Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
t90RvrDNvz.exe

Overview

General Information

Sample name:t90RvrDNvz.exe
renamed because original name is a hash value
Original sample name:f660778402a3bb138486c84706d69a00ee03818437d6dac0fed4ea276561e84a.exe
Analysis ID:1562121
MD5:05ce896e3a0a78a9bf1f12a51d83d215
SHA1:f7e32c1dc592e3c185fece729ebcc0266e86e0cc
SHA256:f660778402a3bb138486c84706d69a00ee03818437d6dac0fed4ea276561e84a
Tags:AdwareTechsnabexeTRADETRUSTLLCuser-JAMESWT_MHT
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
AI detected suspicious sample
Found direct / indirect Syscall (likely to bypass EDR)
Contains functionality to call native functions
HTTP GET or POST without a user agent
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE / OLE file has an invalid certificate
PE file contains more sections than normal
PE file contains sections with non-standard names
Sample file is different than original file name gathered from version info
Suricata IDS alerts with low severity for network traffic

Classification

  • System is w10x64
  • t90RvrDNvz.exe (PID: 1444 cmdline: "C:\Users\user\Desktop\t90RvrDNvz.exe" MD5: 05CE896E3A0A78A9BF1F12A51D83D215)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-11-25T08:33:06.925259+010020283713Unknown Traffic192.168.2.649718172.67.204.237443TCP
2024-11-25T08:33:09.961854+010020283713Unknown Traffic192.168.2.64972018.213.123.165443TCP
2024-11-25T08:33:19.458372+010020283713Unknown Traffic192.168.2.649737172.67.204.237443TCP
2024-11-25T08:33:21.485008+010020283713Unknown Traffic192.168.2.64974318.213.123.165443TCP
2024-11-25T08:33:31.005204+010020283713Unknown Traffic192.168.2.649765172.67.204.237443TCP
2024-11-25T08:33:33.113123+010020283713Unknown Traffic192.168.2.64977218.213.123.165443TCP
2024-11-25T08:33:44.023543+010020283713Unknown Traffic192.168.2.649807172.67.204.237443TCP
2024-11-25T08:33:46.140180+010020283713Unknown Traffic192.168.2.64981318.213.123.165443TCP
2024-11-25T08:33:56.612862+010020283713Unknown Traffic192.168.2.649837172.67.204.237443TCP
2024-11-25T08:33:58.724023+010020283713Unknown Traffic192.168.2.64984318.213.123.165443TCP
2024-11-25T08:34:08.367518+010020283713Unknown Traffic192.168.2.649871172.67.204.237443TCP
2024-11-25T08:34:10.838070+010020283713Unknown Traffic192.168.2.64988118.213.123.165443TCP
2024-11-25T08:34:20.987632+010020283713Unknown Traffic192.168.2.649904172.67.204.237443TCP
2024-11-25T08:34:23.097771+010020283713Unknown Traffic192.168.2.64991018.213.123.165443TCP
2024-11-25T08:34:33.352021+010020283713Unknown Traffic192.168.2.649935172.67.204.237443TCP
2024-11-25T08:34:35.888799+010020283713Unknown Traffic192.168.2.64993918.213.123.165443TCP
2024-11-25T08:34:45.817476+010020283713Unknown Traffic192.168.2.649963172.67.204.237443TCP
2024-11-25T08:34:47.912181+010020283713Unknown Traffic192.168.2.64996918.213.123.165443TCP
2024-11-25T08:34:57.503711+010020283713Unknown Traffic192.168.2.649992172.67.204.237443TCP
2024-11-25T08:34:59.589060+010020283713Unknown Traffic192.168.2.64999618.213.123.165443TCP
2024-11-25T08:35:10.225666+010020283713Unknown Traffic192.168.2.650022172.67.204.237443TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: t90RvrDNvz.exeReversingLabs: Detection: 18%
Source: Submited SampleIntegrated Neural Analysis Model: Matched 97.5% probability
Source: unknownHTTPS traffic detected: 172.67.204.237:443 -> 192.168.2.6:49718 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.213.123.165:443 -> 192.168.2.6:49720 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.204.237:443 -> 192.168.2.6:49737 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.213.123.165:443 -> 192.168.2.6:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.204.237:443 -> 192.168.2.6:49765 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.213.123.165:443 -> 192.168.2.6:49772 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.204.237:443 -> 192.168.2.6:49807 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.213.123.165:443 -> 192.168.2.6:49813 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.204.237:443 -> 192.168.2.6:49837 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.213.123.165:443 -> 192.168.2.6:49843 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.204.237:443 -> 192.168.2.6:49871 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.213.123.165:443 -> 192.168.2.6:49881 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.204.237:443 -> 192.168.2.6:49904 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.213.123.165:443 -> 192.168.2.6:49910 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.204.237:443 -> 192.168.2.6:49935 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.213.123.165:443 -> 192.168.2.6:49939 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.204.237:443 -> 192.168.2.6:49963 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.213.123.165:443 -> 192.168.2.6:49969 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.204.237:443 -> 192.168.2.6:49992 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.213.123.165:443 -> 192.168.2.6:49996 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.204.237:443 -> 192.168.2.6:50022 version: TLS 1.2
Source: t90RvrDNvz.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT
Source: global trafficHTTP traffic detected: GET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1Connection: Keep-AliveHost: eth0.cdn-serveri2004-ns.shop
Source: global trafficHTTP traffic detected: GET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1Connection: Keep-AliveHost: httpbin.org
Source: global trafficHTTP traffic detected: GET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1Connection: Keep-AliveHost: eth0.cdn-serveri2004-ns.shop
Source: global trafficHTTP traffic detected: GET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1Connection: Keep-AliveHost: httpbin.org
Source: global trafficHTTP traffic detected: GET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1Connection: Keep-AliveHost: eth0.cdn-serveri2004-ns.shop
Source: global trafficHTTP traffic detected: GET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1Connection: Keep-AliveHost: httpbin.org
Source: global trafficHTTP traffic detected: GET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1Connection: Keep-AliveHost: eth0.cdn-serveri2004-ns.shop
Source: global trafficHTTP traffic detected: GET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1Connection: Keep-AliveHost: httpbin.org
Source: global trafficHTTP traffic detected: GET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1Connection: Keep-AliveHost: eth0.cdn-serveri2004-ns.shop
Source: global trafficHTTP traffic detected: GET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1Connection: Keep-AliveHost: httpbin.org
Source: global trafficHTTP traffic detected: GET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1Connection: Keep-AliveHost: eth0.cdn-serveri2004-ns.shop
Source: global trafficHTTP traffic detected: GET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1Connection: Keep-AliveHost: httpbin.org
Source: global trafficHTTP traffic detected: GET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1Connection: Keep-AliveHost: eth0.cdn-serveri2004-ns.shop
Source: global trafficHTTP traffic detected: GET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1Connection: Keep-AliveHost: httpbin.org
Source: global trafficHTTP traffic detected: GET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1Connection: Keep-AliveHost: eth0.cdn-serveri2004-ns.shop
Source: global trafficHTTP traffic detected: GET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1Connection: Keep-AliveHost: httpbin.org
Source: global trafficHTTP traffic detected: GET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1Connection: Keep-AliveHost: eth0.cdn-serveri2004-ns.shop
Source: global trafficHTTP traffic detected: GET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1Connection: Keep-AliveHost: httpbin.org
Source: global trafficHTTP traffic detected: GET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1Connection: Keep-AliveHost: eth0.cdn-serveri2004-ns.shop
Source: global trafficHTTP traffic detected: GET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1Connection: Keep-AliveHost: httpbin.org
Source: Joe Sandbox ViewJA3 fingerprint: a0e9f5d64349fb13191bc781f81f42e1
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49718 -> 172.67.204.237:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49720 -> 18.213.123.165:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49765 -> 172.67.204.237:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49743 -> 18.213.123.165:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49737 -> 172.67.204.237:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49772 -> 18.213.123.165:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49837 -> 172.67.204.237:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49843 -> 18.213.123.165:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49881 -> 18.213.123.165:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49871 -> 172.67.204.237:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49910 -> 18.213.123.165:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49813 -> 18.213.123.165:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49935 -> 172.67.204.237:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49969 -> 18.213.123.165:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49807 -> 172.67.204.237:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49939 -> 18.213.123.165:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49904 -> 172.67.204.237:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:50022 -> 172.67.204.237:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49992 -> 172.67.204.237:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49963 -> 172.67.204.237:443
Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.6:49996 -> 18.213.123.165:443
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficHTTP traffic detected: GET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1Connection: Keep-AliveHost: eth0.cdn-serveri2004-ns.shop
Source: global trafficHTTP traffic detected: GET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1Connection: Keep-AliveHost: httpbin.org
Source: global trafficHTTP traffic detected: GET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1Connection: Keep-AliveHost: eth0.cdn-serveri2004-ns.shop
Source: global trafficHTTP traffic detected: GET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1Connection: Keep-AliveHost: httpbin.org
Source: global trafficHTTP traffic detected: GET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1Connection: Keep-AliveHost: eth0.cdn-serveri2004-ns.shop
Source: global trafficHTTP traffic detected: GET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1Connection: Keep-AliveHost: httpbin.org
Source: global trafficHTTP traffic detected: GET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1Connection: Keep-AliveHost: eth0.cdn-serveri2004-ns.shop
Source: global trafficHTTP traffic detected: GET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1Connection: Keep-AliveHost: httpbin.org
Source: global trafficHTTP traffic detected: GET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1Connection: Keep-AliveHost: eth0.cdn-serveri2004-ns.shop
Source: global trafficHTTP traffic detected: GET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1Connection: Keep-AliveHost: httpbin.org
Source: global trafficHTTP traffic detected: GET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1Connection: Keep-AliveHost: eth0.cdn-serveri2004-ns.shop
Source: global trafficHTTP traffic detected: GET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1Connection: Keep-AliveHost: httpbin.org
Source: global trafficHTTP traffic detected: GET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1Connection: Keep-AliveHost: eth0.cdn-serveri2004-ns.shop
Source: global trafficHTTP traffic detected: GET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1Connection: Keep-AliveHost: httpbin.org
Source: global trafficHTTP traffic detected: GET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1Connection: Keep-AliveHost: eth0.cdn-serveri2004-ns.shop
Source: global trafficHTTP traffic detected: GET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1Connection: Keep-AliveHost: httpbin.org
Source: global trafficHTTP traffic detected: GET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1Connection: Keep-AliveHost: eth0.cdn-serveri2004-ns.shop
Source: global trafficHTTP traffic detected: GET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1Connection: Keep-AliveHost: httpbin.org
Source: global trafficHTTP traffic detected: GET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1Connection: Keep-AliveHost: eth0.cdn-serveri2004-ns.shop
Source: global trafficHTTP traffic detected: GET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1Connection: Keep-AliveHost: httpbin.org
Source: global trafficDNS traffic detected: DNS query: eth0.cdn-serveri2004-ns.shop
Source: global trafficDNS traffic detected: DNS query: httpbin.org
Source: t90RvrDNvz.exeString found in binary or memory: http://cert.ssl.com/SSLcom-SubCA-EV-codeSigning-ECC-384-R2.cer0
Source: t90RvrDNvz.exeString found in binary or memory: http://crls.ssl.com/SSLcom-SubCA-EV-codeSigning-ECC-384-R2.crl0
Source: t90RvrDNvz.exeString found in binary or memory: http://crls.ssl.com/ssl.com-EVecc-RootCA.crl0
Source: t90RvrDNvz.exeString found in binary or memory: http://ocsps.ssl.com0
Source: t90RvrDNvz.exeString found in binary or memory: http://ocsps.ssl.com0P
Source: t90RvrDNvz.exeString found in binary or memory: http://www.burnaware.com
Source: t90RvrDNvz.exeString found in binary or memory: http://www.ssl.com/repository/SSLcom-RootCA-EV-ECC-384-R1.crt0
Source: t90RvrDNvz.exe, 00000000.00000003.2608626914.0000000000EF3000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2726605271.0000000000EF3000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2850913461.0000000000EF3000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3217990402.0000000000EF3000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2237692616.0000000000EA3000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2976278142.0000000000EB2000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3100967300.00000000038A3000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2976278142.0000000000EF3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eth0.cdn-serveri2004-ns.shop/
Source: t90RvrDNvz.exe, 00000000.00000003.2976278142.0000000000EF3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eth0.cdn-serveri2004-ns.shop//
Source: t90RvrDNvz.exe, 00000000.00000003.2608626914.0000000000EF3000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2352772201.0000000000EF3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eth0.cdn-serveri2004-ns.shop/011t
Source: t90RvrDNvz.exe, 00000000.00000003.3101051028.0000000000EF3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eth0.cdn-serveri2004-ns.shop/3
Source: t90RvrDNvz.exe, 00000000.00000002.3392308126.0000000000EF3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eth0.cdn-serveri2004-ns.shop/Jt
Source: t90RvrDNvz.exe, 00000000.00000002.3392308126.0000000000EF3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eth0.cdn-serveri2004-ns.shop/O
Source: t90RvrDNvz.exe, 00000000.00000002.3394956509.0000000003874000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000002.3392308126.0000000000E46000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.php
Source: t90RvrDNvz.exe, 00000000.00000002.3392308126.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2976278142.0000000000ECA000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2608626914.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3101051028.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2850913461.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3217990402.0000000000EC8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.php)
Source: t90RvrDNvz.exe, 00000000.00000002.3394956509.0000000003874000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.php3
Source: t90RvrDNvz.exe, 00000000.00000002.3392308126.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2976278142.0000000000ECA000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3101051028.0000000000EC8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.php7aU
Source: t90RvrDNvz.exe, 00000000.00000003.3101051028.0000000000EC8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.phpCc
Source: t90RvrDNvz.exe, 00000000.00000002.3392308126.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3217990402.0000000000EC8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.phpO
Source: t90RvrDNvz.exe, 00000000.00000002.3394956509.0000000003874000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.phpT
Source: t90RvrDNvz.exe, 00000000.00000003.2608626914.0000000000EC8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.phpWc
Source: t90RvrDNvz.exe, 00000000.00000002.3392308126.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2976278142.0000000000ECA000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2608626914.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3101051028.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2850913461.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3217990402.0000000000EC8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.phpkc
Source: t90RvrDNvz.exe, 00000000.00000003.3217883623.0000000003891000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000002.3394956509.0000000003891000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eth0.cdn-serveri2004-ns.shop:443/c2dm/WSVUCGSKHE7PDXHDBW27/api.php
Source: t90RvrDNvz.exe, 00000000.00000003.3217990402.0000000000EE8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2850913461.0000000000EE8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2608626914.0000000000EE7000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2976278142.0000000000EE8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2726605271.0000000000EE8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000002.3392308126.0000000000EE8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000002.3394956509.0000000003891000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3101051028.0000000000EE8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eth0.cdn-serveri2004-ns.shop:443/c2dm/WSVUCGSKHE7PDXHDBW27/api.phpRS
Source: t90RvrDNvz.exe, 00000000.00000003.2850913461.0000000000EAC000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000002.3392308126.0000000000E0C000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2608626914.0000000000EAB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://httpbin.org/
Source: t90RvrDNvz.exe, 00000000.00000003.2608626914.0000000000EE7000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2726605271.0000000000EE8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://httpbin.org/drip?code=200&del
Source: t90RvrDNvz.exe, 00000000.00000003.2352751790.000000000388C000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000002.3394956509.00000000038B1000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000002.3392308126.0000000000EE8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3101382322.0000000003898000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3217990402.0000000000E9E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://httpbin.org/drip?code=200&delay=2&duration=2&numbytes=10
Source: t90RvrDNvz.exe, 00000000.00000002.3392308126.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2976278142.0000000000ECA000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2608626914.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3101051028.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2352751790.000000000388C000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3217990402.0000000000E9E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://httpbin.org/drip?code=200&delay=2&duration=2&numbytes=10LocationETagAuthentication-InfoAgeAc
Source: t90RvrDNvz.exe, 00000000.00000002.3394956509.0000000003874000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://httpbin.org/drip?code=200&delay=2&duration=2&numbytes=10f
Source: t90RvrDNvz.exe, 00000000.00000002.3392308126.0000000000E0C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://httpbin.org/drip?code=200&delay=2&duration=2&numbytes=10i.php
Source: t90RvrDNvz.exe, 00000000.00000002.3394956509.0000000003874000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://httpbin.org/drip?code=200&delay=2&duration=2&numbytes=10i.phpM
Source: t90RvrDNvz.exe, 00000000.00000003.2976278142.0000000000EAC000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2608626914.0000000000EAB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://httpbin.org/p
Source: t90RvrDNvz.exe, 00000000.00000002.3392308126.0000000000E91000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3217883623.0000000003891000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://httpbin.org:443/drip?code=200&delay=2&duration=2&numbytes=10
Source: t90RvrDNvz.exe, 00000000.00000003.3217883623.0000000003891000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://httpbin.org:443/drip?code=200&delay=2&duration=2&numbytes=10gv
Source: t90RvrDNvz.exe, 00000000.00000003.2237692616.0000000000ED9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://httpbin.org:443/drip?code=200&delay=2&duration=2&numbytes=10jD
Source: t90RvrDNvz.exeString found in binary or memory: https://www.ssl.com/repository0
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49843
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49963
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49881
Source: unknownNetwork traffic detected: HTTP traffic on port 49871 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49935 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49939 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 50022 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49963 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49939
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
Source: unknownNetwork traffic detected: HTTP traffic on port 49992 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49904 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49837
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 49881 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49935
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49813
Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49910
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49996
Source: unknownNetwork traffic detected: HTTP traffic on port 49996 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49837 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49969 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
Source: unknownNetwork traffic detected: HTTP traffic on port 49843 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49871
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49992
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50022
Source: unknownNetwork traffic detected: HTTP traffic on port 49910 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49807
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49904
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49969
Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: unknownHTTPS traffic detected: 172.67.204.237:443 -> 192.168.2.6:49718 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.213.123.165:443 -> 192.168.2.6:49720 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.204.237:443 -> 192.168.2.6:49737 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.213.123.165:443 -> 192.168.2.6:49743 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.204.237:443 -> 192.168.2.6:49765 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.213.123.165:443 -> 192.168.2.6:49772 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.204.237:443 -> 192.168.2.6:49807 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.213.123.165:443 -> 192.168.2.6:49813 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.204.237:443 -> 192.168.2.6:49837 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.213.123.165:443 -> 192.168.2.6:49843 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.204.237:443 -> 192.168.2.6:49871 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.213.123.165:443 -> 192.168.2.6:49881 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.204.237:443 -> 192.168.2.6:49904 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.213.123.165:443 -> 192.168.2.6:49910 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.204.237:443 -> 192.168.2.6:49935 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.213.123.165:443 -> 192.168.2.6:49939 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.204.237:443 -> 192.168.2.6:49963 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.213.123.165:443 -> 192.168.2.6:49969 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.204.237:443 -> 192.168.2.6:49992 version: TLS 1.2
Source: unknownHTTPS traffic detected: 18.213.123.165:443 -> 192.168.2.6:49996 version: TLS 1.2
Source: unknownHTTPS traffic detected: 172.67.204.237:443 -> 192.168.2.6:50022 version: TLS 1.2
Source: C:\Users\user\Desktop\t90RvrDNvz.exeCode function: 0_2_0087C7BB NtQuerySystemInformation,0_2_0087C7BB
Source: C:\Users\user\Desktop\t90RvrDNvz.exeCode function: 0_2_0087C3EB NtDelayExecution,0_2_0087C3EB
Source: t90RvrDNvz.exeStatic PE information: invalid certificate
Source: t90RvrDNvz.exeStatic PE information: Number of sections : 11 > 10
Source: t90RvrDNvz.exe, 00000000.00000002.3395384110.0000000004CBE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamevmdbCOM.DLLF vs t90RvrDNvz.exe
Source: t90RvrDNvz.exe, 00000000.00000000.2144326512.0000000000B5D000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenamevmdbCOM.DLLF vs t90RvrDNvz.exe
Source: t90RvrDNvz.exeBinary or memory string: OriginalFilenamevmdbCOM.DLLF vs t90RvrDNvz.exe
Source: classification engineClassification label: mal56.evad.winEXE@1/0@3/2
Source: t90RvrDNvz.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\t90RvrDNvz.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: t90RvrDNvz.exeReversingLabs: Detection: 18%
Source: t90RvrDNvz.exeString found in binary or memory: Africa/Addis_Ababa
Source: t90RvrDNvz.exeString found in binary or memory: Try to re-install the software.
Source: C:\Users\user\Desktop\t90RvrDNvz.exeFile read: C:\Users\user\Desktop\t90RvrDNvz.exeJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: iconcodecservice.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: wtsapi32.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: winsta.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: webio.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: winnsi.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: fwpuclnt.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: schannel.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: mskeyprotect.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: ncryptsslp.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: dpapi.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: t90RvrDNvz.exeStatic PE information: Virtual size of .text is bigger than: 0x100000
Source: t90RvrDNvz.exeStatic file information: File size 26869672 > 1048576
Source: t90RvrDNvz.exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x53b800
Source: t90RvrDNvz.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT
Source: t90RvrDNvz.exeStatic PE information: section name: .didata
Source: C:\Users\user\Desktop\t90RvrDNvz.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exe TID: 7040Thread sleep time: -270000s >= -30000sJump to behavior
Source: t90RvrDNvz.exeBinary or memory string: 1998-2023 VMware, Inc.@
Source: t90RvrDNvz.exe, 00000000.00000003.2237692616.0000000000ED9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW7sP
Source: t90RvrDNvz.exeBinary or memory string: CompanyNameVMware, Inc.F
Source: t90RvrDNvz.exe, 00000000.00000003.2237692616.0000000000ED9000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
Source: t90RvrDNvz.exeBinary or memory string: ProductNameVMware WorkstationP
Source: t90RvrDNvz.exe, 00000000.00000002.3392308126.0000000000E91000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW`
Source: C:\Users\user\Desktop\t90RvrDNvz.exeProcess information queried: ProcessInformationJump to behavior

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Users\user\Desktop\t90RvrDNvz.exeNtDelayExecution: Indirect: 0x87C429Jump to behavior
Source: C:\Users\user\Desktop\t90RvrDNvz.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
Command and Scripting Interpreter
1
DLL Side-Loading
1
Abuse Elevation Control Mechanism
1
Virtualization/Sandbox Evasion
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Abuse Elevation Control Mechanism
LSASS Memory1
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
DLL Side-Loading
Security Account Manager1
Process Discovery
SMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin HookBinary PaddingNTDS2
System Information Discovery
Distributed Component Object ModelInput Capture1
Ingress Tool Transfer
Traffic DuplicationData Destruction
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
t90RvrDNvz.exe18%ReversingLabsWin64.Trojan.Giant
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
https://eth0.cdn-serveri2004-ns.shop/011t0%Avira URL Cloudsafe
https://httpbin.org/drip?code=200&del0%Avira URL Cloudsafe
https://eth0.cdn-serveri2004-ns.shop/O0%Avira URL Cloudsafe
https://eth0.cdn-serveri2004-ns.shop:443/c2dm/WSVUCGSKHE7PDXHDBW27/api.php0%Avira URL Cloudsafe
https://eth0.cdn-serveri2004-ns.shop/Jt0%Avira URL Cloudsafe
https://httpbin.org/p0%Avira URL Cloudsafe
https://httpbin.org:443/drip?code=200&delay=2&duration=2&numbytes=10gv0%Avira URL Cloudsafe
https://httpbin.org/drip?code=200&delay=2&duration=2&numbytes=10i.phpM0%Avira URL Cloudsafe
https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.phpWc0%Avira URL Cloudsafe
https://eth0.cdn-serveri2004-ns.shop/0%Avira URL Cloudsafe
https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.php0%Avira URL Cloudsafe
https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.php30%Avira URL Cloudsafe
https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.phpCc0%Avira URL Cloudsafe
https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.php)0%Avira URL Cloudsafe
https://httpbin.org:443/drip?code=200&delay=2&duration=2&numbytes=100%Avira URL Cloudsafe
https://httpbin.org/drip?code=200&delay=2&duration=2&numbytes=100%Avira URL Cloudsafe
https://eth0.cdn-serveri2004-ns.shop:443/c2dm/WSVUCGSKHE7PDXHDBW27/api.phpRS0%Avira URL Cloudsafe
http://www.burnaware.com0%Avira URL Cloudsafe
https://httpbin.org:443/drip?code=200&delay=2&duration=2&numbytes=10jD0%Avira URL Cloudsafe
https://httpbin.org/drip?code=200&delay=2&duration=2&numbytes=10i.php0%Avira URL Cloudsafe
https://eth0.cdn-serveri2004-ns.shop//0%Avira URL Cloudsafe
https://eth0.cdn-serveri2004-ns.shop/30%Avira URL Cloudsafe
https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.phpT0%Avira URL Cloudsafe
https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.php7aU0%Avira URL Cloudsafe
https://httpbin.org/drip?code=200&delay=2&duration=2&numbytes=10f0%Avira URL Cloudsafe
http://ocsps.ssl.com0P0%Avira URL Cloudsafe
https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.phpkc0%Avira URL Cloudsafe
https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.phpO0%Avira URL Cloudsafe
https://httpbin.org/drip?code=200&delay=2&duration=2&numbytes=10LocationETagAuthentication-InfoAgeAc0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
eth0.cdn-serveri2004-ns.shop
172.67.204.237
truefalse
    unknown
    ax-0001.ax-msedge.net
    150.171.28.10
    truefalse
      high
      httpbin.org
      18.213.123.165
      truefalse
        unknown
        NameMaliciousAntivirus DetectionReputation
        https://httpbin.org/drip?code=200&delay=2&duration=2&numbytes=10false
        • Avira URL Cloud: safe
        unknown
        https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.phpfalse
        • Avira URL Cloud: safe
        unknown
        NameSourceMaliciousAntivirus DetectionReputation
        https://httpbin.org/drip?code=200&delay=2&duration=2&numbytes=10i.phpMt90RvrDNvz.exe, 00000000.00000002.3394956509.0000000003874000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://eth0.cdn-serveri2004-ns.shop/t90RvrDNvz.exe, 00000000.00000003.2608626914.0000000000EF3000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2726605271.0000000000EF3000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2850913461.0000000000EF3000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3217990402.0000000000EF3000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2237692616.0000000000EA3000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2976278142.0000000000EB2000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3100967300.00000000038A3000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2976278142.0000000000EF3000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://httpbin.org/pt90RvrDNvz.exe, 00000000.00000003.2976278142.0000000000EAC000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2608626914.0000000000EAB000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://httpbin.org:443/drip?code=200&delay=2&duration=2&numbytes=10gvt90RvrDNvz.exe, 00000000.00000003.3217883623.0000000003891000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://eth0.cdn-serveri2004-ns.shop/Ot90RvrDNvz.exe, 00000000.00000002.3392308126.0000000000EF3000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://httpbin.org/drip?code=200&delt90RvrDNvz.exe, 00000000.00000003.2608626914.0000000000EE7000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2726605271.0000000000EE8000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        http://cert.ssl.com/SSLcom-SubCA-EV-codeSigning-ECC-384-R2.cer0t90RvrDNvz.exefalse
          high
          https://eth0.cdn-serveri2004-ns.shop/011tt90RvrDNvz.exe, 00000000.00000003.2608626914.0000000000EF3000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2352772201.0000000000EF3000.00000004.00000020.00020000.00000000.sdmpfalse
          • Avira URL Cloud: safe
          unknown
          https://eth0.cdn-serveri2004-ns.shop/Jtt90RvrDNvz.exe, 00000000.00000002.3392308126.0000000000EF3000.00000004.00000020.00020000.00000000.sdmpfalse
          • Avira URL Cloud: safe
          unknown
          https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.phpWct90RvrDNvz.exe, 00000000.00000003.2608626914.0000000000EC8000.00000004.00000020.00020000.00000000.sdmpfalse
          • Avira URL Cloud: safe
          unknown
          https://httpbin.org/t90RvrDNvz.exe, 00000000.00000003.2850913461.0000000000EAC000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000002.3392308126.0000000000E0C000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2608626914.0000000000EAB000.00000004.00000020.00020000.00000000.sdmpfalse
            high
            http://ocsps.ssl.com0t90RvrDNvz.exefalse
              high
              https://eth0.cdn-serveri2004-ns.shop:443/c2dm/WSVUCGSKHE7PDXHDBW27/api.phpt90RvrDNvz.exe, 00000000.00000003.3217883623.0000000003891000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000002.3394956509.0000000003891000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://crls.ssl.com/SSLcom-SubCA-EV-codeSigning-ECC-384-R2.crl0t90RvrDNvz.exefalse
                high
                https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.php3t90RvrDNvz.exe, 00000000.00000002.3394956509.0000000003874000.00000004.00000020.00020000.00000000.sdmpfalse
                • Avira URL Cloud: safe
                unknown
                https://httpbin.org:443/drip?code=200&delay=2&duration=2&numbytes=10t90RvrDNvz.exe, 00000000.00000002.3392308126.0000000000E91000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3217883623.0000000003891000.00000004.00000020.00020000.00000000.sdmpfalse
                • Avira URL Cloud: safe
                unknown
                https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.php)t90RvrDNvz.exe, 00000000.00000002.3392308126.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2976278142.0000000000ECA000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2608626914.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3101051028.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2850913461.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3217990402.0000000000EC8000.00000004.00000020.00020000.00000000.sdmpfalse
                • Avira URL Cloud: safe
                unknown
                https://eth0.cdn-serveri2004-ns.shop:443/c2dm/WSVUCGSKHE7PDXHDBW27/api.phpRSt90RvrDNvz.exe, 00000000.00000003.3217990402.0000000000EE8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2850913461.0000000000EE8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2608626914.0000000000EE7000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2976278142.0000000000EE8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2726605271.0000000000EE8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000002.3392308126.0000000000EE8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000002.3394956509.0000000003891000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3101051028.0000000000EE8000.00000004.00000020.00020000.00000000.sdmpfalse
                • Avira URL Cloud: safe
                unknown
                http://www.ssl.com/repository/SSLcom-RootCA-EV-ECC-384-R1.crt0t90RvrDNvz.exefalse
                  high
                  http://www.burnaware.comt90RvrDNvz.exefalse
                  • Avira URL Cloud: safe
                  unknown
                  https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.phpCct90RvrDNvz.exe, 00000000.00000003.3101051028.0000000000EC8000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: safe
                  unknown
                  https://httpbin.org:443/drip?code=200&delay=2&duration=2&numbytes=10jDt90RvrDNvz.exe, 00000000.00000003.2237692616.0000000000ED9000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: safe
                  unknown
                  https://httpbin.org/drip?code=200&delay=2&duration=2&numbytes=10i.phpt90RvrDNvz.exe, 00000000.00000002.3392308126.0000000000E0C000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: safe
                  unknown
                  https://eth0.cdn-serveri2004-ns.shop//t90RvrDNvz.exe, 00000000.00000003.2976278142.0000000000EF3000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: safe
                  unknown
                  https://www.ssl.com/repository0t90RvrDNvz.exefalse
                    high
                    https://eth0.cdn-serveri2004-ns.shop/3t90RvrDNvz.exe, 00000000.00000003.3101051028.0000000000EF3000.00000004.00000020.00020000.00000000.sdmpfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.php7aUt90RvrDNvz.exe, 00000000.00000002.3392308126.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2976278142.0000000000ECA000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3101051028.0000000000EC8000.00000004.00000020.00020000.00000000.sdmpfalse
                    • Avira URL Cloud: safe
                    unknown
                    http://crls.ssl.com/ssl.com-EVecc-RootCA.crl0t90RvrDNvz.exefalse
                      high
                      https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.phpOt90RvrDNvz.exe, 00000000.00000002.3392308126.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3217990402.0000000000EC8000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.phpTt90RvrDNvz.exe, 00000000.00000002.3394956509.0000000003874000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://httpbin.org/drip?code=200&delay=2&duration=2&numbytes=10LocationETagAuthentication-InfoAgeAct90RvrDNvz.exe, 00000000.00000002.3392308126.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2976278142.0000000000ECA000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2608626914.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3101051028.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2352751790.000000000388C000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3217990402.0000000000E9E000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://httpbin.org/drip?code=200&delay=2&duration=2&numbytes=10ft90RvrDNvz.exe, 00000000.00000002.3394956509.0000000003874000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://eth0.cdn-serveri2004-ns.shop/c2dm/WSVUCGSKHE7PDXHDBW27/api.phpkct90RvrDNvz.exe, 00000000.00000002.3392308126.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2976278142.0000000000ECA000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2608626914.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3101051028.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.2850913461.0000000000EC8000.00000004.00000020.00020000.00000000.sdmp, t90RvrDNvz.exe, 00000000.00000003.3217990402.0000000000EC8000.00000004.00000020.00020000.00000000.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://ocsps.ssl.com0Pt90RvrDNvz.exefalse
                      • Avira URL Cloud: safe
                      unknown
                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs
                      IPDomainCountryFlagASNASN NameMalicious
                      18.213.123.165
                      httpbin.orgUnited States
                      14618AMAZON-AESUSfalse
                      172.67.204.237
                      eth0.cdn-serveri2004-ns.shopUnited States
                      13335CLOUDFLARENETUSfalse
                      Joe Sandbox version:41.0.0 Charoite
                      Analysis ID:1562121
                      Start date and time:2024-11-25 08:32:10 +01:00
                      Joe Sandbox product:CloudBasic
                      Overall analysis duration:0h 5m 27s
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Cookbook file name:default.jbs
                      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                      Number of analysed new started processes analysed:16
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • HCA enabled
                      • EGA enabled
                      • AMSI enabled
                      Analysis Mode:default
                      Analysis stop reason:Timeout
                      Sample name:t90RvrDNvz.exe
                      renamed because original name is a hash value
                      Original Sample Name:f660778402a3bb138486c84706d69a00ee03818437d6dac0fed4ea276561e84a.exe
                      Detection:MAL
                      Classification:mal56.evad.winEXE@1/0@3/2
                      EGA Information:
                      • Successful, ratio: 100%
                      HCA Information:
                      • Successful, ratio: 100%
                      • Number of executed functions: 5
                      • Number of non-executed functions: 0
                      Cookbook Comments:
                      • Found application associated with file extension: .exe
                      • Exclude process from analysis (whitelisted): dllhost.exe, BackgroundTransferHost.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe, svchost.exe
                      • Excluded IPs from analysis (whitelisted): 23.218.208.109
                      • Excluded domains from analysis (whitelisted): www.bing.com, client.wns.windows.com, fs.microsoft.com, otelrules.azureedge.net, slscr.update.microsoft.com, tile-service.weather.microsoft.com, tse1.mm.bing.net, g.bing.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, arc.msn.com, fe3cr.delivery.mp.microsoft.com, e16604.g.akamaiedge.net, prod.fs.microsoft.com.akadns.net
                      • Report size getting too big, too many NtOpenKeyEx calls found.
                      • Report size getting too big, too many NtQueryValueKey calls found.
                      • VT rate limit hit for: t90RvrDNvz.exe
                      TimeTypeDescription
                      02:33:13API Interceptor11x Sleep call for process: t90RvrDNvz.exe modified
                      No context
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      httpbin.orgVM2ICvV5qQ.pdfGet hashmaliciousUnknownBrowse
                      • 34.228.248.173
                      SecuriteInfo.com.Win64.Malware-gen.27241.18801.exeGet hashmaliciousUnknownBrowse
                      • 34.236.15.216
                      SecuriteInfo.com.Win64.Malware-gen.27241.18801.exeGet hashmaliciousUnknownBrowse
                      • 107.22.40.220
                      ActSet.ps1Get hashmaliciousFredy StealerBrowse
                      • 54.84.32.120
                      ActSet.ps1Get hashmaliciousFredy StealerBrowse
                      • 54.84.32.120
                      IDMan.exeGet hashmaliciousFredy StealerBrowse
                      • 3.224.101.31
                      IDMan.exeGet hashmaliciousFredy StealerBrowse
                      • 52.86.188.217
                      Setup_IDM.exeGet hashmaliciousFredy StealerBrowse
                      • 34.199.14.71
                      Setup_IDM.exeGet hashmaliciousFredy StealerBrowse
                      • 34.199.14.71
                      file.exeGet hashmaliciousLummaCBrowse
                      • 18.206.19.26
                      ax-0001.ax-msedge.netasegurar.vbsGet hashmaliciousAsyncRAT, DcRatBrowse
                      • 150.171.28.10
                      2Wr5r2e9vo.msiGet hashmaliciousUnknownBrowse
                      • 150.171.28.10
                      RFQ AE 3003910999.jarGet hashmaliciousCaesium Obfuscator, STRRATBrowse
                      • 150.171.27.10
                      file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                      • 150.171.27.10
                      file.exeGet hashmaliciousStealcBrowse
                      • 150.171.27.10
                      file.exeGet hashmaliciousUnknownBrowse
                      • 150.171.27.10
                      file.exeGet hashmaliciousStealcBrowse
                      • 150.171.27.10
                      file.exeGet hashmaliciousStealcBrowse
                      • 150.171.28.10
                      lw2HMxuVuf.exeGet hashmaliciousUnknownBrowse
                      • 150.171.27.10
                      17324340651fd0721b4a9b07278d0f63e6333ccd4883a9dc52eb27994b32b0d64dfb919b72906.dat-decoded.exeGet hashmaliciousAsyncRAT, PureLog StealerBrowse
                      • 150.171.28.10
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      AMAZON-AESUSfile (1).txt.batGet hashmaliciousUnknownBrowse
                      • 34.193.227.236
                      FGQ-667893.pdfGet hashmaliciousUnknownBrowse
                      • 54.227.187.23
                      apep.mpsl.elfGet hashmaliciousMiraiBrowse
                      • 54.128.146.146
                      apep.arm6.elfGet hashmaliciousMiraiBrowse
                      • 34.196.147.238
                      https://og.oomaal.in/Get hashmaliciousUnknownBrowse
                      • 50.19.252.172
                      arm7.nn.elfGet hashmaliciousMirai, OkiruBrowse
                      • 44.206.94.170
                      mipsel.nn.elfGet hashmaliciousMirai, OkiruBrowse
                      • 34.233.89.80
                      sparc.nn.elfGet hashmaliciousMirai, OkiruBrowse
                      • 18.206.13.133
                      arm.nn.elfGet hashmaliciousMirai, OkiruBrowse
                      • 54.164.156.159
                      x86_64.nn.elfGet hashmaliciousMirai, OkiruBrowse
                      • 54.23.34.251
                      CLOUDFLARENETUSsegura.vbsGet hashmaliciousRemcosBrowse
                      • 172.67.187.200
                      asegurar.vbsGet hashmaliciousAsyncRAT, DcRatBrowse
                      • 104.21.84.67
                      file.exeGet hashmaliciousAmadey, Stealc, VidarBrowse
                      • 172.64.41.3
                      file.exeGet hashmaliciousLummaC StealerBrowse
                      • 172.67.155.47
                      2Brb1DnRS6.wsfGet hashmaliciousUnknownBrowse
                      • 172.67.204.2
                      pm4ozz83c4.vbsGet hashmaliciousUnknownBrowse
                      • 172.67.204.2
                      Cargo Invoice_pdf.vbsGet hashmaliciousRemcos, GuLoaderBrowse
                      • 172.67.191.199
                      NEW P.O.exeGet hashmaliciousMassLogger RAT, PureLog StealerBrowse
                      • 172.67.177.134
                      Synliggre.vbsGet hashmaliciousRemcos, GuLoaderBrowse
                      • 172.67.212.23
                      Salary_Increase_Letter_Nov'24.vbsGet hashmaliciousUnknownBrowse
                      • 172.67.191.199
                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                      a0e9f5d64349fb13191bc781f81f42e1docx008.docx.docGet hashmaliciousUnknownBrowse
                      • 18.213.123.165
                      • 172.67.204.237
                      docx002.docx.docGet hashmaliciousUnknownBrowse
                      • 18.213.123.165
                      • 172.67.204.237
                      docx009.docx.docGet hashmaliciousUnknownBrowse
                      • 18.213.123.165
                      • 172.67.204.237
                      docx007.docx.docGet hashmaliciousUnknownBrowse
                      • 18.213.123.165
                      • 172.67.204.237
                      file.exeGet hashmaliciousLummaC StealerBrowse
                      • 18.213.123.165
                      • 172.67.204.237
                      P0-4856383648383364838364836483.xlsGet hashmaliciousUnknownBrowse
                      • 18.213.123.165
                      • 172.67.204.237
                      file.exeGet hashmaliciousLummaC StealerBrowse
                      • 18.213.123.165
                      • 172.67.204.237
                      file.exeGet hashmaliciousUnknownBrowse
                      • 18.213.123.165
                      • 172.67.204.237
                      file.exeGet hashmaliciousLummaC StealerBrowse
                      • 18.213.123.165
                      • 172.67.204.237
                      file.exeGet hashmaliciousAmadey, LummaC Stealer, Stealc, VidarBrowse
                      • 18.213.123.165
                      • 172.67.204.237
                      No context
                      No created / dropped files found
                      File type:PE32+ executable (GUI) x86-64, for MS Windows
                      Entropy (8bit):7.716970124470014
                      TrID:
                      • Win64 Executable GUI (202006/5) 92.64%
                      • Win64 Executable (generic) (12005/4) 5.51%
                      • Generic Win/DOS Executable (2004/3) 0.92%
                      • DOS Executable Generic (2002/1) 0.92%
                      • VXD Driver (31/22) 0.01%
                      File name:t90RvrDNvz.exe
                      File size:26'869'672 bytes
                      MD5:05ce896e3a0a78a9bf1f12a51d83d215
                      SHA1:f7e32c1dc592e3c185fece729ebcc0266e86e0cc
                      SHA256:f660778402a3bb138486c84706d69a00ee03818437d6dac0fed4ea276561e84a
                      SHA512:3b2190ab1517baab830836aaab84ad30e90017e36293167fbc9d3739793afa7ea2a3a1c2e93f2305a8bc2d60358f5be86eeff8d6ee5f4634a52d1efc22717c33
                      SSDEEP:786432:ubi6R+4Tf4lAt2BpdjzaDJws42F2Tt1s/QM:upRpj4lG2BWDJws5F2h1dM
                      TLSH:8247016F72A8916DC12DC1BBC4A78F50E533B0796B36C5FB52A202650F16AC85E3F760
                      File Content Preview:MZP.....................@...............................................!..L.!..This program must be run under Win64..$7.......................................................................................................................................
                      Icon Hash:74509878e0f8b0f0
                      Entrypoint:0x92ae50
                      Entrypoint Section:.text
                      Digitally signed:true
                      Imagebase:0x400000
                      Subsystem:windows gui
                      Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
                      DLL Characteristics:DYNAMIC_BASE, NX_COMPAT
                      Time Stamp:0x66FBCD2B [Tue Oct 1 10:21:31 2024 UTC]
                      TLS Callbacks:
                      CLR (.Net) Version:
                      OS Version Major:5
                      OS Version Minor:2
                      File Version Major:5
                      File Version Minor:2
                      Subsystem Version Major:5
                      Subsystem Version Minor:2
                      Import Hash:e48acacf71d9ad44306c0021c6e39bc1
                      Signature Valid:false
                      Signature Issuer:CN=SSL.com EV Code Signing Intermediate CA ECC R2, O=SSL Corp, L=Houston, S=Texas, C=US
                      Signature Validation Error:A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file
                      Error Number:-2146762495
                      Not Before, Not After
                      • 18/11/2024 04:47:36 18/11/2025 04:47:36
                      Subject Chain
                      • OID.1.3.6.1.4.1.311.60.2.1.3=UA, OID.2.5.4.15=Private Organization, CN=TRADE TRUST LLC, SERIALNUMBER=37058412, O=TRADE TRUST LLC, L=Dnipro, C=UA
                      Version:3
                      Thumbprint MD5:534B9DBCF3BB2DFA2DAD06DA0709841E
                      Thumbprint SHA-1:FEA61825376A364886B5236EFCB3EDD1B23E9441
                      Thumbprint SHA-256:BD193172C9C4775190F1C906FF5B47D9FB1A342DB35AC211A1A4AC8A9B07B914
                      Serial:4C46DCF5B0C4357F05806830DBA932FD
                      Instruction
                      push ebp
                      dec eax
                      add esp, FFFFFF80h
                      dec eax
                      mov ebp, esp
                      dec eax
                      mov dword ptr [ebp+28h], 00000000h
                      dec eax
                      mov dword ptr [ebp+20h], 00000000h
                      dec eax
                      mov dword ptr [ebp+38h], 00000000h
                      dec eax
                      mov dword ptr [ebp+30h], 00000000h
                      dec eax
                      mov dword ptr [ebp+48h], 00000000h
                      dec eax
                      mov dword ptr [ebp+40h], 00000000h
                      dec eax
                      mov dword ptr [ebp+58h], 00000000h
                      dec eax
                      mov dword ptr [ebp+50h], 00000000h
                      dec eax
                      mov dword ptr [ebp+68h], 00000000h
                      dec eax
                      mov dword ptr [ebp+60h], 00000000h
                      dec eax
                      mov dword ptr [ebp+70h], 00000000h
                      dec eax
                      mov dword ptr [ebp+78h], ebp
                      nop
                      dec eax
                      lea ecx, dword ptr [0000023Ch]
                      call 00007F7C8C69F464h
                      nop
                      nop
                      dec eax
                      mov eax, dword ptr [000B100Eh]
                      dec eax
                      mov ecx, dword ptr [eax]
                      call 00007F7C8C9967A3h
                      dec eax
                      mov eax, dword ptr [000B0FFFh]
                      dec eax
                      mov ecx, dword ptr [eax]
                      mov dl, 01h
                      call 00007F7C8C9990A2h
                      dec eax
                      mov eax, dword ptr [000B0FEEh]
                      dec eax
                      mov ecx, dword ptr [eax]
                      dec eax
                      mov edx, dword ptr [FFFDFABCh]
                      dec esp
                      mov eax, dword ptr [000B113Dh]
                      call 00007F7C8C9967A5h
                      dec eax
                      lea ecx, dword ptr [ebp+70h]
                      mov edx, 00000001h
                      call 00007F7C8C68FB27h
                      dec eax
                      cmp dword ptr [ebp+70h], 00000000h
                      jne 00007F7C8CBB0F64h
                      dec eax
                      mov eax, dword ptr [00000000h]
                      NameVirtual AddressVirtual Size Is in Section
                      IMAGE_DIRECTORY_ENTRY_EXPORT0x75b0000x9a.edata
                      IMAGE_DIRECTORY_ENTRY_IMPORT0x7540000x4dac.idata
                      IMAGE_DIRECTORY_ENTRY_RESOURCE0x7e10000x7eb44.rsrc
                      IMAGE_DIRECTORY_ENTRY_EXCEPTION0x7a60000x3a548.pdata
                      IMAGE_DIRECTORY_ENTRY_SECURITY0x199f6000x9a8
                      IMAGE_DIRECTORY_ENTRY_BASERELOC0x75e0000x474f0
                      IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                      IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                      IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                      IMAGE_DIRECTORY_ENTRY_TLS0x75d0000x28.rdata
                      IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                      IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                      IMAGE_DIRECTORY_ENTRY_IAT0x7553680x1238.idata
                      IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x7590000x1244.didata
                      IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                      IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                      NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                      .text0x10000x53b7d00x53b800d281706cbc69a9664a5c169a8afcb0f5unknownunknownunknownunknownIMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                      .data0x53d0000x9f7800x9f800b6438bf6d7d03c3f60ca850e9e0f47f2False0.23962976342084638data4.356329368111319IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                      .bss0x5dd0000x1760a40x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                      .idata0x7540000x4dac0x4e00470f797341277ad9ffa11407d0ed6c01False0.25931490384615385data4.284835127185531IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                      .didata0x7590000x12440x1400354cc5439968d32091f071d4c6c8df38False0.2478515625data3.2490610880265134IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                      .edata0x75b0000x9a0x200346c31c06f477564c1fd57506a4a227fFalse0.259765625data1.9042232128311023IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                      .tls0x75c0000x2800x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                      .rdata0x75d0000x6d0x2006ef7f2860a434feb9fb0e4f4981c4c1fFalse0.193359375data1.379943032279798IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                      .reloc0x75e0000x474e80x476007ef5ed284d6cfdaf5fafb7ec578613d3False0.4766890597635727data6.477238149065975IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                      .pdata0x7a60000x3a5480x3a600a16ed171e886db87694667ed8d26a71bFalse0.49873695128479656data6.416734311414888IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                      .rsrc0x7e10000x7eb440x7ec0093f74e39358c7296565f286c0c353f7cFalse0.6715167344674556data7.674095407137192IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                      NameRVASizeTypeLanguageCountryZLIB Complexity
                      COLOR0x7e2b380x4data3.0
                      COLOR0x7e2b3c0x4data3.0
                      COLOR0x7e2b400x4data3.0
                      RT_CURSOR0x7e2b440x134dataEnglishUnited States0.43506493506493504
                      RT_CURSOR0x7e2c780x134dataEnglishUnited States0.4642857142857143
                      RT_CURSOR0x7e2dac0x134dataEnglishUnited States0.4805194805194805
                      RT_CURSOR0x7e2ee00x134dataEnglishUnited States0.38311688311688313
                      RT_CURSOR0x7e30140x134dataEnglishUnited States0.36038961038961037
                      RT_CURSOR0x7e31480x134dataEnglishUnited States0.4090909090909091
                      RT_CURSOR0x7e327c0x134Targa image data - RGB 64 x 65536 x 1 +32 "\001"EnglishUnited States0.4967532467532468
                      RT_CURSOR0x7e33b00x134Targa image data - Map 64 x 65536 x 1 +32 "\001"EnglishUnited States0.38636363636363635
                      RT_BITMAP0x7e34e40x528Device independent bitmap graphic, 20 x 16 x 32, image size 12800.048484848484848485
                      RT_BITMAP0x7e3a0c0x468Device independent bitmap graphic, 17 x 16 x 32, image size 10880.07446808510638298
                      RT_BITMAP0x7e3e740x5a8Device independent bitmap graphic, 16 x 22 x 32, image size 14080.0738950276243094
                      RT_BITMAP0x7e441c0x600Device independent bitmap graphic, 17 x 22 x 32, image size 14960.043619791666666664
                      RT_BITMAP0x7e4a1c0x4e8Device independent bitmap graphic, 19 x 16 x 32, image size 12160.05015923566878981
                      RT_BITMAP0x7e4f040x5a8Device independent bitmap graphic, 16 x 22 x 32, image size 14080.06284530386740332
                      RT_BITMAP0x7e54ac0x5a8Device independent bitmap graphic, 16 x 22 x 32, image size 14080.08287292817679558
                      RT_BITMAP0x7e5a540x428Device independent bitmap graphic, 16 x 16 x 32, image size 10240.33270676691729323
                      RT_BITMAP0x7e5e7c0x428Device independent bitmap graphic, 16 x 16 x 32, image size 10240.23966165413533835
                      RT_BITMAP0x7e62a40x468Device independent bitmap graphic, 8 x 8 x 8, image size 640.424645390070922
                      RT_BITMAP0x7e670c0x468Device independent bitmap graphic, 8 x 8 x 8, image size 640.4228723404255319
                      RT_ICON0x7e6b740x26126PNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9963255569378359
                      RT_STRING0x80cc9c0x3b8data0.3697478991596639
                      RT_STRING0x80d0540xb40data0.25972222222222224
                      RT_STRING0x80db940x8e4data0.28866432337434095
                      RT_STRING0x80e4780x414data0.36398467432950193
                      RT_STRING0x80e88c0x41cdata0.33460076045627374
                      RT_STRING0x80eca80x384data0.43444444444444447
                      RT_STRING0x80f02c0x44cdata0.40636363636363637
                      RT_STRING0x80f4780x15cdata0.5747126436781609
                      RT_STRING0x80f5d40xd0data0.6778846153846154
                      RT_STRING0x80f6a40x120data0.6041666666666666
                      RT_STRING0x80f7c40x310data0.44005102040816324
                      RT_STRING0x80fad40x3f8data0.375
                      RT_STRING0x80fecc0x34cdata0.3755924170616114
                      RT_STRING0x8102180x548data0.3143491124260355
                      RT_STRING0x8107600x204data0.28294573643410853
                      RT_STRING0x8109640x430data0.40578358208955223
                      RT_STRING0x810d940x5d4data0.3371313672922252
                      RT_STRING0x8113680x43cdata0.3404059040590406
                      RT_STRING0x8117a40x338data0.4223300970873786
                      RT_STRING0x811adc0x338data0.3883495145631068
                      RT_STRING0x811e140x430data0.4039179104477612
                      RT_STRING0x8122440x174data0.5161290322580645
                      RT_STRING0x8123b80xccdata0.6225490196078431
                      RT_STRING0x8124840x1d0data0.5344827586206896
                      RT_STRING0x8126540x3a8data0.358974358974359
                      RT_STRING0x8129fc0x344data0.39593301435406697
                      RT_STRING0x812d400x2dcdata0.38114754098360654
                      RT_STRING0x81301c0x334data0.3280487804878049
                      RT_RCDATA0x8133500xd5dPNG image data, 36 x 36, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0032154340836013
                      RT_RCDATA0x8140b00xd57PNG image data, 36 x 36, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003221083455344
                      RT_RCDATA0x814e080xcfcPNG image data, 36 x 36, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003309265944645
                      RT_RCDATA0x815b040xcd9PNG image data, 36 x 36, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0033444816053512
                      RT_RCDATA0x8167e00xd5dPNG image data, 36 x 36, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0032154340836013
                      RT_RCDATA0x8175400xd57PNG image data, 36 x 36, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003221083455344
                      RT_RCDATA0x8182980xc4ePNG image data, 36 x 36, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0034920634920634
                      RT_RCDATA0x818ee80xc4ePNG image data, 36 x 36, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0034920634920634
                      RT_RCDATA0x819b380xcb5PNG image data, 36 x 36, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0033814940055334
                      RT_RCDATA0x81a7f00xcb0PNG image data, 36 x 36, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0033866995073892
                      RT_RCDATA0x81b4a00xd56PNG image data, 36 x 36, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0032220269478618
                      RT_RCDATA0x81c1f80xd47PNG image data, 36 x 36, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0032362459546926
                      RT_RCDATA0x81cf400xdc2PNG image data, 36 x 36, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0031232254400908
                      RT_RCDATA0x81dd040xdc5PNG image data, 36 x 36, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0031205673758865
                      RT_RCDATA0x81eacc0xcf3PNG image data, 36 x 36, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003318250377074
                      RT_RCDATA0x81f7c00xcedPNG image data, 36 x 36, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0033242671501965
                      RT_RCDATA0x8204b00xda9PNG image data, 36 x 36, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0031455533314269
                      RT_RCDATA0x82125c0xda6PNG image data, 36 x 36, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0031482541499714
                      RT_RCDATA0x8220040xcf3PNG image data, 36 x 36, 8-bit/color RGBA, non-interlacedEnglishUnited States1.003318250377074
                      RT_RCDATA0x822cf80xcedPNG image data, 36 x 36, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0033242671501965
                      RT_RCDATA0x8239e80x10data1.5
                      RT_RCDATA0x8239f80x148bPNG image data, 64 x 64, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0020916524054002
                      RT_RCDATA0x824e840x111ePNG image data, 64 x 64, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0025102692834322
                      RT_RCDATA0x825fa40xd8cPNG image data, 64 x 64, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0031718569780854
                      RT_RCDATA0x826d300xc58data0.5126582278481012
                      RT_RCDATA0x8279880x2dataEnglishUnited States5.0
                      RT_RCDATA0x82798c0xa5e1Delphi compiled form 'Tfrm_About'0.9672671611915695
                      RT_RCDATA0x831f700x8e9Delphi compiled form 'Tfrm_Add'0.43095133713283645
                      RT_RCDATA0x83285c0x50dDelphi compiled form 'Tfrm_Adding'0.4300077339520495
                      RT_RCDATA0x832d6c0x3cbeDelphi compiled form 'Tfrm_DiscInfo'0.8445659163987138
                      RT_RCDATA0x836a2c0x45dDelphi compiled form 'Tfrm_Discs'0.5344673231871083
                      RT_RCDATA0x836e8c0xc96Delphi compiled form 'Tfrm_Erase'0.9130974549968963
                      RT_RCDATA0x837b240x793Delphi compiled form 'Tfrm_Init'0.853017019082001
                      RT_RCDATA0x8382b80xa4fDelphi compiled form 'Tfrm_InitFix'0.9041303524062144
                      RT_RCDATA0x838d080x2c7Delphi compiled form 'Tfrm_Input'0.5836849507735584
                      RT_RCDATA0x838fd00xc7aDelphi compiled form 'Tfrm_Insert'0.9001252348152786
                      RT_RCDATA0x839c4c0x20ba6Delphi compiled form 'Tfrm_Main'0.6749071269786803
                      RT_RCDATA0x85a7f40x829Delphi compiled form 'Tfrm_MultiProperties'0.6251795117280996
                      RT_RCDATA0x85b0200x22dfDelphi compiled form 'Tfrm_Options'0.30928643441245657
                      RT_RCDATA0x85d3000x95dDelphi compiled form 'Tfrm_Prepare'0.7563621193158114
                      RT_RCDATA0x85dc600x753Delphi compiled form 'Tfrm_Properties'0.3984
                      RT_RCDATA0x85e3b40xce0Delphi compiled form 'Tfrm_ReadDisc'0.9293082524271845
                      RT_GROUP_CURSOR0x85f0940x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.25
                      RT_GROUP_CURSOR0x85f0a80x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                      RT_GROUP_CURSOR0x85f0bc0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.25
                      RT_GROUP_CURSOR0x85f0d00x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                      RT_GROUP_CURSOR0x85f0e40x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                      RT_GROUP_CURSOR0x85f0f80x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                      RT_GROUP_CURSOR0x85f10c0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                      RT_GROUP_CURSOR0x85f1200x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                      RT_GROUP_ICON0x85f1340x14dataEnglishUnited States1.1
                      RT_VERSION0x85f1480x320dataEnglishUnited States0.46625
                      RT_MANIFEST0x85f4680x6dcXML 1.0 document, ASCII text, with CRLF line terminatorsEnglishGreat Britain0.3331435079726651
                      DLLImport
                      shlwapi.dllStrCmpLogicalW, StrFormatByteSizeW, PathMatchSpecW, StrRetToStrW, StrFormatKBSizeW, SHAutoComplete
                      winspool.drvDocumentPropertiesW, ClosePrinter, OpenPrinterW, GetDefaultPrinterW, EnumPrintersW
                      comdlg32.dllChooseColorW, GetSaveFileNameW, GetOpenFileNameW
                      comctl32.dllFlatSB_SetScrollInfo, InitCommonControls, ImageList_DragMove, ImageList_Destroy, _TrackMouseEvent, ImageList_DragShowNolock, ImageList_Add, ImageList_GetDragImage, FlatSB_SetScrollProp, ImageList_Create, ImageList_EndDrag, ImageList_DrawEx, ImageList_SetImageCount, FlatSB_GetScrollPos, FlatSB_SetScrollPos, InitializeFlatSB, ImageList_Copy, FlatSB_GetScrollInfo, ImageList_Write, ImageList_SetBkColor, ImageList_GetBkColor, ImageList_BeginDrag, ImageList_GetIcon, ImageList_Replace, ImageList_GetImageCount, ImageList_DragEnter, ImageList_GetIconSize, ImageList_SetIconSize, ImageList_Read, ImageList_DragLeave, ImageList_Draw, ImageList_Remove, ImageList_ReplaceIcon, ImageList_SetOverlayImage
                      shell32.dllSHBindToParent, DragQueryFileW, SHGetSpecialFolderLocation, ILCombine, Shell_NotifyIconW, SHCreateShellItem, SHGetDataFromIDListW, SHGetPathFromIDListW, ILFindLastID, ILGetNext, SHChangeNotifyDeregister, ILCreateFromPathW, ILFindChild, SHGetFileInfoW, SHGetDesktopFolder, ILRemoveLastID, SHChangeNotify, ILFree, ILClone, IsUserAnAdmin, SHChangeNotification_Unlock, ShellExecuteW
                      user32.dllMoveWindow, CopyImage, SetMenuItemInfoW, GetMenuItemInfoW, DefFrameProcW, GetDlgCtrlID, FrameRect, RegisterWindowMessageW, GetMenuStringW, FillRect, SendMessageA, IsClipboardFormatAvailable, EnumWindows, ShowOwnedPopups, GetClassInfoExW, GetClassInfoW, GetScrollRange, SetActiveWindow, GetActiveWindow, DrawEdge, GetKeyboardLayoutList, LoadBitmapW, EnumChildWindows, GetScrollBarInfo, UnhookWindowsHookEx, SetCapture, GetCapture, ShowCaret, CreatePopupMenu, GetMenuItemID, CharLowerBuffW, PostMessageW, IsZoomed, SetParent, DrawMenuBar, GetClientRect, IsChild, IsIconic, CallNextHookEx, ShowWindow, GetWindowTextW, SetForegroundWindow, IsDialogMessageW, DestroyWindow, RegisterClassW, EndMenu, CharNextW, GetFocus, GetDC, SetFocus, ReleaseDC, SetScrollRange, DrawTextW, PeekMessageA, MessageBeep, RemovePropW, GetSubMenu, DestroyIcon, IsWindowVisible, PtInRect, DispatchMessageA, UnregisterClassW, GetTopWindow, SendMessageW, GetComboBoxInfo, GetWindowLongPtrW, SetWindowLongPtrW, LoadStringW, CreateMenu, CharLowerW, SetWindowPos, SetWindowRgn, GetMenuItemCount, GetSysColorBrush, GetWindowDC, DrawTextExW, EnumClipboardFormats, GetScrollInfo, SetWindowTextW, GetMessageExtraInfo, GetSysColor, EnableScrollBar, TrackPopupMenu, DrawIconEx, GetClassNameW, GetMessagePos, GetIconInfo, SetScrollInfo, GetKeyNameTextW, GetDesktopWindow, SetCursorPos, GetCursorPos, SetMenu, GetMenuState, GetMenu, SetRect, GetKeyState, IsRectEmpty, GetCursor, KillTimer, WaitMessage, TranslateMDISysAccel, GetWindowPlacement, GetMenuItemRect, CreateIconIndirect, CreateWindowExW, ChildWindowFromPoint, GetDCEx, PeekMessageW, MonitorFromWindow, GetUpdateRect, MessageBoxA, SetTimer, WindowFromPoint, BeginPaint, RegisterClipboardFormatW, MapVirtualKeyW, OffsetRect, IsWindowUnicode, DispatchMessageW, DefMDIChildProcW, GetSystemMenu, SetScrollPos, GetScrollPos, InflateRect, DrawFocusRect, ReleaseCapture, LoadCursorW, ScrollWindow, GetLastActivePopup, GetSystemMetrics, CharUpperBuffW, SetClassLongPtrW, GetClassLongPtrW, SetClipboardData, GetClipboardData, ClientToScreen, SetWindowPlacement, GetMonitorInfoW, CheckMenuItem, CharUpperW, DefWindowProcW, GetForegroundWindow, EnableWindow, GetWindowThreadProcessId, RedrawWindow, EndPaint, MsgWaitForMultipleObjectsEx, LoadKeyboardLayoutW, ActivateKeyboardLayout, GetParent, InsertMenuItemW, GetPropW, MessageBoxW, SetPropW, UpdateWindow, MsgWaitForMultipleObjects, DestroyMenu, SetWindowsHookExW, EmptyClipboard, GetDlgItem, AdjustWindowRectEx, IsWindow, DrawIcon, EnumThreadWindows, InvalidateRect, SetKeyboardState, GetKeyboardState, ScreenToClient, DrawFrameControl, SetCursor, CreateIcon, RemoveMenu, GetKeyboardLayoutNameW, OpenClipboard, TranslateMessage, MapWindowPoints, EnumDisplayMonitors, CountClipboardFormats, CallWindowProcW, CloseClipboard, DestroyCursor, PostQuitMessage, ShowScrollBar, EnableMenuItem, HideCaret, FindWindowExW, MonitorFromPoint, LoadIconW, SystemParametersInfoW, GetWindow, GetWindowRect, InsertMenuW, IsWindowEnabled, IsDialogMessageA, GetMenuDefaultItem, FindWindowW, GetKeyboardLayout, DeleteMenu
                      version.dllGetFileVersionInfoSizeW, VerQueryValueW, GetFileVersionInfoW
                      oleaut32.dllGetErrorInfo, VariantInit, SysFreeString, VariantClear, SysReAllocStringLen, SafeArrayCreate, SafeArrayGetElement, SysAllocStringLen, SafeArrayPtrOfIndex, SafeArrayGetUBound, SafeArrayGetLBound, VariantCopy, VariantChangeType, VariantCopyInd
                      advapi32.dllRegEnumKeyExW, CheckTokenMembership, RegFlushKey, RegEnumValueW, RegQueryValueExW, RegCloseKey, RegQueryInfoKeyW, RegOpenKeyExW, AllocateAndInitializeSid, FreeSid
                      netapi32.dllNetWkstaGetInfo, NetApiBufferFree
                      msvcrt.dllmemcpy, memset
                      kernel32.dllSetFileAttributesW, RtlUnwindEx, QueryDosDeviceW, GetACP, GetExitCodeProcess, CloseHandle, LocalFree, GetCurrentProcessId, SizeofResource, VirtualProtect, TerminateThread, QueryPerformanceFrequency, IsDebuggerPresent, FindNextFileW, GetFullPathNameW, VirtualFree, ExitProcess, HeapAlloc, GetCPInfoExW, GetLongPathNameW, RtlUnwind, GetCPInfo, GetStdHandle, GetTimeZoneInformation, FileTimeToLocalFileTime, SystemTimeToTzSpecificLocalTime, GetModuleHandleW, FreeLibrary, HeapDestroy, FileTimeToDosDateTime, ReadFile, CreateProcessW, GetLastError, GetModuleFileNameW, SetLastError, GlobalAlloc, GlobalUnlock, FindResourceW, CreateThread, CompareStringW, CopyFileW, MapViewOfFile, LoadLibraryA, GetVolumeInformationW, ResetEvent, MulDiv, FreeResource, GetDriveTypeW, GetVersion, SetThreadExecutionState, RaiseException, GlobalAddAtomW, FormatMessageW, SwitchToThread, GetExitCodeThread, OutputDebugStringW, GetCurrentThread, GetLogicalDrives, GetFileAttributesExW, ExpandEnvironmentStringsW, LoadLibraryExW, LockResource, FileTimeToSystemTime, GetCurrentThreadId, UnhandledExceptionFilter, VirtualQuery, GlobalFindAtomW, VirtualQueryEx, GlobalFree, Sleep, EnterCriticalSection, SetFilePointer, LoadResource, SuspendThread, GetTickCount, WritePrivateProfileStringW, GetFileSize, GetStartupInfoW, GlobalDeleteAtom, GetFileAttributesW, GetCurrentDirectoryW, SetCurrentDirectoryW, InitializeCriticalSection, GetThreadPriority, GetCurrentProcess, SetThreadPriority, GlobalLock, VirtualAlloc, GetTempPathW, GetSystemInfo, GetCommandLineW, LeaveCriticalSection, GetProcAddress, ResumeThread, GetLogicalDriveStringsW, GetVersionExW, VerifyVersionInfoW, HeapCreate, GetWindowsDirectoryW, DeviceIoControl, GetDiskFreeSpaceW, VerSetConditionMask, FindFirstFileW, GetUserDefaultUILanguage, UnmapViewOfFile, GetModuleFileNameA, lstrlenW, QueryPerformanceCounter, SetEndOfFile, lstrcpyW, lstrcmpW, HeapFree, WideCharToMultiByte, FindClose, MultiByteToWideChar, LoadLibraryW, SetEvent, CreateFileW, GetLocaleInfoW, EnumResourceNamesW, DeleteFileW, GetEnvironmentVariableW, GetLocalTime, WaitForSingleObject, WriteFile, CreateFileMappingW, ExitThread, DeleteCriticalSection, GetDateFormatW, TlsGetValue, SetErrorMode, IsValidLocale, TlsSetValue, CreateDirectoryW, GetSystemDefaultUILanguage, EnumCalendarInfoW, LocalAlloc, RemoveDirectoryW, CreateEventW, GetPrivateProfileStringW, WaitForMultipleObjectsEx, GetThreadLocale, SetThreadLocale
                      ole32.dllRevokeDragDrop, CreateBindCtx, CoCreateInstance, CoUninitialize, OleGetClipboard, CLSIDFromString, ReleaseStgMedium, RegisterDragDrop, IsEqualGUID, OleInitialize, CoInitializeEx, OleUninitialize, CoInitialize, CoTaskMemFree, CoTaskMemAlloc, DoDragDrop, StringFromCLSID
                      gdi32.dllPie, SetPaletteEntries, SetBkMode, CreateCompatibleBitmap, GetEnhMetaFileHeader, RectVisible, AngleArc, ResizePalette, SetAbortProc, SetTextColor, GetTextColor, StretchBlt, RoundRect, RestoreDC, SetRectRgn, GetTextMetricsW, GetWindowOrgEx, SetPixelV, CreatePalette, CreateDCW, PolyBezierTo, CreateICW, GetStockObject, CreateSolidBrush, GetBkMode, Polygon, MoveToEx, PlayEnhMetaFile, Ellipse, StartPage, GetBitmapBits, StartDocW, GetSystemPaletteEntries, GetEnhMetaFileBits, GetEnhMetaFilePaletteEntries, CreatePenIndirect, SetMapMode, CreateFontIndirectW, PolyBezier, EndDoc, GetObjectW, GetCurrentObject, GetWinMetaFileBits, SetROP2, GetEnhMetaFileDescriptionW, ArcTo, Arc, SelectPalette, SetGraphicsMode, ExcludeClipRect, MaskBlt, SetWindowOrgEx, EndPage, DeleteEnhMetaFile, Chord, SetDIBits, GetViewportOrgEx, SetViewportOrgEx, CreateRectRgn, RealizePalette, SetDIBColorTable, GetDIBColorTable, CreateBrushIndirect, PatBlt, SetEnhMetaFileBits, Rectangle, SaveDC, DeleteDC, BitBlt, SetWorldTransform, FrameRgn, GetDeviceCaps, GetTextExtentPoint32W, GetClipBox, IntersectClipRect, Polyline, CreateBitmap, CombineRgn, SetWinMetaFileBits, GetStretchBltMode, CreateDIBitmap, CreateDIBSection, SetStretchBltMode, GetDIBits, ExtCreateRegion, LineTo, GetRgnBox, EnumFontsW, CreateHalftonePalette, SelectObject, DeleteObject, ExtFloodFill, UnrealizeObject, CopyEnhMetaFileW, SetBkColor, CreateCompatibleDC, GetBrushOrgEx, GetCurrentPositionEx, GetNearestPaletteIndex, CreateRoundRectRgn, GetTextExtentPointW, ExtTextOutW, SetBrushOrgEx, GetPixel, GdiFlush, SetPixel, EnumFontFamiliesExW, StretchDIBits, GetPaletteEntries
                      NameOrdinalAddress
                      TMethodImplementationIntercept30x50d530
                      __dbk_fcall_wrapper20x419090
                      dbkFCallWrapperAddr10x9e3290
                      Language of compilation systemCountry where language is spokenMap
                      EnglishUnited States
                      EnglishGreat Britain
                      TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                      2024-11-25T08:33:06.925259+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.649718172.67.204.237443TCP
                      2024-11-25T08:33:09.961854+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.64972018.213.123.165443TCP
                      2024-11-25T08:33:19.458372+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.649737172.67.204.237443TCP
                      2024-11-25T08:33:21.485008+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.64974318.213.123.165443TCP
                      2024-11-25T08:33:31.005204+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.649765172.67.204.237443TCP
                      2024-11-25T08:33:33.113123+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.64977218.213.123.165443TCP
                      2024-11-25T08:33:44.023543+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.649807172.67.204.237443TCP
                      2024-11-25T08:33:46.140180+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.64981318.213.123.165443TCP
                      2024-11-25T08:33:56.612862+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.649837172.67.204.237443TCP
                      2024-11-25T08:33:58.724023+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.64984318.213.123.165443TCP
                      2024-11-25T08:34:08.367518+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.649871172.67.204.237443TCP
                      2024-11-25T08:34:10.838070+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.64988118.213.123.165443TCP
                      2024-11-25T08:34:20.987632+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.649904172.67.204.237443TCP
                      2024-11-25T08:34:23.097771+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.64991018.213.123.165443TCP
                      2024-11-25T08:34:33.352021+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.649935172.67.204.237443TCP
                      2024-11-25T08:34:35.888799+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.64993918.213.123.165443TCP
                      2024-11-25T08:34:45.817476+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.649963172.67.204.237443TCP
                      2024-11-25T08:34:47.912181+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.64996918.213.123.165443TCP
                      2024-11-25T08:34:57.503711+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.649992172.67.204.237443TCP
                      2024-11-25T08:34:59.589060+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.64999618.213.123.165443TCP
                      2024-11-25T08:35:10.225666+01002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.650022172.67.204.237443TCP
                      TimestampSource PortDest PortSource IPDest IP
                      Nov 25, 2024 08:33:05.616060972 CET49718443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:05.616112947 CET44349718172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:05.616185904 CET49718443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:05.617739916 CET49718443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:05.617757082 CET44349718172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:06.925177097 CET44349718172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:06.925259113 CET49718443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:06.927339077 CET49718443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:06.927350044 CET44349718172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:06.927606106 CET44349718172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:06.977803946 CET49718443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:07.170506001 CET49718443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:07.211328030 CET44349718172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:07.855070114 CET44349718172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:07.855129004 CET44349718172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:07.855197906 CET49718443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:07.855498075 CET49718443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:07.855513096 CET44349718172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:07.855565071 CET49718443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:07.855571032 CET44349718172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:08.155848980 CET49720443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:08.155879974 CET4434972018.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:08.155945063 CET49720443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:08.156272888 CET49720443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:08.156281948 CET4434972018.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:09.961770058 CET4434972018.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:09.961853981 CET49720443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:09.966078997 CET49720443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:09.966089964 CET4434972018.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:09.966367006 CET4434972018.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:09.968384981 CET49720443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:10.015333891 CET4434972018.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:12.298209906 CET4434972018.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:12.352866888 CET49720443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:12.352881908 CET4434972018.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:12.399699926 CET49720443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:12.499188900 CET4434972018.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:12.540371895 CET49720443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:12.818989992 CET4434972018.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:12.868554115 CET49720443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:13.020883083 CET4434972018.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:13.071643114 CET49720443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:13.220962048 CET4434972018.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:13.274760962 CET49720443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:13.422166109 CET4434972018.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:13.462168932 CET49720443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:13.623356104 CET4434972018.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:13.665355921 CET49720443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:13.824054003 CET4434972018.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:13.868437052 CET49720443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:14.025018930 CET4434972018.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:14.071547031 CET49720443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:14.224091053 CET4434972018.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:14.224196911 CET4434972018.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:14.224291086 CET49720443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:14.224325895 CET49720443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:14.224342108 CET4434972018.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:14.224364042 CET49720443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:14.224370956 CET4434972018.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:18.230859041 CET49737443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:18.230901003 CET44349737172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:18.231043100 CET49737443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:18.231338024 CET49737443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:18.231350899 CET44349737172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:19.458226919 CET44349737172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:19.458372116 CET49737443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:19.459692955 CET49737443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:19.459705114 CET44349737172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:19.459983110 CET44349737172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:19.460920095 CET49737443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:19.503343105 CET44349737172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:20.242748976 CET44349737172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:20.242891073 CET44349737172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:20.242945910 CET49737443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:20.243170977 CET49737443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:20.243187904 CET44349737172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:20.244745016 CET49743443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:20.244785070 CET4434974318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:20.244884014 CET49743443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:20.245178938 CET49743443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:20.245192051 CET4434974318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:21.484920979 CET4434974318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:21.485008001 CET49743443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:21.486299038 CET49743443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:21.486309052 CET4434974318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:21.486571074 CET4434974318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:21.487390995 CET49743443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:21.531338930 CET4434974318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:23.923090935 CET4434974318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:23.977823019 CET49743443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:23.977843046 CET4434974318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:24.024719000 CET49743443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:24.124185085 CET4434974318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:24.165327072 CET49743443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:24.324650049 CET4434974318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:24.368472099 CET49743443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:24.525207043 CET4434974318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:24.571597099 CET49743443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:25.204109907 CET4434974318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:25.259068966 CET49743443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:25.259097099 CET4434974318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:25.305939913 CET49743443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:25.328190088 CET4434974318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:25.384147882 CET49743443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:25.529894114 CET4434974318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:25.571624994 CET49743443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:25.730036974 CET4434974318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:25.730128050 CET4434974318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:25.730200052 CET49743443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:25.730232954 CET49743443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:25.730252028 CET4434974318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:25.730262995 CET49743443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:25.730269909 CET4434974318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:29.747086048 CET49765443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:29.747114897 CET44349765172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:29.747211933 CET49765443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:29.747524023 CET49765443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:29.747556925 CET44349765172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:31.005047083 CET44349765172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:31.005203962 CET49765443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:31.006568909 CET49765443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:31.006583929 CET44349765172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:31.006834030 CET44349765172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:31.007518053 CET49765443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:31.055341005 CET44349765172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:31.800642014 CET44349765172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:31.800703049 CET44349765172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:31.800785065 CET49765443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:31.800960064 CET49765443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:31.800987005 CET44349765172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:31.802169085 CET49772443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:31.802196980 CET4434977218.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:31.802303076 CET49772443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:31.802557945 CET49772443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:31.802571058 CET4434977218.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:33.112922907 CET4434977218.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:33.113122940 CET49772443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:33.121598005 CET49772443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:33.121611118 CET4434977218.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:33.121818066 CET4434977218.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:33.125711918 CET49772443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:33.171330929 CET4434977218.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:36.097349882 CET4434977218.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:36.149728060 CET49772443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:36.308438063 CET4434977218.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:36.352849960 CET49772443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:36.640544891 CET4434977218.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:36.680982113 CET49772443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:36.850734949 CET4434977218.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:36.899718046 CET49772443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:37.061073065 CET4434977218.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:37.102850914 CET49772443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:37.286087036 CET4434977218.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:37.337215900 CET49772443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:37.498334885 CET4434977218.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:37.540348053 CET49772443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:37.896447897 CET4434977218.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:37.946604013 CET49772443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:38.403079987 CET4434977218.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:38.446604013 CET49772443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:38.613399982 CET4434977218.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:38.665369987 CET49772443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:38.805963993 CET4434977218.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:38.806034088 CET4434977218.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:38.806184053 CET49772443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:38.806251049 CET49772443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:38.806266069 CET4434977218.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:38.806283951 CET49772443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:38.806288958 CET4434977218.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:42.808998108 CET49807443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:42.809039116 CET44349807172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:42.809114933 CET49807443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:42.809480906 CET49807443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:42.809503078 CET44349807172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:44.023473024 CET44349807172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:44.023542881 CET49807443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:44.055746078 CET49807443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:44.055782080 CET44349807172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:44.056744099 CET44349807172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:44.062602043 CET49807443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:44.107340097 CET44349807172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:44.844790936 CET44349807172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:44.844865084 CET44349807172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:44.844913006 CET49807443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:44.847290993 CET49807443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:44.847317934 CET44349807172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:44.847331047 CET49807443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:44.847338915 CET44349807172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:44.867259026 CET49813443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:44.867290020 CET4434981318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:44.867372036 CET49813443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:44.867686033 CET49813443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:44.867691994 CET4434981318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:46.140088081 CET4434981318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:46.140180111 CET49813443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:46.141491890 CET49813443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:46.141503096 CET4434981318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:46.142061949 CET4434981318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:46.143089056 CET49813443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:46.183337927 CET4434981318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:49.148375988 CET4434981318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:49.196948051 CET49813443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:49.196970940 CET4434981318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:49.243602037 CET49813443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:49.519988060 CET4434981318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:49.571815968 CET49813443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:49.722652912 CET4434981318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:49.774817944 CET49813443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:49.922118902 CET4434981318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:49.977863073 CET49813443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:50.123210907 CET4434981318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:50.165389061 CET49813443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:50.324148893 CET4434981318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:50.368530989 CET49813443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:50.912367105 CET4434981318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:50.962230921 CET49813443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:51.113398075 CET4434981318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:51.165405035 CET49813443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:51.315449953 CET4434981318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:51.315547943 CET4434981318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:51.315644979 CET49813443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:51.315768003 CET49813443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:51.315768003 CET49813443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:51.315798998 CET4434981318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:51.315812111 CET4434981318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:55.355592012 CET49837443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:55.355629921 CET44349837172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:55.355767965 CET49837443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:55.356106997 CET49837443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:55.356121063 CET44349837172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:56.612788916 CET44349837172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:56.612862110 CET49837443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:56.614089012 CET49837443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:56.614108086 CET44349837172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:56.614356995 CET44349837172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:56.615047932 CET49837443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:56.655333042 CET44349837172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:57.410990953 CET44349837172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:57.411070108 CET44349837172.67.204.237192.168.2.6
                      Nov 25, 2024 08:33:57.411225080 CET49837443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:57.411493063 CET49837443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:33:57.412728071 CET49843443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:57.412771940 CET4434984318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:57.412894011 CET49843443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:57.413163900 CET49843443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:57.413177967 CET4434984318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:58.723942995 CET4434984318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:58.724023104 CET49843443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:58.725898027 CET49843443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:58.725909948 CET4434984318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:58.726164103 CET4434984318.213.123.165192.168.2.6
                      Nov 25, 2024 08:33:58.726854086 CET49843443192.168.2.618.213.123.165
                      Nov 25, 2024 08:33:58.767338037 CET4434984318.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:01.180512905 CET4434984318.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:01.227902889 CET49843443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:01.227926970 CET4434984318.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:01.274802923 CET49843443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:01.390765905 CET4434984318.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:01.431009054 CET49843443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:01.600805998 CET4434984318.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:01.650276899 CET49843443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:01.833204031 CET4434984318.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:01.884141922 CET49843443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:02.107414961 CET4434984318.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:02.150912046 CET49843443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:02.317641973 CET4434984318.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:02.368508101 CET49843443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:02.528168917 CET4434984318.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:02.583797932 CET49843443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:02.746386051 CET4434984318.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:02.790395975 CET49843443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:02.956703901 CET4434984318.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:03.040400982 CET49843443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:03.111121893 CET4434984318.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:03.111186981 CET4434984318.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:03.111248016 CET49843443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:03.111351013 CET49843443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:03.111366987 CET4434984318.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:03.111388922 CET49843443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:03.111394882 CET4434984318.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:07.155491114 CET49871443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:07.155534029 CET44349871172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:07.155883074 CET49871443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:07.155883074 CET49871443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:07.155924082 CET44349871172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:08.367420912 CET44349871172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:08.367517948 CET49871443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:08.435570955 CET49871443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:08.435607910 CET44349871172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:08.436022043 CET44349871172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:08.447581053 CET49871443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:08.495331049 CET44349871172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:09.192337036 CET44349871172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:09.192408085 CET44349871172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:09.192457914 CET49871443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:09.192548990 CET49871443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:09.192568064 CET44349871172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:09.494111061 CET49881443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:09.494152069 CET4434988118.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:09.494230032 CET49881443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:09.494627953 CET49881443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:09.494657040 CET4434988118.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:10.837984085 CET4434988118.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:10.838069916 CET49881443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:10.839464903 CET49881443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:10.839477062 CET4434988118.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:10.839730978 CET4434988118.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:10.840758085 CET49881443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:10.887341022 CET4434988118.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:13.294425964 CET4434988118.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:13.337291956 CET49881443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:13.337312937 CET4434988118.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:13.384152889 CET49881443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:13.558449984 CET4434988118.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:13.602895975 CET49881443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:13.939359903 CET4434988118.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:13.993573904 CET49881443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:14.165025949 CET4434988118.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:14.212291956 CET49881443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:14.375588894 CET4434988118.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:14.415427923 CET49881443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:14.585916996 CET4434988118.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:14.634205103 CET49881443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:14.796014071 CET4434988118.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:14.837272882 CET49881443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:15.006598949 CET4434988118.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:15.054111004 CET49881443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:15.340363026 CET4434988118.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:15.384170055 CET49881443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:15.538738966 CET4434988118.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:15.538822889 CET4434988118.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:15.538929939 CET49881443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:15.539007902 CET49881443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:15.539027929 CET4434988118.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:15.539046049 CET49881443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:15.539064884 CET4434988118.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:19.544065952 CET49904443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:19.544101954 CET44349904172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:19.544183969 CET49904443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:19.544543028 CET49904443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:19.544548988 CET44349904172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:20.987550020 CET44349904172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:20.987632036 CET49904443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:20.989485025 CET49904443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:20.989497900 CET44349904172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:20.989778042 CET44349904172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:20.990760088 CET49904443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:21.035339117 CET44349904172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:21.786613941 CET44349904172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:21.786675930 CET44349904172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:21.786808014 CET49904443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:21.787189960 CET49904443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:21.787189960 CET49904443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:21.787216902 CET44349904172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:21.787236929 CET44349904172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:21.788502932 CET49910443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:21.788535118 CET4434991018.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:21.788724899 CET49910443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:21.789288998 CET49910443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:21.789302111 CET4434991018.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:23.097697020 CET4434991018.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:23.097770929 CET49910443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:23.099081039 CET49910443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:23.099097013 CET4434991018.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:23.099395037 CET4434991018.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:23.100151062 CET49910443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:23.143328905 CET4434991018.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:25.916294098 CET4434991018.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:25.962276936 CET49910443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:25.962291002 CET4434991018.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:26.009152889 CET49910443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:26.126641989 CET4434991018.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:26.181025028 CET49910443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:26.336982965 CET4434991018.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:26.384157896 CET49910443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:26.547394037 CET4434991018.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:26.587400913 CET49910443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:26.757699966 CET4434991018.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:26.806058884 CET49910443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:26.968038082 CET4434991018.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:27.009172916 CET49910443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:27.178442001 CET4434991018.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:27.227920055 CET49910443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:27.388835907 CET4434991018.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:27.431029081 CET49910443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:27.599046946 CET4434991018.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:27.649776936 CET49910443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:28.082204103 CET4434991018.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:28.082292080 CET4434991018.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:28.082380056 CET49910443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:28.082535028 CET49910443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:28.082556009 CET4434991018.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:28.082571030 CET49910443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:28.082576990 CET4434991018.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:32.093511105 CET49935443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:32.093565941 CET44349935172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:32.093661070 CET49935443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:32.094084024 CET49935443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:32.094098091 CET44349935172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:33.351425886 CET44349935172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:33.352020979 CET49935443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:33.353077888 CET49935443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:33.353102922 CET44349935172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:33.353404045 CET44349935172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:33.354413986 CET49935443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:33.399336100 CET44349935172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:34.153793097 CET44349935172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:34.153851032 CET44349935172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:34.153942108 CET49935443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:34.154099941 CET49935443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:34.154120922 CET44349935172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:34.154186010 CET49935443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:34.154195070 CET44349935172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:34.155854940 CET49939443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:34.155900955 CET4434993918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:34.156011105 CET49939443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:34.156311989 CET49939443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:34.156327963 CET4434993918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:35.888274908 CET4434993918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:35.888798952 CET49939443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:36.013237953 CET49939443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:36.013267040 CET4434993918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:36.013617992 CET4434993918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:36.021287918 CET49939443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:36.063342094 CET4434993918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:38.439547062 CET4434993918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:38.494818926 CET49939443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:38.494854927 CET4434993918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:38.540477037 CET49939443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:38.728410006 CET4434993918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:38.778805017 CET49939443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:39.029016018 CET4434993918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:39.078638077 CET49939443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:39.230034113 CET4434993918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:39.274821997 CET49939443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:39.430603027 CET4434993918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:39.477942944 CET49939443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:39.631154060 CET4434993918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:39.681070089 CET49939443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:39.830854893 CET4434993918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:39.884212971 CET49939443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:40.030791044 CET4434993918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:40.071701050 CET49939443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:40.354468107 CET4434993918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:40.399873972 CET49939443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:40.553952932 CET4434993918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:40.554027081 CET4434993918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:40.554085016 CET49939443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:40.554140091 CET49939443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:40.554157019 CET4434993918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:40.554182053 CET49939443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:40.554189920 CET4434993918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:44.607307911 CET49963443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:44.607379913 CET44349963172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:44.607724905 CET49963443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:44.608207941 CET49963443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:44.608232975 CET44349963172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:45.817372084 CET44349963172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:45.817476034 CET49963443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:45.818881989 CET49963443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:45.818892956 CET44349963172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:45.819143057 CET44349963172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:45.819963932 CET49963443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:45.867332935 CET44349963172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:46.600929976 CET44349963172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:46.600996017 CET44349963172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:46.601042986 CET49963443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:46.601284027 CET49963443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:46.601284027 CET49963443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:46.601305008 CET44349963172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:46.601314068 CET44349963172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:46.602634907 CET49969443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:46.602663994 CET4434996918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:46.602721930 CET49969443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:46.603707075 CET49969443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:46.603714943 CET4434996918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:47.912074089 CET4434996918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:47.912180901 CET49969443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:47.913727045 CET49969443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:47.913764000 CET4434996918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:47.914047956 CET4434996918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:47.914877892 CET49969443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:47.959335089 CET4434996918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:50.369471073 CET4434996918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:50.415838957 CET49969443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:50.415852070 CET4434996918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:50.462357998 CET49969443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:50.579741001 CET4434996918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:50.634227991 CET49969443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:50.790024042 CET4434996918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:50.837482929 CET49969443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:51.000686884 CET4434996918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:51.056099892 CET49969443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:51.211082935 CET4434996918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:51.259208918 CET49969443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:51.421399117 CET4434996918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:51.478028059 CET49969443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:51.631905079 CET4434996918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:51.681075096 CET49969443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:51.842335939 CET4434996918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:51.884238958 CET49969443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:52.052606106 CET4434996918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:52.096777916 CET49969443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:52.234466076 CET4434996918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:52.234549046 CET4434996918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:52.234615088 CET49969443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:52.234800100 CET49969443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:52.234827042 CET4434996918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:52.234855890 CET49969443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:52.234863043 CET4434996918.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:56.246331930 CET49992443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:56.246366024 CET44349992172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:56.246720076 CET49992443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:56.246766090 CET49992443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:56.246773005 CET44349992172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:57.503614902 CET44349992172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:57.503710985 CET49992443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:57.550328970 CET49992443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:57.550345898 CET44349992172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:57.550682068 CET44349992172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:57.561714888 CET49992443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:57.603370905 CET44349992172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:58.323116064 CET44349992172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:58.323205948 CET44349992172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:58.323257923 CET49992443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:58.323463917 CET49992443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:58.323484898 CET44349992172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:58.323502064 CET49992443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:34:58.323507071 CET44349992172.67.204.237192.168.2.6
                      Nov 25, 2024 08:34:58.324839115 CET49996443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:58.324882030 CET4434999618.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:58.324942112 CET49996443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:58.325292110 CET49996443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:58.325301886 CET4434999618.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:59.588593006 CET4434999618.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:59.589060068 CET49996443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:59.603188038 CET49996443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:59.603225946 CET4434999618.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:59.603604078 CET4434999618.213.123.165192.168.2.6
                      Nov 25, 2024 08:34:59.606271982 CET49996443192.168.2.618.213.123.165
                      Nov 25, 2024 08:34:59.647339106 CET4434999618.213.123.165192.168.2.6
                      Nov 25, 2024 08:35:03.081573009 CET4434999618.213.123.165192.168.2.6
                      Nov 25, 2024 08:35:03.134893894 CET49996443192.168.2.618.213.123.165
                      Nov 25, 2024 08:35:03.134907961 CET4434999618.213.123.165192.168.2.6
                      Nov 25, 2024 08:35:03.181104898 CET49996443192.168.2.618.213.123.165
                      Nov 25, 2024 08:35:03.282349110 CET4434999618.213.123.165192.168.2.6
                      Nov 25, 2024 08:35:03.337413073 CET49996443192.168.2.618.213.123.165
                      Nov 25, 2024 08:35:03.483371973 CET4434999618.213.123.165192.168.2.6
                      Nov 25, 2024 08:35:03.525881052 CET49996443192.168.2.618.213.123.165
                      Nov 25, 2024 08:35:03.689202070 CET4434999618.213.123.165192.168.2.6
                      Nov 25, 2024 08:35:03.743578911 CET49996443192.168.2.618.213.123.165
                      Nov 25, 2024 08:35:03.892050028 CET4434999618.213.123.165192.168.2.6
                      Nov 25, 2024 08:35:03.946887016 CET49996443192.168.2.618.213.123.165
                      Nov 25, 2024 08:35:04.092952013 CET4434999618.213.123.165192.168.2.6
                      Nov 25, 2024 08:35:04.134315968 CET49996443192.168.2.618.213.123.165
                      Nov 25, 2024 08:35:04.604098082 CET4434999618.213.123.165192.168.2.6
                      Nov 25, 2024 08:35:04.649869919 CET49996443192.168.2.618.213.123.165
                      Nov 25, 2024 08:35:04.805397987 CET4434999618.213.123.165192.168.2.6
                      Nov 25, 2024 08:35:04.852984905 CET49996443192.168.2.618.213.123.165
                      Nov 25, 2024 08:35:05.020538092 CET4434999618.213.123.165192.168.2.6
                      Nov 25, 2024 08:35:05.071835995 CET49996443192.168.2.618.213.123.165
                      Nov 25, 2024 08:35:05.226661921 CET4434999618.213.123.165192.168.2.6
                      Nov 25, 2024 08:35:05.226763964 CET4434999618.213.123.165192.168.2.6
                      Nov 25, 2024 08:35:05.227068901 CET49996443192.168.2.618.213.123.165
                      Nov 25, 2024 08:35:05.227238894 CET49996443192.168.2.618.213.123.165
                      Nov 25, 2024 08:35:05.227261066 CET4434999618.213.123.165192.168.2.6
                      Nov 25, 2024 08:35:05.227324009 CET49996443192.168.2.618.213.123.165
                      Nov 25, 2024 08:35:05.227332115 CET4434999618.213.123.165192.168.2.6
                      Nov 25, 2024 08:35:08.965668917 CET50022443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:35:08.965708017 CET44350022172.67.204.237192.168.2.6
                      Nov 25, 2024 08:35:08.965929985 CET50022443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:35:08.966453075 CET50022443192.168.2.6172.67.204.237
                      Nov 25, 2024 08:35:08.966464043 CET44350022172.67.204.237192.168.2.6
                      Nov 25, 2024 08:35:10.225570917 CET44350022172.67.204.237192.168.2.6
                      Nov 25, 2024 08:35:10.225666046 CET50022443192.168.2.6172.67.204.237
                      TimestampSource PortDest PortSource IPDest IP
                      Nov 25, 2024 08:33:05.234813929 CET5731253192.168.2.61.1.1.1
                      Nov 25, 2024 08:33:05.610373974 CET53573121.1.1.1192.168.2.6
                      Nov 25, 2024 08:33:07.856807947 CET5104853192.168.2.61.1.1.1
                      Nov 25, 2024 08:33:08.154922009 CET53510481.1.1.1192.168.2.6
                      Nov 25, 2024 08:34:09.193829060 CET5378953192.168.2.61.1.1.1
                      Nov 25, 2024 08:34:09.492912054 CET53537891.1.1.1192.168.2.6
                      TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                      Nov 25, 2024 08:33:05.234813929 CET192.168.2.61.1.1.10x89acStandard query (0)eth0.cdn-serveri2004-ns.shopA (IP address)IN (0x0001)false
                      Nov 25, 2024 08:33:07.856807947 CET192.168.2.61.1.1.10x8c90Standard query (0)httpbin.orgA (IP address)IN (0x0001)false
                      Nov 25, 2024 08:34:09.193829060 CET192.168.2.61.1.1.10xbb48Standard query (0)httpbin.orgA (IP address)IN (0x0001)false
                      TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                      Nov 25, 2024 08:33:05.610373974 CET1.1.1.1192.168.2.60x89acNo error (0)eth0.cdn-serveri2004-ns.shop172.67.204.237A (IP address)IN (0x0001)false
                      Nov 25, 2024 08:33:05.610373974 CET1.1.1.1192.168.2.60x89acNo error (0)eth0.cdn-serveri2004-ns.shop104.21.52.225A (IP address)IN (0x0001)false
                      Nov 25, 2024 08:33:08.154922009 CET1.1.1.1192.168.2.60x8c90No error (0)httpbin.org18.213.123.165A (IP address)IN (0x0001)false
                      Nov 25, 2024 08:33:08.154922009 CET1.1.1.1192.168.2.60x8c90No error (0)httpbin.org18.208.8.205A (IP address)IN (0x0001)false
                      Nov 25, 2024 08:34:03.071160078 CET1.1.1.1192.168.2.60xfb1dNo error (0)g-bing-com.ax-0001.ax-msedge.netax-0001.ax-msedge.netCNAME (Canonical name)IN (0x0001)false
                      Nov 25, 2024 08:34:03.071160078 CET1.1.1.1192.168.2.60xfb1dNo error (0)ax-0001.ax-msedge.net150.171.28.10A (IP address)IN (0x0001)false
                      Nov 25, 2024 08:34:03.071160078 CET1.1.1.1192.168.2.60xfb1dNo error (0)ax-0001.ax-msedge.net150.171.27.10A (IP address)IN (0x0001)false
                      Nov 25, 2024 08:34:09.492912054 CET1.1.1.1192.168.2.60xbb48No error (0)httpbin.org18.213.123.165A (IP address)IN (0x0001)false
                      Nov 25, 2024 08:34:09.492912054 CET1.1.1.1192.168.2.60xbb48No error (0)httpbin.org18.208.8.205A (IP address)IN (0x0001)false
                      • eth0.cdn-serveri2004-ns.shop
                      • httpbin.org
                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      0192.168.2.649718172.67.204.2374431444C:\Users\user\Desktop\t90RvrDNvz.exe
                      TimestampBytes transferredDirectionData
                      2024-11-25 07:33:07 UTC111OUTGET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1
                      Connection: Keep-Alive
                      Host: eth0.cdn-serveri2004-ns.shop
                      2024-11-25 07:33:07 UTC888INHTTP/1.1 302 Found
                      Date: Mon, 25 Nov 2024 07:33:07 GMT
                      Content-Type: text/html; charset=UTF-8
                      Transfer-Encoding: chunked
                      Connection: close
                      Cache-Control: no-store
                      Location: https://httpbin.org/drip?code=200&delay=2&duration=2&numbytes=10
                      cf-cache-status: DYNAMIC
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=zQbc6eMR4j%2F9ELWRML7EY2lS9a67hz%2BJagbh2M5XuOK5RSVd7%2FfKBcGEOhbGc%2FHS701tZjnmCuWwZryjfnahHf2kAF%2FzGHoxsnsQwEoTn8vXZeCsZ1%2BkxRUj0q%2FNszrBfAXOeCEu6KBrNLpXcKS6"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Server: cloudflare
                      CF-RAY: 8e7ff2e0d89dde9b-EWR
                      alt-svc: h3=":443"; ma=86400
                      server-timing: cfL4;desc="?proto=TCP&rtt=1490&sent=5&recv=7&lost=0&retrans=0&sent_bytes=2859&recv_bytes=725&delivery_rate=1921052&cwnd=146&unsent_bytes=0&cid=f45ec54b4728b46c&ts=940&x=0"
                      2024-11-25 07:33:07 UTC5INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      1192.168.2.64972018.213.123.1654431444C:\Users\user\Desktop\t90RvrDNvz.exe
                      TimestampBytes transferredDirectionData
                      2024-11-25 07:33:09 UTC105OUTGET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1
                      Connection: Keep-Alive
                      Host: httpbin.org
                      2024-11-25 07:33:12 UTC232INHTTP/1.1 200 OK
                      Date: Mon, 25 Nov 2024 07:33:12 GMT
                      Content-Type: application/octet-stream
                      Content-Length: 10
                      Connection: close
                      Server: gunicorn/19.9.0
                      Access-Control-Allow-Origin: *
                      Access-Control-Allow-Credentials: true
                      2024-11-25 07:33:12 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:12 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:12 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:13 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:13 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:13 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:13 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:13 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:14 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:14 UTC1INData Raw: 2a
                      Data Ascii: *


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      2192.168.2.649737172.67.204.2374431444C:\Users\user\Desktop\t90RvrDNvz.exe
                      TimestampBytes transferredDirectionData
                      2024-11-25 07:33:19 UTC111OUTGET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1
                      Connection: Keep-Alive
                      Host: eth0.cdn-serveri2004-ns.shop
                      2024-11-25 07:33:20 UTC888INHTTP/1.1 302 Found
                      Date: Mon, 25 Nov 2024 07:33:20 GMT
                      Content-Type: text/html; charset=UTF-8
                      Transfer-Encoding: chunked
                      Connection: close
                      Cache-Control: no-store
                      Location: https://httpbin.org/drip?code=200&delay=2&duration=2&numbytes=10
                      cf-cache-status: DYNAMIC
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=XO1IQkT1g14BQbF%2BH8rYd23sOLbrJ2QDWraZDexIRlpPYpC%2FscuI%2FWnEwCqjKESTotThfWq%2FinUfzVIR0QiRrYvnvf%2FwCcoHl97t3TFt7cDp6g74L1Z7WGW1oHSrXwnFEIgnN%2F%2FVnmRhM6AUnUSG"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Server: cloudflare
                      CF-RAY: 8e7ff32e4a6c726b-EWR
                      alt-svc: h3=":443"; ma=86400
                      server-timing: cfL4;desc="?proto=TCP&rtt=1779&sent=5&recv=7&lost=0&retrans=0&sent_bytes=2861&recv_bytes=725&delivery_rate=1587819&cwnd=237&unsent_bytes=0&cid=644912e9d70a44e9&ts=796&x=0"
                      2024-11-25 07:33:20 UTC5INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      3192.168.2.64974318.213.123.1654431444C:\Users\user\Desktop\t90RvrDNvz.exe
                      TimestampBytes transferredDirectionData
                      2024-11-25 07:33:21 UTC105OUTGET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1
                      Connection: Keep-Alive
                      Host: httpbin.org
                      2024-11-25 07:33:23 UTC232INHTTP/1.1 200 OK
                      Date: Mon, 25 Nov 2024 07:33:23 GMT
                      Content-Type: application/octet-stream
                      Content-Length: 10
                      Connection: close
                      Server: gunicorn/19.9.0
                      Access-Control-Allow-Origin: *
                      Access-Control-Allow-Credentials: true
                      2024-11-25 07:33:23 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:24 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:24 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:24 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:25 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:25 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:25 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:25 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:25 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:25 UTC1INData Raw: 2a
                      Data Ascii: *


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      4192.168.2.649765172.67.204.2374431444C:\Users\user\Desktop\t90RvrDNvz.exe
                      TimestampBytes transferredDirectionData
                      2024-11-25 07:33:31 UTC111OUTGET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1
                      Connection: Keep-Alive
                      Host: eth0.cdn-serveri2004-ns.shop
                      2024-11-25 07:33:31 UTC878INHTTP/1.1 302 Found
                      Date: Mon, 25 Nov 2024 07:33:31 GMT
                      Content-Type: text/html; charset=UTF-8
                      Transfer-Encoding: chunked
                      Connection: close
                      Cache-Control: no-store
                      Location: https://httpbin.org/drip?code=200&delay=2&duration=2&numbytes=10
                      cf-cache-status: DYNAMIC
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=frClXEllGXGCIcZww2XNnbzhcXTiiyv67VUhZtREG1duJ3XW2%2Fg1HZdZBP1tMtu7UHtNbkxhIGqzl%2BsvxtoMPPSYlQkQ6DMOiTqgA1rKTYTGfvjRod7qVvIsjPfDKSEz2mZR6CsAm2zWKdI7MUjs"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Server: cloudflare
                      CF-RAY: 8e7ff3768d390f63-EWR
                      alt-svc: h3=":443"; ma=86400
                      server-timing: cfL4;desc="?proto=TCP&rtt=1510&sent=5&recv=7&lost=0&retrans=0&sent_bytes=2859&recv_bytes=725&delivery_rate=1868202&cwnd=219&unsent_bytes=0&cid=13ffcf8d916166ff&ts=802&x=0"
                      2024-11-25 07:33:31 UTC5INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      5192.168.2.64977218.213.123.1654431444C:\Users\user\Desktop\t90RvrDNvz.exe
                      TimestampBytes transferredDirectionData
                      2024-11-25 07:33:33 UTC105OUTGET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1
                      Connection: Keep-Alive
                      Host: httpbin.org
                      2024-11-25 07:33:36 UTC232INHTTP/1.1 200 OK
                      Date: Mon, 25 Nov 2024 07:33:35 GMT
                      Content-Type: application/octet-stream
                      Content-Length: 10
                      Connection: close
                      Server: gunicorn/19.9.0
                      Access-Control-Allow-Origin: *
                      Access-Control-Allow-Credentials: true
                      2024-11-25 07:33:36 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:36 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:36 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:37 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:37 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:37 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:37 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:38 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:38 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:38 UTC1INData Raw: 2a
                      Data Ascii: *


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      6192.168.2.649807172.67.204.2374431444C:\Users\user\Desktop\t90RvrDNvz.exe
                      TimestampBytes transferredDirectionData
                      2024-11-25 07:33:44 UTC111OUTGET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1
                      Connection: Keep-Alive
                      Host: eth0.cdn-serveri2004-ns.shop
                      2024-11-25 07:33:44 UTC882INHTTP/1.1 302 Found
                      Date: Mon, 25 Nov 2024 07:33:44 GMT
                      Content-Type: text/html; charset=UTF-8
                      Transfer-Encoding: chunked
                      Connection: close
                      Cache-Control: no-store
                      Location: https://httpbin.org/drip?code=200&delay=2&duration=2&numbytes=10
                      cf-cache-status: DYNAMIC
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2BqMzzIb7lQW6Q2fmV2GkwQjIN9HE%2B4xIgbYctROkzI1kIk1IaNpsMRwu0gGEGLcr3e5jn1q4rcRanzK8Ac5XIrNlQUcQGi8cVMPe8GXL1t3OIVfnpFYS0NXf%2BAjv6NeDvx%2BLwKpkijTxh0gpbl3H"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Server: cloudflare
                      CF-RAY: 8e7ff3c7ea40421f-EWR
                      alt-svc: h3=":443"; ma=86400
                      server-timing: cfL4;desc="?proto=TCP&rtt=1574&sent=5&recv=7&lost=0&retrans=0&sent_bytes=2861&recv_bytes=725&delivery_rate=1790312&cwnd=239&unsent_bytes=0&cid=f76cd8915e899473&ts=799&x=0"
                      2024-11-25 07:33:44 UTC5INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      7192.168.2.64981318.213.123.1654431444C:\Users\user\Desktop\t90RvrDNvz.exe
                      TimestampBytes transferredDirectionData
                      2024-11-25 07:33:46 UTC105OUTGET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1
                      Connection: Keep-Alive
                      Host: httpbin.org
                      2024-11-25 07:33:49 UTC232INHTTP/1.1 200 OK
                      Date: Mon, 25 Nov 2024 07:33:48 GMT
                      Content-Type: application/octet-stream
                      Content-Length: 10
                      Connection: close
                      Server: gunicorn/19.9.0
                      Access-Control-Allow-Origin: *
                      Access-Control-Allow-Credentials: true
                      2024-11-25 07:33:49 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:49 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:49 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:49 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:49 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:50 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:50 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:50 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:51 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:33:51 UTC1INData Raw: 2a
                      Data Ascii: *


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      8192.168.2.649837172.67.204.2374431444C:\Users\user\Desktop\t90RvrDNvz.exe
                      TimestampBytes transferredDirectionData
                      2024-11-25 07:33:56 UTC111OUTGET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1
                      Connection: Keep-Alive
                      Host: eth0.cdn-serveri2004-ns.shop
                      2024-11-25 07:33:57 UTC884INHTTP/1.1 302 Found
                      Date: Mon, 25 Nov 2024 07:33:57 GMT
                      Content-Type: text/html; charset=UTF-8
                      Transfer-Encoding: chunked
                      Connection: close
                      Cache-Control: no-store
                      Location: https://httpbin.org/drip?code=200&delay=2&duration=2&numbytes=10
                      cf-cache-status: DYNAMIC
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=vgl306Wf%2BKp6bkpGac0gzrlKFksO6N7R1VYEIynypqmk8zecMDCLEdCuUgws3o4dnYHBwjutcXl8L%2FI2OfXe9oJ2AyKSJWGU3YfIjs7jiI%2B79bqTO3DY1t2FcR%2FlvtAALI1nTMratlQ8czse3%2FfK"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Server: cloudflare
                      CF-RAY: 8e7ff4169eb9c44a-EWR
                      alt-svc: h3=":443"; ma=86400
                      server-timing: cfL4;desc="?proto=TCP&rtt=1473&sent=5&recv=7&lost=0&retrans=0&sent_bytes=2861&recv_bytes=725&delivery_rate=1959731&cwnd=223&unsent_bytes=0&cid=e0e3d36bf2df9516&ts=804&x=0"
                      2024-11-25 07:33:57 UTC5INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      9192.168.2.64984318.213.123.1654431444C:\Users\user\Desktop\t90RvrDNvz.exe
                      TimestampBytes transferredDirectionData
                      2024-11-25 07:33:58 UTC105OUTGET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1
                      Connection: Keep-Alive
                      Host: httpbin.org
                      2024-11-25 07:34:01 UTC232INHTTP/1.1 200 OK
                      Date: Mon, 25 Nov 2024 07:34:01 GMT
                      Content-Type: application/octet-stream
                      Content-Length: 10
                      Connection: close
                      Server: gunicorn/19.9.0
                      Access-Control-Allow-Origin: *
                      Access-Control-Allow-Credentials: true
                      2024-11-25 07:34:01 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:01 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:01 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:01 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:02 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:02 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:02 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:02 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:02 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:03 UTC1INData Raw: 2a
                      Data Ascii: *


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      10192.168.2.649871172.67.204.2374431444C:\Users\user\Desktop\t90RvrDNvz.exe
                      TimestampBytes transferredDirectionData
                      2024-11-25 07:34:08 UTC111OUTGET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1
                      Connection: Keep-Alive
                      Host: eth0.cdn-serveri2004-ns.shop
                      2024-11-25 07:34:09 UTC878INHTTP/1.1 302 Found
                      Date: Mon, 25 Nov 2024 07:34:09 GMT
                      Content-Type: text/html; charset=UTF-8
                      Transfer-Encoding: chunked
                      Connection: close
                      Cache-Control: no-store
                      Location: https://httpbin.org/drip?code=200&delay=2&duration=2&numbytes=10
                      cf-cache-status: DYNAMIC
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=UeQMhRp7kEodQwcsU5Qve083lqjmqfKVN3R9Q04cT4nRd1NXJ66sJs1AZxAH6ieHk5oBKhxddLmg6HXXNRb4%2B46tASTuaTL6c8QZLq2mlnAqs2oZRqWOk1Q3rOvBbqBRUgcGH%2FNU8SZ30V6ATVQr"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Server: cloudflare
                      CF-RAY: 8e7ff4600ff632e2-EWR
                      alt-svc: h3=":443"; ma=86400
                      server-timing: cfL4;desc="?proto=TCP&rtt=1815&sent=5&recv=7&lost=0&retrans=0&sent_bytes=2861&recv_bytes=725&delivery_rate=1584373&cwnd=159&unsent_bytes=0&cid=5b9b84561fb463f4&ts=831&x=0"
                      2024-11-25 07:34:09 UTC5INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      11192.168.2.64988118.213.123.1654431444C:\Users\user\Desktop\t90RvrDNvz.exe
                      TimestampBytes transferredDirectionData
                      2024-11-25 07:34:10 UTC105OUTGET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1
                      Connection: Keep-Alive
                      Host: httpbin.org
                      2024-11-25 07:34:13 UTC232INHTTP/1.1 200 OK
                      Date: Mon, 25 Nov 2024 07:34:13 GMT
                      Content-Type: application/octet-stream
                      Content-Length: 10
                      Connection: close
                      Server: gunicorn/19.9.0
                      Access-Control-Allow-Origin: *
                      Access-Control-Allow-Credentials: true
                      2024-11-25 07:34:13 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:13 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:13 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:14 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:14 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:14 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:14 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:15 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:15 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:15 UTC1INData Raw: 2a
                      Data Ascii: *


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      12192.168.2.649904172.67.204.2374431444C:\Users\user\Desktop\t90RvrDNvz.exe
                      TimestampBytes transferredDirectionData
                      2024-11-25 07:34:20 UTC111OUTGET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1
                      Connection: Keep-Alive
                      Host: eth0.cdn-serveri2004-ns.shop
                      2024-11-25 07:34:21 UTC882INHTTP/1.1 302 Found
                      Date: Mon, 25 Nov 2024 07:34:21 GMT
                      Content-Type: text/html; charset=UTF-8
                      Transfer-Encoding: chunked
                      Connection: close
                      Cache-Control: no-store
                      Location: https://httpbin.org/drip?code=200&delay=2&duration=2&numbytes=10
                      cf-cache-status: DYNAMIC
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=OO3fmGhWROLJm%2FG4k6z4tpEbUg%2BdEHeWJupXdODSkuVMuU7jJfUr0gXv2hBX7XlsRre0qwhAdEbhz2OTu%2BKfbPc1YEDtdWo8%2BJ0xBmi5GVIAqA5p8b576K8u4LVGOqUPuhvebQzCSnvC9XDNQ4KC"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Server: cloudflare
                      CF-RAY: 8e7ff4aefdc67c7b-EWR
                      alt-svc: h3=":443"; ma=86400
                      server-timing: cfL4;desc="?proto=TCP&rtt=1812&sent=5&recv=7&lost=0&retrans=0&sent_bytes=2861&recv_bytes=725&delivery_rate=1516883&cwnd=207&unsent_bytes=0&cid=264f87521c68c6fc&ts=805&x=0"
                      2024-11-25 07:34:21 UTC5INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      13192.168.2.64991018.213.123.1654431444C:\Users\user\Desktop\t90RvrDNvz.exe
                      TimestampBytes transferredDirectionData
                      2024-11-25 07:34:23 UTC105OUTGET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1
                      Connection: Keep-Alive
                      Host: httpbin.org
                      2024-11-25 07:34:25 UTC232INHTTP/1.1 200 OK
                      Date: Mon, 25 Nov 2024 07:34:25 GMT
                      Content-Type: application/octet-stream
                      Content-Length: 10
                      Connection: close
                      Server: gunicorn/19.9.0
                      Access-Control-Allow-Origin: *
                      Access-Control-Allow-Credentials: true
                      2024-11-25 07:34:25 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:26 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:26 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:26 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:26 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:26 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:27 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:27 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:27 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:28 UTC1INData Raw: 2a
                      Data Ascii: *


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      14192.168.2.649935172.67.204.2374431444C:\Users\user\Desktop\t90RvrDNvz.exe
                      TimestampBytes transferredDirectionData
                      2024-11-25 07:34:33 UTC111OUTGET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1
                      Connection: Keep-Alive
                      Host: eth0.cdn-serveri2004-ns.shop
                      2024-11-25 07:34:34 UTC878INHTTP/1.1 302 Found
                      Date: Mon, 25 Nov 2024 07:34:33 GMT
                      Content-Type: text/html; charset=UTF-8
                      Transfer-Encoding: chunked
                      Connection: close
                      Cache-Control: no-store
                      Location: https://httpbin.org/drip?code=200&delay=2&duration=2&numbytes=10
                      cf-cache-status: DYNAMIC
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=wMN9wP9GeEsy3m4jMKCT8AxOQiTPXgFCdkRysCy2qcErQQ6yQXmceTXfWQhGxOW52R24IoyZpKATztzVTNmbPSoy1l9sV1BOgoKkelVQGhxUSoYO8wnHTjbzgKnGYobwquC%2F%2FWTvsYVWWbb20rgc"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Server: cloudflare
                      CF-RAY: 8e7ff4fc2a165e82-EWR
                      alt-svc: h3=":443"; ma=86400
                      server-timing: cfL4;desc="?proto=TCP&rtt=1577&sent=6&recv=7&lost=0&retrans=0&sent_bytes=2861&recv_bytes=725&delivery_rate=1812538&cwnd=216&unsent_bytes=0&cid=03c982f71abf6517&ts=808&x=0"
                      2024-11-25 07:34:34 UTC5INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      15192.168.2.64993918.213.123.1654431444C:\Users\user\Desktop\t90RvrDNvz.exe
                      TimestampBytes transferredDirectionData
                      2024-11-25 07:34:36 UTC105OUTGET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1
                      Connection: Keep-Alive
                      Host: httpbin.org
                      2024-11-25 07:34:38 UTC232INHTTP/1.1 200 OK
                      Date: Mon, 25 Nov 2024 07:34:38 GMT
                      Content-Type: application/octet-stream
                      Content-Length: 10
                      Connection: close
                      Server: gunicorn/19.9.0
                      Access-Control-Allow-Origin: *
                      Access-Control-Allow-Credentials: true
                      2024-11-25 07:34:38 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:38 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:39 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:39 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:39 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:39 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:39 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:40 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:40 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:40 UTC1INData Raw: 2a
                      Data Ascii: *


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      16192.168.2.649963172.67.204.2374431444C:\Users\user\Desktop\t90RvrDNvz.exe
                      TimestampBytes transferredDirectionData
                      2024-11-25 07:34:45 UTC111OUTGET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1
                      Connection: Keep-Alive
                      Host: eth0.cdn-serveri2004-ns.shop
                      2024-11-25 07:34:46 UTC882INHTTP/1.1 302 Found
                      Date: Mon, 25 Nov 2024 07:34:46 GMT
                      Content-Type: text/html; charset=UTF-8
                      Transfer-Encoding: chunked
                      Connection: close
                      Cache-Control: no-store
                      Location: https://httpbin.org/drip?code=200&delay=2&duration=2&numbytes=10
                      cf-cache-status: DYNAMIC
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=TYC19sJyK3GrvTwdSrxlRMYmc5vrSPI1EL5uodkA9uEHU7S5Zouq4j1E2aYLvOnITlztq3o%2FXcwwTs2EGuM%2B9ed6Tefw0LJvETIME%2FVHLDOk%2BfGGpin9kUQXUZLJvaj0IyyASZxKpYnAKUtrTCXI"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Server: cloudflare
                      CF-RAY: 8e7ff54a1ce5429e-EWR
                      alt-svc: h3=":443"; ma=86400
                      server-timing: cfL4;desc="?proto=TCP&rtt=1596&sent=5&recv=6&lost=0&retrans=0&sent_bytes=2860&recv_bytes=725&delivery_rate=1777236&cwnd=192&unsent_bytes=0&cid=930ac95c2dfa93fa&ts=788&x=0"
                      2024-11-25 07:34:46 UTC5INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      17192.168.2.64996918.213.123.1654431444C:\Users\user\Desktop\t90RvrDNvz.exe
                      TimestampBytes transferredDirectionData
                      2024-11-25 07:34:47 UTC105OUTGET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1
                      Connection: Keep-Alive
                      Host: httpbin.org
                      2024-11-25 07:34:50 UTC232INHTTP/1.1 200 OK
                      Date: Mon, 25 Nov 2024 07:34:50 GMT
                      Content-Type: application/octet-stream
                      Content-Length: 10
                      Connection: close
                      Server: gunicorn/19.9.0
                      Access-Control-Allow-Origin: *
                      Access-Control-Allow-Credentials: true
                      2024-11-25 07:34:50 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:50 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:50 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:50 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:51 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:51 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:51 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:51 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:52 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:34:52 UTC1INData Raw: 2a
                      Data Ascii: *


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      18192.168.2.649992172.67.204.2374431444C:\Users\user\Desktop\t90RvrDNvz.exe
                      TimestampBytes transferredDirectionData
                      2024-11-25 07:34:57 UTC111OUTGET /c2dm/WSVUCGSKHE7PDXHDBW27/api.php HTTP/1.1
                      Connection: Keep-Alive
                      Host: eth0.cdn-serveri2004-ns.shop
                      2024-11-25 07:34:58 UTC880INHTTP/1.1 302 Found
                      Date: Mon, 25 Nov 2024 07:34:58 GMT
                      Content-Type: text/html; charset=UTF-8
                      Transfer-Encoding: chunked
                      Connection: close
                      Cache-Control: no-store
                      Location: https://httpbin.org/drip?code=200&delay=2&duration=2&numbytes=10
                      cf-cache-status: DYNAMIC
                      Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=3%2BxULBPHEQdALM2hdaC5JsNpRTAziaO9%2BZ%2FxttjZq0gAmcPV3kKdm7IMOOlElbHNz3RLMoK3hSxvcBh8Ovg6q0Lwbwop4la06OgnuaPk3Ukbrw1Bn67vMr0mc9HnWoggm2LGj3rNxprMYhi4y7WE"}],"group":"cf-nel","max_age":604800}
                      NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                      Server: cloudflare
                      CF-RAY: 8e7ff5931df54346-EWR
                      alt-svc: h3=":443"; ma=86400
                      server-timing: cfL4;desc="?proto=TCP&rtt=1590&sent=5&recv=7&lost=0&retrans=0&sent_bytes=2861&recv_bytes=725&delivery_rate=1849271&cwnd=252&unsent_bytes=0&cid=46e51ecc901e884a&ts=826&x=0"
                      2024-11-25 07:34:58 UTC5INData Raw: 30 0d 0a 0d 0a
                      Data Ascii: 0


                      Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                      19192.168.2.64999618.213.123.1654431444C:\Users\user\Desktop\t90RvrDNvz.exe
                      TimestampBytes transferredDirectionData
                      2024-11-25 07:34:59 UTC105OUTGET /drip?code=200&delay=2&duration=2&numbytes=10 HTTP/1.1
                      Connection: Keep-Alive
                      Host: httpbin.org
                      2024-11-25 07:35:03 UTC232INHTTP/1.1 200 OK
                      Date: Mon, 25 Nov 2024 07:35:02 GMT
                      Content-Type: application/octet-stream
                      Content-Length: 10
                      Connection: close
                      Server: gunicorn/19.9.0
                      Access-Control-Allow-Origin: *
                      Access-Control-Allow-Credentials: true
                      2024-11-25 07:35:03 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:35:03 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:35:03 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:35:03 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:35:03 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:35:04 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:35:04 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:35:04 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:35:05 UTC1INData Raw: 2a
                      Data Ascii: *
                      2024-11-25 07:35:05 UTC1INData Raw: 2a
                      Data Ascii: *


                      Click to jump to process

                      Click to jump to process

                      Click to dive into process behavior distribution

                      Target ID:0
                      Start time:02:33:04
                      Start date:25/11/2024
                      Path:C:\Users\user\Desktop\t90RvrDNvz.exe
                      Wow64 process (32bit):false
                      Commandline:"C:\Users\user\Desktop\t90RvrDNvz.exe"
                      Imagebase:0x400000
                      File size:26'869'672 bytes
                      MD5 hash:05CE896E3A0A78A9BF1F12A51D83D215
                      Has elevated privileges:true
                      Has administrator privileges:true
                      Programmed in:Borland Delphi
                      Reputation:low
                      Has exited:false

                      Reset < >

                        Execution Graph

                        Execution Coverage:15.5%
                        Dynamic/Decrypted Code Coverage:0%
                        Signature Coverage:4.4%
                        Total number of Nodes:206
                        Total number of Limit Nodes:7
                        execution_graph 1649 87dd46 1653 87dc7a 1649->1653 1650 87ab6b GlobalAlloc 1654 87de84 1650->1654 1651 87c3eb NtDelayExecution 1651->1653 1652 87ad3b GlobalAlloc 1652->1653 1653->1651 1653->1652 1655 87dd3f 1653->1655 1656 87ce0b GlobalAlloc 1653->1656 1657 87c71b GlobalAlloc 1654->1657 1662 87de0a 1654->1662 1655->1650 1655->1662 1656->1653 1658 87df6d 1657->1658 1659 87b8ab 2 API calls 1658->1659 1660 87dfba 1659->1660 1661 87c71b GlobalAlloc 1660->1661 1661->1662 1606 87a480 1608 87a494 1606->1608 1607 87a4d3 1608->1607 1610 87cd60 1608->1610 1612 87cd1d 1610->1612 1613 87cd55 1610->1613 1611 87ce0b GlobalAlloc 1611->1612 1612->1610 1612->1611 1612->1613 1613->1608 1614 880f00 1615 880f1c 1614->1615 1616 880f9b 1615->1616 1617 880f20 1615->1617 1619 87dea0 2 API calls 1616->1619 1621 87dea0 1617->1621 1620 880f2b 1619->1620 1622 87deb0 1621->1622 1623 87c71b GlobalAlloc 1622->1623 1624 87df6d 1623->1624 1625 87b8ab 2 API calls 1624->1625 1626 87dfba 1625->1626 1627 87c71b GlobalAlloc 1626->1627 1628 87e006 1627->1628 1628->1620 1636 8809a0 1637 880a80 GlobalAlloc 1636->1637 1638 8809b6 1637->1638 1663 880cc0 1666 87ddf0 1663->1666 1665 880cd5 1667 87de03 1666->1667 1668 87ab6b GlobalAlloc 1667->1668 1675 87de0a 1667->1675 1669 87de84 1668->1669 1670 87c71b GlobalAlloc 1669->1670 1669->1675 1671 87df6d 1670->1671 1672 87b8ab 2 API calls 1671->1672 1673 87dfba 1672->1673 1674 87c71b GlobalAlloc 1673->1674 1674->1675 1675->1665 1676 880b40 1678 880b5e 1676->1678 1680 87dca0 1678->1680 1679 880b80 1683 87dc7a 1680->1683 1681 87c3eb NtDelayExecution 1681->1683 1682 87ad3b GlobalAlloc 1682->1683 1683->1680 1683->1681 1683->1682 1684 87dd3f 1683->1684 1685 87ce0b GlobalAlloc 1683->1685 1686 87ab6b GlobalAlloc 1684->1686 1693 87de0a 1684->1693 1685->1683 1687 87de84 1686->1687 1688 87c71b GlobalAlloc 1687->1688 1687->1693 1689 87df6d 1688->1689 1690 87b8ab 2 API calls 1689->1690 1691 87dfba 1690->1691 1692 87c71b GlobalAlloc 1691->1692 1692->1693 1693->1679 1713 87b76b 1718 87acdb 1713->1718 1715 87b79b 1716 87bdcb 4 API calls 1715->1716 1717 87b7c3 1716->1717 1719 87c71b GlobalAlloc 1718->1719 1720 87acf5 1719->1720 1720->1715 1721 8802e7 1722 880660 1721->1722 1723 880a80 GlobalAlloc 1722->1723 1724 8808a4 1723->1724 1629 880a1e 1632 880a80 1629->1632 1631 880a3a 1634 880a99 1632->1634 1633 880ae2 1633->1631 1634->1633 1635 87cd60 GlobalAlloc 1634->1635 1635->1634 1643 8808bf 1644 8808e8 1643->1644 1645 880a80 GlobalAlloc 1644->1645 1646 88093a 1645->1646 1647 880a80 GlobalAlloc 1646->1647 1648 88096a 1647->1648 1725 87a4f0 1728 87a50e 1725->1728 1726 87a690 1727 87cd60 GlobalAlloc 1727->1728 1728->1726 1728->1727 1694 880c50 1695 880c67 1694->1695 1698 87dd80 1695->1698 1697 880ca5 1699 87ce0b GlobalAlloc 1698->1699 1701 87dc7a 1699->1701 1700 87dd3f 1702 87ab6b GlobalAlloc 1700->1702 1712 87de0a 1700->1712 1701->1700 1703 87c3eb NtDelayExecution 1701->1703 1704 87ad3b GlobalAlloc 1701->1704 1706 87ce0b GlobalAlloc 1701->1706 1705 87de84 1702->1705 1703->1701 1704->1701 1707 87c71b GlobalAlloc 1705->1707 1705->1712 1706->1701 1708 87df6d 1707->1708 1709 87b8ab 2 API calls 1708->1709 1710 87dfba 1709->1710 1711 87c71b GlobalAlloc 1710->1711 1711->1712 1712->1697 1494 87e11b 1497 87d13b 1494->1497 1496 87e12e 1498 87d1d2 1497->1498 1544 87c71b 1498->1544 1500 87d521 1547 87b47b 1500->1547 1502 87d540 1550 87b8ab 1502->1550 1504 87d55e 1505 87c71b GlobalAlloc 1504->1505 1506 87d672 1505->1506 1554 87b3db 1506->1554 1508 87d691 1509 87b8ab 2 API calls 1508->1509 1510 87d6a3 1509->1510 1557 87c7bb 1510->1557 1512 87d739 1514 87d781 1512->1514 1585 87c3eb 1512->1585 1564 87b53b 1514->1564 1516 87d848 1567 87bdcb CreateFileW 1516->1567 1518 87d875 1573 87ca7b 1518->1573 1520 87d8c0 1521 87da65 1520->1521 1522 87d9df 1520->1522 1524 87c71b GlobalAlloc 1521->1524 1538 87da60 1521->1538 1588 87cc6b 1522->1588 1526 87dacb 1524->1526 1528 87c71b GlobalAlloc 1526->1528 1527 87de0a 1527->1496 1529 87db83 1528->1529 1577 87b5ab 1529->1577 1530 87de84 1530->1527 1532 87c71b GlobalAlloc 1530->1532 1534 87df6d 1532->1534 1533 87dbfb 1535 87c71b GlobalAlloc 1533->1535 1533->1538 1536 87b8ab 2 API calls 1534->1536 1542 87dc67 1535->1542 1537 87dfba 1536->1537 1539 87c71b GlobalAlloc 1537->1539 1538->1527 1595 87ab6b 1538->1595 1539->1527 1540 87c3eb NtDelayExecution 1540->1542 1542->1538 1542->1540 1582 87ad3b 1542->1582 1592 87ce0b 1542->1592 1545 87c737 1544->1545 1546 87c74a GlobalAlloc 1544->1546 1545->1546 1546->1500 1548 87c71b GlobalAlloc 1547->1548 1549 87b49d 1548->1549 1549->1502 1551 87c71b GlobalAlloc 1550->1551 1552 87b8c5 1551->1552 1553 87b8d9 LoadLibraryExW 1552->1553 1553->1504 1555 87c71b GlobalAlloc 1554->1555 1556 87b3fd 1555->1556 1556->1508 1559 87c7de 1557->1559 1558 87c71b GlobalAlloc 1558->1559 1559->1558 1560 87c81c NtQuerySystemInformation 1559->1560 1563 87c807 1559->1563 1560->1559 1561 87c858 1560->1561 1562 87c71b GlobalAlloc 1561->1562 1562->1563 1563->1512 1565 87c71b GlobalAlloc 1564->1565 1566 87b55a 1565->1566 1566->1516 1568 87be27 1567->1568 1569 87be2e 1567->1569 1568->1518 1569->1568 1570 87c71b GlobalAlloc 1569->1570 1571 87be7b ReadFile 1570->1571 1571->1568 1572 87bec8 CloseHandle 1571->1572 1572->1568 1574 87ca9d 1573->1574 1575 87b8ab 2 API calls 1574->1575 1576 87cb7d 1575->1576 1576->1520 1578 87c71b GlobalAlloc 1577->1578 1579 87b5c0 1578->1579 1580 87c71b GlobalAlloc 1579->1580 1581 87b5e6 1580->1581 1581->1533 1598 87b09b 1582->1598 1584 87adaa 1584->1542 1604 87bf9b 1585->1604 1589 87ccad 1588->1589 1590 87cd55 1589->1590 1591 87ce0b GlobalAlloc 1589->1591 1590->1538 1591->1589 1593 87b5ab GlobalAlloc 1592->1593 1594 87ce2d 1593->1594 1594->1542 1596 87c71b GlobalAlloc 1595->1596 1597 87ab93 1596->1597 1597->1530 1600 87b0bd 1598->1600 1599 87b0c8 1599->1584 1600->1599 1601 87c71b GlobalAlloc 1600->1601 1602 87b1f6 1601->1602 1603 87c71b GlobalAlloc 1602->1603 1603->1599 1605 87bfb2 NtDelayExecution 1604->1605 1605->1512

                        Callgraph

                        • Executed
                        • Not Executed
                        • Opacity -> Relevance
                        • Disassembly available
                        callgraph 0 Function_0087A480 94 Function_0087CD50 0->94 106 Function_0087CD60 0->106 1 Function_0087A780 37 Function_0087A7D0 1->37 53 Function_0087A7F0 1->53 2 Function_0087DD80 13 Function_0087B29B 2->13 18 Function_0087B8AB 2->18 30 Function_0087B2BB 2->30 42 Function_0087B7DB 2->42 43 Function_0087BCDB 2->43 45 Function_0087D0DB 2->45 48 Function_0087C3EB 2->48 58 Function_0087B8FB 2->58 66 Function_0087CE0B 2->66 71 Function_0087C71B 2->71 83 Function_0087AD3B 2->83 98 Function_0087BD5B 2->98 99 Function_0087C05B 2->99 112 Function_0087AB6B 2->112 115 Function_0087C57B 2->115 3 Function_00880A80 3->94 3->106 4 Function_0087EB8E 5 Function_0087B68B 11 Function_0087CE9B 5->11 5->98 6 Function_0087C48B 78 Function_0087BD1B 6->78 84 Function_0087C13B 6->84 7 Function_0087A090 8 Function_0087A290 9 Function_0087AF9D 10 Function_0087BF9B 12 Function_0087B09B 12->71 12->78 12->98 14 Function_0087E69B 14->14 15 Function_0087DCA0 15->13 15->18 15->30 15->42 15->43 15->45 15->48 15->58 15->66 15->71 15->83 15->98 15->99 15->112 15->115 16 Function_0087DEA0 16->18 16->42 16->43 16->45 16->71 16->98 16->99 16->115 17 Function_008809A0 17->3 34 Function_0087C0CB 18->34 18->71 19 Function_0087ACAB 19->10 20 Function_0087B5AB 20->19 29 Function_0087C1BB 20->29 20->71 21 Function_0087CFAB 97 Function_0087E25B 21->97 22 Function_0087C6AB 22->78 23 Function_0087C9AB 23->14 24 Function_0087A3A8 25 Function_008809BC 25->3 26 Function_008808BF 26->3 27 Function_0087C2BB 28 Function_0087C7BB 28->6 28->10 28->71 120 Function_0087BA7B 28->120 30->78 31 Function_0087D0BB 32 Function_00880CC0 54 Function_0087DDF0 32->54 33 Function_0087E2CB 34->78 35 Function_0087E1CB 36 Function_0087BDCB 36->71 70 Function_0087A810 37->70 38 Function_0087C5DB 39 Function_0087ACDB 39->27 39->71 40 Function_0087E7DB 41 Function_0087EADB 41->10 41->98 117 Function_0087E87B 41->117 101 Function_0087E75B 42->101 44 Function_0087B3DB 57 Function_0087BEFB 44->57 44->71 44->98 44->99 46 Function_0087A3E0 47 Function_0087A6E0 48->10 49 Function_008802E7 49->3 50 Function_00880BFB 51 Function_0087EDF3 52 Function_0087A4F0 52->47 52->94 52->106 54->18 54->42 54->43 54->45 54->71 54->98 54->99 54->112 54->115 55 Function_00880AF1 56 Function_0087BFFB 57->43 57->56 59 Function_0087BAFB 60 Function_0087BBFB 60->84 61 Function_008809F5 62 Function_0087A3F8 63 Function_0087A000 64 Function_00880F00 64->16 65 Function_0087EC0C 66->20 66->38 114 Function_0087C77B 66->114 116 Function_0087E37B 66->116 67 Function_0087AC0B 68 Function_0087C50B 68->43 69 Function_00880A1E 69->3 72 Function_0087E11B 86 Function_0087D13B 72->86 73 Function_0087D11B 74 Function_0087E71B 75 Function_0087C31B 76 Function_0087CA1B 77 Function_0087BB1B 77->31 77->60 79 Function_0087B51B 80 Function_00880B20 81 Function_00880C32 82 Function_0087C43B 82->34 82->78 83->12 83->99 85 Function_0087B53B 85->71 85->115 86->5 86->13 86->18 86->20 86->23 86->28 86->30 86->36 86->42 86->43 86->44 86->45 86->48 86->58 86->66 86->71 86->77 86->83 86->85 86->98 86->99 102 Function_0087B95B 86->102 111 Function_0087CC6B 86->111 86->112 86->115 118 Function_0087B27B 86->118 119 Function_0087B47B 86->119 86->120 122 Function_0087CA7B 86->122 87 Function_0087E13B 88 Function_0087EE39 89 Function_0087DD46 89->13 89->18 89->30 89->42 89->43 89->45 89->48 89->58 89->66 89->71 89->83 89->98 89->99 89->112 89->115 90 Function_0087EC46 91 Function_00880B40 91->15 92 Function_0087BF4B 92->43 92->68 93 Function_0087A756 95 Function_0087AB50 96 Function_00880C50 96->2 97->35 99->43 100 Function_0087B25B 101->43 101->74 102->45 102->101 103 Function_0087ED5B 104 Function_00880A55 105 Function_0087A261 106->11 106->66 106->76 107 Function_0087A06B 108 Function_0087B66B 109 Function_0087B76B 109->29 109->36 109->39 110 Function_0087BC6B 121 Function_0087C17B 110->121 111->10 111->11 111->66 111->76 111->98 112->41 112->71 113 Function_0087CF6A 116->10 116->21 116->87 119->57 119->71 119->98 119->99 120->74 120->78 122->10 122->18 122->102 123 Function_0087EE78

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 13 87c7bb-87c7d6 14 87c7de-87c7e3 13->14 15 87c993-87c997 14->15 16 87c7e9-87c805 call 87c71b 14->16 19 87c807 16->19 20 87c80c-87c84a call 87bf9b NtQuerySystemInformation 16->20 19->15 23 87c84c-87c856 20->23 24 87c858-87c87c call 87c71b 20->24 23->14 27 87c880-87c888 24->27 28 87c88e-87c898 27->28 29 87c98c 27->29 30 87c970-87c987 28->30 31 87c89e-87c8c4 call 87bf9b 28->31 29->15 30->27 34 87c8d0-87c8d8 31->34 35 87c90b-87c942 call 87c48b call 87ba7b 34->35 36 87c8da-87c8ea 34->36 43 87c944-87c94f 35->43 44 87c951-87c963 35->44 36->35 37 87c8ec-87c909 36->37 37->34 43->30 44->30 45 87c965-87c96d 44->45 45->30
                        APIs
                          • Part of subcall function 0087C71B: GlobalAlloc.KERNELBASE ref: 0087C764
                        • NtQuerySystemInformation.NTDLL ref: 0087C83F
                        Memory Dump Source
                        • Source File: 00000000.00000002.3391193513.000000000087A000.00000020.00000001.01000000.00000003.sdmp, Offset: 0087A000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_87a000_t90RvrDNvz.jbxd
                        Similarity
                        • API ID: AllocGlobalInformationQuerySystem
                        • String ID:
                        • API String ID: 3737350999-0
                        • Opcode ID: 2c2e1b94ccae692e9845cdce1a74e634185cc8c57d145ea3b73e9c048b3ae931
                        • Instruction ID: f6c76592d22a96d4037c69e842e85df42ae5dcab228c5d997eeb3086835044c2
                        • Opcode Fuzzy Hash: 2c2e1b94ccae692e9845cdce1a74e634185cc8c57d145ea3b73e9c048b3ae931
                        • Instruction Fuzzy Hash: A451AE70618B888FC394EB2CC484B6ABBE1FB98345F50896DF58DC3264DB74D980CB42

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 51 87c3eb-87c42d call 87bf9b NtDelayExecution
                        APIs
                        Memory Dump Source
                        • Source File: 00000000.00000002.3391193513.000000000087A000.00000020.00000001.01000000.00000003.sdmp, Offset: 0087A000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_87a000_t90RvrDNvz.jbxd
                        Similarity
                        • API ID: DelayExecution
                        • String ID:
                        • API String ID: 1249177460-0
                        • Opcode ID: eb39c1d72cbe717bc85fca09b74d458cc1ecfe8a19ab4362ccb154eff7b4d154
                        • Instruction ID: bea07ff878a7e0f3c9803b5a3905d7fe5fe5e5b03164ae5baaef54e3eb0d0a5f
                        • Opcode Fuzzy Hash: eb39c1d72cbe717bc85fca09b74d458cc1ecfe8a19ab4362ccb154eff7b4d154
                        • Instruction Fuzzy Hash: 53E0E530408B458BC704EF28C44914ABBE0FBD8214F808B1EF499D61A0DB79C2098B42

                        Control-flow Graph

                        APIs
                        Memory Dump Source
                        • Source File: 00000000.00000002.3391193513.000000000087A000.00000020.00000001.01000000.00000003.sdmp, Offset: 0087A000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_87a000_t90RvrDNvz.jbxd
                        Similarity
                        • API ID: CreateFile
                        • String ID:
                        • API String ID: 823142352-0
                        • Opcode ID: 1b9ca64b6430e35908f15df3b6d45bcbbbc675b5257bb09dcee137a8955b3737
                        • Instruction ID: bb3dc0bf853825555a397f8288fed7a09d565e5cce377e41af48e8fd5d868265
                        • Opcode Fuzzy Hash: 1b9ca64b6430e35908f15df3b6d45bcbbbc675b5257bb09dcee137a8955b3737
                        • Instruction Fuzzy Hash: A531C530118B488FDB94DF28C498B6ABBF1FF99345F50496DE189C3260CB75D845CB02

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 46 87b8ab-87b8f4 call 87c71b call 87c0cb LoadLibraryExW
                        APIs
                          • Part of subcall function 0087C71B: GlobalAlloc.KERNELBASE ref: 0087C764
                        • LoadLibraryExW.KERNELBASE ref: 0087B8E3
                        Memory Dump Source
                        • Source File: 00000000.00000002.3391193513.000000000087A000.00000020.00000001.01000000.00000003.sdmp, Offset: 0087A000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_87a000_t90RvrDNvz.jbxd
                        Similarity
                        • API ID: AllocGlobalLibraryLoad
                        • String ID:
                        • API String ID: 3361179946-0
                        • Opcode ID: f19f65336d6bf89c575e026b19d1e6ffc759ff68260c591b755dcf2ac8b3e4d3
                        • Instruction ID: 20eff9beefd7556c31b5b4bc3f09812d3ca2352c1b8b4b9756fbf8c9c13c0db5
                        • Opcode Fuzzy Hash: f19f65336d6bf89c575e026b19d1e6ffc759ff68260c591b755dcf2ac8b3e4d3
                        • Instruction Fuzzy Hash: 82F09870518A488F8684EF1CC448A1ABBE1FBD8355F504A2DA48CD3234CB35D944CB42

                        Control-flow Graph

                        • Executed
                        • Not Executed
                        control_flow_graph 54 87c71b-87c735 55 87c737-87c746 54->55 56 87c74a-87c76e GlobalAlloc 54->56 55->56
                        APIs
                        Memory Dump Source
                        • Source File: 00000000.00000002.3391193513.000000000087A000.00000020.00000001.01000000.00000003.sdmp, Offset: 0087A000, based on PE: false
                        Joe Sandbox IDA Plugin
                        • Snapshot File: hcaresult_0_2_87a000_t90RvrDNvz.jbxd
                        Similarity
                        • API ID: AllocGlobal
                        • String ID:
                        • API String ID: 3761449716-0
                        • Opcode ID: ba1b9466268fe03848d5d9d10af9dd6cf040b6a4df980d2f73a2bd1ec1c171d8
                        • Instruction ID: 84b6eb4d5f7fd24f2af21fe74643d858a0fb54b32e1b5a907ba47e51dea684e9
                        • Opcode Fuzzy Hash: ba1b9466268fe03848d5d9d10af9dd6cf040b6a4df980d2f73a2bd1ec1c171d8
                        • Instruction Fuzzy Hash: DEF048346086488FCB84EB28C488A1ABBF1FB99314F504A6DE58DD7261D736E985CB02