: 06819D7224874086EB608F61E44CB6BA7B1FB84BBCF140725EA6957BD8DF3ED4458780
                      APIs
                      • GetLastError.KERNEL32 ref: 000002674E1B96F3
                      • FlsSetValue.KERNEL32(?,?,8000000000000000,000002674E1B54D5,?,?,?,?,000002674E1BC918), ref: 000002674E1B9729
                      • FlsSetValue.KERNEL32(?,?,8000000000000000,000002674E1B54D5,?,?,?,?,000002674E1BC918), ref: 000002674E1B9756
                      • FlsSetValue.KERNEL32(?,?,8000000000000000,000002674E1B54D5,?,?,?,?,000002674E1BC918), ref: 000002674E1B9767
                      • FlsSetValue.KERNEL32(?,?,8000000000000000,000002674E1B54D5,?,?,?,?,000002674E1BC918), ref: 000002674E1B9778
                      • SetLastError.KERNEL32 ref: 000002674E1B9793
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Value$ErrorLast
                      • String ID:
                      • API String ID: 2506987500-0
                      • Opcode ID: 2dd89ab11e2baa6b4167660281107f76443598ebfbf3f707a767af27e6dfaef9
                      • Instruction ID: 964642533e773dce010b1b30164146a02af71963811772b4b7a2b487c7545cdf
                      • Opcode Fuzzy Hash: 2dd89ab11e2baa6b4167660281107f76443598ebfbf3f707a767af27e6dfaef9
                      • Instruction Fuzzy Hash: 6C11B43438C6814AFA58A731BA5D33B61B29B447BCF144754A9FA07BD7DE2B84029BC0
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: ApisFile__std_exception_destroy__std_fs_code_page
                      • String ID: ", "$: "
                      • API String ID: 376971205-747220369
                      • Opcode ID: 6ce0c9ac678dfffe8216c01570fe0d4b0f0602c9a03263713264cb1912163c92
                      • Instruction ID: e62a392bc5b3f7d9ec364d62fb38e3aaf5fb891336f1f82afb3b1d867f774598
                      • Opcode Fuzzy Hash: 6ce0c9ac678dfffe8216c01570fe0d4b0f0602c9a03263713264cb1912163c92
                      • Instruction Fuzzy Hash: 81A1BE72389A8095EB00DF65E05C3AE2372F748BACF505522DE5D47B9ADF7AC496C380
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: _set_statfp
                      • String ID:
                      • API String ID: 1156100317-0
                      • Opcode ID: c69ac79b0f3061c2541803769b5ffd1031012cb060908421cb0413baa5a14296
                      • Instruction ID: 27c0ebe970b98a29b4b104079901a263ca7fe2b8483c534fca94b2bd36df684f
                      • Opcode Fuzzy Hash: c69ac79b0f3061c2541803769b5ffd1031012cb060908421cb0413baa5a14296
                      • Instruction Fuzzy Hash: D981E23668CA4445F7768F38B45C36BA2B0FB497BCF044305AB9AA65D4DF36C9C18A80
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: _set_statfp
                      • String ID:
                      • API String ID: 1156100317-0
                      • Opcode ID: 81687dc7f27f0f699236e27e88451408a0877f0e146ecd1626c1fdba7a84f29b
                      • Instruction ID: 69ae8e61fd8bccc7610ed3aec7d4d904175963c35a87f51b84e413a47e39fc2e
                      • Opcode Fuzzy Hash: 81687dc7f27f0f699236e27e88451408a0877f0e146ecd1626c1fdba7a84f29b
                      • Instruction Fuzzy Hash: 1811A3B6BDCA0401F7551369F44E36F1070AB5437CF541775AAA6CA6D6CF36CCC26181
                      APIs
                      • FlsGetValue.KERNEL32(?,?,?,000002674E1B0CC7,?,?,00000000,000002674E1B0F62,?,?,?,?,8000000000000000,000002674E1B0EEE), ref: 000002674E1B97CB
                      • FlsSetValue.KERNEL32(?,?,?,000002674E1B0CC7,?,?,00000000,000002674E1B0F62,?,?,?,?,8000000000000000,000002674E1B0EEE), ref: 000002674E1B97EA
                      • FlsSetValue.KERNEL32(?,?,?,000002674E1B0CC7,?,?,00000000,000002674E1B0F62,?,?,?,?,8000000000000000,000002674E1B0EEE), ref: 000002674E1B9812
                      • FlsSetValue.KERNEL32(?,?,?,000002674E1B0CC7,?,?,00000000,000002674E1B0F62,?,?,?,?,8000000000000000,000002674E1B0EEE), ref: 000002674E1B9823
                      • FlsSetValue.KERNEL32(?,?,?,000002674E1B0CC7,?,?,00000000,000002674E1B0F62,?,?,?,?,8000000000000000,000002674E1B0EEE), ref: 000002674E1B9834
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Value
                      • String ID:
                      • API String ID: 3702945584-0
                      • Opcode ID: 5bf10b8481cea46eb87718f866eeea3d889c5210f9494361ea54e7e462e3d6ed
                      • Instruction ID: 3dda2727a2d19490e98f78bf0cb4b8c50ea4673a4ba292db0dd65b55ff014e24
                      • Opcode Fuzzy Hash: 5bf10b8481cea46eb87718f866eeea3d889c5210f9494361ea54e7e462e3d6ed
                      • Instruction Fuzzy Hash: 5F11D33078C64149FA589722BA4D33B71714B443B8F088325A8BA06BE7DE2AD4429280
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: _invalid_parameter_noinfo
                      • String ID: UTF-16LEUNICODE$UTF-8$ccs
                      • API String ID: 3215553584-1196891531
                      • Opcode ID: a2f026dd96aebdf64aff9fb5689b0f0a5eaee935ffed21609211921be484b338
                      • Instruction ID: 2731e99ae9d7c4063952dd3f2026f94e5295c1a4e5a2d6b88e29cbd1dc3985de
                      • Opcode Fuzzy Hash: a2f026dd96aebdf64aff9fb5689b0f0a5eaee935ffed21609211921be484b338
                      • Instruction Fuzzy Hash: D1818C76B8C20087FB658F2DA15CB7F36B1B311FACF598205EA0257295DB2BC88197C1
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: std::_$GetcollLocinfo::_Locinfo_ctorLockitLockit::_
                      • String ID: bad locale name
                      • API String ID: 1287851536-1405518554
                      • Opcode ID: 44b4cec343d40886e1e7ad76c2554702c5d9f8b9f81e0270ea62f239af0d16be
                      • Instruction ID: b4b11fc69df32338e62fede00933464f2c50d940c857eb0cb119259271cb35e5
                      • Opcode Fuzzy Hash: 44b4cec343d40886e1e7ad76c2554702c5d9f8b9f81e0270ea62f239af0d16be
                      • Instruction Fuzzy Hash: 8C718A3274AB408AFB14CFB4E4983AE33B6AB44B6CF044525DE592BA99DE36C451C3C4
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: __std_exception_destroy
                      • String ID: at line $, column
                      • API String ID: 2453523683-191570568
                      • Opcode ID: a747c9751213463625fbff00866fd76cd910883607fb28ded870c6f093becd07
                      • Instruction ID: 929726b46499a4cd32b55f8a95c7c0d611766b884ee6fbc7b06300ea9c84bacc
                      • Opcode Fuzzy Hash: a747c9751213463625fbff00866fd76cd910883607fb28ded870c6f093becd07
                      • Instruction Fuzzy Hash: 8C51B572658B8082EA10DB15F18C75F6772F785BE8F104211EBA807BDADF7AC491C780
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: std::_$GetctypeLocinfo::_Locinfo_ctorLockitLockit::_
                      • String ID: bad locale name
                      • API String ID: 1612978173-1405518554
                      • Opcode ID: 7c5dc37f1ce31c7cc423577a9b21c9b6a6365d6faf8c87315cdadd9cc0908209
                      • Instruction ID: cba31a9a347e8d7b5eb38959833d0f05ceb882e8a246e771b94141a0dc19100a
                      • Opcode Fuzzy Hash: 7c5dc37f1ce31c7cc423577a9b21c9b6a6365d6faf8c87315cdadd9cc0908209
                      • Instruction Fuzzy Hash: C3515A32789B408AFB04CF70E5883EE3375EB4475CF044929DA492BA99EF35C525D384
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: Open
                      • String ID: ?
                      • API String ID: 71445658-1684325040
                      • Opcode ID: 0fe5ad08d041bdafa09c3da29caaf98c2d41aae422f367317a8d547301fe6694
                      • Instruction ID: 7fa79d7043ad2a7c54e7871eb7175cf15f62e94257c374ee143606ce49968cbd
                      • Opcode Fuzzy Hash: 0fe5ad08d041bdafa09c3da29caaf98c2d41aae422f367317a8d547301fe6694
                      • Instruction Fuzzy Hash: 9C41AB72758B8082EB10CB25F48836FB771F7997E8F505215FB9942A99DF79C094CB80
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: FileWrite$ConsoleErrorLastOutput
                      • String ID:
                      • API String ID: 2718003287-0
                      • Opcode ID: ca085b0e8f0622164bcb5eeb9b62e38fcc89866fc0b97dcf386853e0d4b10385
                      • Instruction ID: ccf895462f418dd5a83997151108e053b88f10842f0e55c5d6357fcb2f115862
                      • Opcode Fuzzy Hash: ca085b0e8f0622164bcb5eeb9b62e38fcc89866fc0b97dcf386853e0d4b10385
                      • Instruction Fuzzy Hash: D6D1E132B48A848EEB10CF79E4486AE37B1F3547ACF144216DE9D97B99CE36C546C780
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: ConsoleErrorLastMode
                      • String ID:
                      • API String ID: 953036326-0
                      • Opcode ID: 6b60d506c3f30cc3699963e06d633ced3a4f7ad44ff6771a51fe5f78e0193168
                      • Instruction ID: b9db0fa838012311264d76e758dea514fcf8b70b3a14f69e16456250f2307b29
                      • Opcode Fuzzy Hash: 6b60d506c3f30cc3699963e06d633ced3a4f7ad44ff6771a51fe5f78e0193168
                      • Instruction Fuzzy Hash: B891F272A586908AFB50CB69A48C7BF37B0F3447ACF445146DEAA53695DF36C482C390
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: _invalid_parameter_noinfo$_get_daylight
                      • String ID:
                      • API String ID: 72036449-0
                      • Opcode ID: c326f4a23d9720df872ca245bb9d5f9d3b5c1a0ecfc9e75a475ccc2f369592b4
                      • Instruction ID: 37b64a3488f28f04e4bb52df78309075619a6423d2c919ed3ea5b13c29216f57
                      • Opcode Fuzzy Hash: c326f4a23d9720df872ca245bb9d5f9d3b5c1a0ecfc9e75a475ccc2f369592b4
                      • Instruction Fuzzy Hash: EE51BD3268C24187F7794F2CB52C37F76B0B38473CF194525AA4266AD6DE6AC880C7C1
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID:
                      • API String ID:
                      • Opcode ID: 52fc06e67e27b6edff84cb747008be164aaf46ee979e8c305d596af373f75300
                      • Instruction ID: 91bc89ea6054dd854bb4a7f87ac96161793269f1085c007c030ff6366f2bef35
                      • Opcode Fuzzy Hash: 52fc06e67e27b6edff84cb747008be164aaf46ee979e8c305d596af373f75300
                      • Instruction Fuzzy Hash: 6F41083274874447EA245F31B58C79FA2B1AB447B8F140724AFAA07BD6DF3AD1918780
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: EnvironmentInitStringStringsUnicode$Free
                      • String ID:
                      • API String ID: 2488768755-0
                      • Opcode ID: f3b4b1024bc5240d9d05f18a8e699e4bdfb592a5c05bdfc4938c2f99593866f5
                      • Instruction ID: ded9ad03815d6e3ba7411f7da2937b04343a915fe3e62d9163b546debd69e9f4
                      • Opcode Fuzzy Hash: f3b4b1024bc5240d9d05f18a8e699e4bdfb592a5c05bdfc4938c2f99593866f5
                      • Instruction Fuzzy Hash: C8518A72A18B80C2EB108F25F54836E7770F798BA8F549205EB9903BA5DF79D1E1C380
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: std::_$LockitLockit::_$Concurrency::cancel_current_taskFacet_RegisterSetgloballocalestd::locale::_
                      • String ID:
                      • API String ID: 3698853521-0
                      • Opcode ID: bb669478207201f0d6aad3e746d74185770434263953bfbc06078ba4d2e3e7b5
                      • Instruction ID: 540639a5b0cbccafaf1ab133caf293ffca889f9703d27c91d1bb5d615c0238e4
                      • Opcode Fuzzy Hash: bb669478207201f0d6aad3e746d74185770434263953bfbc06078ba4d2e3e7b5
                      • Instruction Fuzzy Hash: B4419E32258B4082EA10DF25F48C7AB73B4F748BB8F591526EA9D037A5DF3AC441C780
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: std::_$LockitLockit::_$Concurrency::cancel_current_taskFacet_Register
                      • String ID:
                      • API String ID: 1168246061-0
                      • Opcode ID: bc66d5e23df93b0c942b80fe2c5823ab9021a420d770de9600f65181aad1012b
                      • Instruction ID: b88c66c92effb64230ae03e36fafece3bc8974436f5f825473ddf88cbc0c2657
                      • Opcode Fuzzy Hash: bc66d5e23df93b0c942b80fe2c5823ab9021a420d770de9600f65181aad1012b
                      • Instruction Fuzzy Hash: 2541BF32659A4480EA10DF25F94C7ABB771F789BF8F080621EA9E477A5DF3AC441C790
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: std::_$LockitLockit::_$Concurrency::cancel_current_taskFacet_Register
                      • String ID:
                      • API String ID: 1168246061-0
                      • Opcode ID: e96b2e82d93ecaa2b538fed2899b3285f89e7de84e9ce16f7147f64ed71c4740
                      • Instruction ID: 4aca2e865b27ffdfa4a7d0db4371ae6404c9092c6771515cf7aeae77725b06f8
                      • Opcode Fuzzy Hash: e96b2e82d93ecaa2b538fed2899b3285f89e7de84e9ce16f7147f64ed71c4740
                      • Instruction Fuzzy Hash: DF41AF72249A4081EB11DB25F55C7AB7770F798BF8F080621EA9E477A5DF3AD442C780
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: std::_$LockitLockit::_$Concurrency::cancel_current_taskFacet_Register
                      • String ID:
                      • API String ID: 1168246061-0
                      • Opcode ID: 6932be257f3c88376612ec6fa1552a3f20bd87c429f53985244c208c3aadaceb
                      • Instruction ID: 7cd29cbab0d7eadab5d44aa4f73cbd7984052d8dc29fe817cd4f0273a17e9cf4
                      • Opcode Fuzzy Hash: 6932be257f3c88376612ec6fa1552a3f20bd87c429f53985244c208c3aadaceb
                      • Instruction Fuzzy Hash: 8D41BF32259A4480EB24DF15F98C79B77B1F749BB8F480621EA9E477A5CF3AC441C790
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: std::_$LockitLockit::_$Concurrency::cancel_current_taskFacet_Register
                      • String ID:
                      • API String ID: 1168246061-0
                      • Opcode ID: 93a2c95ede573667e3950762093a80cca790c9a02267e79f441c9a35f3b57abb
                      • Instruction ID: 66568c63eec4473d1e369db7d2b958b759f044034b6b302062ea4ea147412686
                      • Opcode Fuzzy Hash: 93a2c95ede573667e3950762093a80cca790c9a02267e79f441c9a35f3b57abb
                      • Instruction Fuzzy Hash: 18418031649A8081EA15DB15F98C7AB7770F788BB8F580521EA9E477A5DF3AC881C780
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: ByteCharErrorLastMultiWide
                      • String ID:
                      • API String ID: 203985260-0
                      • Opcode ID: d43b7eff65a7dae745af3942cdd14e91feac4936b4f3ea3d898aeea0c8b2b936
                      • Instruction ID: 13a53650fb8fa650f46bd77f2a80779226bb2833761df071b9184299b8b63d87
                      • Opcode Fuzzy Hash: d43b7eff65a7dae745af3942cdd14e91feac4936b4f3ea3d898aeea0c8b2b936
                      • Instruction Fuzzy Hash: CA211D76618B8487E7508F16F448B1FB6B4F389BA8F144129DB8593B55DF3AD8418B80
                      APIs
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: AttributesCloseErrorFileHandleLast__std_fs_open_handle
                      • String ID:
                      • API String ID: 833716960-0
                      • Opcode ID: 212cc577b7be2e5c6ea106b2b4fc12f43d225d4dcb5679136c345eabb4b633d0
                      • Instruction ID: f1c19becf8ee2bc29706c9aa0cdb8f8cb5976e506b091f11ab4f1c724914c1f8
                      • Opcode Fuzzy Hash: 212cc577b7be2e5c6ea106b2b4fc12f43d225d4dcb5679136c345eabb4b633d0
                      • Instruction Fuzzy Hash: B911CE3225C60085FAA04B26B48CF2B6671F7887F8F100604FA7787AE9DE3AD4408B80
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID:
                      • String ID: [json.exception.
                      • API String ID: 0-791563284
                      • Opcode ID: 3371d376b1fb0f7f72db62ec8c1ce44848107f54f26edc8b3c89a9c68ecf2878
                      • Instruction ID: abbdab8c275565c9fc2543c1a5db079122cabceef4290edec6a99b57e8c68fe6
                      • Opcode Fuzzy Hash: 3371d376b1fb0f7f72db62ec8c1ce44848107f54f26edc8b3c89a9c68ecf2878
                      • Instruction Fuzzy Hash: 98711472F14B9086FB00CFB9E45839E2771E795BA8F504215DE9917B8ADF7AC092C380
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: std::_$Locinfo::_Locinfo_ctorLockitLockit::_
                      • String ID: bad locale name
                      • API String ID: 3988782225-1405518554
                      • Opcode ID: 6b884abbfe82cca26fa5c3d75b17e478256f2d51f07b413438136a3cdfc1bdf2
                      • Instruction ID: a4bc08528fe30632751bcfe85ec568a3ec125087a193d0c7ce2585afea08905a
                      • Opcode Fuzzy Hash: 6b884abbfe82cca26fa5c3d75b17e478256f2d51f07b413438136a3cdfc1bdf2
                      • Instruction Fuzzy Hash: 91516D32359A40CAEB10DFB1E4993EE3375EB44B2CF040825EA8927A99CF35C921C394
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: std::_$Locinfo::_Locinfo_ctorLockitLockit::_
                      • String ID: bad locale name
                      • API String ID: 3988782225-1405518554
                      • Opcode ID: fa61fe8489eead96f1bcdb6717db0cc4da6c432a113f090fb978a5db9f7204d6
                      • Instruction ID: 224d1b20dde952ab5d16a62e836442971e72b5e630a537649110ae7a51e78962
                      • Opcode Fuzzy Hash: fa61fe8489eead96f1bcdb6717db0cc4da6c432a113f090fb978a5db9f7204d6
                      • Instruction Fuzzy Hash: DD516F32349A40C9EB14DF70E4987EE33B4EB44B6CF040835EA4A67A99DF35C925C384
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: _get_daylight$_invalid_parameter_noinfo
                      • String ID: ?
                      • API String ID: 1286766494-1684325040
                      • Opcode ID: 261cd5bec1a2035031a6129dbaf6c96984a9f4827a3930e8b5c6c4605a5d557d
                      • Instruction ID: b33dbf9b9c15b350de9054ae718fe85abf44be50d354d9bc0ea663e014d77371
                      • Opcode Fuzzy Hash: 261cd5bec1a2035031a6129dbaf6c96984a9f4827a3930e8b5c6c4605a5d557d
                      • Instruction Fuzzy Hash: F441E432358B9046FB649B25B45D3AB66B0E780BBCF144225EF9986BD5EF3AC4C1C740
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: ErrorFileLastWrite
                      • String ID: U
                      • API String ID: 442123175-4171548499
                      • Opcode ID: 8f4fd0c91fb0cd949aa6ea42ff252ce09842b517548967c8e372956fef53ad5c
                      • Instruction ID: 16107f179f45d137c3b4014d60b9e093d191596ccc30d179fbe370d86f9b31c7
                      • Opcode Fuzzy Hash: 8f4fd0c91fb0cd949aa6ea42ff252ce09842b517548967c8e372956fef53ad5c
                      • Instruction Fuzzy Hash: 7C41A232718A8086DB60CF25F84C3AA77B1F3887A8F854121EE8E87798DF79C441C790
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: _set_errno_from_matherr
                      • String ID: exp
                      • API String ID: 1187470696-113136155
                      • Opcode ID: a5b9f233cb04299b36be403a065897f46bab1258e8b14b3ae85cbca89b91c6cb
                      • Instruction ID: 41e43999944717e0737c95e4dc36838794df9fb6b18bd908d39af6b8de30a6a3
                      • Opcode Fuzzy Hash: a5b9f233cb04299b36be403a065897f46bab1258e8b14b3ae85cbca89b91c6cb
                      • Instruction Fuzzy Hash: 9E212636B546148FE750DF78E8486AE37B0F74C75CF401629EA0E92B4ADF39C5808B80
                      APIs
                      Strings
                      Memory Dump Source
                      • Source File: 00000000.00000002.1323509145.000002674E120000.00000040.00001000.00020000.00000000.sdmp, Offset: 000002674E120000, based on PE: true
                      Joe Sandbox IDA Plugin
                      • Snapshot File: hcaresult_0_2_2674e120000_file.jbxd
                      Yara matches
                      Similarity
                      • API ID: ExceptionFileHeaderRaise
                      • String ID: csm
                      • API String ID: 2573137834-1018135373
                      • Opcode ID: 036ca98e85fc673dbf707ecc6b1c2fe227b6d7cd6c56b89ac8b0a1a657246038
                      • Instruction ID: ac2478a5034aef064cf5374c20e3785a95358f3b6f43cb1cecdb5021662efbc0
                      • Opcode Fuzzy Hash: 036ca98e85fc673dbf707ecc6b1c2fe227b6d7cd6c56b89ac8b0a1a657246038
                      • Instruction Fuzzy Hash: 49114F32248B8082EB208F15F44835A77F5F788BA8F284224EF8D07759DF3AC551C780