Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
file.exe

Overview

General Information

Sample name:file.exe
Analysis ID:1562677
MD5:96a7b754ca8e8f35ae9e2b88b9f25658
SHA1:ed24a27a726b87c1d5bf1da60527e5801603bb8e
SHA256:21d262741b3661b4bf1569f744dc5b5e6119cfa4f0748b9c0fa240f75442cc50
Tags:exeuser-Bitsight
Infos:

Detection

DarkTortilla, RHADAMANTHYS
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Found malware configuration
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected AntiVM3
Yara detected DarkTortilla Crypter
Yara detected RHADAMANTHYS Stealer
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
AI detected suspicious sample
Allocates memory in foreign processes
C2 URLs / IPs found in malware configuration
Contains functionality to check if a debugger is running (CheckRemoteDebuggerPresent)
Hides that the sample has been downloaded from the Internet (zone.identifier)
Injects a PE file into a foreign processes
Machine Learning detection for dropped file
Machine Learning detection for sample
Switches to a custom stack to bypass stack traces
Tries to delay execution (extensive OutputDebugStringW loop)
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Writes to foreign memory regions
AV process strings found (often used to terminate AV products)
Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Checks if the current process is being debugged
Contains functionality to call native functions
Contains functionality to dynamically determine API calls
Contains functionality to launch a process as a different user
Contains functionality to read the PEB
Contains functionality to shutdown / reboot the system
Contains long sleeps (>= 3 min)
Creates a DirectInput object (often for capturing keystrokes)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found evasive API chain checking for process token information
Found inlined nop instructions (likely shell or obfuscated code)
Installs a raw input device (often for capturing keystrokes)
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
One or more processes crash
PE file contains executable resources (Code or Archives)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Sigma detected: CurrentVersion Autorun Keys Modification
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)
Yara detected Keylogger Generic

Classification

  • System is w10x64
  • file.exe (PID: 7472 cmdline: "C:\Users\user\Desktop\file.exe" MD5: 96A7B754CA8E8F35AE9E2B88B9F25658)
    • computerlead.exe (PID: 7492 cmdline: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe MD5: 2354E800EEFC681A7D60F3B6B28ACFD9)
      • rundll32.exe (PID: 1340 cmdline: "C:\Windows\system32\rundll32.exe" C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\user\AppData\Local\Temp\IXP000.TMP\" MD5: EF3179D498793BF4234F708D3BE28633)
      • AddInProcess32.exe (PID: 380 cmdline: "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe" MD5: 9827FF3CDF4B83F9C86354606736CA9C)
      • AddInProcess32.exe (PID: 3200 cmdline: "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe" MD5: 9827FF3CDF4B83F9C86354606736CA9C)
      • AddInProcess32.exe (PID: 1340 cmdline: "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe" MD5: 9827FF3CDF4B83F9C86354606736CA9C)
      • AddInProcess32.exe (PID: 884 cmdline: "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe" MD5: 9827FF3CDF4B83F9C86354606736CA9C)
        • fontdrvhost.exe (PID: 7916 cmdline: "C:\Windows\System32\fontdrvhost.exe" MD5: 8D0DA0C5DCF1A14F9D65F5C0BEA53F3D)
          • fontdrvhost.exe (PID: 8124 cmdline: "C:\Windows\System32\fontdrvhost.exe" MD5: BBCB897697B3442657C7D6E3EDDBD25F)
            • WerFault.exe (PID: 6528 cmdline: C:\Windows\system32\WerFault.exe -u -p 8124 -s 136 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0)
        • WerFault.exe (PID: 8092 cmdline: C:\Windows\SysWOW64\WerFault.exe -u -p 884 -s 420 MD5: C31336C1EFC2CCB44B4326EA793040F2)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
DarkTortillaDarkTortilla is a complex and highly configurable .NET-based crypter that has possibly been active since at least August 2015. It typically delivers popular information stealers and remote access trojans (RATs) such as AgentTesla, AsyncRat, NanoCore, and RedLine. While it appears to primarily deliver commodity malware, Secureworks Counter Threat Unit (CTU) researchers identified DarkTortilla samples delivering targeted payloads such as Cobalt Strike and Metasploit. It can also deliver "addon packages" such as additional malicious payloads, benign decoy documents, and executables. It features robust anti-analysis and anti-tamper controls that can make detection, analysis, and eradication challenging.From January 2021 through May 2022, an average of 93 unique DarkTortilla samples per week were uploaded to the VirusTotal analysis service. Code similarities suggest possible links between DarkTortilla and other malware: a crypter operated by the RATs Crew threat group, which was active between 2008 and 2012, and the Gameloader malware that emerged in 2021.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.darktortilla
NameDescriptionAttributionBlogpost URLsLink
RhadamanthysAccording to PCrisk, Rhadamanthys is a stealer-type malware, and as its name implies - it is designed to extract data from infected machines.At the time of writing, this malware is spread through malicious websites mirroring those of genuine software such as AnyDesk, Zoom, Notepad++, and others. Rhadamanthys is downloaded alongside the real program, thus diminishing immediate user suspicion. These sites were promoted through Google ads, which superseded the legitimate search results on the Google search user.
  • Sandworm
https://malpedia.caad.fkie.fraunhofer.de/details/win.rhadamanthys
{"C2 url": "https://104.37.175.218:7982/da03ab84e7f8187e6/o304l70l.g00ox"}
SourceRuleDescriptionAuthorStrings
00000001.00000002.2938052510.00000000056B0000.00000004.08000000.00040000.00000000.sdmpJoeSecurity_DarkTortillaYara detected DarkTortilla CrypterJoe Security
    00000012.00000003.2941844125.0000000000760000.00000004.00001000.00020000.00000000.sdmpJoeSecurity_RHADAMANTHYSYara detected RHADAMANTHYS StealerJoe Security
      00000012.00000003.2946060481.0000000004D00000.00000004.00000001.00020000.00000000.sdmpJoeSecurity_Keylogger_GenericYara detected Keylogger GenericJoe Security
        00000012.00000002.3046180127.0000000000A30000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_RHADAMANTHYSYara detected RHADAMANTHYS StealerJoe Security
          00000012.00000003.2945665948.0000000004AE0000.00000004.00000001.00020000.00000000.sdmpJoeSecurity_Keylogger_GenericYara detected Keylogger GenericJoe Security
            Click to see the 5 entries
            SourceRuleDescriptionAuthorStrings
            1.2.computerlead.exe.56b0000.2.unpackJoeSecurity_DarkTortillaYara detected DarkTortilla CrypterJoe Security
              1.2.computerlead.exe.56b0000.2.raw.unpackJoeSecurity_DarkTortillaYara detected DarkTortilla CrypterJoe Security
                18.3.fontdrvhost.exe.4ae0000.0.unpackJoeSecurity_Keylogger_GenericYara detected Keylogger GenericJoe Security
                  18.3.fontdrvhost.exe.4ae0000.2.unpackJoeSecurity_Keylogger_GenericYara detected Keylogger GenericJoe Security
                    18.3.fontdrvhost.exe.4d00000.7.raw.unpackJoeSecurity_Keylogger_GenericYara detected Keylogger GenericJoe Security
                      Click to see the 2 entries
                      Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\user\AppData\Local\Temp\IXP000.TMP\", EventID: 13, EventType: SetValue, Image: C:\Users\user\Desktop\file.exe, ProcessId: 7472, TargetObject: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\wextract_cleanup0
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2024-11-25T21:35:29.048247+010028548021Domain Observed Used for C2 Detected104.37.175.2187982192.168.2.649910TCP

                      Click to jump to signature section

                      Show All Signature Results

                      AV Detection

                      barindex
                      Source: file.exeAvira: detected
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeAvira: detection malicious, Label: HEUR/AGEN.1358047
                      Source: 00000001.00000002.2936405362.00000000044F8000.00000004.00000800.00020000.00000000.sdmpMalware Configuration Extractor: Rhadamanthys {"C2 url": "https://104.37.175.218:7982/da03ab84e7f8187e6/o304l70l.g00ox"}
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeReversingLabs: Detection: 34%
                      Source: file.exeReversingLabs: Detection: 31%
                      Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeJoe Sandbox ML: detected
                      Source: file.exeJoe Sandbox ML: detected
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E046E8 GetSystemDirectoryA,LoadLibraryA,GetProcAddress,DecryptFileA,FreeLibrary,GetWindowsDirectoryA,SetCurrentDirectoryA,0_2_00007FF7E5E046E8
                      Source: file.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
                      Source: Binary string: wextract.pdb source: file.exe
                      Source: Binary string: wextract.pdbGCTL source: file.exe
                      Source: Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.SetRVA source: computerlead.exe, 00000001.00000002.2938052510.00000000056B0000.00000004.08000000.00040000.00000000.sdmp
                      Source: Binary string: wkernel32.pdb source: fontdrvhost.exe, 00000012.00000003.2945316096.0000000004C00000.00000004.00000001.00020000.00000000.sdmp, fontdrvhost.exe, 00000012.00000003.2945134717.0000000004AE0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: wkernelbase.pdb source: fontdrvhost.exe, 00000012.00000003.2945665948.0000000004AE0000.00000004.00000001.00020000.00000000.sdmp, fontdrvhost.exe, 00000012.00000003.2946060481.0000000004D00000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: ntdll.pdb source: fontdrvhost.exe, 00000012.00000003.2943041755.0000000004AE0000.00000004.00000001.00020000.00000000.sdmp, fontdrvhost.exe, 00000012.00000003.2943531107.0000000004CD0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: wntdll.pdbUGP source: fontdrvhost.exe, 00000012.00000003.2944071441.0000000004AE0000.00000004.00000001.00020000.00000000.sdmp, fontdrvhost.exe, 00000012.00000003.2944366502.0000000004C80000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: ntdll.pdbUGP source: fontdrvhost.exe, 00000012.00000003.2943041755.0000000004AE0000.00000004.00000001.00020000.00000000.sdmp, fontdrvhost.exe, 00000012.00000003.2943531107.0000000004CD0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: wntdll.pdb source: fontdrvhost.exe, 00000012.00000003.2944071441.0000000004AE0000.00000004.00000001.00020000.00000000.sdmp, fontdrvhost.exe, 00000012.00000003.2944366502.0000000004C80000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: wkernel32.pdbUGP source: fontdrvhost.exe, 00000012.00000003.2945316096.0000000004C00000.00000004.00000001.00020000.00000000.sdmp, fontdrvhost.exe, 00000012.00000003.2945134717.0000000004AE0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: wkernelbase.pdbUGP source: fontdrvhost.exe, 00000012.00000003.2945665948.0000000004AE0000.00000004.00000001.00020000.00000000.sdmp, fontdrvhost.exe, 00000012.00000003.2946060481.0000000004D00000.00000004.00000001.00020000.00000000.sdmp
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E026B8 FindFirstFileA,lstrcmpA,lstrcmpA,SetFileAttributesA,DeleteFileA,FindNextFileA,FindClose,RemoveDirectoryA,0_2_00007FF7E5E026B8
                      Source: C:\Windows\System32\fontdrvhost.exeCode function: 4x nop then dec esp22_2_000001BE066E0511

                      Networking

                      barindex
                      Source: Network trafficSuricata IDS: 2854802 - Severity 1 - ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert : 104.37.175.218:7982 -> 192.168.2.6:49910
                      Source: Malware configuration extractorURLs: https://104.37.175.218:7982/da03ab84e7f8187e6/o304l70l.g00ox
                      Source: global trafficTCP traffic: 192.168.2.6:49910 -> 104.37.175.218:7982
                      Source: Joe Sandbox ViewASN Name: MAJESTIC-HOSTING-01US MAJESTIC-HOSTING-01US
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: unknownTCP traffic detected without corresponding DNS query: 104.37.175.218
                      Source: Amcache.hve.24.drString found in binary or memory: http://upx.sf.net
                      Source: fontdrvhost.exe, fontdrvhost.exe, 00000016.00000002.3129592218.000001BE066E0000.00000040.00000001.00020000.00000000.sdmpString found in binary or memory: https://104.37.175.218:7982/da03ab84e7f8187e6/o304l70l.g00ox
                      Source: fontdrvhost.exe, 00000012.00000003.3045309813.0000000004DBB000.00000004.00000020.00020000.00000000.sdmp, fontdrvhost.exe, 00000016.00000002.3129592218.000001BE066E0000.00000040.00000001.00020000.00000000.sdmpString found in binary or memory: https://104.37.175.218:7982/da03ab84e7f8187e6/o304l70l.g00oxkernelbasentdllkernel32GetProcessMitigat
                      Source: fontdrvhost.exe, 00000012.00000002.3045753092.000000000038C000.00000004.00000010.00020000.00000000.sdmpString found in binary or memory: https://104.37.175.218:7982/da03ab84e7f8187e6/o304l70l.g00oxx
                      Source: fontdrvhost.exe, 00000012.00000003.2975846507.0000000004A4B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cloudflare-dns.com/dns-query
                      Source: fontdrvhost.exe, 00000012.00000003.2975846507.0000000004A4B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cloudflare-dns.com/dns-queryPOSTContent-TypeContent-LengthHostapplication/dns-message%dMachi
                      Source: fontdrvhost.exe, 00000012.00000003.2945665948.0000000004AE0000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: DirectInput8Creatememstr_5d029216-b
                      Source: fontdrvhost.exe, 00000012.00000003.2945665948.0000000004AE0000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: GetRawInputDatamemstr_817dd6f5-0
                      Source: Yara matchFile source: 18.3.fontdrvhost.exe.4ae0000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 18.3.fontdrvhost.exe.4ae0000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 18.3.fontdrvhost.exe.4d00000.7.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 18.3.fontdrvhost.exe.4ae0000.6.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 18.3.fontdrvhost.exe.4ae0000.6.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000012.00000003.2946060481.0000000004D00000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000012.00000003.2945665948.0000000004AE0000.00000004.00000001.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: fontdrvhost.exe PID: 7916, type: MEMORYSTR
                      Source: C:\Windows\System32\fontdrvhost.exeCode function: 22_2_000001BE066E1AA4 NtAcceptConnectPort,NtAcceptConnectPort,22_2_000001BE066E1AA4
                      Source: C:\Windows\System32\fontdrvhost.exeCode function: 22_2_000001BE066E1CF4 NtAcceptConnectPort,CloseHandle,22_2_000001BE066E1CF4
                      Source: C:\Windows\System32\fontdrvhost.exeCode function: 22_2_000001BE066E0AC8 NtAcceptConnectPort,NtAcceptConnectPort,22_2_000001BE066E0AC8
                      Source: C:\Windows\System32\fontdrvhost.exeCode function: 22_2_000001BE066E15C0 NtAcceptConnectPort,22_2_000001BE066E15C0
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B7DDE8 CreateProcessAsUserW,1_2_08B7DDE8
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E07FE4 GetVersion,GetModuleHandleW,GetProcAddress,ExitWindowsEx,CloseHandle,0_2_00007FF7E5E07FE4
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E033BC GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,CloseHandle,ExitWindowsEx,0_2_00007FF7E5E033BC
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E058100_2_00007FF7E5E05810
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E01A080_2_00007FF7E5E01A08
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E04BE00_2_00007FF7E5E04BE0
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E05B500_2_00007FF7E5E05B50
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E0521C0_2_00007FF7E5E0521C
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E0721C0_2_00007FF7E5E0721C
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E04BDE0_2_00007FF7E5E04BDE
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E033BC0_2_00007FF7E5E033BC
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E078AE0_2_00007FF7E5E078AE
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_018046A01_2_018046A0
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_031B0DB01_2_031B0DB0
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_031B2F401_2_031B2F40
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_0799D7981_2_0799D798
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_0799C7001_2_0799C700
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_0799EC301_2_0799EC30
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_079904601_2_07990460
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_0799E3A81_2_0799E3A8
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_079909291_2_07990929
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_0799D7871_2_0799D787
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_0799EF701_2_0799EF70
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_079936901_2_07993690
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_0799C6F91_2_0799C6F9
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_079936791_2_07993679
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_0799EC201_2_0799EC20
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_079984481_2_07998448
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_0799E3661_2_0799E366
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B76CE01_2_08B76CE0
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B7CCE81_2_08B7CCE8
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B790581_2_08B79058
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B700401_2_08B70040
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B735A81_2_08B735A8
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B785181_2_08B78518
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B70EE01_2_08B70EE0
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B7E6701_2_08B7E670
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B7E3681_2_08B7E368
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B728A81_2_08B728A8
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B728991_2_08B72899
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B77CF81_2_08B77CF8
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B77CE81_2_08B77CE8
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B76CD21_2_08B76CD2
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B740DD1_2_08B740DD
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B700061_2_08B70006
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B734001_2_08B73400
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B714601_2_08B71460
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B790481_2_08B79048
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B71DB91_2_08B71DB9
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B735A21_2_08B735A2
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B731881_2_08B73188
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B71DC81_2_08B71DC8
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B7ED081_2_08B7ED08
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B785081_2_08B78508
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B731781_2_08B73178
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B741581_2_08B74158
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B7AD481_2_08B7AD48
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B7C6A81_2_08B7C6A8
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B70E011_2_08B70E01
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B72BA81_2_08B72BA8
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B72B981_2_08B72B98
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B733F21_2_08B733F2
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B72F501_2_08B72F50
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B72F411_2_08B72F41
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_08B7BF401_2_08B7BF40
                      Source: C:\Windows\System32\fontdrvhost.exeCode function: 22_2_000001BE066E0C7022_2_000001BE066E0C70
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 884 -s 420
                      Source: file.exeStatic PE information: Resource name: RT_RCDATA type: Microsoft Cabinet archive data, Windows 2000/XP setup, 821649 bytes, 1 file, at 0x2c +A "computerlead.exe", ID 1653, number 1, 36 datablocks, 0x1503 compression
                      Source: file.exeBinary or memory string: OriginalFilename vs file.exe
                      Source: file.exeBinary or memory string: OriginalFilenameWEXTRACT.EXE .MUID vs file.exe
                      Source: computerlead.exe.0.drStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                      Source: computerlead.exe.0.dr, La53Z.csCryptographic APIs: 'CreateDecryptor', 'TransformFinalBlock'
                      Source: computerlead.exe, 00000001.00000002.2936405362.00000000044F8000.00000004.00000800.00020000.00000000.sdmp, computerlead.exe, 00000001.00000002.2936405362.00000000042E1000.00000004.00000800.00020000.00000000.sdmp, computerlead.exe, 00000001.00000002.2936405362.00000000045CF000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 0000000D.00000002.2551601895.0000000000399000.00000040.00000400.00020000.00000000.sdmpBinary or memory string: .a_po^ ojYd.o B U.R G v.Q_F& ZNH K.9.sV`OQ qOq_A( N5.j P.X z.k.Yf_HL.P.L`.C Ue_q_B_t.h{_yr\=A f.3_q_Fvb_H_bm W.UP#.by_iY.Yw I.Y_G p.3c g.Zy S v.U.N C_m Z_i.H_j B l_DH_Pd.iz_O.f~ U z_Mv_d7 T Mz.f.594/}_m kS.v.D u.rZu.S G.N_x.V J.Q.G FO^.X<.6_fv.V ny.L,_E.2.m I_l.b$ Mx sZ.K! p.Y.U.V:U.89 R_H F3.d_R A UQ.C_y y Y Jb.Q_S.N.s< l_Ab~[_w9zV?!C9.N_HQ)*_n R.tP Ww_u aU;.V EPk Xr.Q0.y.A!]_b!7 g.R_pF.E_b o.o.q.o_E.T_rdfw.c}_ck.4.Y_w:_P.B(#`_xy_i.3_Y.A_N.q.6.YE_S_T.R H n.R_d_F.V.s_R68).I aL q.H b.W.Q!.r b_w c c$_va.X_v.tRm l.sln_D c! C.7_F m M_j6 zr.w F i}%_N.RB A7_wG_m.4_A#&.G mCx.Q_s N pTS.n.e C.4_v_C_Q.e J q7E V P.LP_Q.kTN_c.F.D gc.hT_s_Q1
                      Source: computerlead.exe, 00000001.00000002.2936405362.00000000044F8000.00000004.00000800.00020000.00000000.sdmp, computerlead.exe, 00000001.00000002.2936405362.00000000042E1000.00000004.00000800.00020000.00000000.sdmp, computerlead.exe, 00000001.00000002.2936405362.00000000045CF000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 0000000D.00000002.2551601895.0000000000399000.00000040.00000400.00020000.00000000.sdmpBinary or memory string: .tRm l.sln_D c! C.7_F m M_j6 zr.w F i}%_N.RB A7_wG_m.4_A#&.G mCx.Q_s N pTS.n.e C.4_v_
                      Source: classification engineClassification label: mal100.troj.evad.winEXE@18/7@0/1
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E07010 CreateProcessA,WaitForSingleObject,GetExitCodeProcess,CloseHandle,CloseHandle,GetLastError,FormatMessageA,0_2_00007FF7E5E07010
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E033BC GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,CloseHandle,ExitWindowsEx,0_2_00007FF7E5E033BC
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E05B50 GetCurrentDirectoryA,SetCurrentDirectoryA,GetDiskFreeSpaceA,MulDiv,GetVolumeInformationA,memset,GetLastError,FormatMessageA,SetCurrentDirectoryA,memset,GetLastError,FormatMessageA,SetCurrentDirectoryA,0_2_00007FF7E5E05B50
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E05810 memset,memset,CreateEventA,SetEvent,CreateMutexA,GetLastError,CloseHandle,FindResourceExA,LoadResource,#17,0_2_00007FF7E5E05810
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeFile created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\computerlead.exe.logJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMutant created: NULL
                      Source: C:\Windows\System32\WerFault.exeMutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess8124
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeMutant created: \Sessions\1\BaseNamedObjects\MSCTF.Asm.{00000009-b94d4e13-ee73-4f205d-6f5803211868}
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\IXP000.TMPJump to behavior
                      Source: file.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_Processor
                      Source: C:\Users\user\Desktop\file.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess created: C:\Windows\System32\rundll32.exe "C:\Windows\system32\rundll32.exe" C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\user\AppData\Local\Temp\IXP000.TMP\"
                      Source: file.exeReversingLabs: Detection: 31%
                      Source: unknownProcess created: C:\Users\user\Desktop\file.exe "C:\Users\user\Desktop\file.exe"
                      Source: C:\Users\user\Desktop\file.exeProcess created: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess created: C:\Windows\System32\rundll32.exe "C:\Windows\system32\rundll32.exe" C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\user\AppData\Local\Temp\IXP000.TMP\"
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess created: C:\Windows\SysWOW64\fontdrvhost.exe "C:\Windows\System32\fontdrvhost.exe"
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 884 -s 420
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeProcess created: C:\Windows\System32\fontdrvhost.exe "C:\Windows\System32\fontdrvhost.exe"
                      Source: C:\Windows\System32\fontdrvhost.exeProcess created: C:\Windows\System32\WerFault.exe C:\Windows\system32\WerFault.exe -u -p 8124 -s 136
                      Source: C:\Users\user\Desktop\file.exeProcess created: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess created: C:\Windows\System32\rundll32.exe "C:\Windows\system32\rundll32.exe" C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\user\AppData\Local\Temp\IXP000.TMP\"Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess created: C:\Windows\SysWOW64\fontdrvhost.exe "C:\Windows\System32\fontdrvhost.exe"Jump to behavior
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeProcess created: C:\Windows\System32\fontdrvhost.exe "C:\Windows\System32\fontdrvhost.exe"Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: cabinet.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: version.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: feclient.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: iertutil.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: advpack.dllJump to behavior
                      Source: C:\Users\user\Desktop\file.exeSection loaded: apphelp.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeSection loaded: mscoree.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeSection loaded: apphelp.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeSection loaded: version.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeSection loaded: uxtheme.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeSection loaded: windows.storage.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeSection loaded: wldp.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeSection loaded: profapi.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeSection loaded: cryptsp.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeSection loaded: rsaenh.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeSection loaded: cryptbase.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeSection loaded: amsi.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeSection loaded: userenv.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeSection loaded: msasn1.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeSection loaded: gpapi.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeSection loaded: dwrite.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeSection loaded: windowscodecs.dllJump to behavior
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeSection loaded: wbemcomn.dllJump to behavior
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeSection loaded: amsi.dllJump to behavior
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeSection loaded: userenv.dllJump to behavior
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeSection loaded: profapi.dllJump to behavior
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeSection loaded: version.dllJump to behavior
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeSection loaded: uxtheme.dllJump to behavior
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeSection loaded: windows.storage.dllJump to behavior
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeSection loaded: wldp.dllJump to behavior
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeSection loaded: sspicli.dllJump to behavior
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeSection loaded: mpr.dllJump to behavior
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeSection loaded: powrprof.dllJump to behavior
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeSection loaded: umpdc.dllJump to behavior
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeSection loaded: wbemcomn.dllJump to behavior
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeSection loaded: wbemcomn.dllJump to behavior
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeSection loaded: mswsock.dllJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32Jump to behavior
                      Source: Window RecorderWindow detected: More than 3 window changes detected
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
                      Source: file.exeStatic PE information: Image base 0x140000000 > 0x60000000
                      Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
                      Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
                      Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
                      Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
                      Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
                      Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
                      Source: file.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
                      Source: file.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
                      Source: Binary string: wextract.pdb source: file.exe
                      Source: Binary string: wextract.pdbGCTL source: file.exe
                      Source: Binary string: dnlib.DotNet.Pdb.Dss.IMetaDataEmit.SetRVA source: computerlead.exe, 00000001.00000002.2938052510.00000000056B0000.00000004.08000000.00040000.00000000.sdmp
                      Source: Binary string: wkernel32.pdb source: fontdrvhost.exe, 00000012.00000003.2945316096.0000000004C00000.00000004.00000001.00020000.00000000.sdmp, fontdrvhost.exe, 00000012.00000003.2945134717.0000000004AE0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: wkernelbase.pdb source: fontdrvhost.exe, 00000012.00000003.2945665948.0000000004AE0000.00000004.00000001.00020000.00000000.sdmp, fontdrvhost.exe, 00000012.00000003.2946060481.0000000004D00000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: ntdll.pdb source: fontdrvhost.exe, 00000012.00000003.2943041755.0000000004AE0000.00000004.00000001.00020000.00000000.sdmp, fontdrvhost.exe, 00000012.00000003.2943531107.0000000004CD0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: wntdll.pdbUGP source: fontdrvhost.exe, 00000012.00000003.2944071441.0000000004AE0000.00000004.00000001.00020000.00000000.sdmp, fontdrvhost.exe, 00000012.00000003.2944366502.0000000004C80000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: ntdll.pdbUGP source: fontdrvhost.exe, 00000012.00000003.2943041755.0000000004AE0000.00000004.00000001.00020000.00000000.sdmp, fontdrvhost.exe, 00000012.00000003.2943531107.0000000004CD0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: wntdll.pdb source: fontdrvhost.exe, 00000012.00000003.2944071441.0000000004AE0000.00000004.00000001.00020000.00000000.sdmp, fontdrvhost.exe, 00000012.00000003.2944366502.0000000004C80000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: wkernel32.pdbUGP source: fontdrvhost.exe, 00000012.00000003.2945316096.0000000004C00000.00000004.00000001.00020000.00000000.sdmp, fontdrvhost.exe, 00000012.00000003.2945134717.0000000004AE0000.00000004.00000001.00020000.00000000.sdmp
                      Source: Binary string: wkernelbase.pdbUGP source: fontdrvhost.exe, 00000012.00000003.2945665948.0000000004AE0000.00000004.00000001.00020000.00000000.sdmp, fontdrvhost.exe, 00000012.00000003.2946060481.0000000004D00000.00000004.00000001.00020000.00000000.sdmp
                      Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
                      Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
                      Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
                      Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
                      Source: file.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata

                      Data Obfuscation

                      barindex
                      Source: Yara matchFile source: 1.2.computerlead.exe.56b0000.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 1.2.computerlead.exe.56b0000.2.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000001.00000002.2938052510.00000000056B0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000001.00000002.2931668884.00000000032E1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: computerlead.exe PID: 7492, type: MEMORYSTR
                      Source: computerlead.exe.0.dr, Qw4x7F.cs.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[0]}, (string[])null, (Type[])null, (bool[])null, true)
                      Source: computerlead.exe.0.dr, Qw4x7F.cs.Net Code: f1G System.Reflection.Assembly.Load(byte[])
                      Source: computerlead.exe.0.dr, Qw4x7F.cs.Net Code: f8ZQy5 System.Reflection.Assembly.Load(byte[])
                      Source: file.exeStatic PE information: 0xD97FD45F [Sun Aug 19 04:21:51 2085 UTC]
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E01A08 memset,memset,RegCreateKeyExA,RegQueryValueExA,RegCloseKey,GetSystemDirectoryA,LoadLibraryA,GetProcAddress,FreeLibrary,GetSystemDirectoryA,LocalAlloc,GetModuleFileNameA,RegCloseKey,RegSetValueExA,RegCloseKey,LocalFree,0_2_00007FF7E5E01A08
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_018071F8 pushfd ; retf 1_2_01807315
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_0799D682 push 9B0799D0h; iretd 1_2_0799D695
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_07998448 push FFFFFFC3h; ret 1_2_079986B5
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_079972AD pushad ; ret 1_2_079972B3
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeCode function: 18_3_003B6012 push 00000038h; iretd 18_3_003B601D
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeCode function: 18_3_003B5606 pushad ; retf 18_3_003B5619
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeCode function: 18_3_003B225D push eax; ret 18_3_003B225F
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeCode function: 18_3_003B58BC pushad ; ret 18_3_003B58C1
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeCode function: 18_3_003B588E push eax; iretd 18_3_003B589D
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeCode function: 18_3_003B28ED push ebx; ret 18_3_003B28E4
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeCode function: 18_3_003B18C0 push ebp; retf 18_3_003B18C1
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeCode function: 18_3_003B4920 push 0000002Eh; iretd 18_3_003B4922
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeCode function: 18_3_003B5F0C push es; iretd 18_3_003B5F0D
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeCode function: 18_3_003B1179 push FFFFFF82h; iretd 18_3_003B117B
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeCode function: 18_3_003B278B push ebx; ret 18_3_003B28E4
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeCode function: 18_3_003B0FEA push eax; ret 18_3_003B0FF5
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeCode function: 18_3_003B5FEE push FFFFFFD2h; retf 18_3_003B6011
                      Source: computerlead.exe.0.dr, s3JF.csHigh entropy of concatenated method names: 'Rn7s8N', 'MoveNext', 'f8MTe1', 'SetStateMachine', 'r0C2Qj', 'MoveNext', 'e2P9Lf', 'SetStateMachine', 'x8NHg2', 'i9G8'
                      Source: computerlead.exe.0.dr, r8C.csHigh entropy of concatenated method names: 'Nd', 'MoveNext', 'g1', 'SetStateMachine', 'Gi', 'Fy', 'm8', 'Ho', 'Fj', 'o0'
                      Source: computerlead.exe.0.dr, Qw4x7F.csHigh entropy of concatenated method names: 'r8T', 'Nt8', 'Pk0', 'p6C', 'f1G', 'x3Z', 'Cp7', 'a8D', 'y1B', 'Gj6'
                      Source: C:\Users\user\Desktop\file.exeFile created: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeJump to dropped file
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E01D28 CompareStringA,GetFileAttributesA,LocalAlloc,GetPrivateProfileIntA,GetPrivateProfileStringA,GetShortPathNameA,CompareStringA,LocalAlloc,LocalAlloc,GetFileAttributesA,0_2_00007FF7E5E01D28
                      Source: C:\Users\user\Desktop\file.exeRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce wextract_cleanup0Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce wextract_cleanup0Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce wextract_cleanup0Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce wextract_cleanup0Jump to behavior

                      Hooking and other Techniques for Hiding and Protection

                      barindex
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeFile opened: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe\:Zone.Identifier read attributes | deleteJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: FAILCRITICALERRORS | NOGPFAULTERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\System32\WerFault.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

                      Malware Analysis System Evasion

                      barindex
                      Source: Yara matchFile source: Process Memory Space: computerlead.exe PID: 7492, type: MEMORYSTR
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeAPI/Special instruction interceptor: Address: 7FFDB442D044
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeAPI/Special instruction interceptor: Address: 7FFDB442D044
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeAPI/Special instruction interceptor: Address: 4CDB83A
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeSection loaded: OutputDebugStringW count: 1939
                      Source: fontdrvhost.exe, 00000012.00000002.3045986783.0000000000890000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: MP.EXEX64DBG.EXEX32DBG.E
                      Source: computerlead.exe, 00000001.00000002.2936405362.00000000044F8000.00000004.00000800.00020000.00000000.sdmp, computerlead.exe, 00000001.00000002.2936405362.00000000042E1000.00000004.00000800.00020000.00000000.sdmp, computerlead.exe, 00000001.00000002.2936405362.00000000045CF000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 0000000D.00000002.2551601895.0000000000399000.00000040.00000400.00020000.00000000.sdmpBinary or memory string: ORIGINALFILENAMECFF EXPLORER.EXE:
                      Source: fontdrvhost.exe, 00000012.00000002.3045986783.0000000000890000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: X64DBG.EXE
                      Source: computerlead.exe, 00000001.00000002.2936405362.00000000044F8000.00000004.00000800.00020000.00000000.sdmp, computerlead.exe, 00000001.00000002.2936405362.00000000042E1000.00000004.00000800.00020000.00000000.sdmp, computerlead.exe, 00000001.00000002.2936405362.00000000045CF000.00000004.00000800.00020000.00000000.sdmp, AddInProcess32.exe, 0000000D.00000002.2551601895.0000000000399000.00000040.00000400.00020000.00000000.sdmpBinary or memory string: INTERNALNAMECFF EXPLORER.EXE
                      Source: fontdrvhost.exe, 00000012.00000002.3045986783.0000000000890000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: FIDDLER.EXE
                      Source: fontdrvhost.exe, 00000012.00000002.3045986783.0000000000890000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: EVERYWHERE.EXEFIDDLER.EXEIDA.EXEIDA64.EXEIMMU""<
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory allocated: 17A0000 memory reserve | memory write watchJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory allocated: 32E0000 memory reserve | memory write watchJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory allocated: 3120000 memory reserve | memory write watchJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory allocated: 8CC0000 memory reserve | memory write watchJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory allocated: 9CC0000 memory reserve | memory write watchJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory allocated: 9EA0000 memory reserve | memory write watchJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory allocated: AEA0000 memory reserve | memory write watchJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory allocated: B260000 memory reserve | memory write watchJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory allocated: C260000 memory reserve | memory write watchJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 922337203685477Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeWindow / User API: threadDelayed 2802Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeWindow / User API: threadDelayed 7020Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeCheck user administrative privileges: GetTokenInformation,DecisionNodesgraph_0-2519
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -33204139332677172s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -38000s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -37874s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -37765s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -37656s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -37547s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -37438s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -37313s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -37203s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -37094s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -36969s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -36860s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -36735s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -36610s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -36485s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -36360s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -36235s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -36110s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -35985s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -35860s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -35735s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -35610s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -35485s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -35360s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -35181s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -35016s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -34891s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -34781s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -34672s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -34553s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -34438s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -34322s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -34216s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -34109s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -34000s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -33891s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -33781s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -33672s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -33563s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -33438s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -33313s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -33188s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -33078s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -32968s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -32859s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -32745s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -32641s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -32516s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -32406s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -32297s >= -30000sJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe TID: 7664Thread sleep time: -32188s >= -30000sJump to behavior
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_Processor
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E026B8 FindFirstFileA,lstrcmpA,lstrcmpA,SetFileAttributesA,DeleteFileA,FindNextFileA,FindClose,RemoveDirectoryA,0_2_00007FF7E5E026B8
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E041EC GetSystemInfo,CreateDirectoryA,RemoveDirectoryA,0_2_00007FF7E5E041EC
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 922337203685477Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 38000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 37874Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 37765Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 37656Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 37547Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 37438Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 37313Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 37203Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 37094Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 36969Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 36860Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 36735Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 36610Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 36485Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 36360Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 36235Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 36110Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 35985Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 35860Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 35735Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 35610Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 35485Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 35360Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 35181Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 35016Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 34891Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 34781Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 34672Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 34553Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 34438Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 34322Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 34216Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 34109Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 34000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 33891Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 33781Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 33672Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 33563Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 33438Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 33313Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 33188Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 33078Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 32968Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 32859Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 32745Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 32641Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 32516Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 32406Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 32297Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeThread delayed: delay time: 32188Jump to behavior
                      Source: Amcache.hve.24.drBinary or memory string: VMware
                      Source: Amcache.hve.24.drBinary or memory string: VMware Virtual USB Mouse
                      Source: Amcache.hve.24.drBinary or memory string: vmci.syshbin
                      Source: Amcache.hve.24.drBinary or memory string: VMware, Inc.
                      Source: computerlead.exe, 00000001.00000002.2938052510.00000000056B0000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: sandboxierpcssGSOFTWARE\VMware, Inc.\VMware VGAuth
                      Source: Amcache.hve.24.drBinary or memory string: VMware20,1hbin@
                      Source: Amcache.hve.24.drBinary or memory string: c:\windows\system32\driverstore\filerepository\vmci.inf_amd64_68ed49469341f563
                      Source: Amcache.hve.24.drBinary or memory string: Ascsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000
                      Source: Amcache.hve.24.drBinary or memory string: .Z$c:/windows/system32/drivers/vmci.sys
                      Source: fontdrvhost.exe, 00000012.00000002.3046069328.000000000093A000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWi.csvl
                      Source: Amcache.hve.24.drBinary or memory string: VMware-42 27 80 4d 99 30 0e 9c-c1 9b 2a 23 ea 1f c4 20
                      Source: fontdrvhost.exe, 00000012.00000002.3046069328.000000000093A000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
                      Source: Amcache.hve.24.drBinary or memory string: :scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000
                      Source: Amcache.hve.24.drBinary or memory string: pci\ven_15ad&dev_0740&subsys_074015ad,pci\ven_15ad&dev_0740,root\vmwvmcihostdev
                      Source: Amcache.hve.24.drBinary or memory string: c:/windows/system32/drivers/vmci.sys
                      Source: Amcache.hve.24.drBinary or memory string: scsi/cdrom&ven_necvmwar&prod_vmware_sata_cd00/4&224f42ef&0&000000
                      Source: Amcache.hve.24.drBinary or memory string: vmci.sys
                      Source: Amcache.hve.24.drBinary or memory string: vmci.syshbin`
                      Source: Amcache.hve.24.drBinary or memory string: \driver\vmci,\driver\pci
                      Source: Amcache.hve.24.drBinary or memory string: scsi/disk&ven_vmware&prod_virtual_disk/4&1656f219&0&000000
                      Source: fontdrvhost.exe, 00000012.00000003.2946060481.0000000004D00000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: DisableGuestVmNetworkConnectivity
                      Source: Amcache.hve.24.drBinary or memory string: VMware20,1
                      Source: Amcache.hve.24.drBinary or memory string: Microsoft Hyper-V Generation Counter
                      Source: Amcache.hve.24.drBinary or memory string: NECVMWar VMware SATA CD00
                      Source: Amcache.hve.24.drBinary or memory string: VMware Virtual disk SCSI Disk Device
                      Source: computerlead.exe, 00000001.00000002.2938052510.00000000056B0000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: VBoxTrayS
                      Source: Amcache.hve.24.drBinary or memory string: scsi\cdromnecvmwarvmware_sata_cd001.00,scsi\cdromnecvmwarvmware_sata_cd00,scsi\cdromnecvmwar,scsi\necvmwarvmware_sata_cd001,necvmwarvmware_sata_cd001,gencdrom
                      Source: Amcache.hve.24.drBinary or memory string: scsi\diskvmware__virtual_disk____2.0_,scsi\diskvmware__virtual_disk____,scsi\diskvmware__,scsi\vmware__virtual_disk____2,vmware__virtual_disk____2,gendisk
                      Source: Amcache.hve.24.drBinary or memory string: Microsoft Hyper-V Virtualization Infrastructure Driver
                      Source: Amcache.hve.24.drBinary or memory string: VMware PCI VMCI Bus Device
                      Source: Amcache.hve.24.drBinary or memory string: VMware VMCI Bus Device
                      Source: Amcache.hve.24.drBinary or memory string: VMware Virtual RAM
                      Source: fontdrvhost.exe, 00000012.00000003.2946060481.0000000004D00000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: EnableGuestVmNetworkConnectivity
                      Source: Amcache.hve.24.drBinary or memory string: BiosVendor:VMware, Inc.,BiosVersion:VMW201.00V.20829224.B64.2211211842,BiosReleaseDate:11/21/2022,BiosMajorRelease:0xff,BiosMinorRelease:0xff,SystemManufacturer:VMware, Inc.,SystemProduct:VMware20,1,SystemFamily:,SystemSKUNumber:,BaseboardManufacturer:,BaseboardProduct:,BaseboardVersion:,EnclosureType:0x1
                      Source: Amcache.hve.24.drBinary or memory string: vmci.inf_amd64_68ed49469341f563
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess information queried: ProcessInformationJump to behavior

                      Anti Debugging

                      barindex
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeCode function: 1_2_01807FA0 CheckRemoteDebuggerPresent,1_2_01807FA0
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess queried: DebugPortJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess queried: DebugPortJump to behavior
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E01A08 memset,memset,RegCreateKeyExA,RegQueryValueExA,RegCloseKey,GetSystemDirectoryA,LoadLibraryA,GetProcAddress,FreeLibrary,GetSystemDirectoryA,LocalAlloc,GetModuleFileNameA,RegCloseKey,RegSetValueExA,RegCloseKey,LocalFree,0_2_00007FF7E5E01A08
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeCode function: 18_3_003B0283 mov eax, dword ptr fs:[00000030h]18_3_003B0283
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess token adjusted: DebugJump to behavior
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E01404 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00007FF7E5E01404
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E0170E SetUnhandledExceptionFilter,0_2_00007FF7E5E0170E
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory allocated: page read and write | page guardJump to behavior

                      HIPS / PFW / Operating System Protection Evasion

                      barindex
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory allocated: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 350000 protect: page execute and read and writeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory allocated: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 530000 protect: page execute and read and writeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory allocated: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 500000 protect: page execute and read and writeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory allocated: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 400000 protect: page execute and read and writeJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 350000 value starts with: 4D5AJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 530000 value starts with: 4D5AJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 500000 value starts with: 4D5AJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 400000 value starts with: 4D5AJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 350000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 351000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 399000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 3C8000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 3CC000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 3CE000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 4DF008Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 530000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 531000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 579000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 5A8000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 5AC000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 5AE000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 3B1008Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 500000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 501000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 549000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 578000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 57C000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 57E000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 3E2008Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 400000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 401000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 449000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 478000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 47C000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 47E000Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe base: 10A6008Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess created: C:\Windows\System32\rundll32.exe "C:\Windows\system32\rundll32.exe" C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\user\AppData\Local\Temp\IXP000.TMP\"Jump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exeProcess created: C:\Windows\SysWOW64\fontdrvhost.exe "C:\Windows\System32\fontdrvhost.exe"Jump to behavior
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeProcess created: C:\Windows\System32\fontdrvhost.exe "C:\Windows\System32\fontdrvhost.exe"Jump to behavior
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E02590 LoadLibraryA,GetProcAddress,AllocateAndInitializeSid,FreeSid,FreeLibrary,0_2_00007FF7E5E02590
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeQueries volume information: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe VolumeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformationJump to behavior
                      Source: C:\Windows\SysWOW64\fontdrvhost.exeQueries volume information: C:\ VolumeInformationJump to behavior
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E018E4 GetSystemTimeAsFileTime,GetCurrentProcessId,GetCurrentThreadId,GetTickCount,GetTickCount,QueryPerformanceCounter,0_2_00007FF7E5E018E4
                      Source: C:\Users\user\Desktop\file.exeCode function: 0_2_00007FF7E5E07FE4 GetVersion,GetModuleHandleW,GetProcAddress,ExitWindowsEx,CloseHandle,0_2_00007FF7E5E07FE4
                      Source: C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
                      Source: Amcache.hve.24.drBinary or memory string: c:\programdata\microsoft\windows defender\platform\4.18.23080.2006-0\msmpeng.exe
                      Source: Amcache.hve.24.drBinary or memory string: msmpeng.exe
                      Source: Amcache.hve.24.drBinary or memory string: c:\program files\windows defender\msmpeng.exe
                      Source: Amcache.hve.24.drBinary or memory string: c:\programdata\microsoft\windows defender\platform\4.18.23090.2008-0\msmpeng.exe
                      Source: Amcache.hve.24.drBinary or memory string: MsMpEng.exe

                      Stealing of Sensitive Information

                      barindex
                      Source: Yara matchFile source: 00000012.00000003.2941844125.0000000000760000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000012.00000002.3046180127.0000000000A30000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000010.00000002.2946578088.0000000001610000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY

                      Remote Access Functionality

                      barindex
                      Source: Yara matchFile source: 00000012.00000003.2941844125.0000000000760000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000012.00000002.3046180127.0000000000A30000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000010.00000002.2946578088.0000000001610000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
                      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                      Gather Victim Identity InformationAcquire Infrastructure1
                      Valid Accounts
                      11
                      Windows Management Instrumentation
                      1
                      DLL Side-Loading
                      1
                      DLL Side-Loading
                      1
                      Disable or Modify Tools
                      21
                      Input Capture
                      1
                      System Time Discovery
                      Remote Services11
                      Archive Collected Data
                      2
                      Encrypted Channel
                      Exfiltration Over Other Network Medium1
                      System Shutdown/Reboot
                      CredentialsDomainsDefault Accounts2
                      Native API
                      1
                      Valid Accounts
                      1
                      Valid Accounts
                      1
                      Deobfuscate/Decode Files or Information
                      LSASS Memory1
                      File and Directory Discovery
                      Remote Desktop Protocol21
                      Input Capture
                      1
                      Non-Standard Port
                      Exfiltration Over BluetoothNetwork Denial of Service
                      Email AddressesDNS ServerDomain AccountsAt1
                      Registry Run Keys / Startup Folder
                      11
                      Access Token Manipulation
                      2
                      Obfuscated Files or Information
                      Security Account Manager117
                      System Information Discovery
                      SMB/Windows Admin SharesData from Network Shared Drive1
                      Application Layer Protocol
                      Automated ExfiltrationData Encrypted for Impact
                      Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook311
                      Process Injection
                      21
                      Software Packing
                      NTDS431
                      Security Software Discovery
                      Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
                      Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon Script1
                      Registry Run Keys / Startup Folder
                      1
                      Timestomp
                      LSA Secrets1
                      Process Discovery
                      SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
                      Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
                      DLL Side-Loading
                      Cached Domain Credentials151
                      Virtualization/Sandbox Evasion
                      VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                      DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
                      Masquerading
                      DCSync1
                      Application Window Discovery
                      Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
                      Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
                      Valid Accounts
                      Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
                      Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAt151
                      Virtualization/Sandbox Evasion
                      /etc/passwd and /etc/shadowNetwork SniffingDirect Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
                      IP AddressesCompromise InfrastructureSupply Chain CompromisePowerShellCronCron11
                      Access Token Manipulation
                      Network SniffingNetwork Service DiscoveryShared WebrootLocal Data StagingFile Transfer ProtocolsExfiltration Over Asymmetric Encrypted Non-C2 ProtocolExternal Defacement
                      Network Security AppliancesDomainsCompromise Software Dependencies and Development ToolsAppleScriptLaunchdLaunchd311
                      Process Injection
                      Input CaptureSystem Network Connections DiscoverySoftware Deployment ToolsRemote Data StagingMail ProtocolsExfiltration Over Unencrypted Non-C2 ProtocolFirmware Corruption
                      Gather Victim Org InformationDNS ServerCompromise Software Supply ChainWindows Command ShellScheduled TaskScheduled Task1
                      Hidden Files and Directories
                      KeyloggingProcess DiscoveryTaint Shared ContentScreen CaptureDNSExfiltration Over Physical MediumResource Hijacking
                      Determine Physical LocationsVirtual Private ServerCompromise Hardware Supply ChainUnix ShellSystemd TimersSystemd Timers1
                      Rundll32
                      GUI Input CapturePermission Groups DiscoveryReplication Through Removable MediaEmail CollectionProxyExfiltration over USBNetwork Denial of Service
                      Hide Legend

                      Legend:

                      • Process
                      • Signature
                      • Created File
                      • DNS/IP Info
                      • Is Dropped
                      • Is Windows Process
                      • Number of created Registry Values
                      • Number of created Files
                      • Visual Basic
                      • Delphi
                      • Java
                      • .Net C# or VB.NET
                      • C, C++ or other language
                      • Is malicious
                      • Internet
                      behaviorgraph top1 signatures2 2 Behavior Graph ID: 1562677 Sample: file.exe Startdate: 25/11/2024 Architecture: WINDOWS Score: 100 39 Suricata IDS alerts for network traffic 2->39 41 Found malware configuration 2->41 43 Antivirus / Scanner detection for submitted sample 2->43 45 9 other signatures 2->45 10 file.exe 1 3 2->10         started        process3 file4 35 C:\Users\user\AppData\...\computerlead.exe, PE32 10->35 dropped 13 computerlead.exe 3 10->13         started        process5 signatures6 53 Antivirus detection for dropped file 13->53 55 Multi AV Scanner detection for dropped file 13->55 57 Machine Learning detection for dropped file 13->57 59 7 other signatures 13->59 16 AddInProcess32.exe 1 13->16         started        18 AddInProcess32.exe 13->18         started        21 rundll32.exe 13->21         started        23 2 other processes 13->23 process7 signatures8 25 fontdrvhost.exe 16->25         started        29 WerFault.exe 2 16->29         started        47 Switches to a custom stack to bypass stack traces 18->47 process9 dnsIp10 37 104.37.175.218, 49910, 7982 MAJESTIC-HOSTING-01US United States 25->37 49 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 25->49 51 Switches to a custom stack to bypass stack traces 25->51 31 fontdrvhost.exe 25->31         started        signatures11 process12 process13 33 WerFault.exe 23 16 31->33         started       

                      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                      windows-stand
                      SourceDetectionScannerLabelLink
                      file.exe32%ReversingLabsByteCode-MSIL.Trojan.AgentTesla
                      file.exe100%AviraHEUR/AGEN.1358047
                      file.exe100%Joe Sandbox ML
                      SourceDetectionScannerLabelLink
                      C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe100%AviraHEUR/AGEN.1358047
                      C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe100%Joe Sandbox ML
                      C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe34%ReversingLabsByteCode-MSIL.Trojan.AgentTesla
                      No Antivirus matches
                      No Antivirus matches
                      SourceDetectionScannerLabelLink
                      https://104.37.175.218:7982/da03ab84e7f8187e6/o304l70l.g00oxx0%Avira URL Cloudsafe
                      https://104.37.175.218:7982/da03ab84e7f8187e6/o304l70l.g00ox0%Avira URL Cloudsafe
                      https://104.37.175.218:7982/da03ab84e7f8187e6/o304l70l.g00oxkernelbasentdllkernel32GetProcessMitigat0%Avira URL Cloudsafe
                      No contacted domains info
                      NameMaliciousAntivirus DetectionReputation
                      https://104.37.175.218:7982/da03ab84e7f8187e6/o304l70l.g00oxtrue
                      • Avira URL Cloud: safe
                      unknown
                      NameSourceMaliciousAntivirus DetectionReputation
                      https://cloudflare-dns.com/dns-queryfontdrvhost.exe, 00000012.00000003.2975846507.0000000004A4B000.00000004.00000020.00020000.00000000.sdmpfalse
                        high
                        http://upx.sf.netAmcache.hve.24.drfalse
                          high
                          https://cloudflare-dns.com/dns-queryPOSTContent-TypeContent-LengthHostapplication/dns-message%dMachifontdrvhost.exe, 00000012.00000003.2975846507.0000000004A4B000.00000004.00000020.00020000.00000000.sdmpfalse
                            high
                            https://104.37.175.218:7982/da03ab84e7f8187e6/o304l70l.g00oxkernelbasentdllkernel32GetProcessMitigatfontdrvhost.exe, 00000012.00000003.3045309813.0000000004DBB000.00000004.00000020.00020000.00000000.sdmp, fontdrvhost.exe, 00000016.00000002.3129592218.000001BE066E0000.00000040.00000001.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: safe
                            unknown
                            https://104.37.175.218:7982/da03ab84e7f8187e6/o304l70l.g00oxxfontdrvhost.exe, 00000012.00000002.3045753092.000000000038C000.00000004.00000010.00020000.00000000.sdmpfalse
                            • Avira URL Cloud: safe
                            unknown
                            • No. of IPs < 25%
                            • 25% < No. of IPs < 50%
                            • 50% < No. of IPs < 75%
                            • 75% < No. of IPs
                            IPDomainCountryFlagASNASN NameMalicious
                            104.37.175.218
                            unknownUnited States
                            396073MAJESTIC-HOSTING-01UStrue
                            Joe Sandbox version:41.0.0 Charoite
                            Analysis ID:1562677
                            Start date and time:2024-11-25 21:33:08 +01:00
                            Joe Sandbox product:CloudBasic
                            Overall analysis duration:0h 6m 40s
                            Hypervisor based Inspection enabled:false
                            Report type:full
                            Cookbook file name:default.jbs
                            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                            Number of analysed new started processes analysed:25
                            Number of new started drivers analysed:0
                            Number of existing processes analysed:0
                            Number of existing drivers analysed:0
                            Number of injected processes analysed:0
                            Technologies:
                            • HCA enabled
                            • EGA enabled
                            • AMSI enabled
                            Analysis Mode:default
                            Analysis stop reason:Timeout
                            Sample name:file.exe
                            Detection:MAL
                            Classification:mal100.troj.evad.winEXE@18/7@0/1
                            EGA Information:
                            • Successful, ratio: 60%
                            HCA Information:
                            • Successful, ratio: 61%
                            • Number of executed functions: 61
                            • Number of non-executed functions: 37
                            Cookbook Comments:
                            • Found application associated with file extension: .exe
                            • Exclude process from analysis (whitelisted): dllhost.exe, BackgroundTransferHost.exe, WerFault.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe, svchost.exe
                            • Excluded IPs from analysis (whitelisted): 20.190.177.23, 20.190.177.149, 20.190.147.11, 20.190.147.5, 20.190.147.9, 20.190.177.83, 20.190.177.84, 20.190.147.3, 13.89.179.12
                            • Excluded domains from analysis (whitelisted): client.wns.windows.com, prdv4a.aadg.msidentity.com, fs.microsoft.com, otelrules.azureedge.net, slscr.update.microsoft.com, www.tm.v4.a.prd.aadg.trafficmanager.net, ctldl.windowsupdate.com, tse1.mm.bing.net, g.bing.com, onedsblobprdcus17.centralus.cloudapp.azure.com, arc.msn.com, login.msa.msidentity.com, fe3cr.delivery.mp.microsoft.com, ris.api.iris.microsoft.com, ocsp.digicert.com, login.live.com, blobcollector.events.data.trafficmanager.net, umwatson.events.data.microsoft.com, www.tm.lg.prod.aadmsa.trafficmanager.net
                            • Execution Graph export aborted for target fontdrvhost.exe, PID 7916 because there are no executed function
                            • Report size getting too big, too many NtOpenKeyEx calls found.
                            • Report size getting too big, too many NtQueryValueKey calls found.
                            • VT rate limit hit for: file.exe
                            TimeTypeDescription
                            15:34:03API Interceptor216106x Sleep call for process: computerlead.exe modified
                            15:35:41API Interceptor1x Sleep call for process: WerFault.exe modified
                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                            104.37.175.218file.exeGet hashmaliciousRHADAMANTHYSBrowse
                              No context
                              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                              MAJESTIC-HOSTING-01USfile.exeGet hashmaliciousRHADAMANTHYSBrowse
                              • 104.37.175.218
                              doc_1000050408072024.jsGet hashmaliciousRemcosBrowse
                              • 191.101.130.5
                              SLIM00260423 LIM-AMS-BOM.jsGet hashmaliciousRemcosBrowse
                              • 191.101.130.5
                              Arrival_Notice_10008616062024.jsGet hashmaliciousAgentTeslaBrowse
                              • 191.101.130.5
                              1721804764a66192ba8849c107aecf73332780289e57101d88022de3de452c4d4afc349344344.dat-decoded.exeGet hashmaliciousAsyncRAT, DcRatBrowse
                              • 191.101.130.221
                              INV-23072024.vbsGet hashmaliciousAsyncRAT, DcRatBrowse
                              • 191.101.130.221
                              11_deb64ed.exeGet hashmaliciousRemcosBrowse
                              • 191.101.130.68
                              Co0Wd0QVRU.exeGet hashmaliciousRemcos, GuLoaderBrowse
                              • 191.101.130.177
                              172001946670b1e83321a2b0b2afa526495dda6118492d61c1dbccf1f24b87b00c0e2fc524979.dat-decoded.exeGet hashmaliciousRemcosBrowse
                              • 191.101.130.177
                              http://email.robly.com/ls/click?upn=IdEuq0w5NGjcvp67fJm0Fjx7zI0UoacAvfuhX8IXMfi-2FBcyVFfNBAnRRYn3xO-2B1CJBL1_x1qKbjhEBXTMhgFeszlbTPAP7pso9-2FxqCAo9mujVNdxRC-2Fe6szeUW2wUpsJPamXtYEX5TxNxvCL8y7P57m0ckeV4eInxu3K8zf4ZJir3swUgmhxHZ4ueQr8HlG-2FmusQJH6y7p25ps7Tk6J5qNmOony1meVnHS6SWYINya9roE9W5a8qQtJPhUrtwHjPNNr8-2FRq8ri-2Fd5oj6InCgVt40NRVo7kVkD4rXqnd5qh4hVxKxbkv-2B-2Bg5grednXpzEJrVoppO7kdIBlpx5FtxXkVy5jroHsBNlwPLvY7zHyi82KhBukRiMiFN-2Bq8Y5MIpQ3tDOtgM9smS8EBnUo-2BNczWmfSC7A0LEM5yvlMpWf2qtqc4I7FL0Pb-2FOBoG7nzLMuVBmfOyvltwMiXHcvatoR9WpKWTWbswWnOInmA3qfQw2YmDZYZTRlsjGJ1yVr4dcvvE98tzz8ObIb6wBOg-2BtttMS8VRCu3mc-2FvYkvjr5dNSCoVNCXZ0NX-2BlVkto2ZltzhjEciS#doc~mstewart@dsi.usGet hashmaliciousUnknownBrowse
                              • 104.37.172.199
                              No context
                              No context
                              Process:C:\Windows\System32\WerFault.exe
                              File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                              Category:dropped
                              Size (bytes):65536
                              Entropy (8bit):0.6602110881556946
                              Encrypted:false
                              SSDEEP:96:atuHF03e8iqigKJDs3Wrk41yHpHS2QXIDcQkc6tcEycw3ZUtzJzQ+HbHgrZ2ZAXM:5SxiHnDxR0apYKjqzuiFhZ24lO8JO
                              MD5:81EF546AF4F40DD2D7D23F1E5EF9E3F9
                              SHA1:2E1F54C5018DF1FAEB695D53266E8957DA5F6BC5
                              SHA-256:68B80ED1AB3BCEAC2F44DB31FDB89BCE339A6A1B0E2B951AF80A9492F6D29EAA
                              SHA-512:71C3A7F26DAB1B9BC55C1F82FBF01F8FE8F3D3556DAB43F8549B70BD9223C900ECBC2A3CC43F23CDABEA89C82FAAEE6212D107576877FDAB120D380454845D43
                              Malicious:false
                              Reputation:low
                              Preview:..V.e.r.s.i.o.n.=.1.....E.v.e.n.t.T.y.p.e.=.B.E.X.6.4.....E.v.e.n.t.T.i.m.e.=.1.3.3.7.7.0.4.0.5.3.6.5.3.3.6.9.8.5.....R.e.p.o.r.t.T.y.p.e.=.2.....C.o.n.s.e.n.t.=.1.....U.p.l.o.a.d.T.i.m.e.=.1.3.3.7.7.0.4.0.5.3.6.8.1.4.9.5.5.3.....R.e.p.o.r.t.S.t.a.t.u.s.=.5.2.4.3.8.4.....R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.0.6.1.7.5.0.1.e.-.f.2.e.0.-.4.7.5.3.-.9.7.d.1.-.6.0.0.2.f.8.3.4.8.6.a.d.....I.n.t.e.g.r.a.t.o.r.R.e.p.o.r.t.I.d.e.n.t.i.f.i.e.r.=.f.9.e.c.f.f.b.2.-.8.2.6.0.-.4.a.c.4.-.b.4.3.f.-.5.0.2.8.a.3.6.5.0.5.3.0.....W.o.w.6.4.H.o.s.t.=.3.4.4.0.4.....N.s.A.p.p.N.a.m.e.=.f.o.n.t.d.r.v.h.o.s.t...e.x.e.....O.r.i.g.i.n.a.l.F.i.l.e.n.a.m.e.=.f.o.n.t.d.r.v.h.o.s.t...e.x.e.....A.p.p.S.e.s.s.i.o.n.G.u.i.d.=.0.0.0.0.1.f.b.c.-.0.0.0.1.-.0.0.1.5.-.e.3.7.b.-.4.e.9.3.7.9.3.f.d.b.0.1.....T.a.r.g.e.t.A.p.p.I.d.=.W.:.0.0.0.0.f.5.1.9.f.e.e.c.4.8.6.d.e.8.7.e.d.7.3.c.b.9.2.d.3.c.a.c.8.0.2.4.0.0.0.0.0.0.0.0.!.0.0.0.0.5.e.f.b.3.f.9.7.3.4.2.b.a.1.9.5.4.2.4.1.3.4.f.2.8.f.9.7.7.d.a.9.e.0.d.6.a.a.9.1.!.f.o.n.t.d.r.v.h.o.
                              Process:C:\Windows\System32\WerFault.exe
                              File Type:Mini DuMP crash report, 14 streams, Mon Nov 25 20:35:36 2024, 0x1205a4 type
                              Category:dropped
                              Size (bytes):46942
                              Entropy (8bit):1.2971106828745593
                              Encrypted:false
                              SSDEEP:96:5H8IvqORdn9HyNaOK7i76rP0S9FTX2JLaidWIYbIgvlII0:y+q8MyO6rP0S9FD2sik9d0
                              MD5:FF3F459C3FE26EA4E47BFF2D7DB3AD12
                              SHA1:EBD4D3897BE5C7CB608B27FEDE0864B0F20CE687
                              SHA-256:668B5F2AD2E0C138C45C632D14B82D16261B40C3BBA55C39F37CDA6B39AFF4CE
                              SHA-512:91E79FD3AEB7B0AF3733F8388F1F32C7FC4EBA80B19B2CA98151B76219E157ED7A360DF4B2E7244A99A87F427E8176B6F2EFB23184CF11A16E22E9720498C9F1
                              Malicious:false
                              Reputation:low
                              Preview:MDMP..a..... .........Dg....................................$...2!..........T.......8...........T.......................................................................................................................eJ..............Lw......................T.............Dg.............................0..............,...E.a.s.t.e.r.n. .S.t.a.n.d.a.r.d. .T.i.m.e...........................................E.a.s.t.e.r.n. .S.u.m.m.e.r. .T.i.m.e...............................................1.9.0.4.1...1...a.m.d.6.4.f.r.e...v.b._.r.e.l.e.a.s.e...1.9.1.2.0.6.-.1.4.0.6...................................................................................................................................................................................................................................................................................................................................................................................................................................................
                              Process:C:\Windows\System32\WerFault.exe
                              File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
                              Category:dropped
                              Size (bytes):8816
                              Entropy (8bit):3.693239224522388
                              Encrypted:false
                              SSDEEP:192:R6l7wVeJVRCw6YsCkuOgmfr57vHpD089bQO0f7wm:R6lXJzV6YpkuOgmfrFvzQFfJ
                              MD5:167D51808F2B3494A9D349350537B222
                              SHA1:70D2FEA02B16D840CFC04F0B3DC6314745C09166
                              SHA-256:4D90617F7FCDE3941333421A730D27BE885AF438BB2CC4EB49B61EEAE75723C9
                              SHA-512:07C50BA76E65D0195E1C8DDC8AE1E1E0E6088530654B8672278989B2C0C16088ACAA2D5FCF411D0E1BB48310F2539BD7B150355A17F9C7D828D1816CB59B0862
                              Malicious:false
                              Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".U.T.F.-.1.6.".?.>.....<.W.E.R.R.e.p.o.r.t.M.e.t.a.d.a.t.a.>.......<.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.........<.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.1.0...0.<./.W.i.n.d.o.w.s.N.T.V.e.r.s.i.o.n.>.........<.B.u.i.l.d.>.1.9.0.4.5.<./.B.u.i.l.d.>.........<.P.r.o.d.u.c.t.>.(.0.x.3.0.).:. .W.i.n.d.o.w.s. .1.0. .P.r.o.<./.P.r.o.d.u.c.t.>.........<.E.d.i.t.i.o.n.>.P.r.o.f.e.s.s.i.o.n.a.l.<./.E.d.i.t.i.o.n.>.........<.B.u.i.l.d.S.t.r.i.n.g.>.1.9.0.4.1...2.0.0.6...a.m.d.6.4.f.r.e...v.b._.r.e.l.e.a.s.e...1.9.1.2.0.6.-.1.4.0.6.<./.B.u.i.l.d.S.t.r.i.n.g.>.........<.R.e.v.i.s.i.o.n.>.2.0.0.6.<./.R.e.v.i.s.i.o.n.>.........<.F.l.a.v.o.r.>.M.u.l.t.i.p.r.o.c.e.s.s.o.r. .F.r.e.e.<./.F.l.a.v.o.r.>.........<.A.r.c.h.i.t.e.c.t.u.r.e.>.X.6.4.<./.A.r.c.h.i.t.e.c.t.u.r.e.>.........<.L.C.I.D.>.2.0.5.7.<./.L.C.I.D.>.......<./.O.S.V.e.r.s.i.o.n.I.n.f.o.r.m.a.t.i.o.n.>.......<.P.r.o.c.e.s.s.I.n.f.o.r.m.a.t.i.o.n.>.........<.P.i.d.>.8.1.2.4.<./.P.i.
                              Process:C:\Windows\System32\WerFault.exe
                              File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                              Category:dropped
                              Size (bytes):4853
                              Entropy (8bit):4.444610623113313
                              Encrypted:false
                              SSDEEP:48:cvIwWl8zsxJg771I9Ri7WpW8VYwPYm8M4Jk5LvM6Fri5Hoyq8vU5LvMnaMuKkFd:uIjfDI7GiK7V1SJcjMu6HoWsjMn1uKed
                              MD5:94AA50AE90D8CE48BC4622DC1833A9FE
                              SHA1:E2877F3D58B0E9721551AE5778A6357428225588
                              SHA-256:BAF1765D11B80E1AA6D50F59AFE36BC6909ECE742C49FDDBE8E707C64F9BEFC6
                              SHA-512:77BFAD05511EEE5B9296B6D6EFE276CEED5CC6B57BCB657A3C54F24C18293DDBCA357F9281E93127339BE85B9B68FA6D7C7F36FF2766B14B21AFC5855D033DF1
                              Malicious:false
                              Preview:<?xml version="1.0" encoding="UTF-8" standalone="yes"?>..<req ver="2">.. <tlm>.. <src>.. <desc>.. <mach>.. <os>.. <arg nm="vermaj" val="10" />.. <arg nm="vermin" val="0" />.. <arg nm="verbld" val="19045" />.. <arg nm="vercsdbld" val="2006" />.. <arg nm="verqfe" val="2006" />.. <arg nm="csdbld" val="2006" />.. <arg nm="versp" val="0" />.. <arg nm="arch" val="9" />.. <arg nm="lcid" val="2057" />.. <arg nm="geoid" val="223" />.. <arg nm="sku" val="48" />.. <arg nm="domain" val="0" />.. <arg nm="prodsuite" val="256" />.. <arg nm="ntprodtype" val="1" />.. <arg nm="platid" val="2" />.. <arg nm="tmsi" val="604058" />.. <arg nm="osinsty" val="1" />.. <arg nm="iever" val="11.789.19041.0-11.0.1000" />.. <arg nm="portos" val="0" />.. <arg nm="ram" val="409
                              Process:C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe
                              File Type:ASCII text, with CRLF line terminators
                              Category:dropped
                              Size (bytes):1216
                              Entropy (8bit):5.34331486778365
                              Encrypted:false
                              SSDEEP:24:MLU84qpE4KlKDE4KhKiKhIE4Kx1qE4qXKIE4oKNzKoZAE4Kze0E4j:Mgv2HKlYHKh3oIHKx1qHitHo6hAHKzea
                              MD5:FB53815DEEC334028DBDE4E3660E26D0
                              SHA1:7F491359EC244406DFC8AA39FC9B727D677E4FDF
                              SHA-256:C3EC8D6C079B1940D82374A85E9DC41ED9FF683ADA338F89E375AA7AC777749D
                              SHA-512:5CC466901D7911BE1E1731162CC01C371444AAFA9A504F1F22516F60C888048EB78B5C5A12215EE2B127BD67A19677E370686465E85E08BC14015F8FAB049E49
                              Malicious:false
                              Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..2,"Microsoft.VisualBasic, Version=10.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a",0..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\920e3d1d70447c3c10e69e6df0766568\System.ni.dll",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8b2c1203fd20aea8260bfbc518004720\System.Core.ni.dll",0..2,"System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089",0..2,"System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a",0..3,"System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\2192b0d5aa4aa14486ae08118d3b9fcc\System.Configuration.ni.dll",0..3,"System.Xml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a
                              Process:C:\Users\user\Desktop\file.exe
                              File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                              Category:dropped
                              Size (bytes):1177088
                              Entropy (8bit):6.702638857236006
                              Encrypted:false
                              SSDEEP:24576:gyjL5sl1ApXhfQfivGAlMv0YIw0McEH1+edJVVq9Oj:BLXRRvGnvsw0MrVbdFEk
                              MD5:2354E800EEFC681A7D60F3B6B28ACFD9
                              SHA1:10B6A3D9D2283B5F98C9924FA1FCA6DA79EDB720
                              SHA-256:D3C21F6C3892F0C444FFB4B06F962CADDF68D2C3938BBD399A3056DB255007E3
                              SHA-512:0395737B77891D8CF7761266C2B3D594DEB8E742BD5F12F15F58B2C161C242356B953EBF8CD1F41924A917B2C1332BD2E05EF275EFD2419A6134A60729195354
                              Malicious:true
                              Antivirus:
                              • Antivirus: Avira, Detection: 100%
                              • Antivirus: Joe Sandbox ML, Detection: 100%
                              • Antivirus: ReversingLabs, Detection: 34%
                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....F"................................. ... ....@.. .......................`............`.....................................K.... .......................@....................................................... ............... ..H............text........ ...................... ..`.rsrc........ ......................@..@.reloc.......@......................@..B........................H........................N..............................................."...2.-.u....Uo.!.m...g.T_.S.e|.w.A(O..j..X.g0:.9....S.Y=.g....%.5..'N.:....3.8..........Q<.u.0U&...*.....x.;.N.......6.'.9.r:m>.r=....h...y.._..r1#.......O.....:.}.\..k.e.6S.....?...v:.8d0u.._G..A7...._..Z...\+......O....+.....#..X.?.L..8. .:..|.........p\yI..'s..,.....5.'.r.... ..<....%.e^.B...:b....%...5.clW..O@.S.w.-..z.......o...$# ...#.I.P...!..@A.u...f.[.F.4.R.6.
                              Process:C:\Windows\System32\WerFault.exe
                              File Type:MS Windows registry file, NT/2000 or above
                              Category:dropped
                              Size (bytes):1835008
                              Entropy (8bit):4.469550027615803
                              Encrypted:false
                              SSDEEP:6144:bzZfpi6ceLPx9skLmb0fYZWSP3aJG8nAgeiJRMMhA2zX4WABluuNqjDH5S:XZHtYZWOKnMM6bFpoj4
                              MD5:040D263343B8CDC1FE2190B269E3E14D
                              SHA1:57709A95AE7786A50A6C08B514B107511D3DC438
                              SHA-256:A2F697586D13D312BC8F67C248D0ED724BF54861896354EB5B2EFA0C50902DE1
                              SHA-512:DE6DB7AF14C22A7EDDCD143EEF5B68E8612BA87C2D9F97F645B8396B80115522C140E4901BD7102D24769F1B4A87863791AD2DAFBDC63CD8EBA14423359136AF
                              Malicious:false
                              Preview:regfH...H....\.Z.................... ...........\.A.p.p.C.o.m.p.a.t.\.P.r.o.g.r.a.m.s.\.A.m.c.a.c.h.e...h.v.e....c...b...#.......c...b...#...........c...b...#......rmtm..9.y?.............................................................................................................................................................................................................................................................................................................................................../.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                              File type:PE32+ executable (GUI) x86-64, for MS Windows
                              Entropy (8bit):7.828660572290537
                              TrID:
                              • Win64 Executable GUI (202006/5) 92.65%
                              • Win64 Executable (generic) (12005/4) 5.51%
                              • Generic Win/DOS Executable (2004/3) 0.92%
                              • DOS Executable Generic (2002/1) 0.92%
                              • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                              File name:file.exe
                              File size:954'368 bytes
                              MD5:96a7b754ca8e8f35ae9e2b88b9f25658
                              SHA1:ed24a27a726b87c1d5bf1da60527e5801603bb8e
                              SHA256:21d262741b3661b4bf1569f744dc5b5e6119cfa4f0748b9c0fa240f75442cc50
                              SHA512:facb2e44f5a506349710e9b2d29f6664357d057444a6bd994cf3901dee7bea471247b47496cc4480f1ad2fac4b1867117072ea7a0bfa83d55ced4e00dda96745
                              SSDEEP:24576:XjeDC5sl1HpiZOD9/5uzt37m9lny1TX2k/EZ:XjQCILdozJ7ecX//E
                              TLSH:2315011A2FA06D7AF8ECD37877A141B29233FCB113C442FB069C99685B329D054F256D
                              File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$....... .'8d.Ikd.Ikd.Ik/.Lje.Ik/.Jjg.Ik/.Mjw.Ik/.Hju.Ikd.Hk..Ik/.Ajn.Ik/..ke.Ik/.Kje.IkRichd.Ik................PE..d..._............."
                              Icon Hash:92848e869e9a98a2
                              Entrypoint:0x140001150
                              Entrypoint Section:.text
                              Digitally signed:false
                              Imagebase:0x140000000
                              Subsystem:windows gui
                              Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
                              DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
                              Time Stamp:0xD97FD45F [Sun Aug 19 04:21:51 2085 UTC]
                              TLS Callbacks:
                              CLR (.Net) Version:
                              OS Version Major:10
                              OS Version Minor:0
                              File Version Major:10
                              File Version Minor:0
                              Subsystem Version Major:10
                              Subsystem Version Minor:0
                              Import Hash:4cea7ae85c87ddc7295d39ff9cda31d1
                              Instruction
                              dec eax
                              sub esp, 28h
                              call 00007FE964B88430h
                              dec eax
                              add esp, 28h
                              jmp 00007FE964B87CABh
                              int3
                              int3
                              int3
                              int3
                              int3
                              int3
                              dec eax
                              mov dword ptr [esp+08h], ebx
                              dec eax
                              mov dword ptr [esp+10h], edi
                              inc ecx
                              push esi
                              dec eax
                              sub esp, 000000B0h
                              and dword ptr [esp+20h], 00000000h
                              dec eax
                              lea ecx, dword ptr [esp+40h]
                              call dword ptr [000082A5h]
                              nop
                              dec eax
                              mov eax, dword ptr [00000030h]
                              dec eax
                              mov ebx, dword ptr [eax+08h]
                              xor edi, edi
                              xor eax, eax
                              dec eax
                              cmpxchg dword ptr [0000B9D2h], ebx
                              je 00007FE964B87CACh
                              dec eax
                              cmp eax, ebx
                              jne 00007FE964B87CBFh
                              mov edi, 00000001h
                              mov eax, dword ptr [0000B9C8h]
                              cmp eax, 01h
                              jne 00007FE964B87CBCh
                              lea ecx, dword ptr [eax+1Eh]
                              call 00007FE964B882C4h
                              jmp 00007FE964B87D29h
                              mov ecx, 000003E8h
                              call dword ptr [00008253h]
                              jmp 00007FE964B87C66h
                              mov eax, dword ptr [0000B9A3h]
                              test eax, eax
                              jne 00007FE964B87D05h
                              mov dword ptr [0000B995h], 00000001h
                              dec esp
                              lea esi, dword ptr [000084DEh]
                              dec eax
                              lea ebx, dword ptr [000084BFh]
                              dec eax
                              mov dword ptr [esp+30h], ebx
                              mov dword ptr [esp+24h], eax
                              dec ecx
                              cmp ebx, esi
                              jnc 00007FE964B87CD1h
                              test eax, eax
                              jne 00007FE964B87CD1h
                              dec eax
                              cmp dword ptr [ebx], 00000000h
                              je 00007FE964B87CBCh
                              dec ecx
                              mov edx, 5E523070h
                              NameVirtual AddressVirtual Size Is in Section
                              IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                              IMAGE_DIRECTORY_ENTRY_IMPORT0xa3940xb4.rdata
                              IMAGE_DIRECTORY_ENTRY_RESOURCE0xf0000xd9be2.rsrc
                              IMAGE_DIRECTORY_ENTRY_EXCEPTION0xe0000x444.pdata
                              IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                              IMAGE_DIRECTORY_ENTRY_BASERELOC0xe90000x30.reloc
                              IMAGE_DIRECTORY_ENTRY_DEBUG0x9a780x54.rdata
                              IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                              IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                              IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                              IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x90100x140.rdata
                              IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                              IMAGE_DIRECTORY_ENTRY_IAT0x91500x520.rdata
                              IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                              IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                              IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                              NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                              .text0x10000x7eb00x80008f5ddc5fa0c3119d30f7e00d7bfd48aaFalse0.547576904296875data6.109997796878264IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                              .rdata0x90000x24200x300079a5acf192c71ab3579d24a79e81e45bFalse0.3240559895833333data3.9065058401206216IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                              .data0xc0000x1f000x1000f198899505f620007167379f74f8141cFalse0.083251953125data1.0384025678015962IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                              .pdata0xe0000x4440x1000d87d18cc3448a50b581d9a9660a39914False0.164306640625PEX Binary Archive1.4622023798757706IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                              .rsrc0xf0000xd9be20xda0001b267e6f8e3ab83e809071c324a2f1f7False0.9432988997993119data7.9215398279967015IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                              .reloc0xe90000x300x1000b86e33c1f7fc5de5ef683b7d6eea5c32False0.01806640625data0.11282277483477143IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                              NameRVASizeTypeLanguageCountryZLIB Complexity
                              AVI0xf6980x2e1aRIFF (little-endian) data, AVI, 272 x 60, 10.00 fps, video: RLE 8bppEnglishUnited States0.2713099474665311
                              RT_ICON0x124b40x2929PNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9721932238777641
                              RT_ICON0x14de00x4228Device independent bitmap graphic, 64 x 128 x 32, image size 0EnglishUnited States0.09075342465753425
                              RT_ICON0x190080x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 0EnglishUnited States0.11597510373443984
                              RT_ICON0x1b5b00x1a68Device independent bitmap graphic, 40 x 80 x 32, image size 0EnglishUnited States0.13476331360946744
                              RT_ICON0x1d0180x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0EnglishUnited States0.15337711069418386
                              RT_ICON0x1e0c00x988Device independent bitmap graphic, 24 x 48 x 32, image size 0EnglishUnited States0.1737704918032787
                              RT_ICON0x1ea480x6b8Device independent bitmap graphic, 20 x 40 x 32, image size 0EnglishUnited States0.21046511627906977
                              RT_ICON0x1f1000x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.25886524822695034
                              RT_RCDATA0x1f5680x7ASCII text, with no line terminatorsEnglishUnited States2.142857142857143
                              RT_RCDATA0x1f5700xc8991Microsoft Cabinet archive data, Windows 2000/XP setup, 821649 bytes, 1 file, at 0x2c +A "computerlead.exe", ID 1653, number 1, 36 datablocks, 0x1503 compressionEnglishUnited States1.000098582241322
                              RT_RCDATA0xe7f040x4dataEnglishUnited States3.0
                              RT_RCDATA0xe7f080x24dataEnglishUnited States0.5833333333333334
                              RT_RCDATA0xe7f2c0x7ASCII text, with no line terminatorsEnglishUnited States2.142857142857143
                              RT_RCDATA0xe7f340x7ASCII text, with no line terminatorsEnglishUnited States2.142857142857143
                              RT_RCDATA0xe7f3c0x4dataEnglishUnited States3.0
                              RT_RCDATA0xe7f400x7ASCII text, with no line terminatorsEnglishUnited States2.142857142857143
                              RT_RCDATA0xe7f480x4dataEnglishUnited States3.0
                              RT_RCDATA0xe7f4c0x13ASCII text, with no line terminatorsEnglishUnited States1.4210526315789473
                              RT_RCDATA0xe7f600x4dataEnglishUnited States3.0
                              RT_RCDATA0xe7f640x5ASCII text, with no line terminatorsEnglishUnited States2.6
                              RT_RCDATA0xe7f6c0x7ASCII text, with no line terminatorsEnglishUnited States2.142857142857143
                              RT_RCDATA0xe7f740x7ASCII text, with no line terminatorsEnglishUnited States2.142857142857143
                              RT_GROUP_ICON0xe7f7c0x76dataEnglishUnited States0.7372881355932204
                              RT_VERSION0xe7ff40x408dataEnglishUnited States0.42054263565891475
                              RT_MANIFEST0xe83fc0x7e6XML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.37734915924826906
                              DLLImport
                              ADVAPI32.dllGetTokenInformation, RegDeleteValueA, RegOpenKeyExA, RegQueryInfoKeyA, FreeSid, OpenProcessToken, RegSetValueExA, RegCreateKeyExA, LookupPrivilegeValueA, AllocateAndInitializeSid, RegQueryValueExA, EqualSid, RegCloseKey, AdjustTokenPrivileges
                              KERNEL32.dll_lopen, _llseek, CompareStringA, GetLastError, GetFileAttributesA, GetSystemDirectoryA, LoadLibraryA, DeleteFileA, GlobalAlloc, GlobalFree, CloseHandle, WritePrivateProfileStringA, IsDBCSLeadByte, GetWindowsDirectoryA, SetFileAttributesA, GetProcAddress, GlobalLock, LocalFree, RemoveDirectoryA, FreeLibrary, _lclose, CreateDirectoryA, GetPrivateProfileIntA, GetPrivateProfileStringA, GlobalUnlock, ReadFile, SizeofResource, WriteFile, GetDriveTypeA, LoadLibraryExA, SetFileTime, SetFilePointer, FindResourceA, CreateMutexA, GetVolumeInformationA, WaitForSingleObject, GetCurrentDirectoryA, FreeResource, GetVersion, SetCurrentDirectoryA, GetTempPathA, LocalFileTimeToFileTime, CreateFileA, SetEvent, TerminateThread, GetVersionExA, LockResource, GetSystemInfo, CreateThread, ResetEvent, LoadResource, ExitProcess, GetModuleHandleW, CreateProcessA, FormatMessageA, GetTempFileNameA, DosDateTimeToFileTime, CreateEventA, GetExitCodeProcess, ExpandEnvironmentStringsA, LocalAlloc, lstrcmpA, FindNextFileA, GetCurrentProcess, FindFirstFileA, GetModuleFileNameA, GetShortPathNameA, Sleep, GetStartupInfoW, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, UnhandledExceptionFilter, SetUnhandledExceptionFilter, TerminateProcess, QueryPerformanceCounter, GetCurrentProcessId, GetCurrentThreadId, GetSystemTimeAsFileTime, GetTickCount, EnumResourceLanguagesA, GetDiskFreeSpaceA, MulDiv, FindClose
                              GDI32.dllGetDeviceCaps
                              USER32.dllShowWindow, MsgWaitForMultipleObjects, SetWindowPos, GetDC, GetWindowRect, DispatchMessageA, GetSystemMetrics, CallWindowProcA, SetWindowTextA, MessageBoxA, SendDlgItemMessageA, SendMessageA, GetDlgItem, DialogBoxIndirectParamA, GetWindowLongPtrA, SetWindowLongPtrA, SetForegroundWindow, ReleaseDC, EnableWindow, CharNextA, LoadStringA, CharPrevA, EndDialog, MessageBeep, ExitWindowsEx, SetDlgItemTextA, CharUpperA, GetDesktopWindow, PeekMessageA, GetDlgItemTextA
                              msvcrt.dll?terminate@@YAXXZ, _commode, _fmode, _acmdln, __C_specific_handler, memset, __setusermatherr, _ismbblead, _cexit, _exit, exit, __set_app_type, __getmainargs, _amsg_exit, _XcptFilter, memcpy_s, _vsnprintf, _initterm, memcpy
                              COMCTL32.dll
                              Cabinet.dll
                              VERSION.dllVerQueryValueA, GetFileVersionInfoSizeA, GetFileVersionInfoA
                              Language of compilation systemCountry where language is spokenMap
                              EnglishUnited States
                              TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                              2024-11-25T21:35:29.048247+01002854802ETPRO MALWARE Suspected Rhadamanthys Related SSL Cert1104.37.175.2187982192.168.2.649910TCP
                              TimestampSource PortDest PortSource IPDest IP
                              Nov 25, 2024 21:35:27.599230051 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:27.719304085 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:27.719396114 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:27.719599962 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:27.839761019 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:28.927290916 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:28.928208113 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:29.048247099 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.292381048 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.301723003 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:29.421822071 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.681936026 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.681987047 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.681999922 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.682060957 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.682079077 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.682090998 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.682087898 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:29.682104111 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.682168007 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.682173014 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:29.682173014 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:29.682179928 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.682389975 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:29.690434933 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.690483093 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:29.693099022 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.693167925 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.693219900 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:29.802402973 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.802423000 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.802495003 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:29.883441925 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.883462906 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.883518934 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:29.887116909 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.887231112 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.887348890 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:29.894874096 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.894965887 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.895028114 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:29.902242899 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.902354002 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.902409077 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:29.910051107 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.910119057 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.910187006 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:29.917754889 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.917875051 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.918683052 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:29.925503969 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.925618887 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.926526070 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:29.935086966 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.935245037 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.935296059 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:29.941067934 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.941170931 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.941251040 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:29.952758074 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.952770948 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.952861071 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:29.958408117 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.958527088 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.958589077 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:29.965981960 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.966113091 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:29.966305971 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.088121891 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.088242054 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.088298082 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.090679884 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.090692997 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.090745926 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.095380068 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.095546007 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.095590115 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.100439072 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.100589991 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.100672960 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.105165005 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.105318069 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.105369091 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.110167980 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.110450983 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.110516071 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.114497900 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.114690065 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.114739895 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.118261099 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.118273973 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.118343115 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.121148109 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.121277094 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.121347904 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.126504898 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.126522064 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.126584053 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.130422115 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.130547047 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.130619049 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.136879921 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.136893034 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.137104034 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.141670942 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.141820908 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.142015934 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.145662069 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.145819902 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.145854950 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.150389910 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.150511980 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.150698900 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.155196905 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.155215025 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.155291080 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.159989119 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.160006046 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.160109043 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.164683104 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.164697886 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.164772034 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.169542074 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.169554949 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.169617891 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.174237013 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.174395084 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.174427986 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.179011106 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.179024935 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.179069042 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.183775902 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.183937073 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.183969975 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.188651085 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.188662052 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.188728094 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.210400105 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.210702896 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.210947037 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.285701036 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.285825968 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.285897970 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.287626982 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.287746906 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.287780046 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.291507006 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.291613102 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.291651964 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.295361996 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.295471907 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.295520067 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.299253941 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.299384117 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.299427986 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.303033113 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.303137064 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.306672096 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.306833982 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.306842089 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.306869030 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.310241938 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.310329914 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.310376883 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.313795090 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.313858986 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.313906908 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.317253113 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.317450047 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.317492008 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.320662022 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.320801973 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.320843935 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.324548960 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.324559927 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.324594975 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.327503920 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.327568054 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.327713966 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.330908060 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.331031084 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.331063986 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.334348917 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.334438086 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.334475994 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.337691069 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.337821007 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.337862015 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.341093063 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.341228962 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.341262102 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.342987061 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.343060017 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.343101978 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.344851017 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.344922066 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.344963074 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.346771955 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.346982002 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.347023010 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.348644018 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.348756075 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.350522995 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.350564957 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.350627899 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.350707054 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.352432966 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.352547884 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.352590084 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.354351997 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.354463100 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.354502916 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.356281042 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.356484890 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.356725931 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.358206987 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.358326912 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.358366013 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.360054016 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.360157967 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.360193968 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.361943007 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.362042904 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.362569094 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.363863945 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.363969088 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.364011049 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.365776062 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.365971088 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.366003036 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.367660046 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.367782116 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.367943048 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.369522095 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.369627953 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.370949984 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.371443033 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.371515989 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.371548891 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.373325109 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.373439074 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.373481989 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.375221968 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.375279903 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.375453949 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.377233028 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.377367020 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.378948927 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.379060984 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.379348993 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.379455090 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.380966902 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.381127119 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.382951021 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.382988930 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.383300066 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.383347988 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.384735107 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.384787083 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.384829044 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.486838102 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.486927032 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.487068892 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.487752914 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.487890005 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.487927914 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.489643097 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.490319014 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.490367889 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.490372896 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.492129087 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.492191076 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.492213011 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.493966103 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.494025946 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.494060040 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.495807886 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.495944977 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.495970964 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.497529984 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.497565031 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.497648001 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.499259949 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.499368906 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.499385118 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.500931025 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.500983000 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.501019001 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.502629042 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.502665043 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.502741098 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.504347086 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.504391909 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.504419088 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.505916119 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.506040096 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.506079912 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.507514000 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.507628918 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.507638931 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.509125948 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.509179115 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.509213924 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.510622025 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.510678053 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.510735035 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.512247086 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.512285948 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.512424946 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.513744116 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.513851881 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.513856888 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.515261889 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.515402079 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.515423059 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.516793966 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.516860962 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.516932964 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.518309116 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.518343925 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.518404007 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.519867897 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.519951105 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.519962072 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.521398067 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.521513939 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.521564007 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.522916079 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.522965908 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.523020029 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.524480104 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.524521112 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.524557114 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.526026011 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.526062012 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.526124954 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.527544975 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.527599096 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.527654886 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.529104948 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.529166937 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.529186964 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.530620098 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.530694962 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.530711889 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.532155037 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.532207012 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.532247066 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.533700943 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.533736944 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.533767939 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.535264015 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.535303116 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.535304070 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.536787987 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.536840916 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.536873102 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.538338900 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.538388014 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.538456917 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.539809942 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.539864063 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.539927006 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.541385889 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.541423082 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.541456938 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.542910099 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.542953968 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.543020964 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.544507980 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.544547081 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.544625998 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.545984030 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.546025038 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.546058893 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.547509909 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.547624111 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.547671080 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.549007893 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.549045086 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.549129009 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.550574064 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.550659895 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.550699949 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.552119970 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.552170038 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.552294016 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.553657055 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.553699970 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.553735018 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.555202961 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.555252075 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.555288076 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.556751966 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.556792021 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.556818962 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.558304071 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.558357954 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.558423042 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.559820890 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.559832096 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.559874058 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.561331034 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.561382055 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.561404943 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.562865019 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.562901974 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.562987089 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.564495087 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.564558029 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.564560890 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.565931082 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.565973043 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.566031933 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.567480087 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.567517996 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.567565918 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.568960905 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.569020033 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.690165997 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.690251112 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.690315962 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.690648079 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.690763950 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.690810919 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.691843987 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.691979885 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.692033052 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.693032026 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.693078041 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.693123102 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.694287062 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.694329023 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.694422007 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.695476055 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.695605993 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.695648909 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.696692944 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.696712971 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.696772099 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.697910070 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.698030949 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.698091030 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.699115038 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.699239016 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.699306965 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.700326920 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.700504065 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.700553894 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.701555014 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.701718092 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.701761961 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.702769041 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.702886105 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.702929974 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.703979969 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.704085112 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.704121113 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.705193996 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.705302954 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.705343008 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.706418991 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.706523895 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.706573009 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.707612991 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.707801104 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.707931042 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.708837986 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.708964109 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.709003925 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.710079908 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.710242033 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.710283995 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.711287975 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.711411953 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.711452961 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.712593079 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.712812901 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.712852955 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.713743925 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.713835001 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.713874102 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.714972019 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.715076923 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.715118885 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.716155052 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.716268063 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.716308117 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.717381001 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.717603922 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.717648029 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.718596935 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.718724966 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.718764067 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.719863892 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.720005035 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.720046043 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.721019983 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.721143961 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.721189976 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.722218037 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.722341061 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.722484112 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.723468065 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.723572016 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.723613024 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.724666119 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.724798918 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.724838972 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.725879908 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.725996971 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.726036072 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.727138042 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.727178097 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.727220058 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.728317976 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.728436947 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.728476048 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.729537964 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.729625940 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.729665995 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.730750084 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.730873108 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.730914116 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.731985092 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.732108116 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.732407093 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.733175993 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.733268023 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.733314991 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.734415054 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.734504938 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.734544992 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.735611916 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.735740900 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.735785961 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.736855030 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.736968040 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.737008095 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.738059044 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.738130093 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.738183022 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.739274025 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.739382982 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.739437103 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.740516901 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.740647078 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.740688086 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.741707087 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.741811991 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.741854906 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.742955923 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.743024111 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.743077993 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.744184017 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.744303942 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.744345903 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.745347977 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.745502949 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.745542049 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.746567965 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.746696949 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.746731043 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.747932911 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.748027086 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.748786926 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.749043941 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.749114037 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.749150991 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.750207901 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.750328064 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.750368118 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.751465082 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.751593113 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.751693964 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.752681017 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.752821922 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.752865076 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.753807068 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.802037001 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.890178919 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.890374899 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.890427113 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.890850067 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.890917063 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.890958071 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.891028881 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.892158985 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.892201900 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.892258883 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.893520117 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.893789053 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.893816948 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.894649029 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.894752026 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.894797087 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.895781040 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.895839930 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.895893097 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.897016048 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.897059917 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.897095919 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.898214102 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.898257017 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.898269892 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.899456024 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.899523973 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.899550915 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.900675058 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.900721073 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.900804996 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.901853085 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.901918888 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.901947021 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.903094053 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.903136969 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.903212070 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.904314995 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.904360056 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.904397964 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.905510902 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.905620098 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.905666113 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.906753063 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.906795025 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.906829119 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.907944918 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.907989025 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.908148050 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.909185886 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.909197092 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.909229040 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.910391092 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.910427094 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.910459995 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.911595106 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.911638021 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.911710024 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.912822962 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.912883997 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.912916899 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.914011955 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.914057970 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.914074898 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.915326118 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.915368080 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.915395975 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.916455984 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.916502953 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.916546106 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.917721033 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.917802095 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.918147087 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.918912888 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.918962002 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.918986082 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.920098066 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.920140982 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.920222044 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.921441078 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.921480894 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.921547890 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.922574043 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.922683001 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.922688007 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.923773050 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.923861027 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.923882961 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.925017118 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.925060034 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.925091028 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.926172972 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.926306963 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.926337957 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.927411079 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.927454948 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.927525043 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.928622961 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.928684950 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.928698063 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.929838896 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.929883003 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.929986954 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.931061983 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.931109905 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.931149006 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.932285070 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.932326078 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.932360888 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.933506966 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.933547974 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.933598995 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.934746027 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.934797049 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.934818983 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.935916901 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.935969114 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.936028004 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.937128067 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.937159061 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.937203884 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.938381910 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.938492060 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.938524008 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.939587116 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.939635992 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.939677000 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.940856934 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.940901995 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.941000938 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.941999912 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.942044973 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.942085981 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.943242073 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.943279028 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.943321943 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.944417953 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.944489002 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.944552898 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.945672989 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.945724964 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.945729017 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.946865082 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.946903944 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.946913004 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.948100090 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.948152065 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.948183060 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.949281931 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.949322939 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.949387074 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.950536966 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.950550079 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.950584888 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.951807976 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.951883078 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.951919079 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.952963114 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:30.953035116 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:30.953049898 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.005147934 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.091578960 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.091680050 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.091775894 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.092107058 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.092222929 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.092384100 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.093368053 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.093544960 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.093590975 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.094552040 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.094613075 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.094655991 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.102550030 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.102569103 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.102581024 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.102590084 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.102601051 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.102611065 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.102621078 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.102631092 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.102638006 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.102639914 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.102650881 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.102662086 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.102670908 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.102675915 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.102686882 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.102709055 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.103327990 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.103542089 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.103584051 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.104767084 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.104840040 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.104883909 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.105730057 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.105859041 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.105902910 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.106791973 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.106820107 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.106865883 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.107918024 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.108026981 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.108074903 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.109143972 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.109246969 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.109416962 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.110424995 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.110471010 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.110584974 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.111579895 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.111705065 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.111826897 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.112807035 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.112926960 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.112973928 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.114006042 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.114115953 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.114161968 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.115246058 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.115309954 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.115350008 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.116444111 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.116503954 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.116544962 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.117667913 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.117759943 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.117808104 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.118902922 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.119026899 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.119236946 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.120129108 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.120311022 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.120393991 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.121323109 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.121438026 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.121619940 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.122514963 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.122642994 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.122680902 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.123826981 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.123902082 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.123950958 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.124993086 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.125093937 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.125284910 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.126180887 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.126298904 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.126722097 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.127422094 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.127547026 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.127593994 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.128617048 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.128739119 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.128783941 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.129858971 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.130023003 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.130069971 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.131093979 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.131172895 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.131216049 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.132262945 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.132365942 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.132412910 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.133538008 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.133553028 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.133610010 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.134720087 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.134821892 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.134871006 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.135938883 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.136080980 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.136128902 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.137135983 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.137271881 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.137336016 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.138401031 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.138499022 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.138694048 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.139591932 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.139727116 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.139775038 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.140831947 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.140952110 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.141062975 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.141993999 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.142045975 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.142096043 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.143215895 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.143330097 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.143433094 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.144469976 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.144548893 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.144593000 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.145705938 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.145752907 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.145816088 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.146899939 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.147283077 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.147350073 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.148085117 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.148224115 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.148282051 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.149308920 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.149442911 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.150552034 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.150615931 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.150654078 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.150702953 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.151717901 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.151838064 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.151902914 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.153033018 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.153053045 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.153126001 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.154197931 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.154301882 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.154347897 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.155343056 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.208286047 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.292896032 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.292942047 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.293097973 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.293399096 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.293714046 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.293764114 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.294635057 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.294774055 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.294819117 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.295803070 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.295955896 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.296485901 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.297018051 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.297153950 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.297219038 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.298269033 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.298428059 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.298476934 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.299454927 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.299575090 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.300050974 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.300678015 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.300802946 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.300843954 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.301908970 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.302027941 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.302520990 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.303123951 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.303215981 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.303360939 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.304335117 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.304380894 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.304487944 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.305505991 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.305605888 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.305680990 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.306766033 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.306868076 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.306905031 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.308013916 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.308202982 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.308284044 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.309235096 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.309370995 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.309664965 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.310453892 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.310554028 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.310673952 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.311614037 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.311826944 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.312316895 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.312833071 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.312891960 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.312937021 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.314059019 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.314157963 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.314213991 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.315346956 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.315423012 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.315466881 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.316500902 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.316615105 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.316764116 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.317778111 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.317858934 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.318068981 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.318947077 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.319118977 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.319163084 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.320173979 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.320473909 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.320521116 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.321336985 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.321412086 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.321449995 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.322582960 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.322801113 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.322949886 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.323785067 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.323905945 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.324664116 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.324978113 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.325090885 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.325187922 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.326225996 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.326292992 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.326473951 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.327409983 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.327564955 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.327610016 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.329140902 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.329267979 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.329305887 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.329919100 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.330069065 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.330113888 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.331379890 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.331437111 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.331682920 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.332371950 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.332482100 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.332550049 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.333561897 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.333673000 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.333868980 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.334835052 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.335020065 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.335118055 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.335963011 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.335984945 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.336030006 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.337168932 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.337264061 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.337311029 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.338404894 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.338527918 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.338733912 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.339627981 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.339767933 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.339827061 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.340900898 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.340995073 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.341147900 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.342051983 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.342161894 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.342279911 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.343280077 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.343406916 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.343451977 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.344477892 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.344575882 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.344628096 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.345762968 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.345873117 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.345921040 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.346920013 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.347059965 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.347229004 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.348166943 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.348448038 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.348536015 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.349339962 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.349447966 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.349639893 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.350590944 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.350708961 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.350792885 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.351794958 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.351913929 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.351962090 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.352991104 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.353079081 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.353120089 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.354213953 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.354319096 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.354717970 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.355454922 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.355596066 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.355642080 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.356770039 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.411432028 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.493977070 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.494043112 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.494297028 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.494582891 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.494730949 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.494951963 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.495773077 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.495893955 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.496079922 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.496978998 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.497109890 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.497651100 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.498195887 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.498297930 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.498356104 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.499408960 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.499530077 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.500705957 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.500767946 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.500768900 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.500808954 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.501867056 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.501913071 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.502037048 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.503078938 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.503119946 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.503181934 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.504288912 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.504354000 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.504595995 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.505517006 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.505645037 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.506756067 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.506814003 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.506846905 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.506894112 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.507936001 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.507986069 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.508143902 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.509160995 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.509239912 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.509608030 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.510354042 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.510461092 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.510962009 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.511590958 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.511708021 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.512814999 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.512873888 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.512937069 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.514040947 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.514169931 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.514235973 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.515208006 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.515333891 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.515908957 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.516439915 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.516653061 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.516705036 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.517671108 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.517777920 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.517862082 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.518913984 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.519098043 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.519412994 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.520119905 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.520201921 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.520261049 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.521334887 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.521459103 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.521509886 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.522553921 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.522573948 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.522650003 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.523763895 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.523878098 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.523933887 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.524964094 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.525083065 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.525319099 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.526228905 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.526309967 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.526426077 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.527544975 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.527599096 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.527663946 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.528651953 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.528754950 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.528809071 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.529879093 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.530000925 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.530046940 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.531083107 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.531102896 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.531677961 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.532289028 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.532365084 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.532413006 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.533516884 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.533627033 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.533696890 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.534730911 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.534837008 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.534882069 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.535949945 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.536065102 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.536107063 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.537161112 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.537272930 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.537353992 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.538367033 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.538461924 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.538507938 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.539740086 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.539752007 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.539798021 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.540798903 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.540894985 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.540980101 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.542015076 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.542139053 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.542953014 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.543226957 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.543308020 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.544449091 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.544497967 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.544549942 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.544904947 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.545712948 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.545880079 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.545919895 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.546940088 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.547069073 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.547116041 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.548095942 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.548203945 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.548238039 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.549315929 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.549408913 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.549541950 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.550529003 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.550649881 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.550960064 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.551748991 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.551862001 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.552799940 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.552973032 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.553082943 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.553432941 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.554192066 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.554331064 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.554405928 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.555402994 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.555526018 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.555561066 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.556622982 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.556745052 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.556797981 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.557791948 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.598906040 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.695513964 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.695568085 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.695703030 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.696038008 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.696113110 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.696156979 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.697235107 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.697328091 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.697987080 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.698446989 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.698550940 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.698605061 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.699657917 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.699767113 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.699810028 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.700903893 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.701000929 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.701056004 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.702135086 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.702238083 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.702286959 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.703326941 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.703455925 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.703500032 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.704617023 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.704628944 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.704664946 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.705741882 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.705950975 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.706053019 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.706988096 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.707051039 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.707107067 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.708291054 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.708427906 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.708476067 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.709387064 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.709512949 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.709558964 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.710654020 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.710781097 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.710829020 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.711946964 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.712043047 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.712091923 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.713073015 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.713253975 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.713510990 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.714380980 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.714590073 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.714636087 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.715511084 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.715697050 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.715872049 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.716752052 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.716882944 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.716933966 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.717968941 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.718070984 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.718218088 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.719229937 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.719280958 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.719422102 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.720402002 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.720474005 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.720545053 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.721651077 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.721752882 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.721829891 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.723100901 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.723244905 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.723308086 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.724575043 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.724709988 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.724852085 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.725733995 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.725788116 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.725996971 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.726550102 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.726629972 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.726726055 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.727734089 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.727781057 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.727935076 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.728897095 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.729027033 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.729147911 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.730134010 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.730285883 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.730679989 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.731386900 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.731509924 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.731581926 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.732578039 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.732687950 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.732755899 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.733908892 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.733963966 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.734034061 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.735035896 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.735136986 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.735249996 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.736216068 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.736339092 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.736498117 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.737437010 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.737545013 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.737710953 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.738646030 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.738801003 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.738858938 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.740032911 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.740181923 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.740221977 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.741389990 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.741504908 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.741548061 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.742436886 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.742567062 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.742603064 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.743752003 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.743885994 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.744005919 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.744826078 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.744971037 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.745130062 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.746012926 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.746126890 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.746229887 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.747229099 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.747347116 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.747400999 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.748405933 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.748512030 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.748553991 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.749620914 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.749737978 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.749818087 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.750873089 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.751010895 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.751065016 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.752052069 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.752181053 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.752289057 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.753317118 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.753456116 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.753571033 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.754515886 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.754683971 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.754735947 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.755831957 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.755996943 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.756150007 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.757006884 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.757158995 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.757236958 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.758263111 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.758405924 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.758543968 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.759340048 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.802047968 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.896650076 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.896770000 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.897142887 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.897166014 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.897413969 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.897550106 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.897608995 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.898650885 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.898710012 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.898746014 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.899857044 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.899909973 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.900029898 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.901067972 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.901209116 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.901226997 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.902359009 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.902436972 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.902476072 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.903503895 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.903587103 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.903660059 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.904716015 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.904824018 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.904881954 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.905942917 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.906013966 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.906049013 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.907143116 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.907243967 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.907295942 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.908389091 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.908449888 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.908514023 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.909605026 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.909694910 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.909769058 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.910825968 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.910885096 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.911091089 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.912028074 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.912102938 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.912111998 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.913261890 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.913467884 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.913522005 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.914452076 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.914511919 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.914587021 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.915652037 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.915779114 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.915831089 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.916894913 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.916945934 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.916976929 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.918102980 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.918169022 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.918205023 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.919348001 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.919418097 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.919441938 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.920531034 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.920686007 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.920748949 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.921777964 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.921844959 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.921881914 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.922991037 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.923152924 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.923185110 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.924210072 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.924351931 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.924709082 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.925456047 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.925508976 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.925544024 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.926634073 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.926697969 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.926719904 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.927845001 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.927901030 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.927973032 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.929075956 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.929178953 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.929249048 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.930325031 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.930382967 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.930423021 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.931567907 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.931646109 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.931715012 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.932735920 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.932801008 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.932837009 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.934077024 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.934283018 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.934297085 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.935157061 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.935295105 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.935328960 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.936369896 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.936491966 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.936552048 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.937588930 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.937660933 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.937695980 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.938807011 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.938860893 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.938934088 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.940009117 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.940058947 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.940069914 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.941214085 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.941313028 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.941358089 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.942425966 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.942497015 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.942559004 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.943665028 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.943731070 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.943759918 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.944871902 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.944932938 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.945105076 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.946131945 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.946201086 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.946212053 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.947329998 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.947384119 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.947463989 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.948532104 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.948625088 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.948673964 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.949902058 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.949933052 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.949980974 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.950953960 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.951108932 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.951143026 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.952214956 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.952368021 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.952426910 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.953401089 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.953454018 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.953550100 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.954626083 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.954679012 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.954709053 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.955856085 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.955933094 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.956007957 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.957094908 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.957149982 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.957225084 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.958355904 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.958450079 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.958467960 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:31.959502935 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.959578037 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:31.959636927 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.098057032 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.098139048 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.098364115 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.098571062 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.098964930 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.099893093 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.099968910 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.099971056 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.100019932 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.101020098 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.101130009 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.101185083 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.102260113 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.102381945 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.102674961 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.103468895 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.103591919 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.103634119 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.104670048 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.104804039 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.105232000 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.105885983 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.106110096 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.106163025 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.107120991 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.107251883 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.107295990 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.108325005 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.108442068 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.108802080 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.109529972 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.109663010 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.109715939 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.110821009 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.110951900 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.111084938 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.111983061 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.112083912 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.112135887 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.113205910 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.113292933 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.113351107 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.114401102 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.114512920 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.114656925 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.115631104 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.115740061 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.115814924 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.116837025 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.116944075 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.117119074 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.118072033 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.118166924 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.118721962 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.119286060 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.119400978 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.119457960 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.120518923 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.120605946 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.120867014 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.121716022 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.121834993 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.121891022 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.122935057 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.123044968 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.123099089 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.124138117 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.124264956 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.124324083 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.125376940 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.125475883 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.125524998 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.126585007 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.126701117 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.126832962 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.127793074 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.127895117 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.127933979 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.129010916 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.129132986 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.129209995 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.130264997 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.130547047 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.130603075 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.131669998 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.131680965 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.131737947 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.132693052 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.132816076 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.133902073 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.134016991 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.134110928 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.135128975 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.135231972 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.136112928 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.136312008 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.136454105 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.136501074 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.137546062 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.137660980 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.137710094 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.138777971 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.138911009 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.139014006 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.139935970 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.140059948 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.140109062 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.141205072 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.141264915 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.141319036 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.142442942 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.142540932 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.142596006 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.143624067 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.143735886 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.143794060 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.144854069 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.144942045 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.145029068 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.146060944 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.146178007 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.146967888 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.147269964 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.147413969 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.147469044 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.148485899 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.148633957 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.148693085 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.149707079 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.149815083 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.149878025 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.150923014 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.151036024 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.152112961 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.152177095 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.152235031 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.153345108 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.153433084 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.153469086 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.154625893 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.154689074 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.154730082 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.154958010 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.155805111 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.155855894 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.155915022 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.156992912 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.157108068 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.157160997 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.158238888 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.158361912 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.158416986 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.159457922 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.159565926 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.160689116 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.160736084 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.160747051 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.161617041 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.161840916 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.210974932 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.299325943 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.299340963 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.299583912 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.299654007 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.299710989 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.300813913 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.300858021 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.300932884 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.302122116 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.302169085 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.302201986 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.302901030 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.302947044 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.303067923 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.304096937 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.304141998 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.304176092 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.305301905 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.305331945 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.305354118 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.306570053 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.306629896 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.306682110 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.306952000 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.307750940 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.307869911 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.308942080 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.308999062 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.309035063 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.309076071 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.310228109 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.310409069 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.310615063 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.311357975 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.311398029 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.311439991 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.312581062 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.312719107 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.312766075 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.313776970 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.313889027 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.314340115 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.315015078 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.315114975 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.315160036 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.316231966 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.316344023 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.317436934 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.317497969 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.317504883 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.317548990 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.318645954 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.318762064 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.318950891 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.319853067 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.319961071 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.321079969 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.321136951 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.321202993 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.321249962 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.322365046 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.322463036 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.322501898 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.323497057 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.323616982 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.323669910 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.324717045 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.324842930 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.325479031 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.325922012 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.326015949 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.326064110 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.327199936 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.327289104 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.327339888 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.328361034 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.328500032 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.329772949 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.329792023 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.329838037 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.329912901 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.330821037 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.330945969 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.332010984 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.332063913 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.332118988 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.332169056 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.333225965 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.333311081 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.334435940 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.334490061 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.334530115 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.334573984 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.335689068 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.335807085 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.335854053 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.337174892 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.337368965 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.337418079 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.338306904 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.338457108 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.338514090 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.339291096 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.339390993 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.339441061 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.340522051 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.340768099 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.341698885 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.341753006 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.341806889 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.341852903 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.342957020 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.343097925 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.343157053 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.344176054 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.344326019 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.345788002 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.345861912 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.345864058 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.345916033 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.346709967 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.346734047 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.346965075 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.347774982 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.347840071 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.347907066 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.349000931 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.349107027 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.349158049 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.350219965 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.350334883 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.350956917 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.351432085 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.351541042 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.351633072 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.351660013 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.351660013 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.352628946 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.352737904 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.352782965 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.354062080 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.354167938 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.354959011 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.355088949 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.355190992 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.356476068 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.356528997 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.356549025 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.356590986 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.357516050 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.357698917 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.358716965 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.358778954 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.358834028 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.358879089 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.359946966 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.360090971 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.360145092 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.361159086 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.361212015 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.362365961 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.362421036 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.362454891 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.362503052 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.373493910 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.373527050 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.501205921 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.501307011 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.501492977 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.501768112 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.501852989 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.501899004 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.503032923 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.503135920 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.503174067 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.504198074 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.504327059 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.505162954 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.505420923 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.505542040 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.505578995 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.506640911 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.506766081 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.506802082 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.507870913 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.508002996 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.508450985 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.509015083 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.509057045 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.509324074 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.510313988 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.510426044 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.510472059 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.511516094 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.511676073 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.511827946 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.512751102 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.512840986 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.512886047 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.513927937 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.514029980 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.514190912 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.515150070 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.515192986 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.515228033 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.516366005 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.516475916 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.516653061 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.517590046 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.517658949 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.517714977 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.518866062 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.518929958 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.519002914 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.520009041 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.520134926 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.520344973 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.521264076 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.521370888 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.521414995 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.522428036 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.522495985 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.522536993 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.523727894 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.523813963 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.523848057 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.524844885 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.524983883 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.525016069 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.526072025 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.526268005 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.526956081 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.527329922 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.527383089 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.528340101 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.528495073 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.528633118 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.528664112 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.529736996 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.529903889 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.529939890 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.530939102 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.531028986 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.531064987 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.532224894 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.532299042 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.532332897 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.533384085 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.533512115 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.533550024 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.534697056 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.534859896 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.534905910 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.535789967 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.535948992 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.536083937 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.537121058 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.537309885 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.537353039 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.538213968 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.538372993 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.538487911 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.539453983 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.539565086 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.540644884 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.540692091 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.540703058 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.540730953 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.541894913 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.542094946 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.542237043 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.543072939 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.543140888 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.543201923 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.544300079 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.544393063 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.544711113 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.545552969 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.545670986 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.545763969 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.546720982 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.546897888 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.546936989 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.548023939 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.548125029 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.548167944 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.549140930 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.549237967 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.549526930 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.550378084 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.550493002 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.550534010 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.551573038 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.551623106 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.551697016 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.552788019 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.552953005 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.553297043 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.554054976 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.554230928 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.554285049 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.555221081 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.555294037 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.555329084 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.556461096 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.556587934 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.556678057 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.557643890 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.557722092 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.557826996 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.558844090 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.558973074 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.559009075 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.560062885 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.560162067 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.560399055 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.561261892 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.561387062 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.561573982 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.562505960 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.562635899 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.562688112 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.563810110 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.563967943 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.564053059 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.564874887 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.614535093 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.702641010 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.702671051 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.702727079 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.703344107 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.703533888 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.703577995 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.704394102 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.704514980 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.704601049 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.705576897 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.705723047 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.705765963 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.706799984 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.706902981 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.706955910 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.707993984 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.708127975 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.708170891 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.709208012 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.709301949 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.709343910 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.710412025 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.710515976 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.710565090 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.711613894 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.711673975 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.711743116 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.712847948 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.712940931 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.712981939 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.714032888 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.714099884 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.714137077 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.715260029 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.715338945 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.715384007 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.716466904 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.716595888 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.716636896 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.717662096 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.717744112 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.717783928 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.718924046 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.719036102 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.719088078 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.720067978 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.720190048 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.720231056 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.721275091 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.721323013 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.721398115 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.722480059 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.722578049 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.722621918 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.723684072 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.723797083 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.723843098 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.724895000 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.724997044 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.725054026 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.726083994 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.726201057 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.726244926 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.727324963 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.727401018 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.727447987 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.728498936 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.728645086 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.728698015 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.729736090 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.729792118 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.729839087 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.730921030 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.731005907 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.731061935 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.732126951 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.732238054 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.732285976 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.733350039 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.733491898 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.733540058 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.734608889 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.734762907 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.734805107 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.735754967 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.735847950 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.735944033 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.736974955 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.737076998 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.737128019 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.738213062 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.738401890 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.738445997 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.739367008 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.739465952 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.739547014 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.740621090 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.740748882 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.740838051 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.741792917 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.741893053 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.741936922 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.743017912 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.743083954 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.743136883 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.744244099 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.744349003 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.744396925 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.745404005 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.745527029 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.745702028 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.746618986 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.746774912 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.746819019 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.747853041 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.748018980 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.748078108 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.749046087 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.749162912 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.749207020 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.750227928 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.750332117 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.750397921 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.751533031 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.751739025 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.751781940 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.752684116 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.752712965 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.752760887 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.753881931 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.753983974 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.754046917 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.755081892 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.755155087 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.755259037 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.756300926 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.756406069 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.756500959 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.757487059 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.757555962 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.757602930 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.758693933 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.758899927 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.759108067 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.759933949 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.760031939 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.760077000 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.761162996 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.761266947 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.761401892 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.762303114 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.762415886 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.762459040 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.763524055 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.763660908 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.763699055 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.764831066 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.764975071 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.765069962 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.765990019 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.817663908 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.903920889 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.903994083 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.904056072 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.904397011 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.904469013 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.904511929 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.905581951 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.906032085 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.906078100 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.906145096 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.907269001 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.907308102 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.907322884 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.908577919 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.908622980 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.908740044 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.909674883 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.909728050 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.909764051 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.910866022 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.910914898 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.910973072 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.912168980 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.912220955 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.912265062 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.913325071 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.913382053 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.913474083 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.914494991 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.914558887 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.914571047 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.915688992 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.915731907 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.915791988 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.916995049 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.917043924 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.917077065 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.918159008 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.918175936 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.918215036 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.919723988 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.919737101 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.919831991 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.920537949 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.920591116 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.920608997 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.921792984 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.921838045 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.921840906 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.925129890 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.925142050 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.925154924 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.925167084 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.925182104 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.925220966 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.925714970 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.925755024 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.925899029 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.927021980 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.927067995 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.927171946 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.928251982 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.928263903 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.928312063 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.928958893 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.929003954 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.929100990 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.930219889 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.930268049 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.930366993 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.931549072 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.931561947 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.931611061 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.932627916 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.932730913 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.932882071 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.934071064 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.934132099 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.934197903 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.935180902 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.935235977 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.935259104 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.936342001 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.936353922 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.936397076 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.937602997 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.937654018 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.937793016 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.938641071 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.938740015 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.938911915 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.939913034 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.939971924 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.940047026 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.941298962 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.941312075 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.941353083 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.942298889 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.942318916 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.942358017 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.943507910 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.943543911 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.943567991 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.944904089 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.944917917 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.944967985 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.946075916 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.946091890 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.946147919 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.947118044 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.947175980 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.947248936 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.948575020 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.948594093 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.948626041 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.949588060 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.949760914 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.949768066 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.950720072 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.950851917 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.950877905 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.951900005 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.951993942 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.951997042 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.953210115 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.953267097 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.953310013 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.954658985 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.954670906 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.954741955 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.955599070 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.955650091 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.955876112 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.956825018 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.956873894 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.957108021 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.958024979 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.958106995 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.958174944 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.959155083 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.959229946 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.959402084 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.960655928 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.960666895 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.960707903 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.961560965 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.961606979 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.961627007 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.962856054 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.962877035 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.962907076 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.964154959 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.964168072 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.964205027 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.965367079 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.965399027 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.965444088 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:32.966377020 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.966526985 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:32.966581106 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.111358881 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.111471891 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.111515999 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.111891985 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.112029076 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.112082005 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.113125086 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.113192081 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.113236904 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.114314079 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.114478111 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.114528894 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.115533113 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.115662098 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.115703106 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.116754055 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.116806984 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.116869926 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.117978096 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.118052006 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.118093014 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.119209051 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.119334936 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.119395018 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.120326042 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.120434046 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.120480061 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.121543884 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.121642113 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.121699095 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.122816086 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.122932911 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.122986078 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.123981953 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.124097109 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.124182940 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.125200987 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.125308990 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.125371933 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.126410007 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.126456022 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.126493931 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.127650976 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.127794981 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.127837896 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.128823996 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.128935099 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.128978968 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.130031109 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.130150080 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.130192995 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.131213903 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.131359100 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.131405115 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.132405043 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.132551908 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.132601023 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.133656025 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.133776903 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.133821964 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.134917021 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.135030031 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.135077953 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.136037111 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.136190891 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.136241913 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.137290001 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.137434006 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.137475014 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.138459921 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.138575077 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.138784885 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.139668941 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.139786959 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.139831066 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.140866995 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.140943050 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.140985012 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.142318010 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.142565966 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.142610073 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.143481016 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.143580914 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.143631935 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.144511938 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.144628048 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.144748926 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.145771027 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.145910978 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.145975113 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.146931887 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.147041082 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.147085905 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.148179054 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.148313046 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.148370981 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.149343014 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.149451017 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.149591923 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.150532961 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.150621891 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.150665998 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.151819944 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.151925087 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.151971102 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.152957916 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.153052092 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.153110981 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.154201984 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.154301882 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.154350996 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.155383110 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.155509949 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.155556917 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.156595945 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.156728029 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.156785965 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.157881021 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.157973051 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.158020020 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.159063101 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.159158945 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.159208059 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.160207987 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.160339117 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.160382986 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.161411047 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.161514044 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.161559105 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.162587881 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.162719965 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.162766933 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.163825035 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.163914919 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.163955927 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.165076017 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.165177107 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.165222883 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.166224957 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.166332006 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.166371107 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.167463064 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.167644024 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.167689085 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.168638945 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.168756962 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.168802023 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.169846058 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.169915915 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.169959068 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.171083927 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.171224117 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.171262026 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.172261953 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.172379017 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.172424078 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.173522949 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.173604012 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.173652887 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.174633980 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.224054098 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.312474966 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.312609911 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.312797070 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.313256979 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.313563108 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.313647985 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.314348936 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.314410925 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.314459085 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.315511942 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.315608025 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.316253901 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.316705942 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.316845894 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.316890955 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.317925930 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.318034887 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.318178892 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.319127083 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.319230080 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.319284916 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.320318937 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.320439100 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.320489883 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.321547985 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.321651936 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.321866035 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.322807074 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.322897911 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.323117018 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.323971033 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.324059010 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.324109077 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.325177908 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.325382948 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.325448036 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.326455116 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.326500893 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.326616049 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.327605009 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.327711105 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.327765942 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.328833103 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.328969002 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.329019070 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.329982042 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.330104113 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.330177069 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.331219912 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.331338882 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.331950903 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.332382917 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.332489967 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.332542896 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.333600998 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.333709002 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.333764076 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.334889889 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.335005999 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.335088015 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.336067915 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.336409092 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.336463928 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.337225914 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.337332010 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.337403059 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.338432074 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.338548899 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.338711023 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.339637995 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.339746952 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.340329885 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.340863943 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.340977907 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.341022968 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.342080116 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.342165947 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.342398882 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.343266964 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.343349934 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.343395948 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.344481945 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.344577074 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.344621897 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.345659018 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.345792055 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.345868111 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.346898079 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.347018957 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.347071886 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.348170042 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.348270893 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.348318100 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.349320889 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.349451065 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.349498987 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.350584030 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.350708961 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.350755930 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.351743937 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.351902008 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.351949930 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.352938890 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.353048086 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.353096008 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.354229927 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.354374886 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.354430914 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.355362892 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.355509043 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.356002092 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.356568098 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.356796026 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.356842041 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.357845068 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.357990980 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.358032942 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.359133959 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.359222889 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.359270096 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.360174894 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.360274076 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.360323906 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.361484051 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.361562967 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.361603975 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.362658978 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.362755060 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.362806082 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.363836050 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.363957882 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.364557028 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.365045071 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.365164995 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.365211010 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.366242886 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.366353989 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.366410971 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.367532969 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.367620945 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.367687941 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.368632078 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.368752003 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.368841887 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.369832993 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.369956970 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.370008945 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.371057034 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.371176958 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.371352911 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.372250080 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.372370005 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.372420073 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.373461962 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.373601913 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.373660088 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.374686956 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.374758005 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.374809027 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.375802040 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.427023888 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.513890982 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.514115095 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.514168024 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.514359951 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.514514923 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.514559984 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.515696049 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.516180992 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.516340017 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.516515970 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.517216921 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.517298937 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.517324924 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.518574953 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.518634081 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.518745899 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.519656897 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.519704103 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.519727945 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.520812988 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.520874977 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.520917892 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.523494005 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.523554087 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.523642063 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.523783922 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.523797989 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.523900032 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.524832010 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.524878979 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.524960041 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.525991917 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.526041031 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.526119947 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.526954889 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.527061939 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.527076960 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.528278112 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.528325081 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.528440952 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.529341936 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.529390097 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.529450893 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.530716896 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.530730009 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.530766964 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.531677961 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.531723976 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.531857014 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.532924891 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.532975912 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.532995939 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.534106016 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.534148932 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.534286022 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.535329103 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.535375118 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.535410881 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.536528111 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.536588907 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.536612034 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.537722111 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.537781954 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.537834883 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.538933992 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.538981915 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.538990021 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.540132046 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.540220976 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.540234089 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.541344881 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.541393042 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.541424036 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.542562008 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.542614937 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.542692900 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.545025110 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.545037031 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.545051098 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.545077085 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.545109987 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.545156956 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.546472073 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.546516895 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.546633959 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.547677994 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.547729969 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.547836065 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.548573017 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.548708916 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.548753023 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.550019979 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.550034046 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.550075054 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.551086903 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.551168919 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.551201105 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.552346945 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.552432060 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.552495003 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.553570986 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.553585052 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.553628922 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.554609060 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.554662943 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.554721117 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.555870056 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.555922985 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.556001902 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.557049036 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.557156086 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.557229996 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.558320999 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.558382988 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.558454990 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.559602022 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.559705973 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.559717894 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.560678959 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.560775995 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.560908079 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.561887026 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.561939955 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.561956882 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.563103914 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.563211918 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.563263893 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.564307928 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.564363003 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.564443111 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.565484047 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.565589905 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.565648079 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.566701889 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.566756964 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.566787004 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.567925930 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.567939997 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.568070889 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.569122076 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.569161892 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.569238901 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.570295095 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.570400953 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.570455074 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.571495056 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.571551085 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.571625948 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.572753906 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.572879076 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.572985888 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.573955059 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.574091911 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.574143887 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.575160980 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.575390100 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.575438976 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.576354980 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.576436996 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.576487064 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.715187073 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.715310097 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.715373039 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.715781927 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.715862989 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.715971947 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.716978073 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.717411995 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.717456102 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.717525959 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.718687057 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.718744040 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.718916893 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.719868898 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.719928980 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.719968081 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.721050978 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.721110106 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.721149921 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.722304106 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.722367048 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.722384930 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.723844051 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.723855019 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.724052906 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.724694014 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.724754095 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.724781036 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.725893974 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.725971937 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.726011038 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.727087021 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.727143049 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.727210045 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.728388071 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.728435993 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.728542089 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.729512930 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.729566097 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.729587078 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.730705976 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.730756998 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.730834007 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.731930971 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.732021093 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.732033968 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.733158112 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.733243942 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.733251095 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.734311104 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.734359980 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.734421015 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.735539913 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.735593081 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.735619068 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.736735106 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.736785889 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.736944914 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.737934113 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.737981081 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.738013983 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.739175081 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.739224911 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.739301920 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.740346909 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.740392923 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.740462065 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.741574049 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.741624117 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.741682053 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.742794037 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.742842913 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.742875099 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.743999958 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.744056940 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.744077921 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.745230913 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.745276928 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.745337963 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.746386051 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.746424913 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.746500015 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.747606039 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.747656107 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.747663021 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.748830080 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.748959064 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.748995066 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.750097036 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.750143051 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.750225067 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.751238108 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.751290083 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.751427889 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.752429962 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.752501011 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.752521992 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.759370089 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.759392977 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.759404898 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.759416103 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.759428024 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.759438038 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.759448051 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.759459019 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.759460926 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.759480953 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.759495020 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.759510994 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.759535074 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.759654999 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.759769917 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.759795904 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.760870934 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.760971069 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.760986090 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.762069941 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.762132883 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.762178898 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.763369083 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.763416052 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.763444901 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.764653921 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.764873028 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.764930964 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.765747070 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.765841961 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.765899897 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.766921043 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.767044067 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.767096996 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.768115044 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.768158913 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.768224955 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.769382954 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.769418955 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.769474030 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.770545006 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.770602942 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.770652056 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.771768093 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.771828890 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.771884918 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.772984982 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.773070097 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.773102999 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.774204016 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.774310112 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.774367094 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.775427103 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.775597095 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.775645971 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.776618004 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.776715040 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.776729107 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.777777910 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.777880907 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.777941942 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.916842937 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.916920900 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.917155981 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.917327881 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.917483091 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.918574095 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.918632984 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.918670893 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.918783903 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.919724941 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.919837952 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.919936895 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.920922995 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.921077013 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.921137094 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.922113895 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.922221899 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.922333002 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.923378944 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.923552990 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.923614979 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.924505949 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.924618006 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.924685955 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.925682068 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.925806046 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.925882101 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.926923037 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.927045107 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.927207947 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.928102970 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.928229094 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.928328991 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.929311037 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.929400921 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.929790020 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.930480957 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.930557966 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.930604935 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.931725025 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.931898117 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.931969881 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.932934999 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.933114052 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.933244944 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.934084892 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.934247971 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.935183048 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.935269117 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.935405970 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.936439991 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.936501026 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.936501980 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.936557055 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.937668085 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.937777996 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.937824965 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.938868999 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.938972950 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.939032078 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.940032959 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.940093040 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.940273046 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.941239119 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.941337109 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.941653013 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.942425013 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.942548037 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.942692995 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.943635941 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.943739891 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.943856001 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.944808006 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.944916010 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.944960117 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.946006060 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.946115017 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.946233034 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.947195053 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.947325945 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.947369099 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.948385000 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.948677063 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.948724985 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.949635983 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.949807882 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.949918032 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.950925112 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.951005936 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.951150894 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.951972008 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.952034950 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.952157974 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.953224897 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.953318119 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.953612089 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.954379082 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.954474926 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.954516888 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.955585957 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.955705881 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.955745935 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.956840992 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.956914902 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.956980944 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.957968950 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.958066940 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.958159924 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.959156036 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.959261894 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.959445953 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.960366011 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.960468054 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.960519075 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.961576939 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.961659908 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.961705923 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.962779999 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.962891102 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.962940931 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.963929892 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.964039087 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.965034008 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.965126038 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.965239048 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.966300011 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.966373920 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.966415882 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.966464043 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.967535973 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.967623949 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.967685938 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.968734980 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.968838930 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.968887091 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.969929934 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.970079899 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.970140934 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.971112013 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.971210003 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.971261024 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.972297907 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.972415924 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.972518921 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.973473072 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.973606110 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.973783970 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.974769115 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.974970102 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.975068092 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.975925922 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.975938082 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.975991964 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.977075100 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.977180004 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.977226973 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.978275061 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.978390932 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:33.978570938 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:33.979396105 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.020843029 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:34.118000031 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.118163109 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.118551016 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.118603945 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:34.118637085 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.119374037 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:34.119751930 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.119868994 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.120913982 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.120965004 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:34.121022940 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.121100903 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:34.122103930 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.122186899 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.123085976 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:34.123337030 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.123497009 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.124525070 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.124572992 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:34.124629021 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.124672890 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:34.125689983 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.125802040 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.125848055 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:34.126893044 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.127019882 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.128093004 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.128160954 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:34.128209114 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.128242016 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:34.129287958 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.129391909 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.129441977 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:34.130462885 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.130569935 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.130954981 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:34.131673098 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.131769896 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.132900000 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.132952929 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:34.133071899 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.133116961 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:34.134043932 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.134172916 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.134226084 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:34.135381937 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.135504007 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.135711908 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:34.151140928 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:34.161058903 CET499107982192.168.2.6104.37.175.218
                              Nov 25, 2024 21:35:34.271051884 CET798249910104.37.175.218192.168.2.6
                              Nov 25, 2024 21:35:34.281613111 CET798249910104.37.175.218192.168.2.6

                              Click to jump to process

                              Click to jump to process

                              Click to dive into process behavior distribution

                              Click to jump to process

                              Target ID:0
                              Start time:15:34:01
                              Start date:25/11/2024
                              Path:C:\Users\user\Desktop\file.exe
                              Wow64 process (32bit):false
                              Commandline:"C:\Users\user\Desktop\file.exe"
                              Imagebase:0x7ff7e5e00000
                              File size:954'368 bytes
                              MD5 hash:96A7B754CA8E8F35AE9E2B88B9F25658
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Reputation:low
                              Has exited:true

                              Target ID:1
                              Start time:15:34:02
                              Start date:25/11/2024
                              Path:C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe
                              Wow64 process (32bit):true
                              Commandline:C:\Users\user\AppData\Local\Temp\IXP000.TMP\computerlead.exe
                              Imagebase:0xc20000
                              File size:1'177'088 bytes
                              MD5 hash:2354E800EEFC681A7D60F3B6B28ACFD9
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Yara matches:
                              • Rule: JoeSecurity_DarkTortilla, Description: Yara detected DarkTortilla Crypter, Source: 00000001.00000002.2938052510.00000000056B0000.00000004.08000000.00040000.00000000.sdmp, Author: Joe Security
                              • Rule: JoeSecurity_DarkTortilla, Description: Yara detected DarkTortilla Crypter, Source: 00000001.00000002.2931668884.00000000032E1000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                              Antivirus matches:
                              • Detection: 100%, Avira
                              • Detection: 100%, Joe Sandbox ML
                              • Detection: 34%, ReversingLabs
                              Reputation:low
                              Has exited:true

                              Target ID:6
                              Start time:15:34:14
                              Start date:25/11/2024
                              Path:C:\Windows\System32\rundll32.exe
                              Wow64 process (32bit):false
                              Commandline:"C:\Windows\system32\rundll32.exe" C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\user\AppData\Local\Temp\IXP000.TMP\"
                              Imagebase:0x7ff67add0000
                              File size:71'680 bytes
                              MD5 hash:EF3179D498793BF4234F708D3BE28633
                              Has elevated privileges:false
                              Has administrator privileges:false
                              Programmed in:C, C++ or other language
                              Reputation:high
                              Has exited:true

                              Target ID:13
                              Start time:15:34:41
                              Start date:25/11/2024
                              Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe
                              Wow64 process (32bit):false
                              Commandline:"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"
                              Imagebase:0x280000
                              File size:43'008 bytes
                              MD5 hash:9827FF3CDF4B83F9C86354606736CA9C
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Reputation:moderate
                              Has exited:true

                              Target ID:14
                              Start time:15:34:43
                              Start date:25/11/2024
                              Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe
                              Wow64 process (32bit):false
                              Commandline:"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"
                              Imagebase:0x160000
                              File size:43'008 bytes
                              MD5 hash:9827FF3CDF4B83F9C86354606736CA9C
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Reputation:moderate
                              Has exited:true

                              Target ID:15
                              Start time:15:34:46
                              Start date:25/11/2024
                              Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe
                              Wow64 process (32bit):false
                              Commandline:"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"
                              Imagebase:0xe0000
                              File size:43'008 bytes
                              MD5 hash:9827FF3CDF4B83F9C86354606736CA9C
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Reputation:moderate
                              Has exited:true

                              Target ID:16
                              Start time:15:34:49
                              Start date:25/11/2024
                              Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe
                              Wow64 process (32bit):true
                              Commandline:"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe"
                              Imagebase:0xe50000
                              File size:43'008 bytes
                              MD5 hash:9827FF3CDF4B83F9C86354606736CA9C
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Yara matches:
                              • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000010.00000002.2946578088.0000000001610000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                              Reputation:moderate
                              Has exited:true

                              Target ID:18
                              Start time:15:35:22
                              Start date:25/11/2024
                              Path:C:\Windows\SysWOW64\fontdrvhost.exe
                              Wow64 process (32bit):true
                              Commandline:"C:\Windows\System32\fontdrvhost.exe"
                              Imagebase:0xe50000
                              File size:676'584 bytes
                              MD5 hash:8D0DA0C5DCF1A14F9D65F5C0BEA53F3D
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Yara matches:
                              • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000012.00000003.2941844125.0000000000760000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                              • Rule: JoeSecurity_Keylogger_Generic, Description: Yara detected Keylogger Generic, Source: 00000012.00000003.2946060481.0000000004D00000.00000004.00000001.00020000.00000000.sdmp, Author: Joe Security
                              • Rule: JoeSecurity_RHADAMANTHYS, Description: Yara detected RHADAMANTHYS Stealer, Source: 00000012.00000002.3046180127.0000000000A30000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                              • Rule: JoeSecurity_Keylogger_Generic, Description: Yara detected Keylogger Generic, Source: 00000012.00000003.2945665948.0000000004AE0000.00000004.00000001.00020000.00000000.sdmp, Author: Joe Security
                              Reputation:low
                              Has exited:true

                              Target ID:21
                              Start time:15:35:23
                              Start date:25/11/2024
                              Path:C:\Windows\SysWOW64\WerFault.exe
                              Wow64 process (32bit):true
                              Commandline:C:\Windows\SysWOW64\WerFault.exe -u -p 884 -s 420
                              Imagebase:0x650000
                              File size:483'680 bytes
                              MD5 hash:C31336C1EFC2CCB44B4326EA793040F2
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Reputation:high
                              Has exited:true

                              Target ID:22
                              Start time:15:35:33
                              Start date:25/11/2024
                              Path:C:\Windows\System32\fontdrvhost.exe
                              Wow64 process (32bit):false
                              Commandline:"C:\Windows\System32\fontdrvhost.exe"
                              Imagebase:0x7ff7d9200000
                              File size:827'408 bytes
                              MD5 hash:BBCB897697B3442657C7D6E3EDDBD25F
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Reputation:moderate
                              Has exited:true

                              Target ID:24
                              Start time:15:35:36
                              Start date:25/11/2024
                              Path:C:\Windows\System32\WerFault.exe
                              Wow64 process (32bit):false
                              Commandline:C:\Windows\system32\WerFault.exe -u -p 8124 -s 136
                              Imagebase:0x7ff652780000
                              File size:570'736 bytes
                              MD5 hash:FD27D9F6D02763BDE32511B5DF7FF7A0
                              Has elevated privileges:true
                              Has administrator privileges:true
                              Programmed in:C, C++ or other language
                              Reputation:high
                              Has exited:true

                              Reset < >

                                Execution Graph

                                Execution Coverage:24.4%
                                Dynamic/Decrypted Code Coverage:0%
                                Signature Coverage:42.4%
                                Total number of Nodes:989
                                Total number of Limit Nodes:45
                                execution_graph 3139 7ff7e5e0870e 3140 7ff7e5e08718 3139->3140 3141 7ff7e5e0876d SetFilePointer 3140->3141 3142 7ff7e5e0872c 3140->3142 3141->3142 3143 7ff7e5e016be 3144 7ff7e5e016f2 3143->3144 3145 7ff7e5e016cf 3143->3145 3145->3144 3146 7ff7e5e016eb ?terminate@ 3145->3146 3146->3144 3147 7ff7e5e0137e 3148 7ff7e5e01396 3147->3148 3149 7ff7e5e0138d _exit 3147->3149 3150 7ff7e5e0139f _cexit 3148->3150 3151 7ff7e5e013ab 3148->3151 3149->3148 3150->3151 3098 7ff7e5e081d1 3099 7ff7e5e0821c 3098->3099 3100 7ff7e5e08205 3098->3100 3101 7ff7e5e08213 3099->3101 3104 7ff7e5e08232 3099->3104 3105 7ff7e5e08316 3099->3105 3100->3101 3102 7ff7e5e08160 CloseHandle 3100->3102 3103 7ff7e5e013e0 7 API calls 3101->3103 3102->3101 3106 7ff7e5e083bb 3103->3106 3104->3101 3109 7ff7e5e08273 DosDateTimeToFileTime 3104->3109 3107 7ff7e5e08322 SetDlgItemTextA 3105->3107 3108 7ff7e5e08337 3105->3108 3107->3108 3108->3101 3123 7ff7e5e04140 GetFileAttributesA 3108->3123 3109->3101 3111 7ff7e5e08290 LocalFileTimeToFileTime 3109->3111 3111->3101 3113 7ff7e5e082ae SetFileTime 3111->3113 3113->3101 3114 7ff7e5e082d6 3113->3114 3116 7ff7e5e08160 CloseHandle 3114->3116 3115 7ff7e5e08400 29 API calls 3117 7ff7e5e0837b 3115->3117 3118 7ff7e5e082df SetFileAttributesA 3116->3118 3117->3101 3119 7ff7e5e08388 3117->3119 3118->3101 3130 7ff7e5e037dc LocalAlloc 3119->3130 3124 7ff7e5e04163 3123->3124 3128 7ff7e5e041d3 3123->3128 3125 7ff7e5e041bf SetFileAttributesA 3124->3125 3126 7ff7e5e064b0 28 API calls 3124->3126 3124->3128 3125->3128 3127 7ff7e5e041a6 3126->3127 3127->3125 3127->3128 3129 7ff7e5e041b9 3127->3129 3128->3101 3128->3115 3129->3125 3131 7ff7e5e03834 LocalAlloc 3130->3131 3132 7ff7e5e0380a 3130->3132 3135 7ff7e5e03863 3131->3135 3138 7ff7e5e0382d 3131->3138 3133 7ff7e5e061e8 24 API calls 3132->3133 3133->3138 3136 7ff7e5e061e8 24 API calls 3135->3136 3137 7ff7e5e03886 LocalFree 3136->3137 3137->3138 3138->3101 3152 7ff7e5e0143b RtlCaptureContext RtlLookupFunctionEntry 3153 7ff7e5e01485 RtlVirtualUnwind 3152->3153 3154 7ff7e5e014c7 3152->3154 3153->3154 3157 7ff7e5e01404 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 3154->3157 3158 7ff7e5e083fa 3159 7ff7e5e083bc 3158->3159 3160 7ff7e5e083fe 3158->3160 3161 7ff7e5e0847d lstrcmpA 3160->3161 3162 7ff7e5e08450 3160->3162 3164 7ff7e5e08474 3161->3164 3166 7ff7e5e084d4 3161->3166 3163 7ff7e5e061e8 24 API calls 3162->3163 3163->3164 3165 7ff7e5e08528 CreateFileA 3165->3164 3169 7ff7e5e0855e 3165->3169 3166->3164 3166->3165 3167 7ff7e5e085e1 CreateFileA 3167->3164 3168 7ff7e5e085c9 CharNextA 3168->3169 3169->3164 3169->3167 3169->3168 3170 7ff7e5e085b2 CreateDirectoryA 3169->3170 3170->3168 2246 7ff7e5e01150 2265 7ff7e5e018e4 2246->2265 2250 7ff7e5e0119b 2251 7ff7e5e011ad 2250->2251 2252 7ff7e5e011ca Sleep 2250->2252 2253 7ff7e5e011bd _amsg_exit 2251->2253 2256 7ff7e5e011d7 2251->2256 2252->2250 2253->2256 2254 7ff7e5e01259 _initterm 2257 7ff7e5e01276 _IsNonwritableInCurrentImage 2254->2257 2255 7ff7e5e0123a 2256->2254 2256->2255 2256->2257 2257->2255 2258 7ff7e5e012e4 2257->2258 2259 7ff7e5e0135f _ismbblead 2257->2259 2269 7ff7e5e07fe4 GetVersion 2258->2269 2259->2257 2262 7ff7e5e01336 2262->2255 2264 7ff7e5e0133f _cexit 2262->2264 2263 7ff7e5e0132e exit 2263->2262 2264->2255 2266 7ff7e5e01159 GetStartupInfoW 2265->2266 2267 7ff7e5e01910 6 API calls 2265->2267 2266->2250 2268 7ff7e5e0198f 2267->2268 2268->2266 2270 7ff7e5e0805d 2269->2270 2271 7ff7e5e0800b 2269->2271 2293 7ff7e5e05810 2270->2293 2271->2270 2272 7ff7e5e0800f GetModuleHandleW 2271->2272 2272->2270 2274 7ff7e5e08027 GetProcAddress 2272->2274 2274->2270 2277 7ff7e5e08042 2274->2277 2276 7ff7e5e080fa 2279 7ff7e5e08106 CloseHandle 2276->2279 2280 7ff7e5e0131f 2276->2280 2277->2270 2279->2280 2280->2262 2280->2263 2284 7ff7e5e080a4 2284->2276 2286 7ff7e5e080ae 2284->2286 2287 7ff7e5e080d9 2284->2287 2403 7ff7e5e061e8 2286->2403 2288 7ff7e5e080f5 2287->2288 2289 7ff7e5e080e2 ExitWindowsEx 2287->2289 2432 7ff7e5e033bc GetCurrentProcess OpenProcessToken 2288->2432 2289->2276 2294 7ff7e5e08e0d 2293->2294 2295 7ff7e5e0585c memset memset 2294->2295 2440 7ff7e5e05140 FindResourceA SizeofResource 2295->2440 2298 7ff7e5e058b6 CreateEventA SetEvent 2300 7ff7e5e05140 7 API calls 2298->2300 2299 7ff7e5e05a14 2302 7ff7e5e061e8 24 API calls 2299->2302 2301 7ff7e5e058f5 2300->2301 2303 7ff7e5e058f9 2301->2303 2305 7ff7e5e05938 2301->2305 2306 7ff7e5e05a02 2301->2306 2304 7ff7e5e05a37 2302->2304 2308 7ff7e5e061e8 24 API calls 2303->2308 2473 7ff7e5e013e0 2304->2473 2307 7ff7e5e05140 7 API calls 2305->2307 2445 7ff7e5e06768 2306->2445 2311 7ff7e5e0594f 2307->2311 2312 7ff7e5e05917 2308->2312 2311->2303 2315 7ff7e5e0595d CreateMutexA 2311->2315 2312->2304 2315->2306 2317 7ff7e5e05981 GetLastError 2315->2317 2316 7ff7e5e05a23 2318 7ff7e5e05a3c FindResourceExA 2316->2318 2319 7ff7e5e05a2b 2316->2319 2317->2306 2320 7ff7e5e05994 2317->2320 2322 7ff7e5e05a72 2318->2322 2323 7ff7e5e05a5d LoadResource 2318->2323 2481 7ff7e5e026b8 2319->2481 2324 7ff7e5e059c1 2320->2324 2325 7ff7e5e059a9 2320->2325 2327 7ff7e5e05a86 2322->2327 2328 7ff7e5e05a7a #17 2322->2328 2323->2322 2329 7ff7e5e061e8 24 API calls 2324->2329 2326 7ff7e5e061e8 24 API calls 2325->2326 2330 7ff7e5e059bf 2326->2330 2327->2304 2331 7ff7e5e05a96 2327->2331 2328->2327 2332 7ff7e5e059db 2329->2332 2333 7ff7e5e059e0 CloseHandle 2330->2333 2496 7ff7e5e03df0 GetVersionExA 2331->2496 2332->2306 2332->2333 2333->2304 2339 7ff7e5e046e8 2340 7ff7e5e04712 2339->2340 2341 7ff7e5e0473d 2339->2341 2342 7ff7e5e04730 2340->2342 2613 7ff7e5e056c8 2340->2613 2633 7ff7e5e04f18 2341->2633 2802 7ff7e5e04598 2342->2802 2351 7ff7e5e013e0 7 API calls 2353 7ff7e5e0484e 2351->2353 2352 7ff7e5e04757 GetSystemDirectoryA 2354 7ff7e5e0887c CharPrevA 2352->2354 2385 7ff7e5e043cc 2353->2385 2355 7ff7e5e04782 LoadLibraryA 2354->2355 2356 7ff7e5e047cf FreeLibrary 2355->2356 2357 7ff7e5e0479b GetProcAddress 2355->2357 2359 7ff7e5e047ea 2356->2359 2360 7ff7e5e04879 SetCurrentDirectoryA 2356->2360 2357->2356 2358 7ff7e5e047b6 DecryptFileA 2357->2358 2358->2356 2359->2360 2362 7ff7e5e047f6 GetWindowsDirectoryA 2359->2362 2361 7ff7e5e04813 2360->2361 2368 7ff7e5e04897 2360->2368 2366 7ff7e5e061e8 24 API calls 2361->2366 2362->2361 2364 7ff7e5e04860 2362->2364 2363 7ff7e5e04909 2376 7ff7e5e04931 2363->2376 2383 7ff7e5e0483c 2363->2383 2724 7ff7e5e034d8 2363->2724 2696 7ff7e5e05b50 2364->2696 2369 7ff7e5e04831 2366->2369 2368->2363 2373 7ff7e5e04933 2368->2373 2374 7ff7e5e048cd 2368->2374 2821 7ff7e5e06590 GetLastError 2369->2821 2371 7ff7e5e0496a 2380 7ff7e5e04985 2371->2380 2371->2383 2734 7ff7e5e04be0 2373->2734 2378 7ff7e5e064b0 28 API calls 2374->2378 2376->2371 2756 7ff7e5e0721c 2376->2756 2381 7ff7e5e048f8 2378->2381 2833 7ff7e5e04e34 2380->2833 2381->2383 2823 7ff7e5e07bb8 2381->2823 2383->2351 2386 7ff7e5e043f4 2385->2386 2387 7ff7e5e0442c LocalFree LocalFree 2386->2387 2389 7ff7e5e04409 SetFileAttributesA DeleteFileA 2386->2389 2394 7ff7e5e04453 2386->2394 2387->2386 2388 7ff7e5e044f1 2390 7ff7e5e04567 2388->2390 2392 7ff7e5e0450d RegOpenKeyExA 2388->2392 2389->2387 2391 7ff7e5e013e0 7 API calls 2390->2391 2393 7ff7e5e0457e 2391->2393 2392->2390 2395 7ff7e5e0453e RegDeleteValueA RegCloseKey 2392->2395 2393->2276 2393->2284 2399 7ff7e5e02540 2393->2399 2394->2388 2396 7ff7e5e044d4 SetCurrentDirectoryA 2394->2396 2397 7ff7e5e08914 4 API calls 2394->2397 2395->2390 2398 7ff7e5e026b8 16 API calls 2396->2398 2397->2396 2398->2388 2400 7ff7e5e02554 2399->2400 2401 7ff7e5e02566 2399->2401 2402 7ff7e5e034d8 19 API calls 2400->2402 2401->2284 2402->2401 2404 7ff7e5e06261 LoadStringA 2403->2404 2418 7ff7e5e063c1 2403->2418 2405 7ff7e5e062cd 2404->2405 2406 7ff7e5e0628b 2404->2406 2409 7ff7e5e06349 2405->2409 2413 7ff7e5e062d9 LocalAlloc 2405->2413 2408 7ff7e5e08bb4 13 API calls 2406->2408 2407 7ff7e5e013e0 7 API calls 2410 7ff7e5e06494 2407->2410 2411 7ff7e5e06290 2408->2411 2415 7ff7e5e063a2 LocalAlloc 2409->2415 2416 7ff7e5e0635c LocalAlloc 2409->2416 2410->2276 2410->2287 2412 7ff7e5e06299 MessageBoxA 2411->2412 2414 7ff7e5e08ae4 2 API calls 2411->2414 2412->2418 2413->2418 2422 7ff7e5e0632c 2413->2422 2414->2412 2415->2418 2425 7ff7e5e06344 MessageBeep 2415->2425 2416->2418 2424 7ff7e5e0638d 2416->2424 2418->2407 2426 7ff7e5e0366c _vsnprintf 2422->2426 2423 7ff7e5e08bb4 13 API calls 2427 7ff7e5e0642a 2423->2427 2428 7ff7e5e0366c _vsnprintf 2424->2428 2425->2423 2426->2425 2429 7ff7e5e06433 MessageBoxA LocalFree 2427->2429 2431 7ff7e5e08ae4 2 API calls 2427->2431 2428->2425 2429->2418 2431->2429 2433 7ff7e5e0341f LookupPrivilegeValueA AdjustTokenPrivileges CloseHandle 2432->2433 2434 7ff7e5e033fc 2432->2434 2433->2434 2435 7ff7e5e0349c ExitWindowsEx 2433->2435 2436 7ff7e5e061e8 24 API calls 2434->2436 2435->2434 2437 7ff7e5e03418 2435->2437 2436->2437 2438 7ff7e5e013e0 7 API calls 2437->2438 2439 7ff7e5e034ca 2438->2439 2439->2276 2441 7ff7e5e0518b 2440->2441 2442 7ff7e5e051f9 2440->2442 2441->2442 2443 7ff7e5e05194 FindResourceA LoadResource LockResource 2441->2443 2442->2298 2442->2299 2443->2442 2444 7ff7e5e051d3 memcpy_s FreeResource 2443->2444 2444->2442 2446 7ff7e5e06c68 2445->2446 2470 7ff7e5e067b2 2445->2470 2447 7ff7e5e013e0 7 API calls 2446->2447 2448 7ff7e5e05a10 2447->2448 2448->2299 2448->2316 2449 7ff7e5e06891 2449->2446 2451 7ff7e5e068ae GetModuleFileNameA 2449->2451 2450 7ff7e5e067e4 CharNextA 2450->2470 2452 7ff7e5e068dc 2451->2452 2453 7ff7e5e068cf 2451->2453 2452->2446 2537 7ff7e5e08a2c 2453->2537 2455 7ff7e5e06ddc 2545 7ff7e5e015b8 RtlCaptureContext RtlLookupFunctionEntry 2455->2545 2458 7ff7e5e068f8 CharUpperA 2461 7ff7e5e06d78 2458->2461 2458->2470 2459 7ff7e5e06d95 ExitProcess 2542 7ff7e5e029dc 2461->2542 2464 7ff7e5e06d89 CloseHandle 2464->2459 2465 7ff7e5e06a5d CharUpperA 2465->2470 2466 7ff7e5e06a06 CompareStringA 2466->2470 2467 7ff7e5e06abb CharUpperA 2467->2470 2468 7ff7e5e06990 CharUpperA 2468->2470 2469 7ff7e5e06b56 CharUpperA 2469->2470 2470->2446 2470->2449 2470->2450 2470->2455 2470->2458 2470->2465 2470->2466 2470->2467 2470->2468 2470->2469 2471 7ff7e5e089bc IsDBCSLeadByte CharNextA 2470->2471 2472 7ff7e5e0887c CharPrevA 2470->2472 2471->2470 2472->2470 2474 7ff7e5e013e9 2473->2474 2475 7ff7e5e013f4 2474->2475 2476 7ff7e5e01440 RtlCaptureContext RtlLookupFunctionEntry 2474->2476 2475->2276 2475->2339 2477 7ff7e5e01485 RtlVirtualUnwind 2476->2477 2478 7ff7e5e014c7 2476->2478 2477->2478 2551 7ff7e5e01404 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 2478->2551 2482 7ff7e5e026c1 2481->2482 2485 7ff7e5e02897 2481->2485 2483 7ff7e5e02888 2482->2483 2486 7ff7e5e02751 FindFirstFileA 2482->2486 2484 7ff7e5e013e0 7 API calls 2483->2484 2484->2485 2485->2304 2486->2483 2494 7ff7e5e02773 2486->2494 2487 7ff7e5e027ad lstrcmpA 2489 7ff7e5e0284e FindNextFileA 2487->2489 2490 7ff7e5e027cd lstrcmpA 2487->2490 2488 7ff7e5e02818 2491 7ff7e5e02829 SetFileAttributesA DeleteFileA 2488->2491 2492 7ff7e5e0286a FindClose RemoveDirectoryA 2489->2492 2489->2494 2490->2489 2490->2494 2491->2489 2492->2483 2494->2487 2494->2488 2494->2489 2495 7ff7e5e026b8 8 API calls 2494->2495 2552 7ff7e5e0887c 2494->2552 2495->2494 2501 7ff7e5e03e52 2496->2501 2503 7ff7e5e03e4b 2496->2503 2497 7ff7e5e040d0 2499 7ff7e5e013e0 7 API calls 2497->2499 2498 7ff7e5e061e8 24 API calls 2498->2497 2500 7ff7e5e04116 2499->2500 2500->2304 2511 7ff7e5e03118 2500->2511 2501->2497 2501->2503 2504 7ff7e5e03fc4 2501->2504 2556 7ff7e5e022f0 2501->2556 2503->2498 2504->2497 2504->2503 2505 7ff7e5e04083 MessageBeep 2504->2505 2569 7ff7e5e08bb4 2505->2569 2508 7ff7e5e0409f MessageBoxA 2508->2497 2512 7ff7e5e032e1 2511->2512 2513 7ff7e5e03168 2511->2513 2515 7ff7e5e013e0 7 API calls 2512->2515 2604 7ff7e5e02590 LoadLibraryA 2513->2604 2517 7ff7e5e03306 2515->2517 2517->2304 2530 7ff7e5e064b0 FindResourceA 2517->2530 2518 7ff7e5e03179 GetCurrentProcess OpenProcessToken 2518->2512 2519 7ff7e5e031a3 GetTokenInformation 2518->2519 2520 7ff7e5e032cc CloseHandle 2519->2520 2521 7ff7e5e031cc GetLastError 2519->2521 2520->2512 2521->2520 2522 7ff7e5e031e1 LocalAlloc 2521->2522 2522->2520 2523 7ff7e5e031fe GetTokenInformation 2522->2523 2524 7ff7e5e032bd LocalFree 2523->2524 2525 7ff7e5e03228 AllocateAndInitializeSid 2523->2525 2524->2520 2525->2524 2529 7ff7e5e03271 2525->2529 2526 7ff7e5e032ad FreeSid 2526->2524 2527 7ff7e5e0327e EqualSid 2528 7ff7e5e032a2 2527->2528 2527->2529 2528->2526 2529->2526 2529->2527 2529->2528 2531 7ff7e5e0654b 2530->2531 2532 7ff7e5e064eb LoadResource 2530->2532 2534 7ff7e5e061e8 24 API calls 2531->2534 2532->2531 2533 7ff7e5e06505 DialogBoxIndirectParamA FreeResource 2532->2533 2533->2531 2535 7ff7e5e0656a 2533->2535 2534->2535 2535->2312 2538 7ff7e5e08a87 2537->2538 2541 7ff7e5e08a4d 2537->2541 2538->2452 2539 7ff7e5e08a70 CharNextA 2539->2538 2539->2541 2540 7ff7e5e08a55 IsDBCSLeadByte 2540->2541 2541->2539 2541->2540 2543 7ff7e5e061e8 24 API calls 2542->2543 2544 7ff7e5e02a03 2543->2544 2544->2459 2544->2464 2546 7ff7e5e015f5 RtlVirtualUnwind 2545->2546 2547 7ff7e5e01637 2545->2547 2546->2547 2550 7ff7e5e01404 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 2547->2550 2553 7ff7e5e0889c 2552->2553 2553->2553 2554 7ff7e5e088c0 CharPrevA 2553->2554 2555 7ff7e5e088ae 2553->2555 2554->2555 2555->2494 2563 7ff7e5e024f2 2556->2563 2567 7ff7e5e0232d 2556->2567 2557 7ff7e5e02502 2557->2504 2558 7ff7e5e02517 GlobalFree 2558->2557 2560 7ff7e5e02360 GetFileVersionInfoSizeA 2561 7ff7e5e0237e GlobalAlloc 2560->2561 2560->2567 2561->2557 2562 7ff7e5e0239e GlobalLock 2561->2562 2562->2563 2564 7ff7e5e023b9 GetFileVersionInfoA 2562->2564 2563->2557 2563->2558 2565 7ff7e5e023dd VerQueryValueA 2564->2565 2564->2567 2566 7ff7e5e024b1 GlobalUnlock 2565->2566 2565->2567 2566->2567 2567->2560 2567->2563 2567->2566 2568 7ff7e5e02496 GlobalUnlock 2567->2568 2584 7ff7e5e02d34 2567->2584 2568->2558 2570 7ff7e5e08d26 2569->2570 2571 7ff7e5e08bf4 GetVersionExA 2569->2571 2573 7ff7e5e013e0 7 API calls 2570->2573 2571->2570 2572 7ff7e5e08c1d 2571->2572 2572->2570 2575 7ff7e5e08c40 GetSystemMetrics 2572->2575 2574 7ff7e5e04096 2573->2574 2574->2508 2580 7ff7e5e08ae4 2574->2580 2575->2570 2576 7ff7e5e08c57 RegOpenKeyExA 2575->2576 2576->2570 2577 7ff7e5e08c8c RegQueryValueExA RegCloseKey 2576->2577 2577->2570 2579 7ff7e5e08cd6 2577->2579 2578 7ff7e5e08d15 CharNextA 2578->2579 2579->2570 2579->2578 2581 7ff7e5e08b0a EnumResourceLanguagesA 2580->2581 2582 7ff7e5e08b8d 2580->2582 2581->2582 2583 7ff7e5e08b4f EnumResourceLanguagesA 2581->2583 2582->2508 2583->2582 2585 7ff7e5e02d73 CharUpperA CharNextA CharNextA 2584->2585 2586 7ff7e5e02f3d GetSystemDirectoryA 2584->2586 2587 7ff7e5e02db0 2585->2587 2588 7ff7e5e02dee 2585->2588 2589 7ff7e5e02f37 2586->2589 2591 7ff7e5e02db6 2587->2591 2592 7ff7e5e02dd5 GetSystemDirectoryA 2587->2592 2596 7ff7e5e0887c CharPrevA 2588->2596 2590 7ff7e5e0887c CharPrevA 2589->2590 2593 7ff7e5e02f5e 2589->2593 2590->2593 2591->2588 2594 7ff7e5e02dbc GetWindowsDirectoryA 2591->2594 2592->2589 2595 7ff7e5e013e0 7 API calls 2593->2595 2594->2589 2598 7ff7e5e02f6d 2595->2598 2597 7ff7e5e02e4d RegOpenKeyExA 2596->2597 2597->2589 2599 7ff7e5e02e80 RegQueryValueExA 2597->2599 2598->2567 2600 7ff7e5e02f26 RegCloseKey 2599->2600 2601 7ff7e5e02eb3 2599->2601 2600->2589 2602 7ff7e5e02ebc ExpandEnvironmentStringsA 2601->2602 2603 7ff7e5e02eda 2601->2603 2602->2603 2603->2600 2605 7ff7e5e025e5 GetProcAddress 2604->2605 2606 7ff7e5e02689 2604->2606 2608 7ff7e5e02603 AllocateAndInitializeSid 2605->2608 2609 7ff7e5e0267a FreeLibrary 2605->2609 2607 7ff7e5e013e0 7 API calls 2606->2607 2610 7ff7e5e02698 2607->2610 2608->2609 2611 7ff7e5e0264c FreeSid 2608->2611 2609->2606 2610->2512 2610->2518 2611->2609 2614 7ff7e5e05140 7 API calls 2613->2614 2615 7ff7e5e056e3 LocalAlloc 2614->2615 2616 7ff7e5e05701 2615->2616 2617 7ff7e5e0572f 2615->2617 2618 7ff7e5e061e8 24 API calls 2616->2618 2619 7ff7e5e05140 7 API calls 2617->2619 2620 7ff7e5e0571f 2618->2620 2621 7ff7e5e05741 2619->2621 2622 7ff7e5e06590 GetLastError 2620->2622 2623 7ff7e5e05745 2621->2623 2624 7ff7e5e0577e lstrcmpA 2621->2624 2632 7ff7e5e05724 2622->2632 2625 7ff7e5e061e8 24 API calls 2623->2625 2626 7ff7e5e057ae 2624->2626 2627 7ff7e5e05798 LocalFree 2624->2627 2630 7ff7e5e05763 LocalFree 2625->2630 2628 7ff7e5e061e8 24 API calls 2626->2628 2629 7ff7e5e0471f 2627->2629 2631 7ff7e5e057d0 LocalFree 2628->2631 2629->2341 2629->2342 2629->2383 2630->2629 2631->2632 2632->2629 2634 7ff7e5e05140 7 API calls 2633->2634 2635 7ff7e5e04f35 2634->2635 2636 7ff7e5e04f3a 2635->2636 2637 7ff7e5e04f7e 2635->2637 2638 7ff7e5e061e8 24 API calls 2636->2638 2639 7ff7e5e05140 7 API calls 2637->2639 2640 7ff7e5e04f59 2638->2640 2641 7ff7e5e04f97 2639->2641 2642 7ff7e5e04742 2640->2642 2643 7ff7e5e07bb8 13 API calls 2641->2643 2642->2383 2647 7ff7e5e0521c 2642->2647 2644 7ff7e5e04fa3 2643->2644 2644->2642 2645 7ff7e5e04fa7 2644->2645 2646 7ff7e5e061e8 24 API calls 2645->2646 2646->2640 2648 7ff7e5e05140 7 API calls 2647->2648 2649 7ff7e5e0525e LocalAlloc 2648->2649 2650 7ff7e5e052ae 2649->2650 2651 7ff7e5e0527e 2649->2651 2652 7ff7e5e05140 7 API calls 2650->2652 2653 7ff7e5e061e8 24 API calls 2651->2653 2654 7ff7e5e052c0 2652->2654 2655 7ff7e5e0529c 2653->2655 2657 7ff7e5e052c4 2654->2657 2658 7ff7e5e052fd lstrcmpA LocalFree 2654->2658 2656 7ff7e5e06590 GetLastError 2655->2656 2659 7ff7e5e052a1 2656->2659 2660 7ff7e5e061e8 24 API calls 2657->2660 2661 7ff7e5e05344 2658->2661 2662 7ff7e5e0538f 2658->2662 2663 7ff7e5e052a7 2659->2663 2665 7ff7e5e052e2 LocalFree 2660->2665 2670 7ff7e5e041ec 53 API calls 2661->2670 2664 7ff7e5e0566c 2662->2664 2667 7ff7e5e053a7 GetTempPathA 2662->2667 2668 7ff7e5e013e0 7 API calls 2663->2668 2666 7ff7e5e064b0 28 API calls 2664->2666 2665->2663 2666->2663 2669 7ff7e5e053ca 2667->2669 2677 7ff7e5e053fd 2667->2677 2671 7ff7e5e0474f 2668->2671 2846 7ff7e5e041ec 2669->2846 2673 7ff7e5e05364 2670->2673 2671->2352 2671->2383 2673->2663 2674 7ff7e5e0536c 2673->2674 2676 7ff7e5e061e8 24 API calls 2674->2676 2676->2659 2677->2663 2678 7ff7e5e05633 GetWindowsDirectoryA 2677->2678 2679 7ff7e5e05451 GetDriveTypeA 2677->2679 2683 7ff7e5e05b50 38 API calls 2678->2683 2681 7ff7e5e0546e GetFileAttributesA 2679->2681 2694 7ff7e5e05469 2679->2694 2681->2694 2683->2677 2684 7ff7e5e041ec 53 API calls 2684->2677 2685 7ff7e5e054ad GetDiskFreeSpaceA 2687 7ff7e5e054db MulDiv 2685->2687 2685->2694 2686 7ff7e5e0332c 25 API calls 2686->2694 2687->2694 2688 7ff7e5e0555a GetWindowsDirectoryA 2688->2694 2689 7ff7e5e05b50 38 API calls 2689->2694 2690 7ff7e5e0887c CharPrevA 2691 7ff7e5e05582 GetFileAttributesA 2690->2691 2692 7ff7e5e05598 CreateDirectoryA 2691->2692 2691->2694 2692->2694 2693 7ff7e5e055c5 SetFileAttributesA 2693->2694 2694->2663 2694->2678 2694->2679 2694->2681 2694->2685 2694->2686 2694->2688 2694->2689 2694->2690 2694->2693 2695 7ff7e5e041ec 53 API calls 2694->2695 2695->2694 2697 7ff7e5e05b9f GetCurrentDirectoryA SetCurrentDirectoryA 2696->2697 2715 7ff7e5e05b97 2696->2715 2698 7ff7e5e05bca 2697->2698 2699 7ff7e5e05bf7 GetDiskFreeSpaceA 2697->2699 2701 7ff7e5e061e8 24 API calls 2698->2701 2702 7ff7e5e05e16 memset 2699->2702 2703 7ff7e5e05c38 MulDiv 2699->2703 2700 7ff7e5e013e0 7 API calls 2704 7ff7e5e04875 2700->2704 2705 7ff7e5e05be7 2701->2705 2706 7ff7e5e06590 GetLastError 2702->2706 2703->2702 2707 7ff7e5e05c66 GetVolumeInformationA 2703->2707 2704->2360 2704->2383 2708 7ff7e5e06590 GetLastError 2705->2708 2709 7ff7e5e05e2e GetLastError FormatMessageA 2706->2709 2710 7ff7e5e05c9e memset 2707->2710 2711 7ff7e5e05cfd SetCurrentDirectoryA 2707->2711 2712 7ff7e5e05bec 2708->2712 2713 7ff7e5e05e70 2709->2713 2714 7ff7e5e06590 GetLastError 2710->2714 2719 7ff7e5e05d25 2711->2719 2712->2715 2716 7ff7e5e061e8 24 API calls 2713->2716 2717 7ff7e5e05cb6 GetLastError FormatMessageA 2714->2717 2715->2700 2718 7ff7e5e05e8b SetCurrentDirectoryA 2716->2718 2717->2713 2718->2715 2720 7ff7e5e05d68 2719->2720 2721 7ff7e5e05d8c 2719->2721 2722 7ff7e5e061e8 24 API calls 2720->2722 2721->2715 2902 7ff7e5e028b8 2721->2902 2722->2712 2725 7ff7e5e0358f 2724->2725 2726 7ff7e5e034eb 2724->2726 2922 7ff7e5e03044 GetWindowsDirectoryA 2725->2922 2728 7ff7e5e034f4 2726->2728 2729 7ff7e5e03588 2726->2729 2730 7ff7e5e03582 2728->2730 2731 7ff7e5e03502 RegOpenKeyExA 2728->2731 2919 7ff7e5e02f8c RegOpenKeyExA 2729->2919 2730->2376 2731->2730 2733 7ff7e5e03537 RegQueryValueExA RegCloseKey 2731->2733 2733->2730 2735 7ff7e5e05140 7 API calls 2734->2735 2736 7ff7e5e04bfb FindResourceA LoadResource LockResource 2735->2736 2737 7ff7e5e04e1f 2736->2737 2738 7ff7e5e04c4c 2736->2738 2737->2381 2739 7ff7e5e04ca6 2738->2739 2740 7ff7e5e04c58 GetDlgItem ShowWindow GetDlgItem ShowWindow 2738->2740 2930 7ff7e5e07e28 #20 2739->2930 2740->2739 2743 7ff7e5e04caf 2748 7ff7e5e061e8 24 API calls 2743->2748 2744 7ff7e5e04cb9 #20 2744->2743 2745 7ff7e5e04d21 #22 2744->2745 2746 7ff7e5e04da5 2745->2746 2747 7ff7e5e04d65 #23 2745->2747 2750 7ff7e5e04dc5 2746->2750 2751 7ff7e5e04db1 FreeResource 2746->2751 2747->2743 2747->2746 2749 7ff7e5e04da3 2748->2749 2749->2746 2752 7ff7e5e04def 2750->2752 2753 7ff7e5e04dd1 2750->2753 2751->2750 2752->2737 2755 7ff7e5e04e01 SendMessageA 2752->2755 2754 7ff7e5e061e8 24 API calls 2753->2754 2754->2752 2755->2737 2757 7ff7e5e07270 2756->2757 2773 7ff7e5e07287 2756->2773 2758 7ff7e5e05140 7 API calls 2757->2758 2758->2773 2759 7ff7e5e0729d memset 2759->2773 2760 7ff7e5e073b6 2761 7ff7e5e061e8 24 API calls 2760->2761 2799 7ff7e5e073d5 2761->2799 2762 7ff7e5e07655 2764 7ff7e5e013e0 7 API calls 2762->2764 2765 7ff7e5e07666 2764->2765 2765->2371 2766 7ff7e5e0773f 2766->2762 2770 7ff7e5e07759 RegOpenKeyExA 2766->2770 2767 7ff7e5e07457 CompareStringA 2767->2766 2767->2773 2768 7ff7e5e07700 2772 7ff7e5e061e8 24 API calls 2768->2772 2770->2762 2774 7ff7e5e0778e RegQueryValueExA 2770->2774 2771 7ff7e5e05140 7 API calls 2771->2773 2780 7ff7e5e0771f LocalFree 2772->2780 2773->2759 2773->2760 2773->2762 2773->2766 2773->2767 2773->2768 2773->2771 2777 7ff7e5e074f6 2773->2777 2778 7ff7e5e07646 LocalFree 2773->2778 2779 7ff7e5e07614 LocalFree 2773->2779 2784 7ff7e5e07355 CompareStringA 2773->2784 2957 7ff7e5e01d28 2773->2957 2996 7ff7e5e01a08 memset memset RegCreateKeyExA 2773->2996 3023 7ff7e5e07010 2773->3023 2775 7ff7e5e07883 RegCloseKey 2774->2775 2776 7ff7e5e077d3 memset GetSystemDirectoryA 2774->2776 2775->2762 2782 7ff7e5e07804 2776->2782 2783 7ff7e5e0781a 2776->2783 2789 7ff7e5e076db 2777->2789 2790 7ff7e5e07507 GetProcAddress 2777->2790 2800 7ff7e5e075ec FreeLibrary 2777->2800 2801 7ff7e5e0763a FreeLibrary 2777->2801 3039 7ff7e5e065b8 2777->3039 2778->2762 2779->2766 2779->2773 2780->2762 2786 7ff7e5e0887c CharPrevA 2782->2786 2787 7ff7e5e0366c _vsnprintf 2783->2787 2784->2773 2786->2783 2788 7ff7e5e07843 RegSetValueExA 2787->2788 2788->2775 2791 7ff7e5e061e8 24 API calls 2789->2791 2790->2777 2792 7ff7e5e07688 2790->2792 2795 7ff7e5e076fe 2791->2795 2793 7ff7e5e061e8 24 API calls 2792->2793 2796 7ff7e5e076ab FreeLibrary 2793->2796 2797 7ff7e5e076ba LocalFree 2795->2797 2796->2797 2798 7ff7e5e06590 GetLastError 2797->2798 2798->2799 2799->2762 2800->2779 2801->2778 2803 7ff7e5e05140 7 API calls 2802->2803 2804 7ff7e5e045af LocalAlloc 2803->2804 2805 7ff7e5e04601 2804->2805 2806 7ff7e5e045d1 2804->2806 2807 7ff7e5e05140 7 API calls 2805->2807 2808 7ff7e5e061e8 24 API calls 2806->2808 2809 7ff7e5e04613 2807->2809 2810 7ff7e5e045ef 2808->2810 2811 7ff7e5e04654 lstrcmpA 2809->2811 2812 7ff7e5e04617 2809->2812 2813 7ff7e5e06590 GetLastError 2810->2813 2815 7ff7e5e04672 2811->2815 2816 7ff7e5e046bc LocalFree 2811->2816 2814 7ff7e5e061e8 24 API calls 2812->2814 2817 7ff7e5e045f4 2813->2817 2818 7ff7e5e04635 LocalFree 2814->2818 2819 7ff7e5e064b0 28 API calls 2815->2819 2816->2817 2817->2341 2817->2383 2818->2817 2820 7ff7e5e04692 LocalFree 2819->2820 2820->2817 2822 7ff7e5e04836 2821->2822 2822->2383 2824 7ff7e5e07c16 2823->2824 2825 7ff7e5e0366c _vsnprintf 2824->2825 2831 7ff7e5e07c4e FreeResource 2824->2831 2832 7ff7e5e07c99 FreeResource 2824->2832 2826 7ff7e5e07c75 FindResourceA 2825->2826 2827 7ff7e5e07bea LoadResource LockResource 2826->2827 2828 7ff7e5e07c97 2826->2828 2827->2824 2827->2828 2829 7ff7e5e013e0 7 API calls 2828->2829 2830 7ff7e5e07cc4 2829->2830 2830->2363 2831->2824 2832->2828 2834 7ff7e5e05140 7 API calls 2833->2834 2835 7ff7e5e04e4f LocalAlloc 2834->2835 2836 7ff7e5e04e91 2835->2836 2837 7ff7e5e04e71 2835->2837 2839 7ff7e5e05140 7 API calls 2836->2839 2838 7ff7e5e061e8 24 API calls 2837->2838 2840 7ff7e5e04e8f 2838->2840 2841 7ff7e5e04ea3 2839->2841 2840->2383 2842 7ff7e5e04ebd lstrcmpA 2841->2842 2843 7ff7e5e04ea7 2841->2843 2842->2843 2844 7ff7e5e04ef6 LocalFree 2842->2844 2845 7ff7e5e061e8 24 API calls 2843->2845 2844->2840 2845->2844 2847 7ff7e5e0421e 2846->2847 2850 7ff7e5e042e5 2846->2850 2876 7ff7e5e04fd8 2847->2876 2849 7ff7e5e04362 2853 7ff7e5e013e0 7 API calls 2849->2853 2887 7ff7e5e05ed8 2850->2887 2857 7ff7e5e043ae 2853->2857 2855 7ff7e5e042d4 2861 7ff7e5e0887c CharPrevA 2855->2861 2856 7ff7e5e0427f GetSystemInfo 2866 7ff7e5e04299 2856->2866 2857->2663 2870 7ff7e5e0332c GetWindowsDirectoryA 2857->2870 2858 7ff7e5e04332 CreateDirectoryA 2862 7ff7e5e04370 2858->2862 2863 7ff7e5e04347 2858->2863 2859 7ff7e5e04351 2860 7ff7e5e05b50 38 API calls 2859->2860 2864 7ff7e5e0435e 2860->2864 2861->2850 2865 7ff7e5e06590 GetLastError 2862->2865 2863->2859 2864->2849 2869 7ff7e5e04386 RemoveDirectoryA 2864->2869 2868 7ff7e5e04375 2865->2868 2866->2855 2867 7ff7e5e0887c CharPrevA 2866->2867 2867->2855 2868->2849 2869->2849 2871 7ff7e5e0336a 2870->2871 2872 7ff7e5e03388 2870->2872 2873 7ff7e5e061e8 24 API calls 2871->2873 2874 7ff7e5e013e0 7 API calls 2872->2874 2873->2872 2875 7ff7e5e033a3 2874->2875 2875->2677 2875->2684 2878 7ff7e5e0500f 2876->2878 2879 7ff7e5e0887c CharPrevA 2878->2879 2882 7ff7e5e050a0 GetTempFileNameA 2878->2882 2899 7ff7e5e0366c 2878->2899 2880 7ff7e5e05071 RemoveDirectoryA GetFileAttributesA 2879->2880 2880->2878 2881 7ff7e5e05110 CreateDirectoryA 2880->2881 2881->2882 2883 7ff7e5e050e5 2881->2883 2882->2883 2884 7ff7e5e050c0 DeleteFileA CreateDirectoryA 2882->2884 2885 7ff7e5e013e0 7 API calls 2883->2885 2884->2883 2886 7ff7e5e04228 2885->2886 2886->2849 2886->2855 2886->2856 2888 7ff7e5e05ef3 2887->2888 2888->2888 2889 7ff7e5e05efc LocalAlloc 2888->2889 2890 7ff7e5e05f1c 2889->2890 2894 7ff7e5e05f5d 2889->2894 2891 7ff7e5e061e8 24 API calls 2890->2891 2893 7ff7e5e05f3a 2891->2893 2892 7ff7e5e0887c CharPrevA 2895 7ff7e5e05fb6 CreateFileA LocalFree 2892->2895 2896 7ff7e5e06590 GetLastError 2893->2896 2898 7ff7e5e0432e 2893->2898 2894->2892 2895->2893 2897 7ff7e5e06002 CloseHandle GetFileAttributesA 2895->2897 2896->2898 2897->2893 2898->2858 2898->2859 2900 7ff7e5e0369b _vsnprintf 2899->2900 2901 7ff7e5e0368c 2899->2901 2900->2901 2901->2878 2903 7ff7e5e028e5 2902->2903 2904 7ff7e5e02922 2902->2904 2905 7ff7e5e0366c _vsnprintf 2903->2905 2906 7ff7e5e0296b 2904->2906 2907 7ff7e5e02927 2904->2907 2908 7ff7e5e028fd 2905->2908 2911 7ff7e5e0366c _vsnprintf 2906->2911 2917 7ff7e5e0291d 2906->2917 2909 7ff7e5e0366c _vsnprintf 2907->2909 2913 7ff7e5e061e8 24 API calls 2908->2913 2910 7ff7e5e0293f 2909->2910 2914 7ff7e5e061e8 24 API calls 2910->2914 2915 7ff7e5e02987 2911->2915 2912 7ff7e5e013e0 7 API calls 2916 7ff7e5e029c9 2912->2916 2913->2917 2914->2917 2918 7ff7e5e061e8 24 API calls 2915->2918 2916->2715 2917->2912 2918->2917 2920 7ff7e5e03031 2919->2920 2921 7ff7e5e02fcd RegQueryInfoKeyA RegCloseKey 2919->2921 2920->2730 2921->2920 2923 7ff7e5e03081 2922->2923 2924 7ff7e5e030eb 2922->2924 2925 7ff7e5e0887c CharPrevA 2923->2925 2926 7ff7e5e013e0 7 API calls 2924->2926 2927 7ff7e5e03094 WritePrivateProfileStringA _lopen 2925->2927 2928 7ff7e5e030fd 2926->2928 2927->2924 2929 7ff7e5e030c7 _llseek _lclose 2927->2929 2928->2730 2929->2924 2931 7ff7e5e07eb5 2930->2931 2941 7ff7e5e07f2a 2930->2941 2942 7ff7e5e08400 2931->2942 2933 7ff7e5e013e0 7 API calls 2936 7ff7e5e04cab 2933->2936 2935 7ff7e5e07ed5 #21 2937 7ff7e5e07ef0 2935->2937 2935->2941 2936->2743 2936->2744 2937->2941 2954 7ff7e5e08160 2937->2954 2940 7ff7e5e07f17 #23 2940->2941 2941->2933 2943 7ff7e5e0843a 2942->2943 2944 7ff7e5e0847d lstrcmpA 2943->2944 2945 7ff7e5e08450 2943->2945 2947 7ff7e5e07ecc 2944->2947 2948 7ff7e5e084d4 2944->2948 2946 7ff7e5e061e8 24 API calls 2945->2946 2946->2947 2947->2935 2947->2941 2948->2947 2949 7ff7e5e08528 CreateFileA 2948->2949 2949->2947 2951 7ff7e5e0855e 2949->2951 2950 7ff7e5e085e1 CreateFileA 2950->2947 2951->2947 2951->2950 2952 7ff7e5e085c9 CharNextA 2951->2952 2953 7ff7e5e085b2 CreateDirectoryA 2951->2953 2952->2951 2953->2952 2955 7ff7e5e07f12 2954->2955 2956 7ff7e5e08194 CloseHandle 2954->2956 2955->2940 2955->2941 2956->2955 2958 7ff7e5e01d7d 2957->2958 3049 7ff7e5e02c98 2958->3049 2961 7ff7e5e0887c CharPrevA 2963 7ff7e5e01e10 2961->2963 2962 7ff7e5e08a2c 2 API calls 2964 7ff7e5e01eb3 2962->2964 2963->2962 2965 7ff7e5e02102 2964->2965 2966 7ff7e5e01ebc CompareStringA 2964->2966 2967 7ff7e5e08a2c 2 API calls 2965->2967 2966->2965 2968 7ff7e5e01eef GetFileAttributesA 2966->2968 2969 7ff7e5e0210f 2967->2969 2970 7ff7e5e020da 2968->2970 2971 7ff7e5e01f09 2968->2971 2972 7ff7e5e021b2 LocalAlloc 2969->2972 2973 7ff7e5e02118 CompareStringA 2969->2973 2974 7ff7e5e061e8 24 API calls 2970->2974 2971->2970 2976 7ff7e5e02c98 2 API calls 2971->2976 2972->2970 2975 7ff7e5e021d2 GetFileAttributesA 2972->2975 2973->2972 2984 7ff7e5e02147 2973->2984 2994 7ff7e5e01ff5 2974->2994 2982 7ff7e5e021e8 2975->2982 2977 7ff7e5e01f27 2976->2977 2979 7ff7e5e01f51 LocalAlloc 2977->2979 2980 7ff7e5e02c98 2 API calls 2977->2980 2978 7ff7e5e022b1 2983 7ff7e5e013e0 7 API calls 2978->2983 2979->2970 2981 7ff7e5e01f77 GetPrivateProfileIntA GetPrivateProfileStringA 2979->2981 2980->2979 2985 7ff7e5e0206f 2981->2985 2981->2994 2995 7ff7e5e0223b 2982->2995 2986 7ff7e5e022cd 2983->2986 2984->2984 2987 7ff7e5e02168 LocalAlloc 2984->2987 2989 7ff7e5e020a2 2985->2989 2990 7ff7e5e02080 GetShortPathNameA 2985->2990 2986->2773 2987->2970 2991 7ff7e5e02199 2987->2991 2993 7ff7e5e0366c _vsnprintf 2989->2993 2990->2989 2992 7ff7e5e0366c _vsnprintf 2991->2992 2992->2994 2993->2994 2994->2978 3057 7ff7e5e02a10 2995->3057 2997 7ff7e5e01cf2 2996->2997 3003 7ff7e5e01aac 2996->3003 2998 7ff7e5e013e0 7 API calls 2997->2998 2999 7ff7e5e01d01 2998->2999 2999->2773 3000 7ff7e5e0366c _vsnprintf 3001 7ff7e5e01acd RegQueryValueExA 3000->3001 3002 7ff7e5e01b24 GetSystemDirectoryA 3001->3002 3001->3003 3004 7ff7e5e0887c CharPrevA 3002->3004 3003->3000 3005 7ff7e5e01b05 3003->3005 3006 7ff7e5e01b48 LoadLibraryA 3004->3006 3005->3002 3007 7ff7e5e01b07 RegCloseKey 3005->3007 3008 7ff7e5e01b64 GetProcAddress FreeLibrary 3006->3008 3009 7ff7e5e01c30 GetModuleFileNameA 3006->3009 3007->2997 3008->3009 3011 7ff7e5e01b98 GetSystemDirectoryA 3008->3011 3010 7ff7e5e01c53 RegCloseKey 3009->3010 3014 7ff7e5e01bc2 3009->3014 3010->2997 3012 7ff7e5e01baf 3011->3012 3011->3014 3013 7ff7e5e0887c CharPrevA 3012->3013 3013->3014 3014->3014 3015 7ff7e5e01beb LocalAlloc 3014->3015 3016 7ff7e5e01c10 3015->3016 3017 7ff7e5e01c69 3015->3017 3019 7ff7e5e061e8 24 API calls 3016->3019 3018 7ff7e5e0366c _vsnprintf 3017->3018 3020 7ff7e5e01c9d 3018->3020 3021 7ff7e5e01c2e 3019->3021 3020->3020 3022 7ff7e5e01ca6 RegSetValueExA RegCloseKey LocalFree 3020->3022 3021->3010 3022->2997 3024 7ff7e5e0704f CreateProcessA 3023->3024 3036 7ff7e5e07048 3023->3036 3025 7ff7e5e070a5 WaitForSingleObject GetExitCodeProcess 3024->3025 3026 7ff7e5e07181 3024->3026 3027 7ff7e5e070dc 3025->3027 3028 7ff7e5e06590 GetLastError 3026->3028 3034 7ff7e5e02540 19 API calls 3027->3034 3037 7ff7e5e0710d 3027->3037 3030 7ff7e5e07186 GetLastError FormatMessageA 3028->3030 3029 7ff7e5e013e0 7 API calls 3031 7ff7e5e071fd 3029->3031 3032 7ff7e5e061e8 24 API calls 3030->3032 3031->2773 3032->3036 3033 7ff7e5e0714a CloseHandle CloseHandle 3035 7ff7e5e07178 3033->3035 3033->3036 3034->3037 3035->3036 3036->3029 3037->3033 3038 7ff7e5e07140 3037->3038 3038->3033 3040 7ff7e5e065ed 3039->3040 3041 7ff7e5e0887c CharPrevA 3040->3041 3042 7ff7e5e0662b GetFileAttributesA 3041->3042 3043 7ff7e5e06641 3042->3043 3044 7ff7e5e0665e LoadLibraryA 3042->3044 3043->3044 3045 7ff7e5e06645 LoadLibraryExA 3043->3045 3046 7ff7e5e06671 3044->3046 3045->3046 3047 7ff7e5e013e0 7 API calls 3046->3047 3048 7ff7e5e06681 3047->3048 3048->2777 3052 7ff7e5e02cb9 3049->3052 3051 7ff7e5e02cd1 3054 7ff7e5e089bc 2 API calls 3051->3054 3052->3051 3053 7ff7e5e01dd7 3052->3053 3071 7ff7e5e089bc 3052->3071 3053->2961 3053->2963 3055 7ff7e5e02cdf 3054->3055 3055->3053 3056 7ff7e5e089bc 2 API calls 3055->3056 3056->3055 3058 7ff7e5e02c69 3057->3058 3059 7ff7e5e02a47 3057->3059 3061 7ff7e5e013e0 7 API calls 3058->3061 3059->3058 3060 7ff7e5e02a50 GetModuleFileNameA 3059->3060 3060->3058 3070 7ff7e5e02a78 3060->3070 3062 7ff7e5e02c7c 3061->3062 3062->2978 3063 7ff7e5e02a7c IsDBCSLeadByte 3063->3070 3064 7ff7e5e02aa1 CharNextA CharUpperA 3066 7ff7e5e02b95 CharUpperA 3064->3066 3064->3070 3065 7ff7e5e02c3b CharNextA 3067 7ff7e5e02c4d CharNextA 3065->3067 3066->3070 3067->3058 3067->3063 3069 7ff7e5e02ae6 CharPrevA 3069->3070 3070->3063 3070->3064 3070->3065 3070->3067 3070->3069 3076 7ff7e5e08914 3070->3076 3072 7ff7e5e089d4 3071->3072 3073 7ff7e5e08a0d 3072->3073 3074 7ff7e5e089de IsDBCSLeadByte 3072->3074 3075 7ff7e5e089f6 CharNextA 3072->3075 3073->3052 3074->3072 3074->3073 3075->3072 3077 7ff7e5e0892c 3076->3077 3077->3077 3078 7ff7e5e08935 CharPrevA 3077->3078 3079 7ff7e5e08951 CharPrevA 3078->3079 3080 7ff7e5e08949 3079->3080 3082 7ff7e5e08968 3079->3082 3080->3079 3081 7ff7e5e08972 CharPrevA 3080->3081 3083 7ff7e5e0899b 3081->3083 3084 7ff7e5e08989 CharNextA 3081->3084 3082->3081 3082->3083 3082->3084 3083->3070 3084->3083 3171 7ff7e5e06e4f 3172 7ff7e5e06e9d 3171->3172 3173 7ff7e5e0887c CharPrevA 3172->3173 3174 7ff7e5e06ed5 CreateFileA 3173->3174 3175 7ff7e5e06f10 3174->3175 3176 7ff7e5e06f1e WriteFile 3174->3176 3179 7ff7e5e013e0 7 API calls 3175->3179 3177 7ff7e5e06f42 CloseHandle 3176->3177 3177->3175 3180 7ff7e5e06f75 3179->3180 3181 7ff7e5e0813e GlobalAlloc 3182 7ff7e5e0100e 3184 7ff7e5e01022 3182->3184 3189 7ff7e5e01798 GetModuleHandleW 3184->3189 3185 7ff7e5e01089 __set_app_type 3186 7ff7e5e010c6 3185->3186 3187 7ff7e5e010cf __setusermatherr 3186->3187 3188 7ff7e5e010dc 3186->3188 3187->3188 3190 7ff7e5e017ad 3189->3190 3190->3185 3191 7ff7e5e0170e SetUnhandledExceptionFilter 3192 7ff7e5e0604e 3193 7ff7e5e0614c 3192->3193 3195 7ff7e5e06062 3192->3195 3194 7ff7e5e06155 SendDlgItemMessageA 3193->3194 3197 7ff7e5e06145 3193->3197 3194->3197 3198 7ff7e5e060a1 GetDesktopWindow 3195->3198 3199 7ff7e5e0606f 3195->3199 3196 7ff7e5e06090 EndDialog 3196->3197 3202 7ff7e5e03c8c 6 API calls 3198->3202 3199->3196 3199->3197 3204 7ff7e5e03d63 SetWindowPos 3202->3204 3205 7ff7e5e013e0 7 API calls 3204->3205 3206 7ff7e5e03dce 6 API calls 3205->3206 3206->3197 3207 7ff7e5e0114b 3208 7ff7e5e01159 GetStartupInfoW 3207->3208 3209 7ff7e5e018e4 6 API calls 3207->3209 3211 7ff7e5e0119b 3208->3211 3209->3208 3212 7ff7e5e011ad 3211->3212 3213 7ff7e5e011ca Sleep 3211->3213 3214 7ff7e5e011bd _amsg_exit 3212->3214 3216 7ff7e5e011d7 3212->3216 3213->3211 3214->3216 3215 7ff7e5e01259 _initterm 3219 7ff7e5e01276 _IsNonwritableInCurrentImage 3215->3219 3216->3215 3217 7ff7e5e0123a 3216->3217 3216->3219 3218 7ff7e5e012e4 3221 7ff7e5e07fe4 292 API calls 3218->3221 3219->3217 3219->3218 3220 7ff7e5e0135f _ismbblead 3219->3220 3220->3219 3222 7ff7e5e0131f 3221->3222 3223 7ff7e5e01336 3222->3223 3224 7ff7e5e0132e exit 3222->3224 3223->3217 3225 7ff7e5e0133f _cexit 3223->3225 3224->3223 3225->3217 3226 7ff7e5e04bde 3227 7ff7e5e04bfb FindResourceA LoadResource LockResource 3226->3227 3228 7ff7e5e05140 7 API calls 3226->3228 3229 7ff7e5e04c4c 3227->3229 3243 7ff7e5e04e1f 3227->3243 3228->3227 3230 7ff7e5e04ca6 3229->3230 3231 7ff7e5e04c58 GetDlgItem ShowWindow GetDlgItem ShowWindow 3229->3231 3232 7ff7e5e07e28 33 API calls 3230->3232 3231->3230 3233 7ff7e5e04cab 3232->3233 3234 7ff7e5e04caf 3233->3234 3235 7ff7e5e04cb9 #20 3233->3235 3239 7ff7e5e061e8 24 API calls 3234->3239 3235->3234 3236 7ff7e5e04d21 #22 3235->3236 3237 7ff7e5e04da3 3236->3237 3238 7ff7e5e04d65 #23 3236->3238 3240 7ff7e5e04dc5 3237->3240 3241 7ff7e5e04db1 FreeResource 3237->3241 3238->3234 3238->3237 3239->3237 3242 7ff7e5e04def 3240->3242 3244 7ff7e5e061e8 24 API calls 3240->3244 3241->3240 3242->3243 3245 7ff7e5e04e01 SendMessageA 3242->3245 3244->3242 3245->3243 3246 7ff7e5e0499e 3247 7ff7e5e049c3 3246->3247 3248 7ff7e5e04a99 3246->3248 3247->3248 3250 7ff7e5e04aa1 GetDesktopWindow 3247->3250 3251 7ff7e5e049d8 3247->3251 3249 7ff7e5e04baa EndDialog 3248->3249 3257 7ff7e5e049e4 3248->3257 3249->3257 3252 7ff7e5e03c8c 14 API calls 3250->3252 3253 7ff7e5e049dc 3251->3253 3254 7ff7e5e04a0b 3251->3254 3256 7ff7e5e04abf 3252->3256 3253->3257 3258 7ff7e5e049eb TerminateThread 3253->3258 3255 7ff7e5e04a15 ResetEvent 3254->3255 3254->3257 3259 7ff7e5e061e8 24 API calls 3255->3259 3260 7ff7e5e04b2b SetWindowTextA CreateThread 3256->3260 3261 7ff7e5e04ac8 GetDlgItem SendMessageA GetDlgItem SendMessageA 3256->3261 3258->3249 3262 7ff7e5e04a53 3259->3262 3260->3257 3263 7ff7e5e04b78 3260->3263 3261->3260 3265 7ff7e5e04a74 SetEvent 3262->3265 3266 7ff7e5e04a5c SetEvent 3262->3266 3264 7ff7e5e061e8 24 API calls 3263->3264 3264->3248 3267 7ff7e5e07f58 3 API calls 3265->3267 3266->3257 3267->3248 3268 7ff7e5e0619e 3269 7ff7e5e061ac 3268->3269 3270 7ff7e5e061bb CallWindowProcA 3268->3270 3269->3270 3271 7ff7e5e061b7 3269->3271 3270->3271 3272 7ff7e5e0669e 3273 7ff7e5e066ba 3272->3273 3274 7ff7e5e066b2 3272->3274 3276 7ff7e5e0674a EndDialog 3273->3276 3278 7ff7e5e066bf 3273->3278 3274->3273 3275 7ff7e5e066ec GetDesktopWindow 3274->3275 3277 7ff7e5e03c8c 14 API calls 3275->3277 3276->3278 3279 7ff7e5e06703 SetWindowTextA SetDlgItemTextA SetForegroundWindow 3277->3279 3279->3278 3280 7ff7e5e0391b SendMessageA 3281 7ff7e5e083da 3282 7ff7e5e083ae 3281->3282 3283 7ff7e5e083e0 GlobalFree 3281->3283 3284 7ff7e5e013e0 7 API calls 3282->3284 3285 7ff7e5e083bb 3284->3285 3286 7ff7e5e010f0 __getmainargs 3287 7ff7e5e036ee 3288 7ff7e5e03748 GetDesktopWindow 3287->3288 3290 7ff7e5e0371d 3287->3290 3289 7ff7e5e03c8c 14 API calls 3288->3289 3293 7ff7e5e0375f LoadStringA SetDlgItemTextA MessageBeep 3289->3293 3291 7ff7e5e03737 EndDialog 3290->3291 3292 7ff7e5e03733 3290->3292 3291->3292 3294 7ff7e5e013e0 7 API calls 3292->3294 3293->3292 3295 7ff7e5e037c1 3294->3295 3296 7ff7e5e078ae 3297 7ff7e5e07b86 EndDialog 3296->3297 3298 7ff7e5e078d7 3296->3298 3301 7ff7e5e078eb 3297->3301 3299 7ff7e5e07b02 GetDesktopWindow 3298->3299 3300 7ff7e5e078e7 3298->3300 3302 7ff7e5e03c8c 14 API calls 3299->3302 3300->3301 3303 7ff7e5e079b5 GetDlgItemTextA 3300->3303 3304 7ff7e5e078fb 3300->3304 3305 7ff7e5e07b19 SetWindowTextA SendDlgItemMessageA 3302->3305 3313 7ff7e5e079de 3303->3313 3330 7ff7e5e07a69 3303->3330 3306 7ff7e5e07904 3304->3306 3307 7ff7e5e07998 EndDialog 3304->3307 3305->3301 3308 7ff7e5e07b5c GetDlgItem EnableWindow 3305->3308 3306->3301 3309 7ff7e5e07911 LoadStringA 3306->3309 3307->3301 3308->3301 3310 7ff7e5e0795e 3309->3310 3321 7ff7e5e0793d 3309->3321 3333 7ff7e5e03950 LoadLibraryA 3310->3333 3312 7ff7e5e061e8 24 API calls 3312->3301 3315 7ff7e5e07a14 GetFileAttributesA 3313->3315 3313->3330 3318 7ff7e5e07a7a 3315->3318 3319 7ff7e5e07a28 3315->3319 3316 7ff7e5e061e8 24 API calls 3332 7ff7e5e07957 3316->3332 3317 7ff7e5e0796b SetDlgItemTextA 3317->3301 3317->3321 3322 7ff7e5e0887c CharPrevA 3318->3322 3323 7ff7e5e061e8 24 API calls 3319->3323 3320 7ff7e5e07acf EndDialog 3320->3301 3321->3316 3325 7ff7e5e07a8e 3322->3325 3324 7ff7e5e07a4b 3323->3324 3324->3301 3326 7ff7e5e07a54 CreateDirectoryA 3324->3326 3327 7ff7e5e05ed8 31 API calls 3325->3327 3326->3318 3326->3330 3328 7ff7e5e07a96 3327->3328 3329 7ff7e5e07aa1 3328->3329 3328->3330 3331 7ff7e5e05b50 38 API calls 3329->3331 3330->3312 3331->3332 3332->3301 3332->3320 3334 7ff7e5e03994 GetProcAddress 3333->3334 3335 7ff7e5e03b5f 3333->3335 3336 7ff7e5e039b6 GetProcAddress 3334->3336 3337 7ff7e5e03b49 FreeLibrary 3334->3337 3338 7ff7e5e061e8 24 API calls 3335->3338 3336->3337 3339 7ff7e5e039db GetProcAddress 3336->3339 3337->3335 3340 7ff7e5e03b7e 3338->3340 3339->3337 3341 7ff7e5e039fd 3339->3341 3340->3301 3340->3317 3342 7ff7e5e03a11 GetTempPathA 3341->3342 3347 7ff7e5e03a5f FreeLibrary 3341->3347 3343 7ff7e5e03a26 3342->3343 3343->3343 3344 7ff7e5e03a2e CharPrevA 3343->3344 3345 7ff7e5e03a48 CharPrevA 3344->3345 3344->3347 3345->3347 3347->3340 3085 7ff7e5e087a0 3092 7ff7e5e07f58 3085->3092 3088 7ff7e5e087d2 WriteFile 3089 7ff7e5e087ca 3088->3089 3090 7ff7e5e08809 3088->3090 3090->3089 3091 7ff7e5e08835 SendDlgItemMessageA 3090->3091 3091->3089 3093 7ff7e5e07f64 MsgWaitForMultipleObjects 3092->3093 3094 7ff7e5e07fd6 3093->3094 3096 7ff7e5e07f8c 3093->3096 3094->3088 3094->3089 3095 7ff7e5e07fad PeekMessageA 3095->3096 3096->3093 3096->3094 3096->3095 3097 7ff7e5e07f9c DispatchMessageA 3096->3097 3097->3095 3348 7ff7e5e08660 3349 7ff7e5e086c1 ReadFile 3348->3349 3350 7ff7e5e0868d 3348->3350 3349->3350 3351 7ff7e5e08e60 _XcptFilter

                                Callgraph

                                • Executed
                                • Not Executed
                                • Opacity -> Relevance
                                • Disassembly available
                                callgraph 0 Function_00007FF7E5E01404 1 Function_00007FF7E5E01800 2 Function_00007FF7E5E0870E 3 Function_00007FF7E5E08914 4 Function_00007FF7E5E083FA 32 Function_00007FF7E5E061E8 4->32 5 Function_00007FF7E5E02A10 5->3 15 Function_00007FF7E5E013E0 5->15 6 Function_00007FF7E5E05810 6->15 26 Function_00007FF7E5E03DF0 6->26 6->32 39 Function_00007FF7E5E026B8 6->39 55 Function_00007FF7E5E064B0 6->55 79 Function_00007FF7E5E06768 6->79 83 Function_00007FF7E5E05140 6->83 98 Function_00007FF7E5E03118 6->98 7 Function_00007FF7E5E07010 7->15 7->32 69 Function_00007FF7E5E06590 7->69 82 Function_00007FF7E5E02540 7->82 8 Function_00007FF7E5E0100E 27 Function_00007FF7E5E017F0 8->27 54 Function_00007FF7E5E01798 8->54 9 Function_00007FF7E5E0170E 10 Function_00007FF7E5E08400 10->32 11 Function_00007FF7E5E01A08 11->15 11->32 65 Function_00007FF7E5E0887C 11->65 78 Function_00007FF7E5E0366C 11->78 12 Function_00007FF7E5E07FE4 12->6 12->32 33 Function_00007FF7E5E046E8 12->33 36 Function_00007FF7E5E033BC 12->36 45 Function_00007FF7E5E043CC 12->45 12->82 13 Function_00007FF7E5E018E4 14 Function_00007FF7E5E04BE0 14->32 14->83 104 Function_00007FF7E5E07E28 14->104 15->0 16 Function_00007FF7E5E07CE0 17 Function_00007FF7E5E04BDE 17->32 17->83 17->104 18 Function_00007FF7E5E029DC 18->32 19 Function_00007FF7E5E037DC 19->32 20 Function_00007FF7E5E04FD8 20->15 20->65 20->78 21 Function_00007FF7E5E05ED8 21->32 21->65 21->69 22 Function_00007FF7E5E034D8 71 Function_00007FF7E5E02F8C 22->71 80 Function_00007FF7E5E03044 22->80 23 Function_00007FF7E5E083DA 23->15 24 Function_00007FF7E5E019F2 25 Function_00007FF7E5E022F0 100 Function_00007FF7E5E02D34 25->100 26->15 26->25 31 Function_00007FF7E5E08AE4 26->31 26->32 51 Function_00007FF7E5E08BB4 26->51 28 Function_00007FF7E5E010F0 29 Function_00007FF7E5E036EE 29->15 72 Function_00007FF7E5E03C8C 29->72 30 Function_00007FF7E5E041EC 30->15 30->20 30->21 30->65 30->69 87 Function_00007FF7E5E05B50 30->87 32->15 32->31 32->51 32->78 33->14 33->15 33->22 33->32 41 Function_00007FF7E5E07BB8 33->41 46 Function_00007FF7E5E056C8 33->46 53 Function_00007FF7E5E04598 33->53 33->55 33->65 33->69 33->87 95 Function_00007FF7E5E0721C 33->95 96 Function_00007FF7E5E0521C 33->96 99 Function_00007FF7E5E04F18 33->99 101 Function_00007FF7E5E04E34 33->101 34 Function_00007FF7E5E081CA 35 Function_00007FF7E5E016BE 36->15 36->32 37 Function_00007FF7E5E081D1 37->10 37->15 37->16 37->19 61 Function_00007FF7E5E03BA8 37->61 75 Function_00007FF7E5E08160 37->75 81 Function_00007FF7E5E04140 37->81 38 Function_00007FF7E5E019BA 39->15 39->39 60 Function_00007FF7E5E035A8 39->60 39->65 40 Function_00007FF7E5E015B8 40->0 41->15 41->78 42 Function_00007FF7E5E028B8 42->15 42->32 42->78 43 Function_00007FF7E5E065B8 43->15 43->65 44 Function_00007FF7E5E089BC 45->3 45->15 45->39 46->32 46->69 46->83 47 Function_00007FF7E5E08AA9 48 Function_00007FF7E5E0499E 48->32 48->72 73 Function_00007FF7E5E07F58 48->73 49 Function_00007FF7E5E0619E 50 Function_00007FF7E5E0669E 50->72 51->15 52 Function_00007FF7E5E02C98 52->44 53->32 53->55 53->69 53->83 84 Function_00007FF7E5E0173C 54->84 55->32 56 Function_00007FF7E5E018B0 57 Function_00007FF7E5E078AE 57->21 57->32 57->65 57->72 57->87 89 Function_00007FF7E5E03950 57->89 58 Function_00007FF7E5E087A0 58->73 59 Function_00007FF7E5E08DA0 61->60 62 Function_00007FF7E5E01782 63 Function_00007FF7E5E0137E 64 Function_00007FF7E5E08E90 65->60 66 Function_00007FF7E5E08D7C 66->59 67 Function_00007FF7E5E02590 67->15 68 Function_00007FF7E5E06F90 70 Function_00007FF7E5E01890 72->15 74 Function_00007FF7E5E08159 76 Function_00007FF7E5E08660 77 Function_00007FF7E5E08E60 79->15 79->18 79->40 79->44 79->65 79->68 94 Function_00007FF7E5E08A2C 79->94 80->15 80->65 81->55 82->22 85 Function_00007FF7E5E0143B 85->0 86 Function_00007FF7E5E01150 86->12 86->13 88 Function_00007FF7E5E01850 86->88 87->15 87->32 87->42 87->69 88->1 88->56 89->32 90 Function_00007FF7E5E06E4F 90->15 90->65 91 Function_00007FF7E5E0813E 92 Function_00007FF7E5E0604E 92->72 93 Function_00007FF7E5E0114B 93->12 93->13 93->88 95->7 95->11 95->15 95->32 95->43 95->65 95->69 95->78 95->83 103 Function_00007FF7E5E01D28 95->103 96->15 96->30 96->32 96->55 96->65 96->69 96->83 96->87 102 Function_00007FF7E5E0332C 96->102 97 Function_00007FF7E5E0391B 98->15 98->67 99->32 99->41 99->83 100->15 100->65 101->32 101->83 102->15 102->32 103->5 103->15 103->32 103->52 103->60 103->65 103->78 103->94 104->10 104->15 104->75

                                Control-flow Graph

                                • Executed
                                • Not Executed
                                control_flow_graph 0 7ff7e5e0721c-7ff7e5e0726e 1 7ff7e5e07291-7ff7e5e07299 0->1 2 7ff7e5e07270-7ff7e5e0728b call 7ff7e5e05140 0->2 4 7ff7e5e0729d-7ff7e5e072bf memset 1->4 2->1 10 7ff7e5e073b6-7ff7e5e073df call 7ff7e5e061e8 2->10 6 7ff7e5e072c5-7ff7e5e072e0 call 7ff7e5e05140 4->6 7 7ff7e5e073e4-7ff7e5e073f7 4->7 6->10 16 7ff7e5e072e6-7ff7e5e072ec 6->16 9 7ff7e5e073fb-7ff7e5e07405 7->9 13 7ff7e5e07419-7ff7e5e07424 9->13 14 7ff7e5e07407-7ff7e5e0740d 9->14 23 7ff7e5e07655 10->23 15 7ff7e5e07427-7ff7e5e0742a 13->15 14->13 18 7ff7e5e0740f-7ff7e5e07417 14->18 19 7ff7e5e0742c-7ff7e5e07444 call 7ff7e5e05140 15->19 20 7ff7e5e0748a-7ff7e5e0749f call 7ff7e5e01d28 15->20 21 7ff7e5e072f5-7ff7e5e072f8 16->21 22 7ff7e5e072ee-7ff7e5e072f3 16->22 18->9 18->13 19->10 35 7ff7e5e0744a-7ff7e5e07451 19->35 20->23 36 7ff7e5e074a5-7ff7e5e074ac 20->36 26 7ff7e5e07305-7ff7e5e07307 21->26 27 7ff7e5e072fa-7ff7e5e07303 21->27 25 7ff7e5e0730d 22->25 29 7ff7e5e07657-7ff7e5e07686 call 7ff7e5e013e0 23->29 31 7ff7e5e07310-7ff7e5e07313 25->31 26->31 32 7ff7e5e07309 26->32 27->25 31->15 37 7ff7e5e07319-7ff7e5e07323 31->37 32->25 39 7ff7e5e0773f-7ff7e5e07746 35->39 40 7ff7e5e07457-7ff7e5e07484 CompareStringA 35->40 41 7ff7e5e074ae-7ff7e5e074b5 36->41 42 7ff7e5e074cc-7ff7e5e074ce 36->42 43 7ff7e5e07325-7ff7e5e07328 37->43 44 7ff7e5e0738f-7ff7e5e07392 37->44 51 7ff7e5e07894-7ff7e5e07896 39->51 52 7ff7e5e0774c-7ff7e5e07753 39->52 40->20 40->39 41->42 48 7ff7e5e074b7-7ff7e5e074be 41->48 45 7ff7e5e074d4-7ff7e5e074db 42->45 46 7ff7e5e075ff-7ff7e5e0760b call 7ff7e5e07010 42->46 49 7ff7e5e07333-7ff7e5e07335 43->49 50 7ff7e5e0732a-7ff7e5e07331 43->50 44->20 47 7ff7e5e07398-7ff7e5e073b0 call 7ff7e5e05140 44->47 53 7ff7e5e074e1-7ff7e5e074e3 45->53 54 7ff7e5e07700-7ff7e5e0773a call 7ff7e5e061e8 LocalFree 45->54 63 7ff7e5e07610-7ff7e5e07612 46->63 47->10 47->20 48->42 57 7ff7e5e074c0-7ff7e5e074c2 48->57 49->23 59 7ff7e5e0733b 49->59 58 7ff7e5e07342-7ff7e5e07353 call 7ff7e5e05140 50->58 51->29 52->51 60 7ff7e5e07759-7ff7e5e07788 RegOpenKeyExA 52->60 53->46 62 7ff7e5e074e9-7ff7e5e074f0 53->62 54->23 57->45 66 7ff7e5e074c4-7ff7e5e074c7 call 7ff7e5e01a08 57->66 58->10 78 7ff7e5e07355-7ff7e5e07385 CompareStringA 58->78 59->58 60->51 67 7ff7e5e0778e-7ff7e5e077cd RegQueryValueExA 60->67 62->46 71 7ff7e5e074f6-7ff7e5e07501 call 7ff7e5e065b8 62->71 72 7ff7e5e07646-7ff7e5e07650 LocalFree 63->72 73 7ff7e5e07614-7ff7e5e0762a LocalFree 63->73 66->42 68 7ff7e5e07883-7ff7e5e0788f RegCloseKey 67->68 69 7ff7e5e077d3-7ff7e5e07802 memset GetSystemDirectoryA 67->69 68->51 76 7ff7e5e07804-7ff7e5e07815 call 7ff7e5e0887c 69->76 77 7ff7e5e0781a-7ff7e5e07843 call 7ff7e5e0366c 69->77 86 7ff7e5e076db-7ff7e5e076fe call 7ff7e5e061e8 71->86 87 7ff7e5e07507-7ff7e5e07523 GetProcAddress 71->87 72->23 73->39 80 7ff7e5e07630-7ff7e5e07635 73->80 76->77 88 7ff7e5e0784a-7ff7e5e07851 77->88 78->44 82 7ff7e5e07387-7ff7e5e0738a 78->82 80->4 82->20 98 7ff7e5e076ba-7ff7e5e076d6 LocalFree call 7ff7e5e06590 86->98 90 7ff7e5e07529-7ff7e5e07577 87->90 91 7ff7e5e07688-7ff7e5e076b5 call 7ff7e5e061e8 FreeLibrary 87->91 88->88 93 7ff7e5e07853-7ff7e5e0787e RegSetValueExA 88->93 95 7ff7e5e07581-7ff7e5e07589 90->95 96 7ff7e5e07579-7ff7e5e0757d 90->96 91->98 93->68 99 7ff7e5e07593-7ff7e5e07595 95->99 100 7ff7e5e0758b-7ff7e5e0758f 95->100 96->95 98->23 102 7ff7e5e0759f-7ff7e5e075a7 99->102 103 7ff7e5e07597-7ff7e5e0759b 99->103 100->99 105 7ff7e5e075b1-7ff7e5e075b3 102->105 106 7ff7e5e075a9-7ff7e5e075ad 102->106 103->102 107 7ff7e5e075b5-7ff7e5e075b9 105->107 108 7ff7e5e075bd-7ff7e5e075ea 105->108 106->105 107->108 110 7ff7e5e075ec-7ff7e5e075fd FreeLibrary 108->110 111 7ff7e5e0763a-7ff7e5e07641 FreeLibrary 108->111 110->73 111->72
                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Resource$Free$CompareFindLibraryLocalString$AddressLoadLockProcSizeofmemcpy_smemset
                                • String ID: <None>$ADMQCMD$C:\Users\user\AppData\Local\Temp\IXP000.TMP\$Comp$DoInfInstall$POSTRUNPROGRAM$REBOOT$RUNPROGRAM$SHOWWINDOW$Software\Microsoft\Windows\CurrentVersion\RunOnce$USRQCMD$advpack.dll$rundll32.exe %sadvpack.dll,DelNodeRunDLL32 "%s"$wextract_cleanup0
                                • API String ID: 2679723528-1916881147
                                • Opcode ID: 7c15d2287e13f44bf5b0efd27726c7da16db5c9add0c0a7c4d9a2026f4990c77
                                • Instruction ID: 57388ed3ba7390ef447972a8c4b6d4dd32cea146507a191c9504c83bc7230109
                                • Opcode Fuzzy Hash: 7c15d2287e13f44bf5b0efd27726c7da16db5c9add0c0a7c4d9a2026f4990c77
                                • Instruction Fuzzy Hash: 08025171A0864A86EB60AF14EA603B9B7A0FB44B4CFC45137DACD8B694DF3CD545C721

                                Control-flow Graph

                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Close$DirectoryFreeLibraryLocalSystemValuememset$AddressAllocCreateFileLoadModuleNameProcQuery
                                • String ID: %s /D:%s$C:\Users\user\AppData\Local\Temp\IXP000.TMP\$DelNodeRunDLL32$Software\Microsoft\Windows\CurrentVersion\RunOnce$advpack.dll$rundll32.exe %sadvpack.dll,DelNodeRunDLL32 "%s"$wextract_cleanup%d$wextract_cleanup0
                                • API String ID: 1522771004-607953301
                                • Opcode ID: 4787bf835d2d00f0f2994409a2d2f4fd237c0eb5fe9aa116df46f60fe985a84b
                                • Instruction ID: 3e20797b9a79e74fd840edbe2a8a44b33191af95aeeb880b56c062c830c6583c
                                • Opcode Fuzzy Hash: 4787bf835d2d00f0f2994409a2d2f4fd237c0eb5fe9aa116df46f60fe985a84b
                                • Instruction Fuzzy Hash: BE814E32A08B8986E710AF11E9603B9F7A1FB89F58F845136DA8E8B754DF3CD105CB51

                                Control-flow Graph

                                • Executed
                                • Not Executed
                                control_flow_graph 144 7ff7e5e01d28-7ff7e5e01d7a 145 7ff7e5e01d7d-7ff7e5e01d87 144->145 146 7ff7e5e01d9c-7ff7e5e01dae 145->146 147 7ff7e5e01d89-7ff7e5e01d8f 145->147 149 7ff7e5e01db0-7ff7e5e01dbb 146->149 150 7ff7e5e01dbd-7ff7e5e01dc4 146->150 147->146 148 7ff7e5e01d91-7ff7e5e01d9a 147->148 148->145 148->146 151 7ff7e5e01dc8-7ff7e5e01de6 call 7ff7e5e02c98 149->151 150->151 154 7ff7e5e01e52-7ff7e5e01e64 151->154 155 7ff7e5e01de8 151->155 156 7ff7e5e01e69-7ff7e5e01e73 154->156 157 7ff7e5e01deb-7ff7e5e01df2 155->157 158 7ff7e5e01e75-7ff7e5e01e7b 156->158 159 7ff7e5e01e88-7ff7e5e01ea1 call 7ff7e5e0887c 156->159 157->157 160 7ff7e5e01df4-7ff7e5e01df8 157->160 158->159 161 7ff7e5e01e7d-7ff7e5e01e86 158->161 164 7ff7e5e01ea6-7ff7e5e01eb6 call 7ff7e5e08a2c 159->164 160->154 163 7ff7e5e01dfa-7ff7e5e01e01 160->163 161->156 161->159 165 7ff7e5e01e03-7ff7e5e01e06 163->165 166 7ff7e5e01e08-7ff7e5e01e0a 163->166 172 7ff7e5e02102-7ff7e5e02112 call 7ff7e5e08a2c 164->172 173 7ff7e5e01ebc-7ff7e5e01ee9 CompareStringA 164->173 165->166 168 7ff7e5e01e10-7ff7e5e01e20 165->168 166->154 169 7ff7e5e01e0c-7ff7e5e01e0e 166->169 171 7ff7e5e01e23-7ff7e5e01e2d 168->171 169->154 169->168 174 7ff7e5e01e42-7ff7e5e01e50 171->174 175 7ff7e5e01e2f-7ff7e5e01e35 171->175 183 7ff7e5e021b2-7ff7e5e021d0 LocalAlloc 172->183 184 7ff7e5e02118-7ff7e5e02145 CompareStringA 172->184 173->172 177 7ff7e5e01eef-7ff7e5e01f03 GetFileAttributesA 173->177 174->164 175->174 178 7ff7e5e01e37-7ff7e5e01e40 175->178 180 7ff7e5e020da-7ff7e5e020e2 177->180 181 7ff7e5e01f09-7ff7e5e01f0b 177->181 178->171 178->174 182 7ff7e5e020e7-7ff7e5e020fd call 7ff7e5e061e8 180->182 181->180 185 7ff7e5e01f11-7ff7e5e01f2d call 7ff7e5e02c98 181->185 197 7ff7e5e022be-7ff7e5e022e7 call 7ff7e5e013e0 182->197 187 7ff7e5e021d2-7ff7e5e021e6 GetFileAttributesA 183->187 188 7ff7e5e02189-7ff7e5e02194 183->188 184->183 189 7ff7e5e02147-7ff7e5e0214e 184->189 200 7ff7e5e01f51-7ff7e5e01f71 LocalAlloc 185->200 201 7ff7e5e01f2f-7ff7e5e01f4c call 7ff7e5e02c98 185->201 192 7ff7e5e02265-7ff7e5e0226f 187->192 193 7ff7e5e021e8-7ff7e5e021ea 187->193 188->182 194 7ff7e5e02151-7ff7e5e02158 189->194 196 7ff7e5e02276-7ff7e5e02280 192->196 193->192 198 7ff7e5e021ec-7ff7e5e021fd 193->198 194->194 199 7ff7e5e0215a 194->199 204 7ff7e5e02294-7ff7e5e0229f 196->204 205 7ff7e5e02282-7ff7e5e02287 196->205 206 7ff7e5e02204-7ff7e5e0220e 198->206 208 7ff7e5e0215f-7ff7e5e02166 199->208 200->188 203 7ff7e5e01f77-7ff7e5e01ff3 GetPrivateProfileIntA GetPrivateProfileStringA 200->203 201->200 209 7ff7e5e01ff5-7ff7e5e02004 203->209 210 7ff7e5e0206f-7ff7e5e0207e 203->210 212 7ff7e5e022a2-7ff7e5e022ac call 7ff7e5e02a10 204->212 205->204 211 7ff7e5e02289-7ff7e5e02292 205->211 213 7ff7e5e02223-7ff7e5e02234 206->213 214 7ff7e5e02210-7ff7e5e02216 206->214 208->208 216 7ff7e5e02168-7ff7e5e02187 LocalAlloc 208->216 217 7ff7e5e02007-7ff7e5e02011 209->217 221 7ff7e5e020a2 210->221 222 7ff7e5e02080-7ff7e5e020a0 GetShortPathNameA 210->222 211->196 211->204 227 7ff7e5e022b1-7ff7e5e022bb 212->227 213->212 220 7ff7e5e02236-7ff7e5e02239 213->220 214->213 219 7ff7e5e02218-7ff7e5e02221 214->219 216->188 223 7ff7e5e02199-7ff7e5e021ad call 7ff7e5e0366c 216->223 225 7ff7e5e02025-7ff7e5e0203b 217->225 226 7ff7e5e02013-7ff7e5e02018 217->226 219->206 219->213 220->212 228 7ff7e5e0223b-7ff7e5e02263 call 7ff7e5e035a8 * 2 220->228 229 7ff7e5e020a9-7ff7e5e020d5 call 7ff7e5e0366c 221->229 222->229 223->227 233 7ff7e5e0203e-7ff7e5e02048 225->233 226->225 232 7ff7e5e0201a-7ff7e5e02023 226->232 227->197 228->212 229->227 232->217 232->225 236 7ff7e5e0205c-7ff7e5e0206a 233->236 237 7ff7e5e0204a-7ff7e5e0204f 233->237 236->227 237->236 239 7ff7e5e02051-7ff7e5e0205a 237->239 239->233 239->236
                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: String$PrivateProfile$AllocAttributesCompareFileLoadLocalMessageNamePathShort
                                • String ID: .BAT$.INF$AdvancedINF$C:\Users\user\AppData\Local\Temp\IXP000.TMP\$Command.com /c %s$DefaultInstall$Reboot$Version$rundll32.exe %s,InstallHinfSection %s 128 %s$setupapi.dll$setupx.dll
                                • API String ID: 383838535-3614570713
                                • Opcode ID: 2e4a39167a847aef4def7ff9a37549632115461138b4cb5282ed996653afc72e
                                • Instruction ID: c343383e805e228e2662bac3fa10bc37e1c910e8ca9a4df3bb75bd0d8c913fb9
                                • Opcode Fuzzy Hash: 2e4a39167a847aef4def7ff9a37549632115461138b4cb5282ed996653afc72e
                                • Instruction Fuzzy Hash: D3F1B262A0878A95EB11AF10E6603B9B7A0FB45F48FD44132DACD8B795DF3DD90AC311

                                Control-flow Graph

                                • Executed
                                • Not Executed
                                control_flow_graph 242 7ff7e5e0521c-7ff7e5e0527c call 7ff7e5e05140 LocalAlloc 245 7ff7e5e052ae-7ff7e5e052c2 call 7ff7e5e05140 242->245 246 7ff7e5e0527e-7ff7e5e052a1 call 7ff7e5e061e8 call 7ff7e5e06590 242->246 252 7ff7e5e052c4-7ff7e5e052fb call 7ff7e5e061e8 LocalFree 245->252 253 7ff7e5e052fd-7ff7e5e05342 lstrcmpA LocalFree 245->253 258 7ff7e5e052a7-7ff7e5e052a9 246->258 252->258 256 7ff7e5e05344-7ff7e5e05346 253->256 257 7ff7e5e0538f-7ff7e5e05395 253->257 262 7ff7e5e05353 256->262 263 7ff7e5e05348-7ff7e5e05351 256->263 259 7ff7e5e0566c-7ff7e5e05690 call 7ff7e5e064b0 257->259 260 7ff7e5e0539b-7ff7e5e053a1 257->260 264 7ff7e5e05692-7ff7e5e056be call 7ff7e5e013e0 258->264 259->264 260->259 266 7ff7e5e053a7-7ff7e5e053c8 GetTempPathA 260->266 267 7ff7e5e05356-7ff7e5e05366 call 7ff7e5e041ec 262->267 263->262 263->267 270 7ff7e5e05405-7ff7e5e05411 266->270 271 7ff7e5e053ca-7ff7e5e053d6 call 7ff7e5e041ec 266->271 277 7ff7e5e0536c-7ff7e5e0538a call 7ff7e5e061e8 267->277 278 7ff7e5e05667-7ff7e5e0566a 267->278 273 7ff7e5e05414-7ff7e5e05417 270->273 280 7ff7e5e053db-7ff7e5e053dd 271->280 279 7ff7e5e0541c-7ff7e5e05426 273->279 277->258 278->264 282 7ff7e5e05439-7ff7e5e0544b 279->282 283 7ff7e5e05428-7ff7e5e0542d 279->283 280->278 284 7ff7e5e053e3-7ff7e5e053ed call 7ff7e5e0332c 280->284 287 7ff7e5e05633-7ff7e5e0565c GetWindowsDirectoryA call 7ff7e5e05b50 282->287 288 7ff7e5e05451-7ff7e5e05467 GetDriveTypeA 282->288 283->282 286 7ff7e5e0542f-7ff7e5e05437 283->286 284->270 296 7ff7e5e053ef-7ff7e5e053ff call 7ff7e5e041ec 284->296 286->279 286->282 287->258 298 7ff7e5e05662 287->298 290 7ff7e5e0546e-7ff7e5e05482 GetFileAttributesA 288->290 291 7ff7e5e05469-7ff7e5e0546c 288->291 294 7ff7e5e05488-7ff7e5e0548b 290->294 295 7ff7e5e05515-7ff7e5e05528 call 7ff7e5e05b50 290->295 291->290 291->294 300 7ff7e5e05505 294->300 301 7ff7e5e0548d-7ff7e5e05497 294->301 308 7ff7e5e0554c-7ff7e5e05558 call 7ff7e5e0332c 295->308 309 7ff7e5e0552a-7ff7e5e05536 call 7ff7e5e0332c 295->309 296->270 296->278 298->273 304 7ff7e5e05509-7ff7e5e05510 300->304 301->304 305 7ff7e5e05499-7ff7e5e054ab 301->305 307 7ff7e5e0562a-7ff7e5e0562d 304->307 305->304 310 7ff7e5e054ad-7ff7e5e054d9 GetDiskFreeSpaceA 305->310 307->287 307->288 318 7ff7e5e0556e-7ff7e5e05596 call 7ff7e5e0887c GetFileAttributesA 308->318 319 7ff7e5e0555a-7ff7e5e05569 GetWindowsDirectoryA 308->319 309->300 317 7ff7e5e05538-7ff7e5e0554a call 7ff7e5e05b50 309->317 310->300 313 7ff7e5e054db-7ff7e5e054fc MulDiv 310->313 313->300 316 7ff7e5e054fe-7ff7e5e05503 313->316 316->295 316->300 317->300 317->308 324 7ff7e5e055ad 318->324 325 7ff7e5e05598-7ff7e5e055ab CreateDirectoryA 318->325 319->318 326 7ff7e5e055b0-7ff7e5e055b2 324->326 325->326 327 7ff7e5e055c5-7ff7e5e055e6 SetFileAttributesA 326->327 328 7ff7e5e055b4-7ff7e5e055c3 326->328 329 7ff7e5e055e9-7ff7e5e055f3 327->329 328->307 330 7ff7e5e055f5-7ff7e5e055fb 329->330 331 7ff7e5e05607-7ff7e5e05624 call 7ff7e5e041ec 329->331 330->331 332 7ff7e5e055fd-7ff7e5e05605 330->332 331->278 335 7ff7e5e05626 331->335 332->329 332->331 335->307
                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Resource$Free$AttributesDirectoryFileFindLoadLocal$Windows$AllocCreateDialogDiskDriveErrorIndirectLastLockMessageParamPathSizeofSpaceStringTempTypelstrcmpmemcpy_s
                                • String ID: <None>$A:\$C:\Users\user\AppData\Local\Temp\IXP000.TMP\$RUNPROGRAM$Z$msdownld.tmp
                                • API String ID: 3973824516-1370313076
                                • Opcode ID: 5d936fd06448e7924da8f5d7fa4264b0fdc18f972724515d1c910980030b4c7f
                                • Instruction ID: 6f2b3b8bc26c2c14f178166b4700e36659659b9025f4508f04a0398ded195426
                                • Opcode Fuzzy Hash: 5d936fd06448e7924da8f5d7fa4264b0fdc18f972724515d1c910980030b4c7f
                                • Instruction Fuzzy Hash: 03D19531A1864A86EB10AF10A6603BAE7A1FB85F48FD45037DACDCB695DF3DD805CB11

                                Control-flow Graph

                                • Executed
                                • Not Executed
                                control_flow_graph 336 7ff7e5e05810-7ff7e5e058b0 call 7ff7e5e08e0d memset * 2 call 7ff7e5e05140 341 7ff7e5e058b6-7ff7e5e058f7 CreateEventA SetEvent call 7ff7e5e05140 336->341 342 7ff7e5e05b04 336->342 347 7ff7e5e05926-7ff7e5e0592e 341->347 348 7ff7e5e058f9-7ff7e5e058ff 341->348 344 7ff7e5e05b09-7ff7e5e05b18 call 7ff7e5e061e8 342->344 349 7ff7e5e05b1d 344->349 350 7ff7e5e05930-7ff7e5e05932 347->350 351 7ff7e5e05938-7ff7e5e05953 call 7ff7e5e05140 347->351 352 7ff7e5e05901-7ff7e5e05921 call 7ff7e5e061e8 348->352 353 7ff7e5e05b1f-7ff7e5e05b46 call 7ff7e5e013e0 349->353 350->351 354 7ff7e5e05a02-7ff7e5e05a12 call 7ff7e5e06768 350->354 363 7ff7e5e05955-7ff7e5e0595b 351->363 364 7ff7e5e0595d-7ff7e5e0597b CreateMutexA 351->364 352->349 365 7ff7e5e05a14-7ff7e5e05a1e 354->365 366 7ff7e5e05a23-7ff7e5e05a29 354->366 363->352 364->354 367 7ff7e5e05981-7ff7e5e05992 GetLastError 364->367 365->344 368 7ff7e5e05a3c-7ff7e5e05a5b FindResourceExA 366->368 369 7ff7e5e05a2b-7ff7e5e05a37 call 7ff7e5e026b8 366->369 367->354 370 7ff7e5e05994-7ff7e5e059a7 367->370 372 7ff7e5e05a72-7ff7e5e05a78 368->372 373 7ff7e5e05a5d-7ff7e5e05a6f LoadResource 368->373 369->349 374 7ff7e5e059c1-7ff7e5e059de call 7ff7e5e061e8 370->374 375 7ff7e5e059a9-7ff7e5e059bf call 7ff7e5e061e8 370->375 378 7ff7e5e05a86-7ff7e5e05a8c 372->378 379 7ff7e5e05a7a-7ff7e5e05a81 #17 372->379 373->372 374->354 385 7ff7e5e059e0-7ff7e5e059fd CloseHandle 374->385 375->385 382 7ff7e5e05a96-7ff7e5e05aa0 call 7ff7e5e03df0 378->382 383 7ff7e5e05a8e-7ff7e5e05a91 378->383 379->378 382->349 388 7ff7e5e05aa2-7ff7e5e05ab1 382->388 383->353 385->349 388->383 389 7ff7e5e05ab3-7ff7e5e05abd 388->389 389->383 390 7ff7e5e05abf-7ff7e5e05ac6 389->390 390->383 391 7ff7e5e05ac8-7ff7e5e05acf call 7ff7e5e03118 390->391 391->383 394 7ff7e5e05ad1-7ff7e5e05b02 call 7ff7e5e064b0 391->394 394->353
                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Resource$FindLoad$CreateEventmemset$CloseErrorFreeHandleLastLockMessageMutexSizeofStringVersionmemcpy_s
                                • String ID: $Comp$EXTRACTOPT$INSTANCECHECK$TITLE$VERCHECK
                                • API String ID: 3100096412-3832775925
                                • Opcode ID: 8653199e0f438de8d8069cf14c7024af3c928556c2760d006214bcddc3634e53
                                • Instruction ID: bf412251f6e4da0c5d3d3870585a343ea6f819ac23bd62296f0be4f577dd4d7a
                                • Opcode Fuzzy Hash: 8653199e0f438de8d8069cf14c7024af3c928556c2760d006214bcddc3634e53
                                • Instruction Fuzzy Hash: C2816C21A0864B86F760BB10AA653B9E690AB45F8CFC45037D9CDCF695DF3CE441CB22

                                Control-flow Graph

                                • Executed
                                • Not Executed
                                control_flow_graph 397 7ff7e5e05b50-7ff7e5e05b95 398 7ff7e5e05b9f-7ff7e5e05bc8 GetCurrentDirectoryA SetCurrentDirectoryA 397->398 399 7ff7e5e05b97-7ff7e5e05b9a 397->399 401 7ff7e5e05bca-7ff7e5e05bf2 call 7ff7e5e061e8 call 7ff7e5e06590 398->401 402 7ff7e5e05bf7-7ff7e5e05c32 GetDiskFreeSpaceA 398->402 400 7ff7e5e05e9e-7ff7e5e05ecd call 7ff7e5e013e0 399->400 421 7ff7e5e05e9c 401->421 405 7ff7e5e05e16-7ff7e5e05e6b memset call 7ff7e5e06590 GetLastError FormatMessageA 402->405 406 7ff7e5e05c38-7ff7e5e05c60 MulDiv 402->406 417 7ff7e5e05e70-7ff7e5e05e97 call 7ff7e5e061e8 SetCurrentDirectoryA 405->417 406->405 410 7ff7e5e05c66-7ff7e5e05c9c GetVolumeInformationA 406->410 413 7ff7e5e05c9e-7ff7e5e05cf8 memset call 7ff7e5e06590 GetLastError FormatMessageA 410->413 414 7ff7e5e05cfd-7ff7e5e05d21 SetCurrentDirectoryA 410->414 413->417 415 7ff7e5e05d25-7ff7e5e05d2c 414->415 419 7ff7e5e05d3f-7ff7e5e05d52 415->419 420 7ff7e5e05d2e-7ff7e5e05d33 415->420 417->421 425 7ff7e5e05d56-7ff7e5e05d59 419->425 420->419 424 7ff7e5e05d35-7ff7e5e05d3d 420->424 421->400 424->415 424->419 427 7ff7e5e05d8c-7ff7e5e05d93 425->427 428 7ff7e5e05d5b-7ff7e5e05d64 425->428 430 7ff7e5e05d95-7ff7e5e05d9d 427->430 431 7ff7e5e05dc2-7ff7e5e05dd3 427->431 428->425 429 7ff7e5e05d66 428->429 429->427 432 7ff7e5e05d68-7ff7e5e05d87 call 7ff7e5e061e8 429->432 430->431 433 7ff7e5e05d9f-7ff7e5e05dc0 430->433 434 7ff7e5e05dd6-7ff7e5e05dde 431->434 432->421 433->434 435 7ff7e5e05de0-7ff7e5e05de4 434->435 436 7ff7e5e05dfa-7ff7e5e05dfd 434->436 438 7ff7e5e05de6 435->438 439 7ff7e5e05e03-7ff7e5e05e06 436->439 440 7ff7e5e05dff-7ff7e5e05e01 436->440 442 7ff7e5e05e08-7ff7e5e05e11 438->442 443 7ff7e5e05de8-7ff7e5e05df5 call 7ff7e5e028b8 438->443 439->438 440->438 442->400 443->400
                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: CurrentDirectory
                                • String ID: C:\Users\user\AppData\Local\Temp\IXP000.TMP\
                                • API String ID: 1611563598-388467436
                                • Opcode ID: 4926850c6f80b5d2401089667c5e764d4b6a610568242aaae11311db6a7c54a3
                                • Instruction ID: 8baef6e6565f6492ed8948e259254c07ff5ba4b1d1be31ea5c47d3b90b0429ec
                                • Opcode Fuzzy Hash: 4926850c6f80b5d2401089667c5e764d4b6a610568242aaae11311db6a7c54a3
                                • Instruction Fuzzy Hash: 21A19376A0874686E720AF10E6547AAFBA0FB89B48F844137DACD8B754DF3CD445CB11

                                Control-flow Graph

                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Resource$Find$FreeItemLoadLockShowWindow$MessageSendSizeofmemcpy_s
                                • String ID: *MEMCAB$CABINET
                                • API String ID: 1305606123-2642027498
                                • Opcode ID: c58bcb9b074187ce5f9bb8efe3d3a205079a6ea7fdf4a44bf9905c0b86b0ae6c
                                • Instruction ID: 44dd99f467eeb7a0b0734e63f7f2eab99697c40f8809caa8337318ca8354aa48
                                • Opcode Fuzzy Hash: c58bcb9b074187ce5f9bb8efe3d3a205079a6ea7fdf4a44bf9905c0b86b0ae6c
                                • Instruction Fuzzy Hash: C1511A71A08B4A86EB50AB10E6643B5E6A0FF89F49FC44136C9CDCB694DF3CE5058762

                                Control-flow Graph

                                • Executed
                                • Not Executed
                                control_flow_graph 500 7ff7e5e046e8-7ff7e5e04710 501 7ff7e5e04712-7ff7e5e04718 500->501 502 7ff7e5e0473d-7ff7e5e04744 call 7ff7e5e04f18 500->502 503 7ff7e5e04730-7ff7e5e04737 call 7ff7e5e04598 501->503 504 7ff7e5e0471a call 7ff7e5e056c8 501->504 509 7ff7e5e0483c 502->509 510 7ff7e5e0474a-7ff7e5e04751 call 7ff7e5e0521c 502->510 503->502 503->509 511 7ff7e5e0471f-7ff7e5e04721 504->511 514 7ff7e5e0483e-7ff7e5e0485e call 7ff7e5e013e0 509->514 510->509 518 7ff7e5e04757-7ff7e5e04799 GetSystemDirectoryA call 7ff7e5e0887c LoadLibraryA 510->518 511->509 515 7ff7e5e04727-7ff7e5e0472e 511->515 515->502 515->503 522 7ff7e5e047cf-7ff7e5e047e4 FreeLibrary 518->522 523 7ff7e5e0479b-7ff7e5e047b4 GetProcAddress 518->523 525 7ff7e5e047ea-7ff7e5e047f0 522->525 526 7ff7e5e04879-7ff7e5e0488e SetCurrentDirectoryA 522->526 523->522 524 7ff7e5e047b6-7ff7e5e047c9 DecryptFileA 523->524 524->522 525->526 529 7ff7e5e047f6-7ff7e5e04811 GetWindowsDirectoryA 525->529 527 7ff7e5e04890-7ff7e5e04895 526->527 528 7ff7e5e04897-7ff7e5e0489d 526->528 530 7ff7e5e04818-7ff7e5e04836 call 7ff7e5e061e8 call 7ff7e5e06590 527->530 531 7ff7e5e0489f-7ff7e5e048a6 528->531 532 7ff7e5e04917-7ff7e5e0491f 528->532 533 7ff7e5e04813 529->533 534 7ff7e5e04860-7ff7e5e04870 call 7ff7e5e05b50 529->534 530->509 538 7ff7e5e048ab-7ff7e5e048b9 531->538 536 7ff7e5e04921-7ff7e5e04923 532->536 537 7ff7e5e0494b 532->537 533->530 541 7ff7e5e04875-7ff7e5e04877 534->541 536->537 542 7ff7e5e04925-7ff7e5e04931 call 7ff7e5e034d8 536->542 540 7ff7e5e0494d-7ff7e5e0495b 537->540 538->538 543 7ff7e5e048bb-7ff7e5e048c2 538->543 546 7ff7e5e0495d-7ff7e5e04963 540->546 547 7ff7e5e04978-7ff7e5e0497f 540->547 541->509 541->526 542->540 549 7ff7e5e048c4-7ff7e5e048cb 543->549 550 7ff7e5e04933 call 7ff7e5e04be0 543->550 546->547 553 7ff7e5e04965 call 7ff7e5e0721c 546->553 554 7ff7e5e04981-7ff7e5e04983 547->554 555 7ff7e5e0498a-7ff7e5e0498f 547->555 549->550 551 7ff7e5e048cd-7ff7e5e048fb call 7ff7e5e064b0 549->551 561 7ff7e5e04938-7ff7e5e0493a 550->561 565 7ff7e5e048fd-7ff7e5e0490b call 7ff7e5e07bb8 551->565 566 7ff7e5e0493c-7ff7e5e04946 551->566 563 7ff7e5e0496a-7ff7e5e0496c 553->563 554->555 560 7ff7e5e04985 call 7ff7e5e04e34 554->560 555->514 560->555 561->565 561->566 563->509 568 7ff7e5e04972 563->568 565->509 570 7ff7e5e04911 565->570 566->509 568->547 570->532
                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: DirectoryLibrary$AddressAllocDecryptFileFreeLoadLocalProcSystemWindows
                                • String ID: C:\Users\user\AppData\Local\Temp\IXP000.TMP\$DecryptFileA$advapi32.dll
                                • API String ID: 3010855178-2712585282
                                • Opcode ID: d180db5752f1a20bb576ee2c9673d43da1fa3d8942f9ec25ef1480d3d5d04a0c
                                • Instruction ID: e252aa38f7e26a72b472d0e4c0d85954fd96457d5855ab95005cac875d469281
                                • Opcode Fuzzy Hash: d180db5752f1a20bb576ee2c9673d43da1fa3d8942f9ec25ef1480d3d5d04a0c
                                • Instruction Fuzzy Hash: 27712961E0874B86FA60BB50AB61375E690AF94F4DFC44437D9CDCA291DE7CE8418732

                                Control-flow Graph

                                • Executed
                                • Not Executed
                                control_flow_graph 571 7ff7e5e041ec-7ff7e5e04218 572 7ff7e5e0421e-7ff7e5e04223 call 7ff7e5e04fd8 571->572 573 7ff7e5e042e7-7ff7e5e042f6 571->573 576 7ff7e5e04228-7ff7e5e0422a 572->576 575 7ff7e5e042f9-7ff7e5e04303 573->575 577 7ff7e5e04305-7ff7e5e0430b 575->577 578 7ff7e5e04318-7ff7e5e04323 575->578 579 7ff7e5e04230-7ff7e5e04246 576->579 580 7ff7e5e0439c 576->580 577->578 581 7ff7e5e0430d-7ff7e5e04316 577->581 582 7ff7e5e04326-7ff7e5e04330 call 7ff7e5e05ed8 578->582 583 7ff7e5e04249-7ff7e5e04253 579->583 584 7ff7e5e0439e-7ff7e5e043c2 call 7ff7e5e013e0 580->584 581->575 581->578 594 7ff7e5e04332-7ff7e5e04345 CreateDirectoryA 582->594 595 7ff7e5e04351-7ff7e5e04359 call 7ff7e5e05b50 582->595 586 7ff7e5e04255-7ff7e5e0425b 583->586 587 7ff7e5e04268-7ff7e5e0427d 583->587 586->587 590 7ff7e5e0425d-7ff7e5e04266 586->590 591 7ff7e5e042d4-7ff7e5e042e5 call 7ff7e5e0887c 587->591 592 7ff7e5e0427f-7ff7e5e04297 GetSystemInfo 587->592 590->583 590->587 591->582 598 7ff7e5e042c3 592->598 599 7ff7e5e04299-7ff7e5e0429c 592->599 600 7ff7e5e04370-7ff7e5e0437b call 7ff7e5e06590 594->600 601 7ff7e5e04347 594->601 603 7ff7e5e0435e-7ff7e5e04360 595->603 602 7ff7e5e042ca-7ff7e5e042cf call 7ff7e5e0887c 598->602 606 7ff7e5e0429e-7ff7e5e042a1 599->606 607 7ff7e5e042ba-7ff7e5e042c1 599->607 600->580 601->595 602->591 609 7ff7e5e04362-7ff7e5e0436e 603->609 610 7ff7e5e0437d-7ff7e5e04384 603->610 612 7ff7e5e042a3-7ff7e5e042a6 606->612 613 7ff7e5e042b1-7ff7e5e042b8 606->613 607->602 609->584 610->580 614 7ff7e5e04386-7ff7e5e04397 RemoveDirectoryA 610->614 612->591 615 7ff7e5e042a8-7ff7e5e042af 612->615 613->602 614->580 615->602
                                APIs
                                • CreateDirectoryA.KERNEL32(?,?,?,?,?,?,0000000A,00007FF7E5E0807B), ref: 00007FF7E5E04337
                                  • Part of subcall function 00007FF7E5E04FD8: RemoveDirectoryA.KERNELBASE(0000000A,00007FF7E5E0807B), ref: 00007FF7E5E05074
                                  • Part of subcall function 00007FF7E5E04FD8: GetFileAttributesA.KERNELBASE ref: 00007FF7E5E05083
                                  • Part of subcall function 00007FF7E5E04FD8: GetTempFileNameA.KERNEL32 ref: 00007FF7E5E050B0
                                  • Part of subcall function 00007FF7E5E04FD8: DeleteFileA.KERNEL32 ref: 00007FF7E5E050C8
                                  • Part of subcall function 00007FF7E5E04FD8: CreateDirectoryA.KERNEL32 ref: 00007FF7E5E050D9
                                • GetSystemInfo.KERNEL32(?,?,?,?,?,?,0000000A,00007FF7E5E0807B), ref: 00007FF7E5E04284
                                • RemoveDirectoryA.KERNEL32(?,?,?,?,?,?,0000000A,00007FF7E5E0807B), ref: 00007FF7E5E04390
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Directory$File$CreateRemove$AttributesDeleteInfoNameSystemTemp
                                • String ID: C:\Users\user\AppData\Local\Temp\IXP000.TMP\$alpha$i386$mips$ppc
                                • API String ID: 1979080616-1143122538
                                • Opcode ID: ef5d81014ef313249934d52286ddd07c22df379486773ae6037eb97752fc4e5b
                                • Instruction ID: 27bc51c52d7a5c4f43ec83922da84037137ea7918d57c36b804111ff251bf0d5
                                • Opcode Fuzzy Hash: ef5d81014ef313249934d52286ddd07c22df379486773ae6037eb97752fc4e5b
                                • Instruction Fuzzy Hash: 15514D61B0C74A81EA54AB15AB243B9E7A0AF45F48FD85137C9CDCB691CF7CE805C362

                                Control-flow Graph

                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: CloseHandleProcess$CodeCreateExitObjectSingleWait
                                • String ID:
                                • API String ID: 976364251-3916222277
                                • Opcode ID: 19170bdb0185dcc4558629786d1e3b276faf8172c778104cd8efa3f0263b16b4
                                • Instruction ID: 898ab0aed02d69a819ec2a32598b8ccee44cd6b6dd4efb051a6db915c1a6ac2d
                                • Opcode Fuzzy Hash: 19170bdb0185dcc4558629786d1e3b276faf8172c778104cd8efa3f0263b16b4
                                • Instruction Fuzzy Hash: CF51303290874986E760AF10EA6537AF7A0FB89B5CF944136DACECA694CF7CD444CB11

                                Control-flow Graph

                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Handle$AddressCloseExitModuleProcVersionWindows
                                • String ID: @$HeapSetInformation$Kernel32.dll
                                • API String ID: 1302179841-1204263913
                                • Opcode ID: 83a8c1ea104aff54c4d7c9c4dbf1586e791a1727480c60f852360176ee8197a3
                                • Instruction ID: 65934a306a3bc1c2ccef0134ab9ac900a1043d3f6dc09bf7b4290e9c75ac0912
                                • Opcode Fuzzy Hash: 83a8c1ea104aff54c4d7c9c4dbf1586e791a1727480c60f852360176ee8197a3
                                • Instruction Fuzzy Hash: BA318221E0C24A86FA547F50A761377E690AF49F4CFC48033DA8ECB695CE7CE4418766

                                Control-flow Graph

                                APIs
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: File$Find$lstrcmp$AttributesCloseDeleteDirectoryFirstNextRemove
                                • String ID:
                                • API String ID: 836429354-0
                                • Opcode ID: 18f7d0d8df672b7f8ff2bc21405c924839be97c8656361e9f06e7a67ef0dde56
                                • Instruction ID: 4ecaedbc82360754ccd22105812c94891c404d6c61664bb848681a8cd56e9ea3
                                • Opcode Fuzzy Hash: 18f7d0d8df672b7f8ff2bc21405c924839be97c8656361e9f06e7a67ef0dde56
                                • Instruction Fuzzy Hash: C151863661878A95EB01AF20D9603F9B7A1FB45F48FC48172DA8D8B695DF3CD909C321

                                Control-flow Graph

                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: DeleteFileFreeLocal$AttributesCloseCurrentDirectoryOpenValue
                                • String ID: C:\Users\user\AppData\Local\Temp\IXP000.TMP\$Software\Microsoft\Windows\CurrentVersion\RunOnce$wextract_cleanup0
                                • API String ID: 3049360512-2186971993
                                • Opcode ID: 945d950d7bb6d2b03bb19646d956afc38b938c28c29c6955e31643fe977d61b4
                                • Instruction ID: 612c051b53cba5b2f7bb7a37a0ceea51e8628b0b8f4c1c360075ddc30df6dbf8
                                • Opcode Fuzzy Hash: 945d950d7bb6d2b03bb19646d956afc38b938c28c29c6955e31643fe977d61b4
                                • Instruction Fuzzy Hash: 4C512121A0874A86EB50AB10E764379F7A0FB89F49FC45132D68D8B694DF7CE844C722

                                Control-flow Graph

                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: File$Directory$AttributesCreateDeleteNameRemoveTemp
                                • String ID: IXP$IXP%03d.TMP
                                • API String ID: 4001122843-3932986939
                                • Opcode ID: 950e06c3cc114e96d21c71c189c663bea0479e63569984cfb08e3cb431742b4e
                                • Instruction ID: eab5ea4a334ac479241f94ce9a5028fc97a9edae558a78cfa760d4c24ed93330
                                • Opcode Fuzzy Hash: 950e06c3cc114e96d21c71c189c663bea0479e63569984cfb08e3cb431742b4e
                                • Instruction Fuzzy Hash: D2319131608A4586EA10AF15A9203FAB795FB8DF88FD99132CD8ECB391CE3CD445C721

                                Control-flow Graph

                                • Executed
                                • Not Executed
                                control_flow_graph 693 7ff7e5e01150-7ff7e5e01199 call 7ff7e5e018e4 GetStartupInfoW 697 7ff7e5e0119b-7ff7e5e011a6 693->697 698 7ff7e5e011b2-7ff7e5e011bb 697->698 699 7ff7e5e011a8-7ff7e5e011ab 697->699 702 7ff7e5e011bd-7ff7e5e011c5 _amsg_exit 698->702 703 7ff7e5e011d7-7ff7e5e011df 698->703 700 7ff7e5e011ad 699->700 701 7ff7e5e011ca-7ff7e5e011d5 Sleep 699->701 700->698 701->697 704 7ff7e5e0124e-7ff7e5e01257 702->704 705 7ff7e5e01244 703->705 706 7ff7e5e011e1-7ff7e5e011fe 703->706 707 7ff7e5e01276-7ff7e5e01278 704->707 708 7ff7e5e01259-7ff7e5e0126c _initterm 704->708 705->704 709 7ff7e5e01202-7ff7e5e01205 706->709 710 7ff7e5e01283-7ff7e5e0128b 707->710 711 7ff7e5e0127a-7ff7e5e0127c 707->711 708->707 712 7ff7e5e01236-7ff7e5e01238 709->712 713 7ff7e5e01207-7ff7e5e01209 709->713 715 7ff7e5e012c1-7ff7e5e012d0 710->715 716 7ff7e5e0128d-7ff7e5e0129b call 7ff7e5e01850 710->716 711->710 712->704 714 7ff7e5e0123a-7ff7e5e0123f 712->714 713->714 717 7ff7e5e0120b-7ff7e5e0120f 713->717 719 7ff7e5e013ab-7ff7e5e013c0 714->719 718 7ff7e5e012d4-7ff7e5e012da 715->718 716->715 731 7ff7e5e0129d-7ff7e5e012b7 716->731 721 7ff7e5e01211-7ff7e5e01227 717->721 722 7ff7e5e0122b-7ff7e5e01234 717->722 723 7ff7e5e0134d-7ff7e5e01350 718->723 724 7ff7e5e012dc-7ff7e5e012de 718->724 721->722 722->709 729 7ff7e5e01352-7ff7e5e0135b 723->729 730 7ff7e5e0135f-7ff7e5e01367 _ismbblead 723->730 727 7ff7e5e012e4-7ff7e5e012e9 724->727 728 7ff7e5e012e0-7ff7e5e012e2 724->728 732 7ff7e5e012eb-7ff7e5e012f5 727->732 733 7ff7e5e012f7-7ff7e5e0132c call 7ff7e5e07fe4 727->733 728->723 728->727 729->730 734 7ff7e5e01371-7ff7e5e01379 730->734 735 7ff7e5e01369-7ff7e5e0136c 730->735 731->715 732->727 738 7ff7e5e01336-7ff7e5e0133d 733->738 739 7ff7e5e0132e-7ff7e5e01330 exit 733->739 734->718 734->719 735->734 740 7ff7e5e0133f-7ff7e5e01345 _cexit 738->740 741 7ff7e5e0134b 738->741 739->738 740->741 741->719
                                APIs
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Current$CountTickTime$CounterFileImageInfoNonwritablePerformanceProcessQuerySleepStartupSystemThread_amsg_exit_cexit_initterm_ismbbleadexit
                                • String ID:
                                • API String ID: 2995914023-0
                                • Opcode ID: dc0a5e20638ea67c63c6f64c653ebcfbc2cd40491069adb64e4f082b60295cf1
                                • Instruction ID: 6df7338730a2e636dab2d924ae948df9b416ba1a16e4f42eb5841536cc723a6d
                                • Opcode Fuzzy Hash: dc0a5e20638ea67c63c6f64c653ebcfbc2cd40491069adb64e4f082b60295cf1
                                • Instruction Fuzzy Hash: F0615931A0864A86E724BB60EA61379A3A1FB44B48FC40037DACDCF694DF3CE444C722
                                APIs
                                  • Part of subcall function 00007FF7E5E05140: FindResourceA.KERNEL32(?,?,0000000A,00007FF7E5E058A6), ref: 00007FF7E5E05168
                                  • Part of subcall function 00007FF7E5E05140: SizeofResource.KERNEL32(?,?,0000000A,00007FF7E5E058A6), ref: 00007FF7E5E05179
                                  • Part of subcall function 00007FF7E5E05140: FindResourceA.KERNEL32(?,?,0000000A,00007FF7E5E058A6), ref: 00007FF7E5E0519F
                                  • Part of subcall function 00007FF7E5E05140: LoadResource.KERNEL32(?,?,0000000A,00007FF7E5E058A6), ref: 00007FF7E5E051B0
                                  • Part of subcall function 00007FF7E5E05140: LockResource.KERNEL32(?,?,0000000A,00007FF7E5E058A6), ref: 00007FF7E5E051BF
                                  • Part of subcall function 00007FF7E5E05140: memcpy_s.MSVCRT ref: 00007FF7E5E051DE
                                  • Part of subcall function 00007FF7E5E05140: FreeResource.KERNEL32(?,?,0000000A,00007FF7E5E058A6), ref: 00007FF7E5E051ED
                                • LocalAlloc.KERNEL32(?,?,?,?,00000000,00007FF7E5E0471F), ref: 00007FF7E5E056ED
                                • LocalFree.KERNEL32 ref: 00007FF7E5E05766
                                  • Part of subcall function 00007FF7E5E061E8: LoadStringA.USER32 ref: 00007FF7E5E06278
                                  • Part of subcall function 00007FF7E5E061E8: MessageBoxA.USER32 ref: 00007FF7E5E062B8
                                  • Part of subcall function 00007FF7E5E06590: GetLastError.KERNEL32 ref: 00007FF7E5E06594
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Resource$FindFreeLoadLocal$AllocErrorLastLockMessageSizeofStringmemcpy_s
                                • String ID: $<None>$UPROMPT
                                • API String ID: 957408736-2569542085
                                • Opcode ID: aea35292e0b0d1d5dd38c3033b5e2eace57c3e947cdaa261d3646570dc64e0d9
                                • Instruction ID: b5a7e1cb1176c4323e7aa94a6ba4ca0ea8141bb06b1395d16e121c98694668f1
                                • Opcode Fuzzy Hash: aea35292e0b0d1d5dd38c3033b5e2eace57c3e947cdaa261d3646570dc64e0d9
                                • Instruction Fuzzy Hash: 13319432A08246C6E720AB20E760379F650EB85B4CF844537DA8ECB695DF3CD0008B12
                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: CreateFile$lstrcmp
                                • String ID: *MEMCAB
                                • API String ID: 1301100335-3211172518
                                • Opcode ID: 882ecc141dfa2a6022f31e20c1b0ac6f4acce46d394e68a6a22d01aa207dc993
                                • Instruction ID: 5bbe98cdfa7693abdacce89e66c97ecc6b1467771a4e09ee26b45989c6380c8d
                                • Opcode Fuzzy Hash: 882ecc141dfa2a6022f31e20c1b0ac6f4acce46d394e68a6a22d01aa207dc993
                                • Instruction Fuzzy Hash: 1D61B762A0C74A86F7609F14A6A0379B691F755F68F845336CAED877C0CF7CD0018B61
                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: FileTime$AttributesDateItemLocalText
                                • String ID: C:\Users\user\AppData\Local\Temp\IXP000.TMP\
                                • API String ID: 851750970-388467436
                                • Opcode ID: 1b29dbb9e3ca8058bb845d1cdcb3f6214ba747c613cdf2411ff3bfa011323251
                                • Instruction ID: 59ee5d54e32cf62b253d9d58326f086dbd90016e4899495499c4198b0ea8e213
                                • Opcode Fuzzy Hash: 1b29dbb9e3ca8058bb845d1cdcb3f6214ba747c613cdf2411ff3bfa011323251
                                • Instruction Fuzzy Hash: 7551B121A0C94A81EA60AF51D6243B9E760FF84F58F945233D98DCB6D4CF7CD445C7A1
                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: AllocLocal
                                • String ID: TMP4351$.TMP
                                • API String ID: 3494564517-2619824408
                                • Opcode ID: f6643adad851909dc84ab3123c3a019038264e65fc77465c454a882d24c4d207
                                • Instruction ID: fddbd99234b7f65e58cc6436f1f6be87f69050aca9cf39c8724b4e7265d2c1ff
                                • Opcode Fuzzy Hash: f6643adad851909dc84ab3123c3a019038264e65fc77465c454a882d24c4d207
                                • Instruction Fuzzy Hash: F131B631A1868586F7106F15A620379F790EB85FA8F984336DAED8B7D1CF3CD4058711
                                APIs
                                • RegOpenKeyExA.KERNELBASE(?,?,?,?,00000000,00007FF7E5E02566), ref: 00007FF7E5E03527
                                • RegQueryValueExA.KERNELBASE(?,?,?,?,00000000,00007FF7E5E02566), ref: 00007FF7E5E03558
                                • RegCloseKey.KERNELBASE(?,?,?,?,00000000,00007FF7E5E02566), ref: 00007FF7E5E03576
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: CloseOpenQueryValue
                                • String ID: PendingFileRenameOperations$System\CurrentControlSet\Control\Session Manager
                                • API String ID: 3677997916-3057196482
                                • Opcode ID: 340b8b646548313282c693838e7f25eceb0ba4f0296da7f4314fc4dbeecda6e5
                                • Instruction ID: 462daa7a19dec79b946736bcb014bbd7834cbb6faa291a2438257b088459b40f
                                • Opcode Fuzzy Hash: 340b8b646548313282c693838e7f25eceb0ba4f0296da7f4314fc4dbeecda6e5
                                • Instruction Fuzzy Hash: 40116031A0864687E7206F19E56423AF6A1FB8DB59F904136DACD87B68CF3DD804CB11
                                APIs
                                  • Part of subcall function 00007FF7E5E07F58: MsgWaitForMultipleObjects.USER32(?,?,?,?,?,?,?,?,?,00000001,00007FF7E5E04A99), ref: 00007FF7E5E07F7C
                                  • Part of subcall function 00007FF7E5E07F58: PeekMessageA.USER32 ref: 00007FF7E5E07FC2
                                • WriteFile.KERNELBASE ref: 00007FF7E5E087F4
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: FileMessageMultipleObjectsPeekWaitWrite
                                • String ID:
                                • API String ID: 3430465807-0
                                • Opcode ID: 991d4bdccbb001d71ab861eb250e50ad34ff21f81909168724640f7d797acd5b
                                • Instruction ID: 877836426dbd134facb2c012a955ff3314e2ddd98ea197faa8f939d535eb694f
                                • Opcode Fuzzy Hash: 991d4bdccbb001d71ab861eb250e50ad34ff21f81909168724640f7d797acd5b
                                • Instruction Fuzzy Hash: A521B321A0854686E7109F16E660335E760FB84F9CFC48236D99C8B6E4CF7CE015CB61
                                APIs
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Resource$AttributesFile$DialogFindFreeIndirectLoadParam
                                • String ID:
                                • API String ID: 2018477427-0
                                • Opcode ID: 4737db5ac4d1f4b61336884d07e3be5c2f7f4e323d7d01ce83fef1e9a7c030ba
                                • Instruction ID: 53c043221fec808d9d5d149ced858685347f3f11cf1ba6fb6a4eb5ebe83538ca
                                • Opcode Fuzzy Hash: 4737db5ac4d1f4b61336884d07e3be5c2f7f4e323d7d01ce83fef1e9a7c030ba
                                • Instruction Fuzzy Hash: 49117931A0874E86FB507F10AB64336E6A0BF59B5CF944133C9CCCA694CF3CA8468762
                                APIs
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: CharPrev
                                • String ID:
                                • API String ID: 122130370-0
                                • Opcode ID: 8245624d2b9ebc6079e72f8030c20bb1c2af5584c94ac8071bf526b29981342a
                                • Instruction ID: 46c8d6ca220de53061cbd5fedf9d725b05025599305a407afeb9cd2ca6c74fdc
                                • Opcode Fuzzy Hash: 8245624d2b9ebc6079e72f8030c20bb1c2af5584c94ac8071bf526b29981342a
                                • Instruction Fuzzy Hash: 87010411E0C7C9C6F3006B11A55032AFA90A745FA4FD892B1DBE98B7C5CFBCD4428762
                                APIs
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: CloseHandle
                                • String ID:
                                • API String ID: 2962429428-0
                                • Opcode ID: 631afb329a542f924e594eb567a6f67e576df5b656a914a684b149cc5fb41dd4
                                • Instruction ID: 312dd7f11a7736dcb327a7f180a00eb638b5585717bf1c6ac7281b2a55283c51
                                • Opcode Fuzzy Hash: 631afb329a542f924e594eb567a6f67e576df5b656a914a684b149cc5fb41dd4
                                • Instruction Fuzzy Hash: A3F0623160C78682DB185F25F690278B360EB48F5CF804236DA6B8B6C4CE78D481C761
                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Window$DialogItem$DesktopEnableLoadMessageSendStringText
                                • String ID: $C:\Users\user\AppData\Local\Temp\IXP000.TMP\$Comp
                                • API String ID: 3530494346-1320786786
                                • Opcode ID: 03c4772cdb7d6fccc57bfd75d5555ef236f98fe06d2964a5862beba3be9f39ab
                                • Instruction ID: 95f70b304e3b8e4babe06bed54e488264474bb05e1e5327f60332b5dd5f6564d
                                • Opcode Fuzzy Hash: 03c4772cdb7d6fccc57bfd75d5555ef236f98fe06d2964a5862beba3be9f39ab
                                • Instruction Fuzzy Hash: 5A719861E0864A86F7507B11A720379EB92EB85F98FD48136CACDCB685CF3CE545C722
                                APIs
                                  • Part of subcall function 00007FF7E5E05140: FindResourceA.KERNEL32(?,?,0000000A,00007FF7E5E058A6), ref: 00007FF7E5E05168
                                  • Part of subcall function 00007FF7E5E05140: SizeofResource.KERNEL32(?,?,0000000A,00007FF7E5E058A6), ref: 00007FF7E5E05179
                                  • Part of subcall function 00007FF7E5E05140: FindResourceA.KERNEL32(?,?,0000000A,00007FF7E5E058A6), ref: 00007FF7E5E0519F
                                  • Part of subcall function 00007FF7E5E05140: LoadResource.KERNEL32(?,?,0000000A,00007FF7E5E058A6), ref: 00007FF7E5E051B0
                                  • Part of subcall function 00007FF7E5E05140: LockResource.KERNEL32(?,?,0000000A,00007FF7E5E058A6), ref: 00007FF7E5E051BF
                                  • Part of subcall function 00007FF7E5E05140: memcpy_s.MSVCRT ref: 00007FF7E5E051DE
                                  • Part of subcall function 00007FF7E5E05140: FreeResource.KERNEL32(?,?,0000000A,00007FF7E5E058A6), ref: 00007FF7E5E051ED
                                • FindResourceA.KERNEL32(?,?,?,?,?,?,?,?,00000000,00007FF7E5E04938), ref: 00007FF7E5E04C10
                                • LoadResource.KERNEL32(?,?,?,?,?,?,?,?,00000000,00007FF7E5E04938), ref: 00007FF7E5E04C21
                                • LockResource.KERNEL32(?,?,?,?,?,?,?,?,00000000,00007FF7E5E04938), ref: 00007FF7E5E04C30
                                • GetDlgItem.USER32 ref: 00007FF7E5E04C5D
                                • ShowWindow.USER32(?,?,?,?,?,?,?,?,00000000,00007FF7E5E04938), ref: 00007FF7E5E04C6E
                                • GetDlgItem.USER32 ref: 00007FF7E5E04C86
                                • ShowWindow.USER32(?,?,?,?,?,?,?,?,00000000,00007FF7E5E04938), ref: 00007FF7E5E04C9A
                                • FreeResource.KERNEL32 ref: 00007FF7E5E04DB1
                                • SendMessageA.USER32 ref: 00007FF7E5E04E13
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Resource$Find$FreeItemLoadLockShowWindow$MessageSendSizeofmemcpy_s
                                • String ID: CABINET
                                • API String ID: 1305606123-1940454314
                                • Opcode ID: 76ef0e94f0549deaf640b9006555d490fc3bb0e5fe2d088055cbb579db64d552
                                • Instruction ID: 827515a9e096d14aaa622efcd9db9e26e4f092d59e44d45502897ee8b8d517c8
                                • Opcode Fuzzy Hash: 76ef0e94f0549deaf640b9006555d490fc3bb0e5fe2d088055cbb579db64d552
                                • Instruction Fuzzy Hash: 62416F71A0874A86FB506B21A765775EA90FF89F49FC48136CA8DCB690CF3CE4458722
                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: FreeLibrary$AddressAllocateInitializeLoadProc
                                • String ID: CheckTokenMembership$advapi32.dll
                                • API String ID: 4204503880-1888249752
                                • Opcode ID: e160c6785fde90a48b04fb9c74fff3393dcd095ced99b921061e37aaea61ca71
                                • Instruction ID: 92afecb741839ede933a3204f5441731badbdf9183c5c0971c876ff8488205bf
                                • Opcode Fuzzy Hash: e160c6785fde90a48b04fb9c74fff3393dcd095ced99b921061e37aaea61ca71
                                • Instruction Fuzzy Hash: 04316132608B498AD7109F16F4542AAFBA0FB89F94F855136EE8E87714DF3CE445CB00
                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: ProcessToken$AdjustCloseCurrentExitHandleLookupOpenPrivilegePrivilegesValueWindows
                                • String ID: SeShutdownPrivilege
                                • API String ID: 2829607268-3733053543
                                • Opcode ID: 68f57858d0a37f1d9b97d15ccc180e4361d8fc185c2eeebe84e4efed2f4b6a83
                                • Instruction ID: 09369aa830b206fcbb239e4bab67f63d5bbc2e97c7cfd0b87f27ad9f4f0eaeb6
                                • Opcode Fuzzy Hash: 68f57858d0a37f1d9b97d15ccc180e4361d8fc185c2eeebe84e4efed2f4b6a83
                                • Instruction Fuzzy Hash: 9C21D532A1864683F7509F60F56537EFBA0FB89B49F809136DA8E8BA54CF3CD0448B11
                                APIs
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: CountCurrentTickTime$CounterFilePerformanceProcessQuerySystemThread
                                • String ID:
                                • API String ID: 4104442557-0
                                • Opcode ID: a1a8c30bc5a850f7df6bb2e960b2db2709fe8c778fbb0e1b446c87b4c6fef4b3
                                • Instruction ID: 0a066ab698ecfc3370c1ac7e28e57de0c29970b7e79457e8c643d6e0bcb069fc
                                • Opcode Fuzzy Hash: a1a8c30bc5a850f7df6bb2e960b2db2709fe8c778fbb0e1b446c87b4c6fef4b3
                                • Instruction Fuzzy Hash: EC115421604B4586EB40EF70EC552A973A4F748B5CF800A31EAADCB754DF7CD194C350
                                APIs
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: ExceptionFilterUnhandled
                                • String ID:
                                • API String ID: 3192549508-0
                                • Opcode ID: 33b5d242f9dae548e22f746f2c14e26181d9d5e8b558b2e26dfd9b2729eaeda7
                                • Instruction ID: 27bc76e58c127330ac8def243e351b886c6ca8241ebb615cc2b29c9793ed0994
                                • Opcode Fuzzy Hash: 33b5d242f9dae548e22f746f2c14e26181d9d5e8b558b2e26dfd9b2729eaeda7
                                • Instruction Fuzzy Hash: D7B024037030C301C10077F00F4404415400F47D307CC1554C314C3F40CC1CD15D0310
                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: EventItemMessageSendThreadWindow$CreateDesktopDialogResetTerminateText
                                • String ID: $Comp
                                • API String ID: 2654313074-3360895561
                                • Opcode ID: 161ecbf182c25f1165986d72c8c0059cd173de4edb9b55fbd2b049afc53b66ca
                                • Instruction ID: dfe02fe1b88338a96d86122c0d56f172823d750819ac7c7d36b22e0ec959c74f
                                • Opcode Fuzzy Hash: 161ecbf182c25f1165986d72c8c0059cd173de4edb9b55fbd2b049afc53b66ca
                                • Instruction Fuzzy Hash: 23516631D0874686E710BF11EB64379E6A1FB89F59F848132CA9DCB794CF3C94458B22
                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Char$Upper$Next$ByteCloseCompareExitFileHandleLeadModuleNameProcessString
                                • String ID: "$:$RegServer
                                • API String ID: 23972181-766454958
                                • Opcode ID: 30a90c34f7cbb46e34736c76c13f057931b7289761545bddfdfb8314716cf64c
                                • Instruction ID: a6a7dd96660e2ff73fccbb652dd921339972abf69b88e7d7e2eb7638eba8a590
                                • Opcode Fuzzy Hash: 30a90c34f7cbb46e34736c76c13f057931b7289761545bddfdfb8314716cf64c
                                • Instruction Fuzzy Hash: 7E12C461E0C68A41EE20AB149674379EBA1AF41F5CFD44137C9DE8E695CE3DE402E722
                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: AddressLibraryProc$CharFreePrev$LoadPathTemp
                                • String ID: SHBrowseForFolder$SHELL32.DLL$SHGetPathFromIDList
                                • API String ID: 1865808269-1731843650
                                • Opcode ID: a68a2c2134a308fc5224faae6e68b9a8e707b355ac96a450fb768dad26968aab
                                • Instruction ID: d0ef24ab51e4e98450f94edcaf6635d7e53d293f233186ae3debb7fd63458757
                                • Opcode Fuzzy Hash: a68a2c2134a308fc5224faae6e68b9a8e707b355ac96a450fb768dad26968aab
                                • Instruction Fuzzy Hash: 96518421A0978A86EB11AF11AA20379FBA1FB49F98FC45136CACD8B790DF3CD445C711
                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: CharDirectory$NextSystem$CloseEnvironmentExpandOpenQueryStringsUpperValueWindows
                                • String ID: Software\Microsoft\Windows\CurrentVersion\App Paths
                                • API String ID: 229715263-2428544900
                                • Opcode ID: 1142a4cd6e006e845246af9bdb5df0897ae5876e42b73e5154f1751647277efe
                                • Instruction ID: ebe81a85937dc468477b3e625b88d1ccb4ff3c66d50349411b7be577cc55676b
                                • Opcode Fuzzy Hash: 1142a4cd6e006e845246af9bdb5df0897ae5876e42b73e5154f1751647277efe
                                • Instruction Fuzzy Hash: D551827260868586EA119F10E5643B9FBA0FB89F88FD45032DA8E8B794DF3CD845C711
                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Local$AllocMessage$EnumLanguagesResource$BeepCharCloseFreeLoadMetricsNextOpenQueryStringSystemValueVersion
                                • String ID: Comp$rce.
                                • API String ID: 2929476258-2451881752
                                • Opcode ID: 3ed11fbad5beae089dae1fca1131bae79aefec419c72aa5072dd9cc5e96e98b3
                                • Instruction ID: b5201e1d5a8232caf0a7f802c8720bd8ba057079a1241d09918125dad5cf2ee7
                                • Opcode Fuzzy Hash: 3ed11fbad5beae089dae1fca1131bae79aefec419c72aa5072dd9cc5e96e98b3
                                • Instruction Fuzzy Hash: CA71D721E0878986FA51AB25A6203B9E790BF55F5CF845232DECD8B7C1DF3CE4458721
                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Window$Item$LongText$DesktopDialogForegroundMessageSend
                                • String ID: Comp
                                • API String ID: 3785188418-1798881284
                                • Opcode ID: b99bfbc71c6e47e8d2dd802e5a3d49e478e887f1f55d0a3e4aad63706f5b073e
                                • Instruction ID: 50c270c8b6b7e83892e0dbe04c0a5c891ae5d7971909088d2c1d2a7f3e5abd69
                                • Opcode Fuzzy Hash: b99bfbc71c6e47e8d2dd802e5a3d49e478e887f1f55d0a3e4aad63706f5b073e
                                • Instruction Fuzzy Hash: 9C31493090464A86EA106F61A5243B5FB51FB8AF69FC49232C99ECB3D0CF3CA545D722
                                APIs
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Free$Token$AllocateInformationInitializeLibraryLocalProcess$AddressAllocCloseCurrentEqualErrorHandleLastLoadOpenProc
                                • String ID:
                                • API String ID: 2168512254-0
                                • Opcode ID: 5aa378a5a02dea733385acf5e55f93e1415a95ae54cf52c9b480b087f5f96856
                                • Instruction ID: 414743ddc9ed97ebd4ae0d605ec56ababe25f8df95a16e045b152891a14a79c7
                                • Opcode Fuzzy Hash: 5aa378a5a02dea733385acf5e55f93e1415a95ae54cf52c9b480b087f5f96856
                                • Instruction Fuzzy Hash: ED514F32604B46CBE710AF21E5A42A9BBA4FB4DF88F815136DA8E9B754DF38D444CB11
                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: CharCloseMetricsNextOpenQuerySystemValueVersion
                                • String ID: Control Panel\Desktop\ResourceLocale
                                • API String ID: 3346862599-1109908249
                                • Opcode ID: 79618cbf566f24ba719aea2154ce45ce3ef321f6ac2e06029fa2153c5c1a82fb
                                • Instruction ID: b1abbdcc0fb44189e334dd6753218605f850d7943c624e22f2351e2764aaf134
                                • Opcode Fuzzy Hash: 79618cbf566f24ba719aea2154ce45ce3ef321f6ac2e06029fa2153c5c1a82fb
                                • Instruction Fuzzy Hash: 71510872A086458BE7109F20E5502B8F7A5F755F58F815233CA9E8B784CF7CE405CB52
                                APIs
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Char$Next$Upper$ByteFileLeadModuleNamePrev
                                • String ID:
                                • API String ID: 975904313-0
                                • Opcode ID: aa7ba7297077793f7d626753686711e9c4ffdaff21383c5eed26811cbffd48fb
                                • Instruction ID: 96dda7a94d5f9aeb5f9eda7815c1077a6b30a3790fc91735a39863be5cbd0625
                                • Opcode Fuzzy Hash: aa7ba7297077793f7d626753686711e9c4ffdaff21383c5eed26811cbffd48fb
                                • Instruction Fuzzy Hash: 55719851A0C68945FF616F25D574378EBD1AB49FA8F884172CADE8B3C1CE3C98058722
                                APIs
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Global$Char$FileInfoNextUnlockVersion$AllocDirectoryFreeLockQuerySizeUpperValueWindows
                                • String ID:
                                • API String ID: 2920131565-0
                                • Opcode ID: e2c6928dca72d3c9787df6f30925460e70e82d21755a383799fca88f808043d4
                                • Instruction ID: 681b525e6a6b2ea6a5d42f3e843991171e1794de81651becc4792fd229b09df6
                                • Opcode Fuzzy Hash: e2c6928dca72d3c9787df6f30925460e70e82d21755a383799fca88f808043d4
                                • Instruction Fuzzy Hash: 7A61B272A0465A8AEB509F15D6642BCB7E1FB04B98F804432DE8D9B784DF38EC41C722
                                APIs
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Window$CapsDeviceRect$Release
                                • String ID:
                                • API String ID: 2212493051-0
                                • Opcode ID: 6bf25506a061de764c46ff11c3dabc26361253386e945ff23246536f7576ff98
                                • Instruction ID: 4bb302016b752a75e3afd61a3c66ef626f63c70d4a502d91a6966a5972ed4647
                                • Opcode Fuzzy Hash: 6bf25506a061de764c46ff11c3dabc26361253386e945ff23246536f7576ff98
                                • Instruction Fuzzy Hash: A0318C32B206058AE7109F65E914ABDBBA1F74CB99F985132CE4997B44CF38E445CB10
                                APIs
                                  • Part of subcall function 00007FF7E5E05140: FindResourceA.KERNEL32(?,?,0000000A,00007FF7E5E058A6), ref: 00007FF7E5E05168
                                  • Part of subcall function 00007FF7E5E05140: SizeofResource.KERNEL32(?,?,0000000A,00007FF7E5E058A6), ref: 00007FF7E5E05179
                                  • Part of subcall function 00007FF7E5E05140: FindResourceA.KERNEL32(?,?,0000000A,00007FF7E5E058A6), ref: 00007FF7E5E0519F
                                  • Part of subcall function 00007FF7E5E05140: LoadResource.KERNEL32(?,?,0000000A,00007FF7E5E058A6), ref: 00007FF7E5E051B0
                                  • Part of subcall function 00007FF7E5E05140: LockResource.KERNEL32(?,?,0000000A,00007FF7E5E058A6), ref: 00007FF7E5E051BF
                                  • Part of subcall function 00007FF7E5E05140: memcpy_s.MSVCRT ref: 00007FF7E5E051DE
                                  • Part of subcall function 00007FF7E5E05140: FreeResource.KERNEL32(?,?,0000000A,00007FF7E5E058A6), ref: 00007FF7E5E051ED
                                • LocalAlloc.KERNEL32(?,?,?,?,?,00007FF7E5E04735), ref: 00007FF7E5E045B9
                                • LocalFree.KERNEL32 ref: 00007FF7E5E0463C
                                  • Part of subcall function 00007FF7E5E061E8: LoadStringA.USER32 ref: 00007FF7E5E06278
                                  • Part of subcall function 00007FF7E5E061E8: MessageBoxA.USER32 ref: 00007FF7E5E062B8
                                  • Part of subcall function 00007FF7E5E06590: GetLastError.KERNEL32 ref: 00007FF7E5E06594
                                • lstrcmpA.KERNEL32(?,?,?,?,?,00007FF7E5E04735), ref: 00007FF7E5E04662
                                • LocalFree.KERNEL32(?,?,?,?,?,00007FF7E5E04735), ref: 00007FF7E5E046C3
                                  • Part of subcall function 00007FF7E5E064B0: FindResourceA.KERNEL32 ref: 00007FF7E5E064DA
                                  • Part of subcall function 00007FF7E5E064B0: LoadResource.KERNEL32 ref: 00007FF7E5E064F1
                                  • Part of subcall function 00007FF7E5E064B0: DialogBoxIndirectParamA.USER32 ref: 00007FF7E5E06527
                                  • Part of subcall function 00007FF7E5E064B0: FreeResource.KERNEL32 ref: 00007FF7E5E06539
                                • LocalFree.KERNEL32 ref: 00007FF7E5E0469C
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Resource$Free$Local$FindLoad$AllocDialogErrorIndirectLastLockMessageParamSizeofStringlstrcmpmemcpy_s
                                • String ID: <None>$LICENSE
                                • API String ID: 2414642746-383193767
                                • Opcode ID: d8f725790712cab8ff229354588275550b10545e7930818d23b6b2a348e3f118
                                • Instruction ID: f8916c9dc1a28d5a0086387251ef2c8162f1dceafb2aa117eb3c41dfb6d3344a
                                • Opcode Fuzzy Hash: d8f725790712cab8ff229354588275550b10545e7930818d23b6b2a348e3f118
                                • Instruction Fuzzy Hash: E2314D31A1960A82F710BF10E734776A660EB85F4DFC05536C98DCE690EF7CE4008B22
                                APIs
                                • LoadResource.KERNEL32(?,?,?,?,?,?,?,?,00000000,00007FF7E5E04FA3), ref: 00007FF7E5E07BEF
                                • LockResource.KERNEL32(?,?,?,?,?,?,?,?,00000000,00007FF7E5E04FA3), ref: 00007FF7E5E07BFE
                                • FreeResource.KERNEL32(?,?,?,?,?,?,?,?,00000000,00007FF7E5E04FA3), ref: 00007FF7E5E07C4E
                                • FindResourceA.KERNEL32(?,?,?,?,?,?,?,?,00000000,00007FF7E5E04FA3), ref: 00007FF7E5E07C82
                                • FreeResource.KERNEL32(?,?,?,?,?,?,?,?,00000000,00007FF7E5E04FA3), ref: 00007FF7E5E07C9B
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Resource$Free$FindLoadLock
                                • String ID: UPDFILE%lu
                                • API String ID: 3629466761-2329316264
                                • Opcode ID: d41cb9711b44c5778f8d685044e0478faac0a7e9c0355c6fd43fe1abdcbe4688
                                • Instruction ID: e1f8b108236f4fdef6316f4f0f965ee7125360cd3c29704ebab2a17419328f53
                                • Opcode Fuzzy Hash: d41cb9711b44c5778f8d685044e0478faac0a7e9c0355c6fd43fe1abdcbe4688
                                • Instruction Fuzzy Hash: A2319731A08645C6E714AF15A520279F7A1FF89F54F954236EA9E8B394CF3CE444CB11
                                APIs
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Resource$Find$FreeLoadLockSizeofmemcpy_s
                                • String ID:
                                • API String ID: 3370778649-0
                                • Opcode ID: eaca51f8d58b0d414e22daa5353a49b1fbb1179a865c63ac3ffb404108bcea55
                                • Instruction ID: d84d1d5ecfe1c3616fcbe500476ba4b3985e1efc66a27da637649c423595d978
                                • Opcode Fuzzy Hash: eaca51f8d58b0d414e22daa5353a49b1fbb1179a865c63ac3ffb404108bcea55
                                • Instruction Fuzzy Hash: 1D115E31708B4587E7146B62A624239FAA0FB4EFC5B849036DE4ECB744DF3CD4458711
                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: DirectoryPrivateProfileStringWindowsWrite_lclose_llseek_lopen
                                • String ID: wininit.ini
                                • API String ID: 3273605193-4206010578
                                • Opcode ID: 9400fdb6d7a44d6df7f18705ef269f017eb9ad4388b642ce147a901e5ae05de9
                                • Instruction ID: 13dacafef3383b1335c6b9d46210f9138a4c2ec38e70171302f468054755d8b0
                                • Opcode Fuzzy Hash: 9400fdb6d7a44d6df7f18705ef269f017eb9ad4388b642ce147a901e5ae05de9
                                • Instruction Fuzzy Hash: 66112E32608A8587E710AF21E5643AAB7A1FB8DB18F859232DA8EC7654DF3CD545CB10
                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Window$Text$DesktopDialogForegroundItem
                                • String ID: Comp
                                • API String ID: 761066910-1798881284
                                • Opcode ID: d27efb2bfb772949979602fae28f15f48041aa30681c92464f837cb170850190
                                • Instruction ID: 7bb35161432070f87600a62aec840f8921efaa92de03f15eca886c8efc319139
                                • Opcode Fuzzy Hash: d27efb2bfb772949979602fae28f15f48041aa30681c92464f837cb170850190
                                • Instruction Fuzzy Hash: 3F111265A0860A87F6542B25B628374DA51EB4AF59FD89032C88ECF394DF7CE444D722
                                APIs
                                  • Part of subcall function 00007FF7E5E05140: FindResourceA.KERNEL32(?,?,0000000A,00007FF7E5E058A6), ref: 00007FF7E5E05168
                                  • Part of subcall function 00007FF7E5E05140: SizeofResource.KERNEL32(?,?,0000000A,00007FF7E5E058A6), ref: 00007FF7E5E05179
                                  • Part of subcall function 00007FF7E5E05140: FindResourceA.KERNEL32(?,?,0000000A,00007FF7E5E058A6), ref: 00007FF7E5E0519F
                                  • Part of subcall function 00007FF7E5E05140: LoadResource.KERNEL32(?,?,0000000A,00007FF7E5E058A6), ref: 00007FF7E5E051B0
                                  • Part of subcall function 00007FF7E5E05140: LockResource.KERNEL32(?,?,0000000A,00007FF7E5E058A6), ref: 00007FF7E5E051BF
                                  • Part of subcall function 00007FF7E5E05140: memcpy_s.MSVCRT ref: 00007FF7E5E051DE
                                  • Part of subcall function 00007FF7E5E05140: FreeResource.KERNEL32(?,?,0000000A,00007FF7E5E058A6), ref: 00007FF7E5E051ED
                                • LocalAlloc.KERNEL32(?,?,?,?,00000000,00007FF7E5E0498A), ref: 00007FF7E5E04E5D
                                • LocalFree.KERNEL32(?,?,?,?,00000000,00007FF7E5E0498A), ref: 00007FF7E5E04EF9
                                  • Part of subcall function 00007FF7E5E061E8: LoadStringA.USER32 ref: 00007FF7E5E06278
                                  • Part of subcall function 00007FF7E5E061E8: MessageBoxA.USER32 ref: 00007FF7E5E062B8
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Resource$FindFreeLoadLocal$AllocLockMessageSizeofStringmemcpy_s
                                • String ID: <None>$@$FINISHMSG
                                • API String ID: 3507850446-4126004490
                                • Opcode ID: 46f6a34e6422b476f92bef806b9afb6e738230eab6fd6dc1f836e9041f14e154
                                • Instruction ID: 6e4259193c41a8cff80e52a8541adff75db677f3113bfdec04aa1733f89177b5
                                • Opcode Fuzzy Hash: 46f6a34e6422b476f92bef806b9afb6e738230eab6fd6dc1f836e9041f14e154
                                • Instruction Fuzzy Hash: 4211A772A0874683FB20AF21E62077AE650EB89B48FC45136DA8DCF685DF3CD5008B11
                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: LibraryLoad$AttributesFile
                                • String ID: C:\Users\user\AppData\Local\Temp\IXP000.TMP\$advpack.dll
                                • API String ID: 438848745-1955609190
                                • Opcode ID: 963a3f96620efcd57751c6ee7ade2dcdaa22df72e3894113d12d29ba1fba980a
                                • Instruction ID: fe322b07c0e82f2a890c7aca5ce0b24401891deeff6ba5955e39d299bbb1662e
                                • Opcode Fuzzy Hash: 963a3f96620efcd57751c6ee7ade2dcdaa22df72e3894113d12d29ba1fba980a
                                • Instruction Fuzzy Hash: 71115031A1868A85EE21AF10E5613F9B7A0FB99F08FC44233C6CD86691DF3DD509C721
                                APIs
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: BeepDesktopDialogItemLoadMessageStringTextWindow
                                • String ID:
                                • API String ID: 1273765764-0
                                • Opcode ID: 65e6fbf51a895507969a40468058746c97c4b6aea9fe2f97e498a7505ce86659
                                • Instruction ID: 6414a4db79cb4cd37274a097ec1357ac6fa17d0f5547e664ffca4221db028244
                                • Opcode Fuzzy Hash: 65e6fbf51a895507969a40468058746c97c4b6aea9fe2f97e498a7505ce86659
                                • Instruction Fuzzy Hash: 61217571A086CA86E6206B21F5643BAE660FB8DF58F884132D9CE8B7D5CF3CD105C761
                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Message$BeepVersion
                                • String ID: Comp
                                • API String ID: 2519184315-1798881284
                                • Opcode ID: fb4eab478caa6204bae9f5f6a9d13087627c7f1f2c010f1b9df14a39c7a39b7c
                                • Instruction ID: b1dbfa5555cfe01ab1eb6091200d0e54e77c04ee5f1ddf716437861faeeb4ef4
                                • Opcode Fuzzy Hash: fb4eab478caa6204bae9f5f6a9d13087627c7f1f2c010f1b9df14a39c7a39b7c
                                • Instruction Fuzzy Hash: 0CA1C772E1C25A86F764AF15976037AF6A0FB48F58F900137D98DDB294CE3CE8418722
                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: File$CloseCreateHandleWrite
                                • String ID: C:\Users\user\AppData\Local\Temp\IXP000.TMP\
                                • API String ID: 1065093856-388467436
                                • Opcode ID: 0e03046e849406695a98d42d2011d6eb0c047299338339c8bc95bd8c917e975f
                                • Instruction ID: bbe44443f65b607d8e2d925013051093d0081a82a431920fbf511659dad136cf
                                • Opcode Fuzzy Hash: 0e03046e849406695a98d42d2011d6eb0c047299338339c8bc95bd8c917e975f
                                • Instruction Fuzzy Hash: DA31853260868586EB119F50E5507BAF760FB49B98F844236DADD8B784CF7CD508CB21
                                APIs
                                Strings
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID:
                                • String ID: *MEMCAB
                                • API String ID: 0-3211172518
                                • Opcode ID: d326e7aa94b67cf4d4d3d0379e3d5024a1c04b5e8baa646fa99e55709f362e69
                                • Instruction ID: 5b046ed5600812c04c139c6ab5440cd2821584f0b52867b405fce0f96ea27cd8
                                • Opcode Fuzzy Hash: d326e7aa94b67cf4d4d3d0379e3d5024a1c04b5e8baa646fa99e55709f362e69
                                • Instruction Fuzzy Hash: 50316031A1CF4A85EA40AB10E6643B9B3A0FB44B98F814233D9DC8A390DF7CD445C751
                                APIs
                                Strings
                                • System\CurrentControlSet\Control\Session Manager\FileRenameOperations, xrefs: 00007FF7E5E02FAF
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: CloseInfoOpenQuery
                                • String ID: System\CurrentControlSet\Control\Session Manager\FileRenameOperations
                                • API String ID: 2142960691-1430103811
                                • Opcode ID: 47349caa1c797a3ce88789d8bb3edd23980ba6ecef902e538d3c134507dba548
                                • Instruction ID: a7f3c5019fc07b749d992f8cf6e724678fbd36d93e9478d8edde9d8bc4bd0cf7
                                • Opcode Fuzzy Hash: 47349caa1c797a3ce88789d8bb3edd23980ba6ecef902e538d3c134507dba548
                                • Instruction Fuzzy Hash: 05110732A18B8587E7109F25F45052AFBA8F789744B945229EBC983B28CB38D0558F00
                                APIs
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: CaptureContextEntryFunctionLookupUnwindVirtual__raise_securityfailure
                                • String ID:
                                • API String ID: 140117192-0
                                • Opcode ID: 4f65c121b0890e46cb18bda7ebc0f2de684189390e2c9d24e6a7faa72a08dfdf
                                • Instruction ID: c2263ecb4caae676db3d2232d1038b0461426d11c47cbac000220c9c474e3f46
                                • Opcode Fuzzy Hash: 4f65c121b0890e46cb18bda7ebc0f2de684189390e2c9d24e6a7faa72a08dfdf
                                • Instruction Fuzzy Hash: 8841B735A18B0981EA50AB58E9A1365F364FB84B48F905136DACDCB7A4DF3CD445C722
                                APIs
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Current$CountTickTime$CounterFileImageInfoNonwritablePerformanceProcessQuerySleepStartupSystemThread_amsg_exit_cexit_inittermexit
                                • String ID:
                                • API String ID: 1267577977-0
                                • Opcode ID: 67f1339d4cfeb4c52d404ce0f2d4713285857e4fe6d3d857e098854071e4ffab
                                • Instruction ID: 8065b98d88aab8262513c4f53fd588f2ac036e95b557b3e58c54a68ac56331b1
                                • Opcode Fuzzy Hash: 67f1339d4cfeb4c52d404ce0f2d4713285857e4fe6d3d857e098854071e4ffab
                                • Instruction Fuzzy Hash: 91313C2190864A86E618BB21EE71379A3A1EF45B58FD40437DACDCF2A5DE3CE444C722
                                APIs
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: CaptureContextEntryFunctionLookupUnwindVirtual__raise_securityfailure
                                • String ID:
                                • API String ID: 140117192-0
                                • Opcode ID: 0495dd60c7ced2f9c3233f3fe49d434584880a05317a0e056b8bda12f970aa15
                                • Instruction ID: bc6b87f65131e0efe27774baf4101b94fd305ed80fe139061a385923b6524c9d
                                • Opcode Fuzzy Hash: 0495dd60c7ced2f9c3233f3fe49d434584880a05317a0e056b8bda12f970aa15
                                • Instruction Fuzzy Hash: DE311735608B0581EB10AF58F9A1366F364FB88B48F905136DACD8BBA4DF3CD448C721
                                APIs
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Resource$DialogFindFreeIndirectLoadParam
                                • String ID:
                                • API String ID: 1214682469-0
                                • Opcode ID: f84731171d3fff93161b8d11559f90ff40e31cde7bbef708dcb137f56a2588f9
                                • Instruction ID: 0ede8bed26c46db538c30034f8e02401a2d06c65748c758c87c78ea4f7be1173
                                • Opcode Fuzzy Hash: f84731171d3fff93161b8d11559f90ff40e31cde7bbef708dcb137f56a2588f9
                                • Instruction Fuzzy Hash: 15112131A09B4586EA109F11F514369FA60FB5AFD8F884635EEDD4BB98DF3CD1418B10
                                APIs
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: Char$Prev$Next
                                • String ID:
                                • API String ID: 3260447230-0
                                • Opcode ID: 02f17945edf2851cb969e6e0e4490fbce2b65d3964085eb94fd71e724a66b365
                                • Instruction ID: 1dd130ada49a07f10d052bd96bae8f2628b8e92fbb66c2931c9a41dcd3587895
                                • Opcode Fuzzy Hash: 02f17945edf2851cb969e6e0e4490fbce2b65d3964085eb94fd71e724a66b365
                                • Instruction Fuzzy Hash: DB11AB6190C68585FF116B22A614339EE91B74AFE4FC85231CADE8B3C5CA7C94418353
                                APIs
                                Memory Dump Source
                                • Source File: 00000000.00000002.2943753803.00007FF7E5E01000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7E5E00000, based on PE: true
                                • Associated: 00000000.00000002.2943730251.00007FF7E5E00000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943783741.00007FF7E5E09000.00000002.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943810288.00007FF7E5E0C000.00000004.00000001.01000000.00000003.sdmpDownload File
                                • Associated: 00000000.00000002.2943833523.00007FF7E5E0E000.00000002.00000001.01000000.00000003.sdmpDownload File
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_0_2_7ff7e5e00000_file.jbxd
                                Similarity
                                • API ID: CaptureContextEntryFunctionLookupUnwindVirtual__raise_securityfailure
                                • String ID:
                                • API String ID: 140117192-0
                                • Opcode ID: 89b728313985ec8d8bc5760cebbad4f07023fb81a7c1741a44e0131cd2ee41d3
                                • Instruction ID: 19478461060ae4c10cb77330c72ec4c8c2c933e7fbb8ada579ea9ea422eee60b
                                • Opcode Fuzzy Hash: 89b728313985ec8d8bc5760cebbad4f07023fb81a7c1741a44e0131cd2ee41d3
                                • Instruction Fuzzy Hash: D021C535918F4A81E700AB44F9A1369F364FB85B48F900136DACD8BBA4DF7DD045C722

                                Execution Graph

                                Execution Coverage:15.4%
                                Dynamic/Decrypted Code Coverage:100%
                                Signature Coverage:7%
                                Total number of Nodes:86
                                Total number of Limit Nodes:6
                                execution_graph 30075 799d6d8 30076 799d720 VirtualProtect 30075->30076 30077 799d75a 30076->30077 30142 7990878 30143 79908be DeleteFileW 30142->30143 30145 79908f7 30143->30145 30090 31b1b88 30091 31b1bcd Wow64SetThreadContext 30090->30091 30093 31b1c15 30091->30093 30078 1808748 30079 1808758 30078->30079 30082 1807fa0 30079->30082 30086 1807fb8 30079->30086 30083 1808898 CheckRemoteDebuggerPresent 30082->30083 30085 180891e 30083->30085 30085->30079 30088 1808a20 OutputDebugStringW 30086->30088 30089 1808a9f 30088->30089 30089->30079 30094 799c640 30095 799c654 30094->30095 30096 799c6cd 30095->30096 30104 8b75505 30095->30104 30108 8b74b8a 30095->30108 30112 8b762af 30095->30112 30116 8b7531f 30095->30116 30120 8b74873 30095->30120 30124 8b75374 30095->30124 30128 8b74a25 30095->30128 30132 8b767d0 30104->30132 30135 8b767c8 30104->30135 30105 8b7551f 30110 8b767d0 VirtualProtect 30108->30110 30111 8b767c8 VirtualProtect 30108->30111 30109 8b74b9b 30110->30109 30111->30109 30114 8b767d0 VirtualProtect 30112->30114 30115 8b767c8 VirtualProtect 30112->30115 30113 8b762c0 30114->30113 30115->30113 30118 8b767d0 VirtualProtect 30116->30118 30119 8b767c8 VirtualProtect 30116->30119 30117 8b75333 30118->30117 30119->30117 30122 8b767d0 VirtualProtect 30120->30122 30123 8b767c8 VirtualProtect 30120->30123 30121 8b74884 30122->30121 30123->30121 30126 8b767d0 VirtualProtect 30124->30126 30127 8b767c8 VirtualProtect 30124->30127 30125 8b753b2 30126->30125 30127->30125 30130 8b767d0 VirtualProtect 30128->30130 30131 8b767c8 VirtualProtect 30128->30131 30129 8b74a49 30130->30129 30131->30129 30133 8b76818 VirtualProtect 30132->30133 30134 8b76852 30133->30134 30134->30105 30136 8b76818 VirtualProtect 30135->30136 30137 8b76852 30136->30137 30137->30105 30174 799fb60 30175 799fba8 WriteProcessMemory 30174->30175 30177 799fbff 30175->30177 30178 799f820 30179 799f860 VirtualAllocEx 30178->30179 30181 799f89d 30179->30181 30146 31b1f30 30147 31b20bb 30146->30147 30149 31b1f56 30146->30149 30149->30147 30150 31b0128 30149->30150 30151 31b21b0 PostMessageW 30150->30151 30152 31b221c 30151->30152 30152->30149 30153 31b1df0 30154 31b1e30 ResumeThread 30153->30154 30156 31b1e61 30154->30156 30182 31b13a0 30183 31b13e8 VirtualProtectEx 30182->30183 30185 31b1426 30183->30185 30138 8b7f9a8 30139 8b7f9ed Wow64GetThreadContext 30138->30139 30141 8b7fa35 30139->30141 30157 8b79058 30158 8b7908b 30157->30158 30159 8b794b9 30158->30159 30162 8b7ba60 30158->30162 30166 8b7b558 30158->30166 30164 8b7ba87 30162->30164 30163 8b7bb4b 30163->30158 30164->30163 30170 8b7dde8 30164->30170 30167 8b7b566 30166->30167 30169 8b7b56d 30166->30169 30167->30158 30168 8b7dde8 CreateProcessAsUserW 30168->30169 30169->30167 30169->30168 30171 8b7de67 CreateProcessAsUserW 30170->30171 30173 8b7df68 30171->30173

                                Control-flow Graph

                                • Executed
                                • Not Executed
                                control_flow_graph 259 8b7dde8-8b7de73 261 8b7de75-8b7de7b 259->261 262 8b7de7e-8b7de85 259->262 261->262 263 8b7de87-8b7de8d 262->263 264 8b7de90-8b7dea8 262->264 263->264 265 8b7deaa-8b7deb6 264->265 266 8b7deb9-8b7df66 CreateProcessAsUserW 264->266 265->266 268 8b7df6f-8b7dfee 266->268 269 8b7df68-8b7df6e 266->269 276 8b7e000-8b7e007 268->276 277 8b7dff0-8b7dff6 268->277 269->268 278 8b7e01e 276->278 279 8b7e009-8b7e018 276->279 277->276 279->278
                                APIs
                                • CreateProcessAsUserW.KERNELBASE(?,?,?,0000000A,?,?,?,?,?,?,?), ref: 08B7DF53
                                Memory Dump Source
                                • Source File: 00000001.00000002.2942907195.0000000008B70000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B70000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_8b70000_computerlead.jbxd
                                Similarity
                                • API ID: CreateProcessUser
                                • String ID:
                                • API String ID: 2217836671-0
                                • Opcode ID: ad31e634ad0c559589b88713fc13f16ce07a0f30b64c3fe97d0ee51bd05a37f4
                                • Instruction ID: 6943b55f2dbef5729c45ec1e23c3b6532ea459231dcec0048eddc90957def454
                                • Opcode Fuzzy Hash: ad31e634ad0c559589b88713fc13f16ce07a0f30b64c3fe97d0ee51bd05a37f4
                                • Instruction Fuzzy Hash: 5851F47190022ADFDB24CF99C840BDDBBB5BF88710F1484EAE918B7254DB759A85CF90

                                Control-flow Graph

                                • Executed
                                • Not Executed
                                control_flow_graph 359 1807fa0-180891c CheckRemoteDebuggerPresent 362 1808925-1808960 359->362 363 180891e-1808924 359->363 363->362
                                APIs
                                • CheckRemoteDebuggerPresent.KERNELBASE(00000000,?,?,?,?,?,?,?,?,018087FF), ref: 0180890F
                                Memory Dump Source
                                • Source File: 00000001.00000002.2931288288.0000000001800000.00000040.00000800.00020000.00000000.sdmp, Offset: 01800000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_1800000_computerlead.jbxd
                                Similarity
                                • API ID: CheckDebuggerPresentRemote
                                • String ID:
                                • API String ID: 3662101638-0
                                • Opcode ID: d3020c1922b1343f55a40d8da56177e3fc4184a17f7c600dee1aa6bec611c191
                                • Instruction ID: 7f04ed3c547ac5d8017ebe3e764bddcdf21749f285e6e9783090c005fd78480f
                                • Opcode Fuzzy Hash: d3020c1922b1343f55a40d8da56177e3fc4184a17f7c600dee1aa6bec611c191
                                • Instruction Fuzzy Hash: 812166718042598FDB00CF9AC884BEEFBF4EF49310F14846AE949A3240D378AA44CFA1

                                Control-flow Graph

                                • Executed
                                • Not Executed
                                control_flow_graph 366 1808890-180891c CheckRemoteDebuggerPresent 368 1808925-1808960 366->368 369 180891e-1808924 366->369 369->368
                                APIs
                                • CheckRemoteDebuggerPresent.KERNELBASE(00000000,?,?,?,?,?,?,?,?,018087FF), ref: 0180890F
                                Memory Dump Source
                                • Source File: 00000001.00000002.2931288288.0000000001800000.00000040.00000800.00020000.00000000.sdmp, Offset: 01800000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_1800000_computerlead.jbxd
                                Similarity
                                • API ID: CheckDebuggerPresentRemote
                                • String ID:
                                • API String ID: 3662101638-0
                                • Opcode ID: 4caeac09a36bb972149da1f9c760448603e6678e147e9e268e4ae75d5c294695
                                • Instruction ID: 43f77a1c91b44041b72e9abe05ce535330e9c5b91c9742fc580b601ed9f58c51
                                • Opcode Fuzzy Hash: 4caeac09a36bb972149da1f9c760448603e6678e147e9e268e4ae75d5c294695
                                • Instruction Fuzzy Hash: D1214871800259CFDB14DF9AD884BEEBBF4EF49310F14845AE958A7350D7789A44CF61

                                Control-flow Graph

                                • Executed
                                • Not Executed
                                control_flow_graph 372 31b1b81-31b1bd3 374 31b1be3-31b1be6 372->374 375 31b1bd5-31b1be1 372->375 376 31b1bed-31b1c13 Wow64SetThreadContext 374->376 375->374 377 31b1c1c-31b1c4c 376->377 378 31b1c15-31b1c1b 376->378 378->377
                                APIs
                                • Wow64SetThreadContext.KERNEL32(?,00000000), ref: 031B1C06
                                Memory Dump Source
                                • Source File: 00000001.00000002.2931561950.00000000031B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 031B0000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_31b0000_computerlead.jbxd
                                Similarity
                                • API ID: ContextThreadWow64
                                • String ID:
                                • API String ID: 983334009-0
                                • Opcode ID: ee1124ade636343ad85aef8a427cb25c8237d67f4fe72cecfccd28142124058c
                                • Instruction ID: 0ed1c9c534bd2124d85c3204105cfdc9c41a02b9a8ea175aaad38efd21fb3948
                                • Opcode Fuzzy Hash: ee1124ade636343ad85aef8a427cb25c8237d67f4fe72cecfccd28142124058c
                                • Instruction Fuzzy Hash: A3213875D003099FEB10DFAAC985BEEBBF4EF88314F14842AD519A7241CB789644CFA4

                                Control-flow Graph

                                • Executed
                                • Not Executed
                                control_flow_graph 382 799d6ba-799d758 VirtualProtect 384 799d75a-799d760 382->384 385 799d761-799d782 382->385 384->385
                                APIs
                                • VirtualProtect.KERNELBASE(?,?,?,?), ref: 0799D74B
                                Memory Dump Source
                                • Source File: 00000001.00000002.2940502389.0000000007990000.00000040.00000800.00020000.00000000.sdmp, Offset: 07990000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_7990000_computerlead.jbxd
                                Similarity
                                • API ID: ProtectVirtual
                                • String ID:
                                • API String ID: 544645111-0
                                • Opcode ID: e8bd022fc7ae04e6eee5e622ce55a3b6142559c32f97fd40d9d9528fc4b13459
                                • Instruction ID: 02b2cc09b90df6db8854899030faaec522d53e1c8c3f0d7f10945a82e144beeb
                                • Opcode Fuzzy Hash: e8bd022fc7ae04e6eee5e622ce55a3b6142559c32f97fd40d9d9528fc4b13459
                                • Instruction Fuzzy Hash: F12136B69047898FDB11CFAAC584BDEBBF4AB49310F14806AE458A7251C3399545CFA1

                                Control-flow Graph

                                • Executed
                                • Not Executed
                                control_flow_graph 397 8b7f9a8-8b7f9f3 399 8b7f9f5-8b7fa01 397->399 400 8b7fa03-8b7fa33 Wow64GetThreadContext 397->400 399->400 402 8b7fa35-8b7fa3b 400->402 403 8b7fa3c-8b7fa6c 400->403 402->403
                                APIs
                                • Wow64GetThreadContext.KERNEL32(?,00000000), ref: 08B7FA26
                                Memory Dump Source
                                • Source File: 00000001.00000002.2942907195.0000000008B70000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B70000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_8b70000_computerlead.jbxd
                                Similarity
                                • API ID: ContextThreadWow64
                                • String ID:
                                • API String ID: 983334009-0
                                • Opcode ID: c6ef12f8b26db13623ea5f6ed90fd3e7b1f1c0d27812c365d7ca2f88a7744d15
                                • Instruction ID: cea573d66d91f3bcc59ed77f5aa7b5df0589586710cd9a8d6cd76cd8845a4024
                                • Opcode Fuzzy Hash: c6ef12f8b26db13623ea5f6ed90fd3e7b1f1c0d27812c365d7ca2f88a7744d15
                                • Instruction Fuzzy Hash: 6A211871D003498FEB10DFAAC4857EEBBF4EF88325F14842AD559A7241DB789944CFA4

                                Control-flow Graph

                                • Executed
                                • Not Executed
                                control_flow_graph 387 31b1b88-31b1bd3 389 31b1be3-31b1c13 Wow64SetThreadContext 387->389 390 31b1bd5-31b1be1 387->390 392 31b1c1c-31b1c4c 389->392 393 31b1c15-31b1c1b 389->393 390->389 393->392
                                APIs
                                • Wow64SetThreadContext.KERNEL32(?,00000000), ref: 031B1C06
                                Memory Dump Source
                                • Source File: 00000001.00000002.2931561950.00000000031B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 031B0000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_31b0000_computerlead.jbxd
                                Similarity
                                • API ID: ContextThreadWow64
                                • String ID:
                                • API String ID: 983334009-0
                                • Opcode ID: 96257be1d8e03ff7ebdd298c75e7ff9489251874a3222728ce2c8d9e6ed2a8fa
                                • Instruction ID: 182a44be4c3eef8c557e8a21a2de6ac548a3a3c020a38c71b6ad7968c0a3b974
                                • Opcode Fuzzy Hash: 96257be1d8e03ff7ebdd298c75e7ff9489251874a3222728ce2c8d9e6ed2a8fa
                                • Instruction Fuzzy Hash: 7D211571D003099FEB10DFAAC585BEEBBF4EF88324F14842AD559A7241DB789944CFA4

                                Control-flow Graph

                                • Executed
                                • Not Executed
                                control_flow_graph 407 31b139a-31b13ee 409 31b13f5-31b1424 VirtualProtectEx 407->409 410 31b142d-31b145d 409->410 411 31b1426-31b142c 409->411 411->410
                                APIs
                                • VirtualProtectEx.KERNELBASE(?,?,?,?,?), ref: 031B1417
                                Memory Dump Source
                                • Source File: 00000001.00000002.2931561950.00000000031B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 031B0000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_31b0000_computerlead.jbxd
                                Similarity
                                • API ID: ProtectVirtual
                                • String ID:
                                • API String ID: 544645111-0
                                • Opcode ID: f428ce701f0b240b355688ba5203a838513d5f5dac1d5ff5ed7fd40b83193f9e
                                • Instruction ID: a377d6bb73b4bd129fcdd8f73297358938e43fdb0e063853d61aa8ed50984333
                                • Opcode Fuzzy Hash: f428ce701f0b240b355688ba5203a838513d5f5dac1d5ff5ed7fd40b83193f9e
                                • Instruction Fuzzy Hash: 6F213571C002499FEB10CFAAC981BEEBBF5FF88320F14842AD519A7250CB389554CFA0
                                APIs
                                • VirtualProtectEx.KERNELBASE(?,?,?,?,?), ref: 031B1417
                                Memory Dump Source
                                • Source File: 00000001.00000002.2931561950.00000000031B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 031B0000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_31b0000_computerlead.jbxd
                                Similarity
                                • API ID: ProtectVirtual
                                • String ID:
                                • API String ID: 544645111-0
                                • Opcode ID: 0fcbe3d5764f41cafc7a0b200f04e3d0173f780fdb36f7c66de0e8724e4f88ba
                                • Instruction ID: 2e5e52f4dd22e8a7890f62b0dd827fa535a1f91a36a4b5f9fc78e5c86e8ba8db
                                • Opcode Fuzzy Hash: 0fcbe3d5764f41cafc7a0b200f04e3d0173f780fdb36f7c66de0e8724e4f88ba
                                • Instruction Fuzzy Hash: 622135718002499FEB10DFAAC841BEEBBF5EF88320F14842AD519A7240C7789950CFA0
                                APIs
                                • WriteProcessMemory.KERNELBASE(?,?,00000000,?,?), ref: 0799FBF0
                                Memory Dump Source
                                • Source File: 00000001.00000002.2940502389.0000000007990000.00000040.00000800.00020000.00000000.sdmp, Offset: 07990000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_7990000_computerlead.jbxd
                                Similarity
                                • API ID: MemoryProcessWrite
                                • String ID:
                                • API String ID: 3559483778-0
                                • Opcode ID: cc6e6b52c6625716cebfd55ed1ed3852fcfe287db1b126d09783b7eec4304227
                                • Instruction ID: f79efb8cf988ef8a1767bb410bc0b0e8f39306e1954bacf7d1f92673a2ffaae8
                                • Opcode Fuzzy Hash: cc6e6b52c6625716cebfd55ed1ed3852fcfe287db1b126d09783b7eec4304227
                                • Instruction Fuzzy Hash: 0F2106B190035A9FEF10DFAAC885BDEBBF5FF48314F148429E919A7250C7789940CBA4
                                APIs
                                • DeleteFileW.KERNELBASE(00000000), ref: 079908E8
                                Memory Dump Source
                                • Source File: 00000001.00000002.2940502389.0000000007990000.00000040.00000800.00020000.00000000.sdmp, Offset: 07990000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_7990000_computerlead.jbxd
                                Similarity
                                • API ID: DeleteFile
                                • String ID:
                                • API String ID: 4033686569-0
                                • Opcode ID: c71cd5982d06b9b5ca38a69184e5b9beeb0554044393dacb05636d664596839c
                                • Instruction ID: 638a355e7babbfb277e2400ef5243018d76ec27ebbd055a7617293a27dc4764b
                                • Opcode Fuzzy Hash: c71cd5982d06b9b5ca38a69184e5b9beeb0554044393dacb05636d664596839c
                                • Instruction Fuzzy Hash: 9C2144B1C0066A9BDB14CFAAC5447AEFBB0EF48724F15812AD818A7640D338A944CFA4
                                APIs
                                • VirtualProtect.KERNELBASE(?,?,?,?), ref: 08B76843
                                Memory Dump Source
                                • Source File: 00000001.00000002.2942907195.0000000008B70000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B70000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_8b70000_computerlead.jbxd
                                Similarity
                                • API ID: ProtectVirtual
                                • String ID:
                                • API String ID: 544645111-0
                                • Opcode ID: 14a0965c96fc5b94a6e4594569a39a9df390c7aec88b10118891f0215773072d
                                • Instruction ID: 76e7b52f849856583f44070b2283f545cb0bf4e560eedf1408fa8eef39cc5950
                                • Opcode Fuzzy Hash: 14a0965c96fc5b94a6e4594569a39a9df390c7aec88b10118891f0215773072d
                                • Instruction Fuzzy Hash: 30213675D002499FDB10CF9AC544BDEBBF4FB48310F10802AE858A7251D3789554CFA1
                                APIs
                                • WriteProcessMemory.KERNELBASE(?,?,00000000,?,?), ref: 0799FBF0
                                Memory Dump Source
                                • Source File: 00000001.00000002.2940502389.0000000007990000.00000040.00000800.00020000.00000000.sdmp, Offset: 07990000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_7990000_computerlead.jbxd
                                Similarity
                                • API ID: MemoryProcessWrite
                                • String ID:
                                • API String ID: 3559483778-0
                                • Opcode ID: f0bb75d50cae9a7f2a9d7a7aa675c8c5feda9f3cc19e7df626f5341aea81ba2d
                                • Instruction ID: 6f2be5a00ad477ee16d9e06484ae7ce8da24584bbe36f461a5db3eea4842aeae
                                • Opcode Fuzzy Hash: f0bb75d50cae9a7f2a9d7a7aa675c8c5feda9f3cc19e7df626f5341aea81ba2d
                                • Instruction Fuzzy Hash: 6E2122B190035A9FEF10DFA9C985BDEBBF5FF48314F148829E919A7250C7789940CBA4
                                APIs
                                • VirtualAllocEx.KERNELBASE(?,?,?,?,?), ref: 0799F88E
                                Memory Dump Source
                                • Source File: 00000001.00000002.2940502389.0000000007990000.00000040.00000800.00020000.00000000.sdmp, Offset: 07990000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_7990000_computerlead.jbxd
                                Similarity
                                • API ID: AllocVirtual
                                • String ID:
                                • API String ID: 4275171209-0
                                • Opcode ID: 1c299a3d43731fe7a014b7ed285beac4c29e38a3ec951c842ec39edc517e13ae
                                • Instruction ID: d085a83faa2aefe85208a10bbcb6a7a47d571ff057c476a1a3698ea679fa5150
                                • Opcode Fuzzy Hash: 1c299a3d43731fe7a014b7ed285beac4c29e38a3ec951c842ec39edc517e13ae
                                • Instruction Fuzzy Hash: 861156728002499FEF10CFAAC845BDFFBF5EF88324F248819E519A7250C7359554CBA0
                                APIs
                                • DeleteFileW.KERNELBASE(00000000), ref: 079908E8
                                Memory Dump Source
                                • Source File: 00000001.00000002.2940502389.0000000007990000.00000040.00000800.00020000.00000000.sdmp, Offset: 07990000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_7990000_computerlead.jbxd
                                Similarity
                                • API ID: DeleteFile
                                • String ID:
                                • API String ID: 4033686569-0
                                • Opcode ID: 8353c9e39b9373d0b696a0986166dbe12cf86fe5be72a6ae5be27bc6ca21b0f5
                                • Instruction ID: bf10c984107e4372998e9b775aa1a8bb94aec4a3b94fc0c55a1b8e67e1de5ff4
                                • Opcode Fuzzy Hash: 8353c9e39b9373d0b696a0986166dbe12cf86fe5be72a6ae5be27bc6ca21b0f5
                                • Instruction Fuzzy Hash: 971133B1C0066A9BDB14DF9AC445BAEFBF4EF48724F14812AD818A7240D738A944CFE5
                                APIs
                                • VirtualProtect.KERNELBASE(?,?,?,?), ref: 08B76843
                                Memory Dump Source
                                • Source File: 00000001.00000002.2942907195.0000000008B70000.00000040.00000800.00020000.00000000.sdmp, Offset: 08B70000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_8b70000_computerlead.jbxd
                                Similarity
                                • API ID: ProtectVirtual
                                • String ID:
                                • API String ID: 544645111-0
                                • Opcode ID: 5c1b1f3d0c3465587897a868bf076ecdd019e44f5a9baf70fb333aad0992cd87
                                • Instruction ID: 7d72f1a8f71c3502baec3483c2e006f5a28e62a95a9e28c537a86625d7ac2837
                                • Opcode Fuzzy Hash: 5c1b1f3d0c3465587897a868bf076ecdd019e44f5a9baf70fb333aad0992cd87
                                • Instruction Fuzzy Hash: D621D3B59006499FDB10CF9AC885BDEFBF4EB48320F10842AE958A7251D378A954CFA5
                                APIs
                                • VirtualProtect.KERNELBASE(?,?,?,?), ref: 0799D74B
                                Memory Dump Source
                                • Source File: 00000001.00000002.2940502389.0000000007990000.00000040.00000800.00020000.00000000.sdmp, Offset: 07990000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_7990000_computerlead.jbxd
                                Similarity
                                • API ID: ProtectVirtual
                                • String ID:
                                • API String ID: 544645111-0
                                • Opcode ID: aad644eebe5166b0d5db8ba5caea465b22b3904cf5e66e5456a12aa7847da42c
                                • Instruction ID: 5c327a5b001c55903f47b5c5e21cfac4829437bbe458c80a93a20e12c2233098
                                • Opcode Fuzzy Hash: aad644eebe5166b0d5db8ba5caea465b22b3904cf5e66e5456a12aa7847da42c
                                • Instruction Fuzzy Hash: B121E4B59002499FDB10DF9AC985BDEFBF4FF48324F108429E958A7250D378A544CFA5
                                APIs
                                • VirtualAllocEx.KERNELBASE(?,?,?,?,?), ref: 0799F88E
                                Memory Dump Source
                                • Source File: 00000001.00000002.2940502389.0000000007990000.00000040.00000800.00020000.00000000.sdmp, Offset: 07990000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_7990000_computerlead.jbxd
                                Similarity
                                • API ID: AllocVirtual
                                • String ID:
                                • API String ID: 4275171209-0
                                • Opcode ID: 39dbcdb000e0b7b658f7c742a8f3ac2dc49c62488d212a94bcd1082a21bfda2a
                                • Instruction ID: e1f09ace8191fef2a3544c92b873a78f55367e150cd2ef7fec63ef756793dd3a
                                • Opcode Fuzzy Hash: 39dbcdb000e0b7b658f7c742a8f3ac2dc49c62488d212a94bcd1082a21bfda2a
                                • Instruction Fuzzy Hash: 811126718002499FEF10DFAAC845BDEFBF5EF88324F248819E515A7250C7759550CBA4
                                APIs
                                • OutputDebugStringW.KERNELBASE(00000000,?,?,?,00000000,?,?,01808850), ref: 01808A90
                                Memory Dump Source
                                • Source File: 00000001.00000002.2931288288.0000000001800000.00000040.00000800.00020000.00000000.sdmp, Offset: 01800000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_1800000_computerlead.jbxd
                                Similarity
                                • API ID: DebugOutputString
                                • String ID:
                                • API String ID: 1166629820-0
                                • Opcode ID: 70c49479595e831dba6958fdd9bab15415b5d1098e69ec13c9ac6702653b5c7e
                                • Instruction ID: e9008439de555fe048031704f5945ab2cf4cbcad6870a011bbee6c8370d98546
                                • Opcode Fuzzy Hash: 70c49479595e831dba6958fdd9bab15415b5d1098e69ec13c9ac6702653b5c7e
                                • Instruction Fuzzy Hash: 8B1144B1C0064A9FDB14CF9AD840B9EFBB4FB49720F10811AD918A7640D334A680CFA1
                                APIs
                                • OutputDebugStringW.KERNELBASE(00000000,?,?,?,00000000,?,?,01808850), ref: 01808A90
                                Memory Dump Source
                                • Source File: 00000001.00000002.2931288288.0000000001800000.00000040.00000800.00020000.00000000.sdmp, Offset: 01800000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_1800000_computerlead.jbxd
                                Similarity
                                • API ID: DebugOutputString
                                • String ID:
                                • API String ID: 1166629820-0
                                • Opcode ID: b8c5d29c456dae907703fd00aaba489bbd04dca02ae56cfefe99e073432c41d1
                                • Instruction ID: bbbe715ed981504207e4d1f41b49445b3f3f0ce774b30eb4c16218ad5f33fd36
                                • Opcode Fuzzy Hash: b8c5d29c456dae907703fd00aaba489bbd04dca02ae56cfefe99e073432c41d1
                                • Instruction Fuzzy Hash: DE1142B1C0464A9BDB14CF9AD844B9EFBB4FB49320F10812AD918B3640D374AA80CFA5
                                APIs
                                Memory Dump Source
                                • Source File: 00000001.00000002.2931561950.00000000031B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 031B0000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_31b0000_computerlead.jbxd
                                Similarity
                                • API ID: ResumeThread
                                • String ID:
                                • API String ID: 947044025-0
                                • Opcode ID: c8f149d5126ef27f6ade96e99866bde5c7d99d8335ac4e72f46446772770049f
                                • Instruction ID: 817bc1b4dd3b3134507fd67bb0df51c9fc1c812aa3f8be893f211b7fa1386c20
                                • Opcode Fuzzy Hash: c8f149d5126ef27f6ade96e99866bde5c7d99d8335ac4e72f46446772770049f
                                • Instruction Fuzzy Hash: 30115B719003498FEB24DFA9C886BEEFBF4EF88324F248429D419A7240CB759940CB94
                                APIs
                                Memory Dump Source
                                • Source File: 00000001.00000002.2931561950.00000000031B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 031B0000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_31b0000_computerlead.jbxd
                                Similarity
                                • API ID: ResumeThread
                                • String ID:
                                • API String ID: 947044025-0
                                • Opcode ID: 3c9f6d535cf46d73814070af00c1aa77f2118838cc35e7af7bbef265dcbb8d60
                                • Instruction ID: 225a248a292638069baf9fe9f57810de3bddef1f795dd15d3909b5659dfb4455
                                • Opcode Fuzzy Hash: 3c9f6d535cf46d73814070af00c1aa77f2118838cc35e7af7bbef265dcbb8d60
                                • Instruction Fuzzy Hash: 5F1125719003498FEB10DFAAC845BDEFBF5AF88624F248429D519A7240CB79A944CBA4
                                APIs
                                • PostMessageW.USER32(?,00000010,00000000,?), ref: 031B220D
                                Memory Dump Source
                                • Source File: 00000001.00000002.2931561950.00000000031B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 031B0000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_31b0000_computerlead.jbxd
                                Similarity
                                • API ID: MessagePost
                                • String ID:
                                • API String ID: 410705778-0
                                • Opcode ID: 51c6ee13ff7ebac50e46f4fdf9da2c335deb9cbd966d95b423a1f6227d19a8d9
                                • Instruction ID: a0c44b562a1c26190fa85a7f9a0423a215eac55a21bb5fb35d241e0c893ae9b2
                                • Opcode Fuzzy Hash: 51c6ee13ff7ebac50e46f4fdf9da2c335deb9cbd966d95b423a1f6227d19a8d9
                                • Instruction Fuzzy Hash: 9011F2B58003499FDB10DF9AD885BDEFBF8EB48320F108859E958A7200C375A994CFA5
                                APIs
                                • PostMessageW.USER32(?,00000010,00000000,?), ref: 031B220D
                                Memory Dump Source
                                • Source File: 00000001.00000002.2931561950.00000000031B0000.00000040.00000800.00020000.00000000.sdmp, Offset: 031B0000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_31b0000_computerlead.jbxd
                                Similarity
                                • API ID: MessagePost
                                • String ID:
                                • API String ID: 410705778-0
                                • Opcode ID: aa31e77cae00681ad24dcd9c8b364e003768294992bd97eb5711b5d893cb52df
                                • Instruction ID: a1f46b3fcc4e0862e3325f75d1e0878fdb0cd0aa8a82e9a536bc974220fc1592
                                • Opcode Fuzzy Hash: aa31e77cae00681ad24dcd9c8b364e003768294992bd97eb5711b5d893cb52df
                                • Instruction Fuzzy Hash: CF11F2B58002499FDB10CF99D985BDEBBF4EB48310F24845AE558B7250C379A654CFA1
                                Memory Dump Source
                                • Source File: 00000001.00000002.2930789467.000000000171D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0171D000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_171d000_computerlead.jbxd
                                Similarity
                                • API ID:
                                • String ID:
                                • API String ID:
                                • Opcode ID: 6c3c6ec46652e2e5af36541349efc6b5518c499590411da4750c9f001be99011
                                • Instruction ID: 5effea209da571f782e755ed26972088911ddb88a2c1f3c41c2ae1b7c4b79f79
                                • Opcode Fuzzy Hash: 6c3c6ec46652e2e5af36541349efc6b5518c499590411da4750c9f001be99011
                                • Instruction Fuzzy Hash: D5212571604204DFDB21DF58C9C8B16FB61FB84314F20C6ADD9094B246C336D446CE61
                                Memory Dump Source
                                • Source File: 00000001.00000002.2930789467.000000000171D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0171D000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_171d000_computerlead.jbxd
                                Similarity
                                • API ID:
                                • String ID:
                                • API String ID:
                                • Opcode ID: dc69c394bbac40071a67975d34eecf997951e241eb4b0c69b4c12a8b4f8a5a7e
                                • Instruction ID: 301c3b0d61e8d0e970df4cad7973ac35ee79df1dc58a3fbcc20b4a7280155d33
                                • Opcode Fuzzy Hash: dc69c394bbac40071a67975d34eecf997951e241eb4b0c69b4c12a8b4f8a5a7e
                                • Instruction Fuzzy Hash: C8213771608300EFDB25DF98D5C8B56FB61FB88324F20C5ADD8094B25AC376D446CEA1
                                Memory Dump Source
                                • Source File: 00000001.00000002.2930789467.000000000171D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0171D000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_171d000_computerlead.jbxd
                                Similarity
                                • API ID:
                                • String ID:
                                • API String ID:
                                • Opcode ID: f5dd070f47a673dda7babee824c8441981cc2d376d27ad6ac8e2bf7ef2f1688d
                                • Instruction ID: 8b95e46a9369d1ba24196dcfe28a258257ad3e4c3c89dbb63c836f5a0edecbdf
                                • Opcode Fuzzy Hash: f5dd070f47a673dda7babee824c8441981cc2d376d27ad6ac8e2bf7ef2f1688d
                                • Instruction Fuzzy Hash: 2911BB75508280CFCB16CF58D5C4B55FBA2FB88224F24C6A9D8094B65AC33AD40ACFA1
                                Memory Dump Source
                                • Source File: 00000001.00000002.2930789467.000000000171D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0171D000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_171d000_computerlead.jbxd
                                Similarity
                                • API ID:
                                • String ID:
                                • API String ID:
                                • Opcode ID: f5dd070f47a673dda7babee824c8441981cc2d376d27ad6ac8e2bf7ef2f1688d
                                • Instruction ID: 9d162ae8032268b5df4850006f61b98447c9363c8627c55c5eee8f6480ec396b
                                • Opcode Fuzzy Hash: f5dd070f47a673dda7babee824c8441981cc2d376d27ad6ac8e2bf7ef2f1688d
                                • Instruction Fuzzy Hash: A711BE75504244CFCB12CF58C5C4B15FB61FB44314F24C6A9D8494B656C33AD44ACF61
                                Memory Dump Source
                                • Source File: 00000001.00000002.2930753067.000000000170D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0170D000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_170d000_computerlead.jbxd
                                Similarity
                                • API ID:
                                • String ID:
                                • API String ID:
                                • Opcode ID: 248a3ea8ce8762fd81a5b15678d565d794449d4e07c2d723c42e1baf18e62792
                                • Instruction ID: 8a2d37a6901326198005f319af5d99af64f0cbd4dc5525f2072ac5f0b7900efe
                                • Opcode Fuzzy Hash: 248a3ea8ce8762fd81a5b15678d565d794449d4e07c2d723c42e1baf18e62792
                                • Instruction Fuzzy Hash: 6101A771404345DAE7324AD9CD84767FFD8EF45324F18C55AEE094A2C2D2799445C6B1
                                Memory Dump Source
                                • Source File: 00000001.00000002.2930753067.000000000170D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0170D000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_1_2_170d000_computerlead.jbxd
                                Similarity
                                • API ID:
                                • String ID:
                                • API String ID:
                                • Opcode ID: 94c55ac16430cf214470339b675c71569def45e315b1255db788f787951a1dc5
                                • Instruction ID: 680fe44e0543c29487c28ca0ed75023f73c2b0ae1312a3420bd5ac5bc8be7032
                                • Opcode Fuzzy Hash: 94c55ac16430cf214470339b675c71569def45e315b1255db788f787951a1dc5
                                • Instruction Fuzzy Hash: C8F062714453449AE7218A5ADDC4B62FFD8EF41624F18C45AED4C4F2C6D2799844CAB1
                                APIs
                                • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000004,00000000,?,?), ref: 003B0326
                                  • Part of subcall function 003B00A4: VirtualAlloc.KERNELBASE(00000000,00001012,00001000,00000004), ref: 003B00CD
                                  • Part of subcall function 003B00A4: VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 003B0279
                                • VirtualAlloc.KERNELBASE(00000000,00400000,00001000,00000004), ref: 003B0378
                                • VirtualProtect.KERNELBASE(0000002C,?,00000040,?), ref: 003B03E7
                                • VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 003B0407
                                • MapViewOfFile.KERNELBASE(?,00000004,00000000,00000000,00000000), ref: 003B042E
                                • VirtualAlloc.KERNELBASE(00000000,?,00001000,00000004), ref: 003B0456
                                • CloseHandle.KERNELBASE(?), ref: 003B0471
                                Strings
                                Memory Dump Source
                                • Source File: 00000012.00000003.2942125599.00000000003B0000.00000040.00000001.00020000.00000000.sdmp, Offset: 003B0000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_18_3_3b0000_fontdrvhost.jbxd
                                Similarity
                                • API ID: Virtual$Alloc$Free$CloseFileHandleProtectView
                                • String ID: ,
                                • API String ID: 3867569247-3772416878
                                • Opcode ID: 35eb397ea14406336b01ea38f36e06f8461e94550e7b98cd084062937234d485
                                • Instruction ID: 1c9d4f5e4ade5c3b40a3ae19ab8db31b381e6b41bcd68358aaa8345c081742c2
                                • Opcode Fuzzy Hash: 35eb397ea14406336b01ea38f36e06f8461e94550e7b98cd084062937234d485
                                • Instruction Fuzzy Hash: 58611BB5900209EFDB25DFA9C985ADEBBB8FF08354F14851AFA59A7640D730E940CF60
                                APIs
                                • VirtualAlloc.KERNELBASE(00000000,00001012,00001000,00000004), ref: 003B00CD
                                • VirtualFree.KERNELBASE(00000000,00000000,00008000), ref: 003B0279
                                Memory Dump Source
                                • Source File: 00000012.00000003.2942125599.00000000003B0000.00000040.00000001.00020000.00000000.sdmp, Offset: 003B0000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_18_3_3b0000_fontdrvhost.jbxd
                                Similarity
                                • API ID: Virtual$AllocFree
                                • String ID:
                                • API String ID: 2087232378-0
                                • Opcode ID: 7dc8e79fde86babc96161718fc4e5f80a5398d7d893a888eaa0e52eee754c683
                                • Instruction ID: 0bd7b0c051b2dcb398ab0b6f281a8ee4e8c4a9cb9bf81def1b0ce3eef05600f4
                                • Opcode Fuzzy Hash: 7dc8e79fde86babc96161718fc4e5f80a5398d7d893a888eaa0e52eee754c683
                                • Instruction Fuzzy Hash: F771BC71E04249DFCB4ACF98C985BEEBBF0AF08318F244495E561FB641C234AA85DF64
                                Memory Dump Source
                                • Source File: 00000012.00000003.2942125599.00000000003B0000.00000040.00000001.00020000.00000000.sdmp, Offset: 003B0000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_18_3_3b0000_fontdrvhost.jbxd
                                Similarity
                                • API ID:
                                • String ID:
                                • API String ID:
                                • Opcode ID: d558d006f42668ff0cb3938fe5626bc0e09627662ae6e14989234e2d35bd114b
                                • Instruction ID: 6308e2aa110c7a6b6384c50dd125ec815ad1bd154548ed83b13553b283834439
                                • Opcode Fuzzy Hash: d558d006f42668ff0cb3938fe5626bc0e09627662ae6e14989234e2d35bd114b
                                • Instruction Fuzzy Hash: 7DF0A979A012009F8B2ACF09C5488D6B7B6EB90728B2649A5D504AF661D3B1ED88CB60

                                Execution Graph

                                Execution Coverage:33.4%
                                Dynamic/Decrypted Code Coverage:100%
                                Signature Coverage:83.3%
                                Total number of Nodes:24
                                Total number of Limit Nodes:0
                                execution_graph 415 1be066e1cf4 417 1be066e1d19 415->417 416 1be066e1fa1 417->416 426 1be066e15c0 417->426 419 1be066e1f98 CloseHandle 419->416 420 1be066e1f88 NtAcceptConnectPort 420->419 421 1be066e1e3a 421->419 421->420 423 1be066e1ecd 421->423 429 1be066e0ac8 421->429 423->423 435 1be066e1aa4 NtAcceptConnectPort 423->435 427 1be066e15f4 NtAcceptConnectPort 426->427 427->421 430 1be066e0c62 429->430 431 1be066e0ae8 429->431 430->423 431->430 432 1be066e0be8 NtAcceptConnectPort 431->432 432->430 433 1be066e0c1b 432->433 433->430 434 1be066e0c33 NtAcceptConnectPort 433->434 434->430 436 1be066e1af7 435->436 437 1be066e1c04 435->437 441 1be066e1870 436->441 437->420 439 1be066e1b10 440 1be066e1bb6 NtAcceptConnectPort 439->440 440->437 443 1be066e1889 441->443 442 1be066e1949 442->439 443->442 444 1be066e1930 GetProcessMitigationPolicy 443->444 444->442

                                Callgraph

                                Control-flow Graph

                                APIs
                                Memory Dump Source
                                • Source File: 00000016.00000002.3129592218.000001BE066E0000.00000040.00000001.00020000.00000000.sdmp, Offset: 000001BE066E0000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_22_2_1be066e0000_fontdrvhost.jbxd
                                Similarity
                                • API ID: AcceptCloseConnectHandlePort
                                • String ID:
                                • API String ID: 3811980168-0
                                • Opcode ID: 8de21919ba4e7da2ec8babe99db5fa309179d4a6fc20011960c2bc0dbfe1bd07
                                • Instruction ID: 4040db794e2186e829ae5d95e18e1e5a2ee9ba238aca2123ad7e77768fc7019f
                                • Opcode Fuzzy Hash: 8de21919ba4e7da2ec8babe99db5fa309179d4a6fc20011960c2bc0dbfe1bd07
                                • Instruction Fuzzy Hash: BB91A930608E088FD765EF1CD4457E5B3E1FB96310F24465EF49BC729AEBB4A9428B81

                                Control-flow Graph

                                APIs
                                Memory Dump Source
                                • Source File: 00000016.00000002.3129592218.000001BE066E0000.00000040.00000001.00020000.00000000.sdmp, Offset: 000001BE066E0000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_22_2_1be066e0000_fontdrvhost.jbxd
                                Similarity
                                • API ID: AcceptConnectPort
                                • String ID:
                                • API String ID: 1658770261-0
                                • Opcode ID: edb00cfd68506d9e2dba1711408e29722439e3f5d75e8330a2fbe30d3ffa3586
                                • Instruction ID: b8570472d2c9c6ede7dc043367330e12df8942593c3e99726e5fbaa824c146f0
                                • Opcode Fuzzy Hash: edb00cfd68506d9e2dba1711408e29722439e3f5d75e8330a2fbe30d3ffa3586
                                • Instruction Fuzzy Hash: A1512430A18A150EE32CB738A8953F9B7D0F782705F34059EF0E3C5197EBA5C5468A82

                                Control-flow Graph

                                APIs
                                Memory Dump Source
                                • Source File: 00000016.00000002.3129592218.000001BE066E0000.00000040.00000001.00020000.00000000.sdmp, Offset: 000001BE066E0000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_22_2_1be066e0000_fontdrvhost.jbxd
                                Similarity
                                • API ID: AcceptConnectPort$MitigationPolicyProcess
                                • String ID:
                                • API String ID: 2923266908-0
                                • Opcode ID: 37ffde8be01af1a53292e533ef779818db057a4d2febe365c0e37f81bdd73f96
                                • Instruction ID: a5b3ed2bf3029cc4779908b2f657c784a04cbf21265cf44adabc501b9c72030c
                                • Opcode Fuzzy Hash: 37ffde8be01af1a53292e533ef779818db057a4d2febe365c0e37f81bdd73f96
                                • Instruction Fuzzy Hash: EC41F430208B488FDB44EF2C98897D57BD1EB56320F1443AEE85ACB2D7DB74C9498B95

                                Control-flow Graph

                                • Executed
                                • Not Executed
                                control_flow_graph 118 1be066e15c0-1be066e15f2 119 1be066e15f9-1be066e15fb 118->119 120 1be066e15f4-1be066e15f7 118->120 122 1be066e15fd-1be066e1609 119->122 123 1be066e160b-1be066e160d 119->123 121 1be066e161f-1be066e166d NtAcceptConnectPort 120->121 122->121 124 1be066e161d 123->124 125 1be066e160f-1be066e161b 123->125 124->121 125->121
                                APIs
                                • NtAcceptConnectPort.NTDLL(?,?,?,?,?,?,?,?,00000000,000001BE066E1E3A), ref: 000001BE066E1654
                                Memory Dump Source
                                • Source File: 00000016.00000002.3129592218.000001BE066E0000.00000040.00000001.00020000.00000000.sdmp, Offset: 000001BE066E0000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_22_2_1be066e0000_fontdrvhost.jbxd
                                Similarity
                                • API ID: AcceptConnectPort
                                • String ID:
                                • API String ID: 1658770261-0
                                • Opcode ID: 31ad342f5252e0eae0e69cb0d148a17bac8dd2f383a05ec1edad7c50bb2dab19
                                • Instruction ID: 3b3ae7dea9d991a22db6a409f84dc1e8f946c176c0d360bacd219ce187a1bd1f
                                • Opcode Fuzzy Hash: 31ad342f5252e0eae0e69cb0d148a17bac8dd2f383a05ec1edad7c50bb2dab19
                                • Instruction Fuzzy Hash: 65215171608B088FDB58DF18C4C9AAAF7E1FB6A305F140A6EF44AC7260D731D489CB41

                                Control-flow Graph

                                • Executed
                                • Not Executed
                                control_flow_graph 95 1be066e1870-1be066e18a0 call 1be066e08a4 * 2 100 1be066e18a6-1be066e18a9 95->100 101 1be066e1954-1be066e195b 95->101 100->101 102 1be066e18af-1be066e18b9 100->102 102->101 103 1be066e18bf-1be066e18c4 102->103 103->101 104 1be066e18ca-1be066e18d7 103->104 104->101 105 1be066e18d9-1be066e18e1 104->105 105->101 106 1be066e18e3-1be066e18ee 105->106 106->101 107 1be066e18f0-1be066e18f7 106->107 107->101 108 1be066e18f9-1be066e18fc 107->108 108->101 109 1be066e18fe-1be066e1906 108->109 109->101 110 1be066e1908-1be066e190b 109->110 110->101 111 1be066e190d-1be066e1916 110->111 111->101 112 1be066e1918-1be066e191c 111->112 112->101 113 1be066e191e-1be066e192e 112->113 113->101 115 1be066e1930-1be066e1947 GetProcessMitigationPolicy 113->115 115->101 116 1be066e1949-1be066e194e 115->116 116->101 117 1be066e1950-1be066e1951 116->117 117->101
                                APIs
                                Memory Dump Source
                                • Source File: 00000016.00000002.3129592218.000001BE066E0000.00000040.00000001.00020000.00000000.sdmp, Offset: 000001BE066E0000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_22_2_1be066e0000_fontdrvhost.jbxd
                                Similarity
                                • API ID: MitigationPolicyProcess
                                • String ID:
                                • API String ID: 1088084561-0
                                • Opcode ID: 99997b7cfe94d00fabebebec2ac1473308d63281a908fb467bb5077a366d1b6f
                                • Instruction ID: 354b386b90435c54861621087d28ab4731024a688b685913cb6953d625416645
                                • Opcode Fuzzy Hash: 99997b7cfe94d00fabebebec2ac1473308d63281a908fb467bb5077a366d1b6f
                                • Instruction Fuzzy Hash: B831A530300A074EEBA5B768E4947F1B2D0EB96312F2411B9F015D71D9EBB5C949DB60
                                Memory Dump Source
                                • Source File: 00000016.00000002.3129592218.000001BE066E0000.00000040.00000001.00020000.00000000.sdmp, Offset: 000001BE066E0000, based on PE: false
                                Joe Sandbox IDA Plugin
                                • Snapshot File: hcaresult_22_2_1be066e0000_fontdrvhost.jbxd
                                Similarity
                                • API ID:
                                • String ID:
                                • API String ID:
                                • Opcode ID: 247c94ababd4710b0196191072c8bbb5758b71c13019f7a788401a9348e82e18
                                • Instruction ID: 1684949b0e2b346c4f6e13502068689c61c9b2d028cdf62c4328b71d82623ec0
                                • Opcode Fuzzy Hash: 247c94ababd4710b0196191072c8bbb5758b71c13019f7a788401a9348e82e18
                                • Instruction Fuzzy Hash: CFB01130E2AA00C2E3880E0AB8023A0F2B2C30B300F02B2322002F3220CA28CC08028F