Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
hNgIvHRuTU.dll

Overview

General Information

Sample name:hNgIvHRuTU.dll
renamed because original name is a hash value
Original sample name:8e6635b3dcb090c8478fc392ca94722e.dll
Analysis ID:1592050
MD5:8e6635b3dcb090c8478fc392ca94722e
SHA1:937ba8b6fa1778a3fcbb3731c114c9364f7170b8
SHA256:1fc5e4c8809b39d79324848bceac749000ea572d050c81275ae3053a83ba7d12
Tags:dllexeuser-mentality
Infos:

Detection

Wannacry
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected Wannacry ransomware
AI detected suspicious sample
Connects to many different private IPs (likely to spread or exploit)
Connects to many different private IPs via SMB (likely to spread or exploit)
Drops executables to the windows directory (C:\Windows) and starts them
Machine Learning detection for dropped file
Machine Learning detection for sample
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
HTTP GET or POST without a user agent
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file does not import any functions
Sample execution stops while process was sleeping (likely an evasion)
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses insecure TLS / SSL version for HTTPS connection
Yara signature match

Classification

  • System is w10x64
  • loaddll32.exe (PID: 3920 cmdline: loaddll32.exe "C:\Users\user\Desktop\hNgIvHRuTU.dll" MD5: 51E6071F9CBA48E79F10C84515AAE618)
    • conhost.exe (PID: 3572 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • cmd.exe (PID: 1848 cmdline: cmd.exe /C rundll32.exe "C:\Users\user\Desktop\hNgIvHRuTU.dll",#1 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • rundll32.exe (PID: 3748 cmdline: rundll32.exe "C:\Users\user\Desktop\hNgIvHRuTU.dll",#1 MD5: 889B99C52A60DD49227C5E485A016679)
        • mssecsvr.exe (PID: 3292 cmdline: C:\WINDOWS\mssecsvr.exe MD5: 526B41F0EBCFED2206ED1C567D79D1FD)
    • rundll32.exe (PID: 5560 cmdline: rundll32.exe C:\Users\user\Desktop\hNgIvHRuTU.dll,PlayGame MD5: 889B99C52A60DD49227C5E485A016679)
    • rundll32.exe (PID: 3380 cmdline: rundll32.exe "C:\Users\user\Desktop\hNgIvHRuTU.dll",PlayGame MD5: 889B99C52A60DD49227C5E485A016679)
      • mssecsvr.exe (PID: 2380 cmdline: C:\WINDOWS\mssecsvr.exe MD5: 526B41F0EBCFED2206ED1C567D79D1FD)
  • mssecsvr.exe (PID: 6640 cmdline: C:\WINDOWS\mssecsvr.exe -m security MD5: 526B41F0EBCFED2206ED1C567D79D1FD)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
hNgIvHRuTU.dllJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
    hNgIvHRuTU.dllWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
    • 0x45604:$x1: icacls . /grant Everyone:F /T /C /Q
    • 0x353d0:$x3: tasksche.exe
    • 0x455e0:$x3: tasksche.exe
    • 0x455bc:$x4: Global\MsWinZonesCacheCounterMutexA
    • 0x45634:$x5: WNcry@2ol7
    • 0x353a8:$x8: C:\%s\qeriuwjhrf
    • 0x45604:$x9: icacls . /grant Everyone:F /T /C /Q
    • 0x3014:$s1: C:\%s\%s
    • 0x12098:$s1: C:\%s\%s
    • 0x1b39c:$s1: C:\%s\%s
    • 0x353bc:$s1: C:\%s\%s
    • 0x45534:$s3: cmd.exe /c "%s"
    • 0x77a88:$s4: msg/m_portuguese.wnry
    • 0x326f0:$s5: \\192.168.56.20\IPC$
    • 0x1fae5:$s6: \\172.16.99.5\IPC$
    • 0xd195:$op1: 10 AC 72 0D 3D FF FF 1F AC 77 06 B8 01 00 00 00
    • 0x78da:$op2: 44 24 64 8A C6 44 24 65 0E C6 44 24 66 80 C6 44
    • 0x5449:$op3: 18 DF 6C 24 14 DC 64 24 2C DC 6C 24 5C DC 15 88
    hNgIvHRuTU.dllwanna_cry_ransomware_genericdetects wannacry ransomware on disk and in virtual pageus-cert code analysis team
    • 0x455e0:$s11: 74 61 73 6B 73 63 68 65 2E 65 78 65 00 00 00 00 54 61 73 6B 53 74 61 72 74 00 00 00 74 2E 77 6E 72 79 00 00 69 63 61 63
    • 0x45608:$s12: 6C 73 20 2E 20 2F 67 72 61 6E 74 20 45 76 65 72 79 6F 6E 65 3A 46 20 2F 54 20 2F 43 20 2F 51 00 61 74 74 72 69 62 20 2B 68
    SourceRuleDescriptionAuthorStrings
    C:\Windows\tasksche.exeJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
      C:\Windows\tasksche.exeWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
      • 0xf4fc:$x1: icacls . /grant Everyone:F /T /C /Q
      • 0xf4d8:$x3: tasksche.exe
      • 0xf4b4:$x4: Global\MsWinZonesCacheCounterMutexA
      • 0xf52c:$x5: WNcry@2ol7
      • 0xf4fc:$x9: icacls . /grant Everyone:F /T /C /Q
      • 0xf42c:$s3: cmd.exe /c "%s"
      • 0x41980:$s4: msg/m_portuguese.wnry
      C:\Windows\tasksche.exewanna_cry_ransomware_genericdetects wannacry ransomware on disk and in virtual pageus-cert code analysis team
      • 0xf4d8:$s11: 74 61 73 6B 73 63 68 65 2E 65 78 65 00 00 00 00 54 61 73 6B 53 74 61 72 74 00 00 00 74 2E 77 6E 72 79 00 00 69 63 61 63
      • 0xf500:$s12: 6C 73 20 2E 20 2F 67 72 61 6E 74 20 45 76 65 72 79 6F 6E 65 3A 46 20 2F 54 20 2F 43 20 2F 51 00 61 74 74 72 69 62 20 2B 68
      SourceRuleDescriptionAuthorStrings
      00000005.00000000.2135064930.000000000040F000.00000008.00000001.01000000.00000004.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
        00000009.00000000.2164308144.000000000040F000.00000008.00000001.01000000.00000004.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
          00000005.00000002.2168405539.000000000040F000.00000008.00000001.01000000.00000004.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
            00000007.00000002.2802226931.000000000042E000.00000004.00000001.01000000.00000004.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
              00000007.00000000.2156076914.000000000040F000.00000008.00000001.01000000.00000004.sdmpJoeSecurity_WannacryYara detected Wannacry ransomwareJoe Security
                Click to see the 20 entries
                SourceRuleDescriptionAuthorStrings
                7.2.mssecsvr.exe.1d7f128.2.unpackWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
                • 0xe8fc:$x1: icacls . /grant Everyone:F /T /C /Q
                • 0xe8d8:$x3: tasksche.exe
                • 0xe8b4:$x4: Global\MsWinZonesCacheCounterMutexA
                • 0xe92c:$x5: WNcry@2ol7
                • 0xe8fc:$x9: icacls . /grant Everyone:F /T /C /Q
                • 0xe82c:$s3: cmd.exe /c "%s"
                7.2.mssecsvr.exe.1d7f128.2.unpackwanna_cry_ransomware_genericdetects wannacry ransomware on disk and in virtual pageus-cert code analysis team
                • 0xe8d8:$s11: 74 61 73 6B 73 63 68 65 2E 65 78 65 00 00 00 00 54 61 73 6B 53 74 61 72 74 00 00 00 74 2E 77 6E 72 79 00 00 69 63 61 63
                • 0xe900:$s12: 6C 73 20 2E 20 2F 67 72 61 6E 74 20 45 76 65 72 79 6F 6E 65 3A 46 20 2F 54 20 2F 43 20 2F 51 00 61 74 74 72 69 62 20 2B 68
                9.2.mssecsvr.exe.7100a4.1.unpackWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
                • 0xe8fc:$x1: icacls . /grant Everyone:F /T /C /Q
                • 0xe8d8:$x3: tasksche.exe
                • 0xe8b4:$x4: Global\MsWinZonesCacheCounterMutexA
                • 0xe92c:$x5: WNcry@2ol7
                • 0xe8fc:$x9: icacls . /grant Everyone:F /T /C /Q
                • 0xe82c:$s3: cmd.exe /c "%s"
                9.2.mssecsvr.exe.7100a4.1.unpackwanna_cry_ransomware_genericdetects wannacry ransomware on disk and in virtual pageus-cert code analysis team
                • 0xe8d8:$s11: 74 61 73 6B 73 63 68 65 2E 65 78 65 00 00 00 00 54 61 73 6B 53 74 61 72 74 00 00 00 74 2E 77 6E 72 79 00 00 69 63 61 63
                • 0xe900:$s12: 6C 73 20 2E 20 2F 67 72 61 6E 74 20 45 76 65 72 79 6F 6E 65 3A 46 20 2F 54 20 2F 43 20 2F 51 00 61 74 74 72 69 62 20 2B 68
                5.0.mssecsvr.exe.7100a4.1.unpackWannaCry_RansomwareDetects WannaCry RansomwareFlorian Roth (with the help of binar.ly)
                • 0xe8fc:$x1: icacls . /grant Everyone:F /T /C /Q
                • 0xe8d8:$x3: tasksche.exe
                • 0xe8b4:$x4: Global\MsWinZonesCacheCounterMutexA
                • 0xe92c:$x5: WNcry@2ol7
                • 0xe8fc:$x9: icacls . /grant Everyone:F /T /C /Q
                • 0xe82c:$s3: cmd.exe /c "%s"
                Click to see the 87 entries
                No Sigma rule has matched
                TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                2025-01-15T17:47:09.680654+010028033043Unknown Traffic192.168.2.549717103.224.212.21580TCP
                2025-01-15T17:47:11.364702+010028033043Unknown Traffic192.168.2.549720103.224.212.21580TCP
                TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                2025-01-15T17:47:08.760608+010028300181A Network Trojan was detected192.168.2.5654781.1.1.153UDP

                Click to jump to signature section

                Show All Signature Results

                AV Detection

                barindex
                Source: hNgIvHRuTU.dllAvira: detected
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com//iAvira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250116-0347-098f-a7ce-9f0e9ab6a8f5Avira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/sAvira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250116-0347-119b-90f6-837dd48231adAvira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250116-0347-12c5-b838-b08634650eAvira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250116-0347-098f-a7ce-9f0e9ab6a8Avira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250116-0347-119b-90f6-837dd48231Avira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/33ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwAvira URL Cloud: Label: malware
                Source: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250116-0347-12c5-b838-b08634650efcAvira URL Cloud: Label: malware
                Source: C:\WINDOWS\qeriuwjhrf (copy)ReversingLabs: Detection: 85%
                Source: C:\Windows\tasksche.exeReversingLabs: Detection: 85%
                Source: hNgIvHRuTU.dllVirustotal: Detection: 93%Perma Link
                Source: hNgIvHRuTU.dllReversingLabs: Detection: 92%
                Source: Submited SampleIntegrated Neural Analysis Model: Matched 99.6% probability
                Source: C:\Windows\tasksche.exeJoe Sandbox ML: detected
                Source: hNgIvHRuTU.dllJoe Sandbox ML: detected

                Exploits

                barindex
                Source: global trafficTCP traffic: 192.168.2.39:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.38:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.42:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.41:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.44:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.43:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.46:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.45:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.48:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.47:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.40:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.28:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.27:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.29:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.31:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.30:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.33:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.32:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.35:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.34:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.37:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.36:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.17:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.16:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.19:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.18:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.20:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.22:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.21:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.24:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.23:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.26:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.25:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.97:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.96:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.11:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.99:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.10:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.98:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.13:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.12:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.15:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.14:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.91:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.90:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.93:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.92:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.95:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.94:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.2:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.1:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.8:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.7:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.9:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.4:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.3:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.6:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.5:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.86:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.104:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.85:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.105:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.88:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.102:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.87:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.103:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.108:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.89:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.109:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.106:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.107:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.80:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.82:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.100:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.81:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.101:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.84:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.83:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.75:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.74:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.77:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.113:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.76:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.114:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.79:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.78:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.71:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.111:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.70:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.112:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.73:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.72:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.110:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.64:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.63:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.66:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.65:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.68:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.67:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.69:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.60:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.62:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.61:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.49:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.53:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.52:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.55:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.54:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.57:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.56:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.59:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.58:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.51:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.50:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.39:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.38:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.42:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.41:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.44:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.43:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.46:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.45:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.48:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.47:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.40:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.28:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.27:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.29:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.31:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.30:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.33:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.32:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.35:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.34:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.37:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.36:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.17:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.16:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.19:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.18:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.20:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.22:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.21:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.24:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.23:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.26:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.25:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.97:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.96:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.11:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.99:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.10:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.98:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.13:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.12:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.15:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.14:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.91:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.90:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.93:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.92:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.95:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.94:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.2:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.1:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.8:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.7:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.9:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.4:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.3:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.6:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.5:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.86:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.104:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.85:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.105:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.88:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.102:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.87:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.103:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.108:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.89:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.109:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.106:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.107:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.80:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.82:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.100:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.81:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.101:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.84:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.83:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.75:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.74:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.77:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.113:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.76:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.114:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.79:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.78:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.71:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.111:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.70:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.112:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.73:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.72:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.110:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.64:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.63:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.66:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.65:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.68:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.67:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.69:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.60:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.62:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.61:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.49:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.53:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.52:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.55:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.54:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.57:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.56:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.59:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.58:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.51:445Jump to behavior
                Source: global trafficTCP traffic: 192.168.2.50:445Jump to behavior
                Source: hNgIvHRuTU.dllStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DLL
                Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49931 version: TLS 1.0
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:49712 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:49718 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:49737 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:49813 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:49885 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:50063 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:50174 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:50283 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:50373 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:50638 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:50639 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:50640 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:50641 version: TLS 1.2

                Networking

                barindex
                Source: Network trafficSuricata IDS: 2830018 - Severity 1 - ETPRO MALWARE Observed WannaCry Domain (iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff .com in DNS Lookup) : 192.168.2.5:65478 -> 1.1.1.1:53
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cache
                Source: global trafficHTTP traffic detected: GET /?subid1=20250116-0347-098f-a7ce-9f0e9ab6a8f5 HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cache
                Source: global trafficHTTP traffic detected: GET /?subid1=20250116-0347-119b-90f6-837dd48231ad HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cacheCookie: __tad=1736959629.6434080
                Source: global trafficHTTP traffic detected: GET /?subid1=20250116-0347-12c5-b838-b08634650efc HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-AliveCookie: parking_session=16b7b141-0abf-4f9e-8c4f-1c3090e5ffce
                Source: Joe Sandbox ViewJA3 fingerprint: 1138de370e523e824bbca92d049a3777
                Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
                Source: Network trafficSuricata IDS: 2803304 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern HCa : 192.168.2.5:49717 -> 103.224.212.215:80
                Source: Network trafficSuricata IDS: 2803304 - Severity 3 - ETPRO MALWARE Common Downloader Header Pattern HCa : 192.168.2.5:49720 -> 103.224.212.215:80
                Source: unknownHTTPS traffic detected: 23.1.237.91:443 -> 192.168.2.5:49931 version: TLS 1.0
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
                Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 23.1.237.91
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.126.32.133
                Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
                Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
                Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
                Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
                Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
                Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
                Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
                Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
                Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
                Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
                Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
                Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
                Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
                Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
                Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
                Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
                Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
                Source: unknownTCP traffic detected without corresponding DNS query: 40.115.3.253
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cache
                Source: global trafficHTTP traffic detected: GET /?subid1=20250116-0347-098f-a7ce-9f0e9ab6a8f5 HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cache
                Source: global trafficHTTP traffic detected: GET /?subid1=20250116-0347-119b-90f6-837dd48231ad HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comCache-Control: no-cacheCookie: __tad=1736959629.6434080
                Source: global trafficHTTP traffic detected: GET /?subid1=20250116-0347-12c5-b838-b08634650efc HTTP/1.1Cache-Control: no-cacheHost: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comConnection: Keep-AliveCookie: parking_session=16b7b141-0abf-4f9e-8c4f-1c3090e5ffce
                Source: global trafficDNS traffic detected: DNS query: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                Source: global trafficDNS traffic detected: DNS query: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                Source: mssecsvr.exe, 00000005.00000002.2168698777.00000000009A4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsoLF
                Source: mssecsvr.exe, 00000007.00000002.2802700197.0000000000C88000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000009.00000002.2177448708.0000000000CDE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/
                Source: mssecsvr.exe, 00000007.00000002.2802700197.0000000000C88000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com//i
                Source: mssecsvr.exe, 00000005.00000002.2168698777.00000000009A4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/33ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrw
                Source: mssecsvr.exe, 00000005.00000002.2168698777.0000000000966000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250116-0347-098f-a7ce-9f0e9ab6a8
                Source: mssecsvr.exe, 00000007.00000002.2802700197.0000000000CAB000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000007.00000002.2802700197.0000000000CF0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250116-0347-119b-90f6-837dd48231
                Source: mssecsvr.exe, 00000009.00000002.2177448708.0000000000CDE000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000009.00000002.2177448708.0000000000D07000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250116-0347-12c5-b838-b08634650e
                Source: mssecsvr.exe, 00000009.00000002.2177448708.0000000000CDE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/s
                Source: hNgIvHRuTU.dllString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                Source: mssecsvr.exe, 00000005.00000002.2168698777.000000000097E000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000005.00000002.2168698777.0000000000966000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000007.00000002.2802700197.0000000000C88000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000009.00000002.2177448708.0000000000CA8000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000009.00000002.2177448708.0000000000CDE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/
                Source: mssecsvr.exe, 00000009.00000002.2177448708.0000000000CDE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/S
                Source: mssecsvr.exe, 00000007.00000002.2802057332.000000000019D000.00000004.00000010.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comJ
                Source: mssecsvr.exe, 00000009.00000002.2177448708.0000000000CDE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comc
                Source: mssecsvr.exe, 00000007.00000002.2802700197.0000000000C88000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comgsohB&
                Source: mssecsvr.exe, 00000009.00000002.2177448708.0000000000CA8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comyC
                Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49885
                Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 50063 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50638
                Source: unknownNetwork traffic detected: HTTP traffic on port 50174 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50639
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50373
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50174
                Source: unknownNetwork traffic detected: HTTP traffic on port 50283 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 50638 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50063
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50283
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
                Source: unknownNetwork traffic detected: HTTP traffic on port 50641 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49813
                Source: unknownNetwork traffic detected: HTTP traffic on port 49885 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49931
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
                Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49673 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 50639 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49931 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50641
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50640
                Source: unknownNetwork traffic detected: HTTP traffic on port 50373 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
                Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 50640 -> 443
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:49712 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:49718 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:49737 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:49813 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:49885 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:50063 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:50174 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:50283 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:50373 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:50638 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:50639 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:50640 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 40.115.3.253:443 -> 192.168.2.5:50641 version: TLS 1.2

                Spam, unwanted Advertisements and Ransom Demands

                barindex
                Source: Yara matchFile source: hNgIvHRuTU.dll, type: SAMPLE
                Source: Yara matchFile source: 7.2.mssecsvr.exe.22a596c.8.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.0.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.2.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 5.0.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.2.mssecsvr.exe.1d7f128.2.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 5.2.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 9.0.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.2.mssecsvr.exe.1d5c104.5.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 9.2.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.2.mssecsvr.exe.2282948.7.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.2.mssecsvr.exe.22738c8.9.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.2.mssecsvr.exe.1d4d084.4.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 5.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 9.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 5.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 9.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.2.mssecsvr.exe.1d5c104.5.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.2.mssecsvr.exe.1d580a4.3.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.2.mssecsvr.exe.2282948.7.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.2.mssecsvr.exe.227e8e8.6.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000005.00000000.2135064930.000000000040F000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000009.00000000.2164308144.000000000040F000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000005.00000002.2168405539.000000000040F000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000007.00000002.2802226931.000000000042E000.00000004.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000007.00000000.2156076914.000000000040F000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000009.00000002.2177053960.0000000000710000.00000002.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000009.00000000.2164431927.0000000000710000.00000002.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000009.00000002.2176853198.000000000040F000.00000008.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000007.00000000.2156180423.0000000000710000.00000002.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000005.00000002.2168553618.0000000000710000.00000002.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000007.00000002.2803344917.0000000002282000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000005.00000000.2135200599.0000000000710000.00000002.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000007.00000002.2803025512.0000000001D5C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000007.00000002.2802339283.0000000000710000.00000002.00000001.01000000.00000004.sdmp, type: MEMORY
                Source: Yara matchFile source: Process Memory Space: mssecsvr.exe PID: 3292, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: mssecsvr.exe PID: 6640, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: mssecsvr.exe PID: 2380, type: MEMORYSTR
                Source: Yara matchFile source: C:\Windows\tasksche.exe, type: DROPPED

                System Summary

                barindex
                Source: hNgIvHRuTU.dll, type: SAMPLEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: hNgIvHRuTU.dll, type: SAMPLEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 7.2.mssecsvr.exe.1d7f128.2.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.1d7f128.2.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 9.2.mssecsvr.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 9.2.mssecsvr.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 5.0.mssecsvr.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 5.0.mssecsvr.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 7.0.mssecsvr.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.0.mssecsvr.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 9.0.mssecsvr.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 9.0.mssecsvr.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 5.2.mssecsvr.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 5.2.mssecsvr.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 7.2.mssecsvr.exe.1d4d084.4.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.22a596c.8.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.22a596c.8.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 7.2.mssecsvr.exe.22a596c.8.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.22a596c.8.raw.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 7.0.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.0.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 7.2.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 5.0.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 5.0.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 7.2.mssecsvr.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 7.2.mssecsvr.exe.22738c8.9.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.1d7f128.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.1d7f128.2.raw.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 5.2.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 5.2.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 9.0.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 9.0.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 7.2.mssecsvr.exe.1d5c104.5.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.1d5c104.5.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 7.2.mssecsvr.exe.1d5c104.5.raw.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 9.2.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 9.2.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 7.2.mssecsvr.exe.2282948.7.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.2282948.7.raw.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 7.2.mssecsvr.exe.2282948.7.raw.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 7.2.mssecsvr.exe.22738c8.9.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.22738c8.9.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 7.2.mssecsvr.exe.1d4d084.4.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.1d4d084.4.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 7.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 7.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 5.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 5.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 5.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 9.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 9.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 9.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 7.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 7.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 5.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 5.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 5.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 9.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 9.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (based on rule by US CERT)
                Source: 9.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 7.2.mssecsvr.exe.1d5c104.5.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.1d5c104.5.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 7.2.mssecsvr.exe.1d580a4.3.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.1d580a4.3.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 7.2.mssecsvr.exe.2282948.7.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.2282948.7.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 7.2.mssecsvr.exe.227e8e8.6.unpack, type: UNPACKEDPEMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: 7.2.mssecsvr.exe.227e8e8.6.unpack, type: UNPACKEDPEMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 00000009.00000002.2177053960.0000000000710000.00000002.00000001.01000000.00000004.sdmp, type: MEMORYMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 00000009.00000000.2164431927.0000000000710000.00000002.00000001.01000000.00000004.sdmp, type: MEMORYMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 00000007.00000000.2156180423.0000000000710000.00000002.00000001.01000000.00000004.sdmp, type: MEMORYMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 00000005.00000002.2168553618.0000000000710000.00000002.00000001.01000000.00000004.sdmp, type: MEMORYMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 00000007.00000002.2803344917.0000000002282000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 00000005.00000000.2135200599.0000000000710000.00000002.00000001.01000000.00000004.sdmp, type: MEMORYMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 00000007.00000002.2803025512.0000000001D5C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: 00000007.00000002.2802339283.0000000000710000.00000002.00000001.01000000.00000004.sdmp, type: MEMORYMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: C:\Windows\tasksche.exe, type: DROPPEDMatched rule: Detects WannaCry Ransomware Author: Florian Roth (with the help of binar.ly)
                Source: C:\Windows\tasksche.exe, type: DROPPEDMatched rule: detects wannacry ransomware on disk and in virtual page Author: us-cert code analysis team
                Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\WINDOWS\mssecsvr.exeJump to behavior
                Source: C:\Windows\mssecsvr.exeFile created: C:\WINDOWS\tasksche.exeJump to behavior
                Source: C:\Windows\mssecsvr.exeFile created: C:\WINDOWS\tasksche.exeJump to behavior
                Source: tasksche.exe.5.drStatic PE information: No import functions for PE file found
                Source: hNgIvHRuTU.dllStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DLL
                Source: hNgIvHRuTU.dll, type: SAMPLEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: hNgIvHRuTU.dll, type: SAMPLEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 7.2.mssecsvr.exe.1d7f128.2.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.1d7f128.2.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 9.2.mssecsvr.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 9.2.mssecsvr.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 5.0.mssecsvr.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 5.0.mssecsvr.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 7.0.mssecsvr.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.0.mssecsvr.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 9.0.mssecsvr.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 9.0.mssecsvr.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 5.2.mssecsvr.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 5.2.mssecsvr.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 7.2.mssecsvr.exe.1d4d084.4.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.22a596c.8.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.22a596c.8.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 7.2.mssecsvr.exe.22a596c.8.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.22a596c.8.raw.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 7.0.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.0.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 7.2.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 5.0.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 5.0.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 7.2.mssecsvr.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.7100a4.1.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 7.2.mssecsvr.exe.22738c8.9.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.1d7f128.2.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.1d7f128.2.raw.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 5.2.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 5.2.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 9.0.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 9.0.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 7.2.mssecsvr.exe.1d5c104.5.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.1d5c104.5.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 7.2.mssecsvr.exe.1d5c104.5.raw.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 9.2.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 9.2.mssecsvr.exe.7100a4.1.raw.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 7.2.mssecsvr.exe.2282948.7.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.2282948.7.raw.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 7.2.mssecsvr.exe.2282948.7.raw.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 7.2.mssecsvr.exe.22738c8.9.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.22738c8.9.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 7.2.mssecsvr.exe.1d4d084.4.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.1d4d084.4.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 7.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 7.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 5.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 5.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 5.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 9.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 9.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 9.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 7.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 7.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 5.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 5.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 5.0.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 9.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 9.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware_Gen date = 2017-05-12, hash3 = 4384bf4530fb2e35449a8e01c7e0ad94e3a25811ba94f7847c1e6612bbb45359, hash2 = 8e5b5841a3fe81cade259ce2a678ccb4451725bba71f6662d0cc1f08148da8df, hash1 = 9fe91d542952e145f2244572f314632d93eb1e8657621087b2ca7f7df2b0cb05, author = Florian Roth (based on rule by US CERT), description = Detects WannaCry Ransomware, reference = https://www.us-cert.gov/ncas/alerts/TA17-132A
                Source: 9.2.mssecsvr.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 7.2.mssecsvr.exe.1d5c104.5.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.1d5c104.5.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 7.2.mssecsvr.exe.1d580a4.3.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.1d580a4.3.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 7.2.mssecsvr.exe.2282948.7.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.2282948.7.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 7.2.mssecsvr.exe.227e8e8.6.unpack, type: UNPACKEDPEMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: 7.2.mssecsvr.exe.227e8e8.6.unpack, type: UNPACKEDPEMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 00000009.00000002.2177053960.0000000000710000.00000002.00000001.01000000.00000004.sdmp, type: MEMORYMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 00000009.00000000.2164431927.0000000000710000.00000002.00000001.01000000.00000004.sdmp, type: MEMORYMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 00000007.00000000.2156180423.0000000000710000.00000002.00000001.01000000.00000004.sdmp, type: MEMORYMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 00000005.00000002.2168553618.0000000000710000.00000002.00000001.01000000.00000004.sdmp, type: MEMORYMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 00000007.00000002.2803344917.0000000002282000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 00000005.00000000.2135200599.0000000000710000.00000002.00000001.01000000.00000004.sdmp, type: MEMORYMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 00000007.00000002.2803025512.0000000001D5C000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: 00000007.00000002.2802339283.0000000000710000.00000002.00000001.01000000.00000004.sdmp, type: MEMORYMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: C:\Windows\tasksche.exe, type: DROPPEDMatched rule: WannaCry_Ransomware date = 2017-05-12, hash1 = ed01ebfbc9eb5bbea545af4d01bf5f1071661840480439c6e5babe8e080e41aa, author = Florian Roth (with the help of binar.ly), description = Detects WannaCry Ransomware, reference = https://goo.gl/HG2j5T
                Source: C:\Windows\tasksche.exe, type: DROPPEDMatched rule: wanna_cry_ransomware_generic date = 2017/05/12, hash0 = 4da1f312a214c07143abeeafb695d904, author = us-cert code analysis team, description = detects wannacry ransomware on disk and in virtual page, reference = not set
                Source: tasksche.exe.5.drStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                Source: tasksche.exe.5.drStatic PE information: Section: .rdata ZLIB complexity 1.0007621951219512
                Source: tasksche.exe.5.drStatic PE information: Section: .data ZLIB complexity 1.001953125
                Source: tasksche.exe.5.drStatic PE information: Section: .rsrc ZLIB complexity 1.0007408405172413
                Source: hNgIvHRuTU.dll, tasksche.exe.5.drBinary or memory string: @.der.pfx.key.crt.csr.p12.pem.odt.ott.sxw.stw.uot.3ds.max.3dm.ods.ots.sxc.stc.dif.slk.wb2.odp.otp.sxd.std.uop.odg.otg.sxm.mml.lay.lay6.asc.sqlite3.sqlitedb.sql.accdb.mdb.db.dbf.odb.frm.myd.myi.ibd.mdf.ldf.sln.suo.cs.c.cpp.pas.h.asm.js.cmd.bat.ps1.vbs.vb.pl.dip.dch.sch.brd.jsp.php.asp.rb.java.jar.class.sh.mp3.wav.swf.fla.wmv.mpg.vob.mpeg.asf.avi.mov.mp4.3gp.mkv.3g2.flv.wma.mid.m3u.m4u.djvu.svg.ai.psd.nef.tiff.tif.cgm.raw.gif.png.bmp.jpg.jpeg.vcd.iso.backup.zip.rar.7z.gz.tgz.tar.bak.tbk.bz2.PAQ.ARC.aes.gpg.vmx.vmdk.vdi.sldm.sldx.sti.sxi.602.hwp.snt.onetoc2.dwg.pdf.wk1.wks.123.rtf.csv.txt.vsdx.vsd.edb.eml.msg.ost.pst.potm.potx.ppam.ppsx.ppsm.pps.pot.pptm.pptx.ppt.xltm.xltx.xlc.xlm.xlt.xlw.xlsb.xlsm.xlsx.xls.dotx.dotm.dot.docm.docb.docx.docWANACRY!%s\%sCloseHandleDeleteFileWMoveFileExWMoveFileWReadFileWriteFileCreateFileWkernel32.dll
                Source: classification engineClassification label: mal100.rans.expl.evad.winDLL@18/2@2/100
                Source: C:\Windows\mssecsvr.exeCode function: sprintf,OpenSCManagerA,InternetCloseHandle,CreateServiceA,CloseServiceHandle,StartServiceA,CloseServiceHandle,CloseServiceHandle,5_2_00407C40
                Source: C:\Windows\mssecsvr.exeCode function: sprintf,OpenSCManagerA,InternetCloseHandle,CreateServiceA,CloseServiceHandle,StartServiceA,CloseServiceHandle,CloseServiceHandle,7_2_00407C40
                Source: C:\Windows\mssecsvr.exeCode function: 5_2_00407CE0 InternetCloseHandle,GetModuleHandleW,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,CreateProcessA,FindResourceA,LoadResource,LockResource,SizeofResource,sprintf,sprintf,sprintf,MoveFileExA,CreateFileA,WriteFile,CloseHandle,CreateProcessA,CloseHandle,CloseHandle,5_2_00407CE0
                Source: C:\Windows\mssecsvr.exeCode function: 5_2_00407C40 sprintf,OpenSCManagerA,InternetCloseHandle,CreateServiceA,CloseServiceHandle,StartServiceA,CloseServiceHandle,CloseServiceHandle,5_2_00407C40
                Source: C:\Windows\mssecsvr.exeCode function: 5_2_00408090 GetModuleFileNameA,__p___argc,OpenSCManagerA,InternetCloseHandle,OpenServiceA,CloseServiceHandle,CloseServiceHandle,CloseServiceHandle,StartServiceCtrlDispatcherA,5_2_00408090
                Source: C:\Windows\mssecsvr.exeCode function: 7_2_00408090 GetModuleFileNameA,__p___argc,OpenSCManagerA,InternetCloseHandle,OpenServiceA,CloseServiceHandle,CloseServiceHandle,CloseServiceHandle,StartServiceCtrlDispatcherA,7_2_00408090
                Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3572:120:WilError_03
                Source: hNgIvHRuTU.dllStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                Source: C:\Windows\System32\loaddll32.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\hNgIvHRuTU.dll,PlayGame
                Source: hNgIvHRuTU.dllVirustotal: Detection: 93%
                Source: hNgIvHRuTU.dllReversingLabs: Detection: 92%
                Source: unknownProcess created: C:\Windows\System32\loaddll32.exe loaddll32.exe "C:\Users\user\Desktop\hNgIvHRuTU.dll"
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\hNgIvHRuTU.dll",#1
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\hNgIvHRuTU.dll,PlayGame
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\hNgIvHRuTU.dll",#1
                Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\mssecsvr.exe C:\WINDOWS\mssecsvr.exe
                Source: unknownProcess created: C:\Windows\mssecsvr.exe C:\WINDOWS\mssecsvr.exe -m security
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\hNgIvHRuTU.dll",PlayGame
                Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\mssecsvr.exe C:\WINDOWS\mssecsvr.exe
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\hNgIvHRuTU.dll",#1Jump to behavior
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe C:\Users\user\Desktop\hNgIvHRuTU.dll,PlayGameJump to behavior
                Source: C:\Windows\System32\loaddll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\hNgIvHRuTU.dll",PlayGameJump to behavior
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\hNgIvHRuTU.dll",#1Jump to behavior
                Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\mssecsvr.exe C:\WINDOWS\mssecsvr.exeJump to behavior
                Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\mssecsvr.exe C:\WINDOWS\mssecsvr.exeJump to behavior
                Source: C:\Windows\System32\loaddll32.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Windows\System32\loaddll32.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Windows\SysWOW64\cmd.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: msvcp60.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: wininet.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: iertutil.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: winnsi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: urlmon.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: srvcli.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: netutils.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: dnsapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: rasadhlp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: fwpuclnt.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: msvcp60.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: wininet.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: iertutil.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: winnsi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: urlmon.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: srvcli.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: netutils.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: dnsapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: rasadhlp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: fwpuclnt.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: cryptsp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: rsaenh.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: cryptbase.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: dhcpcsvc.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: dhcpcsvc6.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: msvcp60.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: wininet.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: iertutil.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: winnsi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: urlmon.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: srvcli.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: netutils.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: dnsapi.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: rasadhlp.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeSection loaded: fwpuclnt.dllJump to behavior
                Source: C:\Windows\mssecsvr.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{057EEE47-2572-4AA1-88D7-60CE2149E33C}\InProcServer32Jump to behavior
                Source: hNgIvHRuTU.dllStatic file information: File size 5267459 > 1048576
                Source: hNgIvHRuTU.dllStatic PE information: Raw size of .rsrc is bigger than: 0x100000 < 0x501000
                Source: tasksche.exe.5.drStatic PE information: section name: .text entropy: 7.64063717569669

                Persistence and Installation Behavior

                barindex
                Source: C:\Windows\SysWOW64\rundll32.exeExecutable created and started: C:\WINDOWS\mssecsvr.exeJump to behavior
                Source: C:\Windows\mssecsvr.exeFile created: C:\WINDOWS\qeriuwjhrf (copy)Jump to dropped file
                Source: C:\Windows\mssecsvr.exeFile created: C:\Windows\tasksche.exeJump to dropped file
                Source: C:\Windows\mssecsvr.exeFile created: C:\WINDOWS\qeriuwjhrf (copy)Jump to dropped file
                Source: C:\Windows\mssecsvr.exeFile created: C:\Windows\tasksche.exeJump to dropped file
                Source: C:\Windows\mssecsvr.exeCode function: 5_2_00407C40 sprintf,OpenSCManagerA,InternetCloseHandle,CreateServiceA,CloseServiceHandle,StartServiceA,CloseServiceHandle,CloseServiceHandle,5_2_00407C40
                Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\mssecsvr.exeThread delayed: delay time: 86400000Jump to behavior
                Source: C:\Windows\mssecsvr.exeDropped PE file which has not been started: C:\WINDOWS\qeriuwjhrf (copy)Jump to dropped file
                Source: C:\Windows\mssecsvr.exeDropped PE file which has not been started: C:\Windows\tasksche.exeJump to dropped file
                Source: C:\Windows\mssecsvr.exe TID: 5816Thread sleep count: 93 > 30Jump to behavior
                Source: C:\Windows\mssecsvr.exe TID: 5816Thread sleep time: -186000s >= -30000sJump to behavior
                Source: C:\Windows\mssecsvr.exe TID: 6336Thread sleep count: 128 > 30Jump to behavior
                Source: C:\Windows\mssecsvr.exe TID: 6336Thread sleep count: 45 > 30Jump to behavior
                Source: C:\Windows\mssecsvr.exe TID: 5816Thread sleep time: -86400000s >= -30000sJump to behavior
                Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
                Source: C:\Windows\System32\loaddll32.exeThread delayed: delay time: 120000Jump to behavior
                Source: C:\Windows\mssecsvr.exeThread delayed: delay time: 86400000Jump to behavior
                Source: mssecsvr.exe, 00000005.00000002.2168698777.0000000000997000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000005.00000002.2168698777.0000000000966000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000007.00000002.2802700197.0000000000CF0000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000007.00000002.2802700197.0000000000C88000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000009.00000002.2177448708.0000000000D11000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000009.00000002.2177448708.0000000000CA8000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\hNgIvHRuTU.dll",#1Jump to behavior
                ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
                Service Execution
                4
                Windows Service
                4
                Windows Service
                12
                Masquerading
                OS Credential Dumping1
                Network Share Discovery
                Remote ServicesData from Local System2
                Encrypted Channel
                Exfiltration Over Other Network MediumAbuse Accessibility Features
                CredentialsDomainsDefault AccountsScheduled Task/Job1
                DLL Side-Loading
                11
                Process Injection
                21
                Virtualization/Sandbox Evasion
                LSASS Memory11
                Security Software Discovery
                Remote Desktop ProtocolData from Removable Media1
                Ingress Tool Transfer
                Exfiltration Over BluetoothNetwork Denial of Service
                Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
                DLL Side-Loading
                11
                Process Injection
                Security Account Manager21
                Virtualization/Sandbox Evasion
                SMB/Windows Admin SharesData from Network Shared Drive2
                Non-Application Layer Protocol
                Automated ExfiltrationData Encrypted for Impact
                Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
                Obfuscated Files or Information
                NTDS1
                System Information Discovery
                Distributed Component Object ModelInput Capture3
                Application Layer Protocol
                Traffic DuplicationData Destruction
                Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
                Rundll32
                LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
                Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts3
                Software Packing
                Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
                DLL Side-Loading
                DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
                Hide Legend

                Legend:

                • Process
                • Signature
                • Created File
                • DNS/IP Info
                • Is Dropped
                • Is Windows Process
                • Number of created Registry Values
                • Number of created Files
                • Visual Basic
                • Delphi
                • Java
                • .Net C# or VB.NET
                • C, C++ or other language
                • Is malicious
                • Internet
                behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1592050 Sample: hNgIvHRuTU.dll Startdate: 15/01/2025 Architecture: WINDOWS Score: 100 36 www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com 2->36 38 ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com 2->38 40 77026.bodis.com 2->40 48 Suricata IDS alerts for network traffic 2->48 50 Malicious sample detected (through community Yara rule) 2->50 52 Antivirus detection for URL or domain 2->52 54 7 other signatures 2->54 9 loaddll32.exe 1 2->9         started        11 mssecsvr.exe 12 2->11         started        signatures3 process4 dnsIp5 15 rundll32.exe 9->15         started        18 cmd.exe 1 9->18         started        20 conhost.exe 9->20         started        22 rundll32.exe 1 9->22         started        42 192.168.2.102 unknown unknown 11->42 44 192.168.2.103 unknown unknown 11->44 46 98 other IPs or domains 11->46 56 Connects to many different private IPs via SMB (likely to spread or exploit) 11->56 58 Connects to many different private IPs (likely to spread or exploit) 11->58 signatures6 process7 signatures8 60 Drops executables to the windows directory (C:\Windows) and starts them 15->60 24 mssecsvr.exe 13 15->24         started        27 rundll32.exe 18->27         started        process9 file10 32 C:\WINDOWS\qeriuwjhrf (copy), PE32 24->32 dropped 29 mssecsvr.exe 13 27->29         started        process11 file12 34 C:\Windows\tasksche.exe, PE32 29->34 dropped

                This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                windows-stand
                SourceDetectionScannerLabelLink
                hNgIvHRuTU.dll93%VirustotalBrowse
                hNgIvHRuTU.dll92%ReversingLabsWin32.Ransomware.WannaCry
                hNgIvHRuTU.dll100%AviraTR/AD.DPulsarShellcode.fqgnr
                hNgIvHRuTU.dll100%Joe Sandbox ML
                SourceDetectionScannerLabelLink
                C:\Windows\tasksche.exe100%Joe Sandbox ML
                C:\WINDOWS\qeriuwjhrf (copy)86%ReversingLabsWin32.Ransomware.WannaCry
                C:\Windows\tasksche.exe86%ReversingLabsWin32.Ransomware.WannaCry
                No Antivirus matches
                No Antivirus matches
                SourceDetectionScannerLabelLink
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com//i100%Avira URL Cloudmalware
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250116-0347-098f-a7ce-9f0e9ab6a8f5100%Avira URL Cloudmalware
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/s100%Avira URL Cloudmalware
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250116-0347-119b-90f6-837dd48231ad100%Avira URL Cloudmalware
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250116-0347-12c5-b838-b08634650e100%Avira URL Cloudmalware
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250116-0347-098f-a7ce-9f0e9ab6a8100%Avira URL Cloudmalware
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250116-0347-119b-90f6-837dd48231100%Avira URL Cloudmalware
                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comyC0%Avira URL Cloudsafe
                http://ww25.iuqerfsoLF0%Avira URL Cloudsafe
                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comgsohB&0%Avira URL Cloudsafe
                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comc0%Avira URL Cloudsafe
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/33ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrw100%Avira URL Cloudmalware
                http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250116-0347-12c5-b838-b08634650efc100%Avira URL Cloudmalware
                NameIPActiveMaliciousAntivirus DetectionReputation
                bg.microsoft.map.fastly.net
                199.232.214.172
                truefalse
                  high
                  77026.bodis.com
                  199.59.243.228
                  truefalse
                    high
                    www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                    103.224.212.215
                    truefalse
                      high
                      ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                      unknown
                      unknownfalse
                        high
                        NameMaliciousAntivirus DetectionReputation
                        http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250116-0347-098f-a7ce-9f0e9ab6a8f5false
                        • Avira URL Cloud: malware
                        unknown
                        http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/false
                          high
                          http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250116-0347-119b-90f6-837dd48231adfalse
                          • Avira URL Cloud: malware
                          unknown
                          http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250116-0347-12c5-b838-b08634650efcfalse
                          • Avira URL Cloud: malware
                          unknown
                          NameSourceMaliciousAntivirus DetectionReputation
                          http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250116-0347-12c5-b838-b08634650emssecsvr.exe, 00000009.00000002.2177448708.0000000000CDE000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000009.00000002.2177448708.0000000000D07000.00000004.00000020.00020000.00000000.sdmpfalse
                          • Avira URL Cloud: malware
                          unknown
                          http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/mssecsvr.exe, 00000007.00000002.2802700197.0000000000C88000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000009.00000002.2177448708.0000000000CDE000.00000004.00000020.00020000.00000000.sdmpfalse
                            high
                            http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comhNgIvHRuTU.dllfalse
                              high
                              http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com//imssecsvr.exe, 00000007.00000002.2802700197.0000000000C88000.00000004.00000020.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: malware
                              unknown
                              http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/smssecsvr.exe, 00000009.00000002.2177448708.0000000000CDE000.00000004.00000020.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: malware
                              unknown
                              http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250116-0347-098f-a7ce-9f0e9ab6a8mssecsvr.exe, 00000005.00000002.2168698777.0000000000966000.00000004.00000020.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: malware
                              unknown
                              http://ww25.iuqerfsoLFmssecsvr.exe, 00000005.00000002.2168698777.00000000009A4000.00000004.00000020.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250116-0347-119b-90f6-837dd48231mssecsvr.exe, 00000007.00000002.2802700197.0000000000CAB000.00000004.00000020.00020000.00000000.sdmp, mssecsvr.exe, 00000007.00000002.2802700197.0000000000CF0000.00000004.00000020.00020000.00000000.sdmpfalse
                              • Avira URL Cloud: malware
                              unknown
                              http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comJmssecsvr.exe, 00000007.00000002.2802057332.000000000019D000.00000004.00000010.00020000.00000000.sdmpfalse
                                high
                                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comyCmssecsvr.exe, 00000009.00000002.2177448708.0000000000CA8000.00000004.00000020.00020000.00000000.sdmpfalse
                                • Avira URL Cloud: safe
                                unknown
                                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comgsohB&mssecsvr.exe, 00000007.00000002.2802700197.0000000000C88000.00000004.00000020.00020000.00000000.sdmpfalse
                                • Avira URL Cloud: safe
                                unknown
                                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comcmssecsvr.exe, 00000009.00000002.2177448708.0000000000CDE000.00000004.00000020.00020000.00000000.sdmpfalse
                                • Avira URL Cloud: safe
                                unknown
                                http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/Smssecsvr.exe, 00000009.00000002.2177448708.0000000000CDE000.00000004.00000020.00020000.00000000.sdmpfalse
                                  high
                                  http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/33ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwmssecsvr.exe, 00000005.00000002.2168698777.00000000009A4000.00000004.00000020.00020000.00000000.sdmpfalse
                                  • Avira URL Cloud: malware
                                  unknown
                                  • No. of IPs < 25%
                                  • 25% < No. of IPs < 50%
                                  • 50% < No. of IPs < 75%
                                  • 75% < No. of IPs
                                  IPDomainCountryFlagASNASN NameMalicious
                                  101.5.197.1
                                  unknownChina
                                  4538ERX-CERNET-BKBChinaEducationandResearchNetworkCenterfalse
                                  78.130.181.2
                                  unknownBulgaria
                                  9070COOOLBOXBGfalse
                                  78.130.181.1
                                  unknownBulgaria
                                  9070COOOLBOXBGfalse
                                  101.5.197.2
                                  unknownChina
                                  4538ERX-CERNET-BKBChinaEducationandResearchNetworkCenterfalse
                                  35.81.47.1
                                  unknownUnited States
                                  237MERIT-AS-14USfalse
                                  13.229.164.1
                                  unknownUnited States
                                  16509AMAZON-02USfalse
                                  13.229.164.2
                                  unknownUnited States
                                  16509AMAZON-02USfalse
                                  25.38.30.167
                                  unknownUnited Kingdom
                                  7922COMCAST-7922USfalse
                                  31.52.246.6
                                  unknownUnited Kingdom
                                  2856BT-UK-ASBTnetUKRegionalnetworkGBfalse
                                  31.52.246.1
                                  unknownUnited Kingdom
                                  2856BT-UK-ASBTnetUKRegionalnetworkGBfalse
                                  35.81.47.184
                                  unknownUnited States
                                  237MERIT-AS-14USfalse
                                  41.240.115.2
                                  unknownSudan
                                  36998SDN-MOBITELSDfalse
                                  41.240.115.1
                                  unknownSudan
                                  36998SDN-MOBITELSDfalse
                                  126.75.17.59
                                  unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
                                  2.139.197.109
                                  unknownSpain
                                  3352TELEFONICA_DE_ESPANAESfalse
                                  129.17.117.58
                                  unknownUnited States
                                  2841CHALMERSSEfalse
                                  218.112.212.165
                                  unknownJapan17676GIGAINFRASoftbankBBCorpJPfalse
                                  13.229.164.57
                                  unknownUnited States
                                  16509AMAZON-02USfalse
                                  116.101.184.130
                                  unknownViet Nam
                                  24086VIETTEL-AS-VNViettelCorporationVNfalse
                                  129.17.117.1
                                  unknownUnited States
                                  2841CHALMERSSEfalse
                                  144.29.150.72
                                  unknownUnited States
                                  26258BASF-CORPUSfalse
                                  208.140.179.1
                                  unknownUnited States
                                  3561CENTURYLINK-LEGACY-SAVVISUSfalse
                                  208.140.179.2
                                  unknownUnited States
                                  3561CENTURYLINK-LEGACY-SAVVISUSfalse
                                  IP
                                  192.168.2.148
                                  192.168.2.149
                                  192.168.2.146
                                  192.168.2.147
                                  192.168.2.140
                                  192.168.2.141
                                  192.168.2.144
                                  192.168.2.145
                                  192.168.2.142
                                  192.168.2.143
                                  192.168.2.159
                                  192.168.2.157
                                  192.168.2.158
                                  192.168.2.151
                                  192.168.2.152
                                  192.168.2.150
                                  192.168.2.155
                                  192.168.2.156
                                  192.168.2.153
                                  192.168.2.154
                                  192.168.2.126
                                  192.168.2.247
                                  192.168.2.127
                                  192.168.2.248
                                  192.168.2.124
                                  192.168.2.245
                                  192.168.2.125
                                  192.168.2.246
                                  192.168.2.128
                                  192.168.2.249
                                  192.168.2.129
                                  192.168.2.240
                                  192.168.2.122
                                  192.168.2.243
                                  192.168.2.123
                                  192.168.2.244
                                  192.168.2.120
                                  192.168.2.241
                                  192.168.2.121
                                  192.168.2.242
                                  192.168.2.97
                                  192.168.2.137
                                  192.168.2.96
                                  192.168.2.138
                                  192.168.2.99
                                  192.168.2.135
                                  192.168.2.98
                                  192.168.2.136
                                  192.168.2.139
                                  192.168.2.250
                                  192.168.2.130
                                  192.168.2.251
                                  192.168.2.91
                                  192.168.2.90
                                  192.168.2.93
                                  192.168.2.133
                                  192.168.2.254
                                  192.168.2.92
                                  192.168.2.134
                                  192.168.2.95
                                  192.168.2.131
                                  192.168.2.252
                                  192.168.2.94
                                  192.168.2.132
                                  192.168.2.253
                                  192.168.2.104
                                  192.168.2.225
                                  192.168.2.105
                                  192.168.2.226
                                  192.168.2.102
                                  192.168.2.223
                                  192.168.2.103
                                  192.168.2.224
                                  192.168.2.108
                                  192.168.2.229
                                  192.168.2.109
                                  192.168.2.106
                                  Joe Sandbox version:42.0.0 Malachite
                                  Analysis ID:1592050
                                  Start date and time:2025-01-15 17:46:07 +01:00
                                  Joe Sandbox product:CloudBasic
                                  Overall analysis duration:0h 5m 23s
                                  Hypervisor based Inspection enabled:false
                                  Report type:full
                                  Cookbook file name:default.jbs
                                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                  Number of analysed new started processes analysed:12
                                  Number of new started drivers analysed:0
                                  Number of existing processes analysed:0
                                  Number of existing drivers analysed:0
                                  Number of injected processes analysed:0
                                  Technologies:
                                  • HCA enabled
                                  • EGA enabled
                                  • AMSI enabled
                                  Analysis Mode:default
                                  Analysis stop reason:Timeout
                                  Sample name:hNgIvHRuTU.dll
                                  renamed because original name is a hash value
                                  Original Sample Name:8e6635b3dcb090c8478fc392ca94722e.dll
                                  Detection:MAL
                                  Classification:mal100.rans.expl.evad.winDLL@18/2@2/100
                                  EGA Information:
                                  • Successful, ratio: 100%
                                  HCA Information:Failed
                                  Cookbook Comments:
                                  • Found application associated with file extension: .dll
                                  • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
                                  • Excluded IPs from analysis (whitelisted): 40.126.31.67, 40.126.31.71, 20.190.159.64, 20.190.159.0, 20.190.159.68, 20.190.159.75, 20.190.159.4, 20.190.159.71, 2.23.77.188, 199.232.214.172, 184.30.131.245, 13.107.246.45, 20.12.23.50
                                  • Excluded domains from analysis (whitelisted): client.wns.windows.com, prdv4a.aadg.msidentity.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, www.tm.v4.a.prd.aadg.trafficmanager.net, ctldl.windowsupdate.com, login.msa.msidentity.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, login.live.com, wu-b-net.trafficmanager.net, www.tm.lg.prod.aadmsa.trafficmanager.net
                                  • Not all processes where analyzed, report is missing behavior information
                                  • Report size getting too big, too many NtQueryValueKey calls found.
                                  TimeTypeDescription
                                  11:47:10API Interceptor1x Sleep call for process: loaddll32.exe modified
                                  11:47:45API Interceptor112x Sleep call for process: mssecsvr.exe modified
                                  No context
                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                  77026.bodis.comq4e7rZQEkL.dllGet hashmaliciousWannacryBrowse
                                  • 199.59.243.228
                                  Gn8CvJE07O.dllGet hashmaliciousWannacryBrowse
                                  • 199.59.243.228
                                  zTrDsX9gXl.dllGet hashmaliciousWannacryBrowse
                                  • 199.59.243.228
                                  mLm1d1GV4R.dllGet hashmaliciousWannacryBrowse
                                  • 199.59.243.228
                                  V01vdyUACe.dllGet hashmaliciousWannacryBrowse
                                  • 199.59.243.228
                                  NLWfV87ouS.dllGet hashmaliciousWannacryBrowse
                                  • 199.59.243.228
                                  hVgcaX2SV8.dllGet hashmaliciousWannacryBrowse
                                  • 199.59.243.228
                                  GUtEaDsc9X.dllGet hashmaliciousWannacryBrowse
                                  • 199.59.243.228
                                  D3W41IdtQA.dllGet hashmaliciousWannacryBrowse
                                  • 199.59.243.228
                                  F1G5BkUV74.dllGet hashmaliciousWannacryBrowse
                                  • 199.59.243.228
                                  bg.microsoft.map.fastly.netACH REMITTANCE DOCUMENT 15.01.25.xlsbGet hashmaliciousUnknownBrowse
                                  • 199.232.214.172
                                  Personliche Nachricht fur e4060738.pdfGet hashmaliciousUnknownBrowse
                                  • 199.232.214.172
                                  https://drive.google.com/file/d/1dNrtjTqb59ZQTE3gUuVhSjEbFXuJRXW7/view?usp=sharing&ts=6786e61fGet hashmaliciousUnknownBrowse
                                  • 199.232.214.172
                                  Sample1.exeGet hashmaliciousUnknownBrowse
                                  • 199.232.214.172
                                  alN48K3xcD.dllGet hashmaliciousWannacryBrowse
                                  • 199.232.214.172
                                  RFQ # PC25-1301.xlsxGet hashmaliciousUnknownBrowse
                                  • 199.232.210.172
                                  21033090848109083.jsGet hashmaliciousStrela DownloaderBrowse
                                  • 199.232.210.172
                                  https://www.pdfforge.org/pdfcreator?srsltid=AfmBOoq1lpA5qNxfcLUyxjmEXAioeKYtqPTpBsIbZ5VOdq3uhOg1WclGGet hashmaliciousUnknownBrowse
                                  • 199.232.214.172
                                  0969686.vbeGet hashmaliciousAgentTeslaBrowse
                                  • 199.232.210.172
                                  00.ps1Get hashmaliciousPureCrypter, LummaC, LummaC StealerBrowse
                                  • 199.232.210.172
                                  www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comq4e7rZQEkL.dllGet hashmaliciousWannacryBrowse
                                  • 103.224.212.215
                                  Gn8CvJE07O.dllGet hashmaliciousWannacryBrowse
                                  • 103.224.212.215
                                  zTrDsX9gXl.dllGet hashmaliciousWannacryBrowse
                                  • 103.224.212.215
                                  mLm1d1GV4R.dllGet hashmaliciousWannacryBrowse
                                  • 103.224.212.215
                                  V01vdyUACe.dllGet hashmaliciousWannacryBrowse
                                  • 103.224.212.215
                                  NLWfV87ouS.dllGet hashmaliciousWannacryBrowse
                                  • 103.224.212.215
                                  hVgcaX2SV8.dllGet hashmaliciousWannacryBrowse
                                  • 103.224.212.215
                                  GUtEaDsc9X.dllGet hashmaliciousWannacryBrowse
                                  • 103.224.212.215
                                  D3W41IdtQA.dllGet hashmaliciousWannacryBrowse
                                  • 103.224.212.215
                                  F1G5BkUV74.dllGet hashmaliciousWannacryBrowse
                                  • 103.224.212.215
                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                  ERX-CERNET-BKBChinaEducationandResearchNetworkCenterbot.x86.elfGet hashmaliciousUnknownBrowse
                                  • 211.64.121.81
                                  bot.sh4.elfGet hashmaliciousUnknownBrowse
                                  • 49.52.78.27
                                  JRTn7b1kHg.dllGet hashmaliciousWannacryBrowse
                                  • 210.39.38.201
                                  arm5.elfGet hashmaliciousMiraiBrowse
                                  • 49.122.176.54
                                  i486.elfGet hashmaliciousMiraiBrowse
                                  • 219.245.251.243
                                  xd.arm.elfGet hashmaliciousMiraiBrowse
                                  • 218.193.82.69
                                  xd.sh4.elfGet hashmaliciousMiraiBrowse
                                  • 222.200.203.195
                                  sh4.elfGet hashmaliciousMiraiBrowse
                                  • 125.219.170.30
                                  arm4.elfGet hashmaliciousMiraiBrowse
                                  • 211.81.11.203
                                  x86_64.elfGet hashmaliciousMiraiBrowse
                                  • 202.202.204.242
                                  COOOLBOXBGres.x86.elfGet hashmaliciousUnknownBrowse
                                  • 78.130.235.19
                                  i686.elfGet hashmaliciousMiraiBrowse
                                  • 78.130.224.140
                                  jklspc.elfGet hashmaliciousUnknownBrowse
                                  • 89.25.106.40
                                  nklspc.elfGet hashmaliciousUnknownBrowse
                                  • 89.25.106.96
                                  nshkppc.elfGet hashmaliciousMiraiBrowse
                                  • 89.25.106.83
                                  powerpc.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                  • 89.25.110.124
                                  jew.arm.elfGet hashmaliciousUnknownBrowse
                                  • 87.118.186.92
                                  sora.mpsl.elfGet hashmaliciousMiraiBrowse
                                  • 78.130.211.86
                                  arm5.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                  • 78.130.235.71
                                  sh4.elfGet hashmaliciousUnknownBrowse
                                  • 94.155.240.169
                                  COOOLBOXBGres.x86.elfGet hashmaliciousUnknownBrowse
                                  • 78.130.235.19
                                  i686.elfGet hashmaliciousMiraiBrowse
                                  • 78.130.224.140
                                  jklspc.elfGet hashmaliciousUnknownBrowse
                                  • 89.25.106.40
                                  nklspc.elfGet hashmaliciousUnknownBrowse
                                  • 89.25.106.96
                                  nshkppc.elfGet hashmaliciousMiraiBrowse
                                  • 89.25.106.83
                                  powerpc.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                  • 89.25.110.124
                                  jew.arm.elfGet hashmaliciousUnknownBrowse
                                  • 87.118.186.92
                                  sora.mpsl.elfGet hashmaliciousMiraiBrowse
                                  • 78.130.211.86
                                  arm5.nn.elfGet hashmaliciousMirai, OkiruBrowse
                                  • 78.130.235.71
                                  sh4.elfGet hashmaliciousUnknownBrowse
                                  • 94.155.240.169
                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                  1138de370e523e824bbca92d049a37772lX8Z3eydC.dllGet hashmaliciousWannacryBrowse
                                  • 23.1.237.91
                                  ACH REMITTANCE DOCUMENT 15.01.25.xlsbGet hashmaliciousUnknownBrowse
                                  • 23.1.237.91
                                  Personliche Nachricht fur e4060738.pdfGet hashmaliciousUnknownBrowse
                                  • 23.1.237.91
                                  https://clickme.thryv.com/ls/click?upn=u001.5dsdCa4YiGVzoib36gWoSPT0wVekqsfeOZRSaz9d28itE0eTxOetbwlGaCx05rQJywXo_UNbDpVWBvKTmUslwem1E0EC2Cp68hMzvjQfllUT9E4DZqDf2uiRmAk3QSMceJiv-2FShXGXSXiT9Fl37dFQYscKLxEMcTJj4tm5gMav6Ov9aRXzCg4yzvno75Wb80hSd5kw8Ua5r4R2pwCFTS4zDFYiEkWB-2BYk1VUWtpkJwb9IQIMAq1SSLT005wiJ2XiGw1jPEr6v61MJQRnC7AeLVtxYgqGlydBoPFbs1IP04-2BxPajuRI3fTsnzWZ9ty3RasYpwuqdrF0E8VoyYkggeeLEm9ENK69uYTCVHWHpxCPkzirQSIkvpt5FNZojg491ibS35IgO0LPU5gnpEaeaUj4-2BZoFUHIAAzMMy-2BYqsZ9F9Ldu1c-3D#XGet hashmaliciousHTMLPhisherBrowse
                                  • 23.1.237.91
                                  NLWfV87ouS.dllGet hashmaliciousWannacryBrowse
                                  • 23.1.237.91
                                  330tqxXVzm.dllGet hashmaliciousWannacryBrowse
                                  • 23.1.237.91
                                  https://asalto-bart.eu/o/dcvGet hashmaliciousUnknownBrowse
                                  • 23.1.237.91
                                  https://teiegram-mg.org/Get hashmaliciousUnknownBrowse
                                  • 23.1.237.91
                                  https://sreamconmymnltty.com/scerty/bliun/bolopGet hashmaliciousUnknownBrowse
                                  • 23.1.237.91
                                  https://reviewpolicysocialreach.vercel.app/help&z/Get hashmaliciousHTMLPhisherBrowse
                                  • 23.1.237.91
                                  3b5074b1b5d032e5620f69f9f700ff0elummm_lzmb.exeGet hashmaliciousLummaCBrowse
                                  • 40.115.3.253
                                  2lX8Z3eydC.dllGet hashmaliciousWannacryBrowse
                                  • 40.115.3.253
                                  aASfOObWpW.exeGet hashmaliciousUnknownBrowse
                                  • 40.115.3.253
                                  aASfOObWpW.exeGet hashmaliciousUnknownBrowse
                                  • 40.115.3.253
                                  Updater.exeGet hashmaliciousUnknownBrowse
                                  • 40.115.3.253
                                  Updater.exeGet hashmaliciousUnknownBrowse
                                  • 40.115.3.253
                                  Personliche Nachricht fur e4060738.pdfGet hashmaliciousUnknownBrowse
                                  • 40.115.3.253
                                  https://pub-2d00d32ff6d84ef6999828eaf509b772.r2.dev/index.html#watson.becky@aidb.orgGet hashmaliciousHTMLPhisherBrowse
                                  • 40.115.3.253
                                  Invoice No 1122207 pdf.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                  • 40.115.3.253
                                  No context
                                  Process:C:\Windows\mssecsvr.exe
                                  File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                  Category:dropped
                                  Size (bytes):2061938
                                  Entropy (8bit):4.746672560135426
                                  Encrypted:false
                                  SSDEEP:12288:nti62ybaIMu7L5NVErCA4z2g6rTcbckPU82900Ve7zw+K+DHeQYSUjEXFGeXE3Ty:tihdmMSirYbcMNgef0QeQjG/D8kI
                                  MD5:52AA9FB068FDAC0FCA843445F6307EB1
                                  SHA1:FA23F0832161F16C71EDC22C29F3EF0778984C7D
                                  SHA-256:AF0F8D57126E3588D7C846CB326A71DF2CADD861A88FBFFDA0DBC992C509552C
                                  SHA-512:B512E0A21D222418E39DF683DBCB1D8E74E98F07991C87B4C520AEF2288DA33166A9018A33141350076311840B3573E633938E754CB8772DE4D6C185C01B6E6C
                                  Malicious:true
                                  Antivirus:
                                  • Antivirus: ReversingLabs, Detection: 86%
                                  Reputation:low
                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&K.WG%.WG%.WG%.^?..LG%.^?...G%.^?..BG%.WG$.G%.^?..0G%.^?..VG%.^?..VG%.^?..VG%.RichWG%.................PE..L......U..........................................@..........................`......................................p...3............ ..(9..............................................................@............................................text.............................. ..`.rdata...P.......R..................@..@.data...(...........................@....rsrc...(9... ...:..................@..@........................................................................................................................................................................................................................................................................................................................................................................
                                  Process:C:\Windows\mssecsvr.exe
                                  File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                  Category:dropped
                                  Size (bytes):2061938
                                  Entropy (8bit):4.746672560135426
                                  Encrypted:false
                                  SSDEEP:12288:nti62ybaIMu7L5NVErCA4z2g6rTcbckPU82900Ve7zw+K+DHeQYSUjEXFGeXE3Ty:tihdmMSirYbcMNgef0QeQjG/D8kI
                                  MD5:52AA9FB068FDAC0FCA843445F6307EB1
                                  SHA1:FA23F0832161F16C71EDC22C29F3EF0778984C7D
                                  SHA-256:AF0F8D57126E3588D7C846CB326A71DF2CADD861A88FBFFDA0DBC992C509552C
                                  SHA-512:B512E0A21D222418E39DF683DBCB1D8E74E98F07991C87B4C520AEF2288DA33166A9018A33141350076311840B3573E633938E754CB8772DE4D6C185C01B6E6C
                                  Malicious:true
                                  Yara Hits:
                                  • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: C:\Windows\tasksche.exe, Author: Joe Security
                                  • Rule: WannaCry_Ransomware, Description: Detects WannaCry Ransomware, Source: C:\Windows\tasksche.exe, Author: Florian Roth (with the help of binar.ly)
                                  • Rule: wanna_cry_ransomware_generic, Description: detects wannacry ransomware on disk and in virtual page, Source: C:\Windows\tasksche.exe, Author: us-cert code analysis team
                                  Antivirus:
                                  • Antivirus: Joe Sandbox ML, Detection: 100%
                                  • Antivirus: ReversingLabs, Detection: 86%
                                  Reputation:low
                                  Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&K.WG%.WG%.WG%.^?..LG%.^?...G%.^?..BG%.WG$.G%.^?..0G%.^?..VG%.^?..VG%.^?..VG%.RichWG%.................PE..L......U..........................................@..........................`......................................p...3............ ..(9..............................................................@............................................text.............................. ..`.rdata...P.......R..................@..@.data...(...........................@....rsrc...(9... ...:..................@..@........................................................................................................................................................................................................................................................................................................................................................................
                                  File type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                  Entropy (8bit):2.4405660616262628
                                  TrID:
                                  • Win32 Dynamic Link Library (generic) (1002004/3) 99.60%
                                  • Generic Win/DOS Executable (2004/3) 0.20%
                                  • DOS Executable Generic (2002/1) 0.20%
                                  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                  File name:hNgIvHRuTU.dll
                                  File size:5'267'459 bytes
                                  MD5:8e6635b3dcb090c8478fc392ca94722e
                                  SHA1:937ba8b6fa1778a3fcbb3731c114c9364f7170b8
                                  SHA256:1fc5e4c8809b39d79324848bceac749000ea572d050c81275ae3053a83ba7d12
                                  SHA512:ccb266c561bc4d39007625f942863516d57a6e2097105281d38ab1598b126b11f2b7213666a8e231719d6f2cb6a16cdc6cdd626d204c99319da4f27b43431d20
                                  SSDEEP:24576:RbLgurihdmMSirYbcMNgef0QeQjG/D8kI:RnnMSPbcBVQej/
                                  TLSH:BA36239A75AC51F8D21A3274A4774B26A1B73C6D31BD9B0F9B808A211C03B91FB54F63
                                  File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......}.r_9...9...9.......=...9...6.....A.:.......8.......8.......:...Rich9...........................PE..L...QW.Y...........!.......
                                  Icon Hash:7ae282899bbab082
                                  Entrypoint:0x100011e9
                                  Entrypoint Section:.text
                                  Digitally signed:false
                                  Imagebase:0x10000000
                                  Subsystem:windows gui
                                  Image File Characteristics:EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DLL
                                  DLL Characteristics:
                                  Time Stamp:0x59145751 [Thu May 11 12:21:37 2017 UTC]
                                  TLS Callbacks:
                                  CLR (.Net) Version:
                                  OS Version Major:4
                                  OS Version Minor:0
                                  File Version Major:4
                                  File Version Minor:0
                                  Subsystem Version Major:4
                                  Subsystem Version Minor:0
                                  Import Hash:2e5708ae5fed0403e8117c645fb23e5b
                                  Instruction
                                  push ebp
                                  mov ebp, esp
                                  push ebx
                                  mov ebx, dword ptr [ebp+08h]
                                  push esi
                                  mov esi, dword ptr [ebp+0Ch]
                                  push edi
                                  mov edi, dword ptr [ebp+10h]
                                  test esi, esi
                                  jne 00007F7AE48339EBh
                                  cmp dword ptr [10003140h], 00000000h
                                  jmp 00007F7AE4833A08h
                                  cmp esi, 01h
                                  je 00007F7AE48339E7h
                                  cmp esi, 02h
                                  jne 00007F7AE4833A04h
                                  mov eax, dword ptr [10003150h]
                                  test eax, eax
                                  je 00007F7AE48339EBh
                                  push edi
                                  push esi
                                  push ebx
                                  call eax
                                  test eax, eax
                                  je 00007F7AE48339EEh
                                  push edi
                                  push esi
                                  push ebx
                                  call 00007F7AE48338FAh
                                  test eax, eax
                                  jne 00007F7AE48339E6h
                                  xor eax, eax
                                  jmp 00007F7AE4833A30h
                                  push edi
                                  push esi
                                  push ebx
                                  call 00007F7AE48337ACh
                                  cmp esi, 01h
                                  mov dword ptr [ebp+0Ch], eax
                                  jne 00007F7AE48339EEh
                                  test eax, eax
                                  jne 00007F7AE4833A19h
                                  push edi
                                  push eax
                                  push ebx
                                  call 00007F7AE48338D6h
                                  test esi, esi
                                  je 00007F7AE48339E7h
                                  cmp esi, 03h
                                  jne 00007F7AE4833A08h
                                  push edi
                                  push esi
                                  push ebx
                                  call 00007F7AE48338C5h
                                  test eax, eax
                                  jne 00007F7AE48339E5h
                                  and dword ptr [ebp+0Ch], eax
                                  cmp dword ptr [ebp+0Ch], 00000000h
                                  je 00007F7AE48339F3h
                                  mov eax, dword ptr [10003150h]
                                  test eax, eax
                                  je 00007F7AE48339EAh
                                  push edi
                                  push esi
                                  push ebx
                                  call eax
                                  mov dword ptr [ebp+0Ch], eax
                                  mov eax, dword ptr [ebp+0Ch]
                                  pop edi
                                  pop esi
                                  pop ebx
                                  pop ebp
                                  retn 000Ch
                                  jmp dword ptr [10002028h]
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  add byte ptr [eax], al
                                  Programming Language:
                                  • [ C ] VS98 (6.0) build 8168
                                  • [C++] VS98 (6.0) build 8168
                                  • [RES] VS98 (6.0) cvtres build 1720
                                  • [LNK] VS98 (6.0) imp/exp build 8168
                                  NameVirtual AddressVirtual Size Is in Section
                                  IMAGE_DIRECTORY_ENTRY_EXPORT0x21900x48.rdata
                                  IMAGE_DIRECTORY_ENTRY_IMPORT0x203c0x3c.rdata
                                  IMAGE_DIRECTORY_ENTRY_RESOURCE0x40000x500060.rsrc
                                  IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                  IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                  IMAGE_DIRECTORY_ENTRY_BASERELOC0x5050000x5c.reloc
                                  IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                  IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                  IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                  IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                  IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_IAT0x20000x3c.rdata
                                  IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                  IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                  IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                  NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                  .text0x10000x28c0x10008de9a2cb31e4c74bd008b871d14bfafcFalse0.13037109375data1.4429971244731552IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                  .rdata0x20000x1d80x10003dd394f95ab218593f2bc8eb65184db4False0.072509765625data0.7346018133622799IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                  .data0x30000x1540x10009b27c3f254416f775f5a51102ef8fb84False0.016845703125Matlab v4 mat-file (little endian) C:\%s\%s, numeric, rows 0, columns 00.085726967663312IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                  .rsrc0x40000x5000600x5010006f52f32d0ed35f249bab626131943177unknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                  .reloc0x5050000x2ac0x1000620f0b67a91f7f74151bc5be745b7110False0.00634765625data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                  NameRVASizeTypeLanguageCountryZLIB Complexity
                                  W0x40600x500000dataEnglishUnited States0.8791799545288086
                                  DLLImport
                                  KERNEL32.dllCloseHandle, WriteFile, CreateFileA, SizeofResource, LockResource, LoadResource, FindResourceA, CreateProcessA
                                  MSVCRT.dllfree, _initterm, malloc, _adjust_fdiv, sprintf
                                  NameOrdinalAddress
                                  PlayGame10x10001114
                                  Language of compilation systemCountry where language is spokenMap
                                  EnglishUnited States
                                  TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                  2025-01-15T17:47:08.760608+01002830018ETPRO MALWARE Observed WannaCry Domain (iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff .com in DNS Lookup)1192.168.2.5654781.1.1.153UDP
                                  2025-01-15T17:47:09.680654+01002803304ETPRO MALWARE Common Downloader Header Pattern HCa3192.168.2.549717103.224.212.21580TCP
                                  2025-01-15T17:47:11.364702+01002803304ETPRO MALWARE Common Downloader Header Pattern HCa3192.168.2.549720103.224.212.21580TCP
                                  TimestampSource PortDest PortSource IPDest IP
                                  Jan 15, 2025 17:47:02.391900063 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:02.391930103 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:02.391938925 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:02.391946077 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:02.391954899 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:02.392117023 CET49710443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:02.392160892 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:02.392219067 CET49710443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:02.392236948 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:02.392249107 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:02.392261028 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:02.392297983 CET49710443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:02.392692089 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:02.392713070 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:02.392724037 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:02.392730951 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:02.392750978 CET49710443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:02.392777920 CET49710443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:02.393354893 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:02.393368006 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:02.393412113 CET49710443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:02.396961927 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:02.396984100 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:02.397012949 CET49710443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:02.452544928 CET49710443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:02.478621006 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:02.478637934 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:02.478841066 CET49710443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:02.527669907 CET49706443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:02.527709007 CET49706443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:02.532601118 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:02.532628059 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:02.532697916 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:02.532706976 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.171241045 CET49674443192.168.2.523.1.237.91
                                  Jan 15, 2025 17:47:03.171241045 CET49675443192.168.2.523.1.237.91
                                  Jan 15, 2025 17:47:03.177598000 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.177615881 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.177628040 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.177640915 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.177678108 CET49706443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:03.177711964 CET49706443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:03.177834034 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.177897930 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.177908897 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.177921057 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.177932024 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.177942991 CET49706443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:03.177968025 CET49706443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:03.178750038 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.178762913 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.178802013 CET49706443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:03.199673891 CET49710443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:03.199739933 CET49710443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:03.204545975 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.204560041 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.204672098 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.204680920 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.297979116 CET49673443192.168.2.523.1.237.91
                                  Jan 15, 2025 17:47:03.692935944 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.692965984 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.692976952 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.692986012 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.693000078 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.693010092 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.693018913 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.693030119 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.693037987 CET49710443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:03.693079948 CET49710443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:03.693598032 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.693608046 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.693617105 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.693624973 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.693651915 CET49710443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:03.693667889 CET49710443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:03.721461058 CET49706443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:03.721523046 CET49706443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:03.726366043 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.726377964 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.726428032 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.726438046 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:03.726558924 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:04.104610920 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:04.104645014 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:04.104655981 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:04.104729891 CET49706443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:04.104813099 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:04.104845047 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:04.104856968 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:04.104867935 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:04.104885101 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:04.104907036 CET49706443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:04.104933023 CET49706443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:04.104947090 CET49706443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:04.105679035 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:04.105727911 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:47:04.105772972 CET49706443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:47:04.413244009 CET49712443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:04.413301945 CET4434971240.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:04.413399935 CET49712443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:04.414098024 CET49712443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:04.414112091 CET4434971240.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:05.223386049 CET4434971240.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:05.223507881 CET49712443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:05.226553917 CET49712443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:05.226563931 CET4434971240.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:05.227498055 CET4434971240.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:05.228554964 CET49712443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:05.228609085 CET49712443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:05.228831053 CET49712443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:05.228832960 CET4434971240.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:05.275330067 CET4434971240.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:05.636130095 CET4434971240.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:05.636225939 CET4434971240.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:05.636389017 CET49712443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:05.636461973 CET49712443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:05.636482954 CET4434971240.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:09.077476025 CET4971780192.168.2.5103.224.212.215
                                  Jan 15, 2025 17:47:09.082539082 CET8049717103.224.212.215192.168.2.5
                                  Jan 15, 2025 17:47:09.082640886 CET4971780192.168.2.5103.224.212.215
                                  Jan 15, 2025 17:47:09.082789898 CET4971780192.168.2.5103.224.212.215
                                  Jan 15, 2025 17:47:09.087589025 CET8049717103.224.212.215192.168.2.5
                                  Jan 15, 2025 17:47:09.138021946 CET49718443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:09.138053894 CET4434971840.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:09.138142109 CET49718443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:09.138907909 CET49718443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:09.138925076 CET4434971840.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:09.680531025 CET8049717103.224.212.215192.168.2.5
                                  Jan 15, 2025 17:47:09.680553913 CET8049717103.224.212.215192.168.2.5
                                  Jan 15, 2025 17:47:09.680654049 CET4971780192.168.2.5103.224.212.215
                                  Jan 15, 2025 17:47:09.684052944 CET4971780192.168.2.5103.224.212.215
                                  Jan 15, 2025 17:47:09.688853979 CET8049717103.224.212.215192.168.2.5
                                  Jan 15, 2025 17:47:09.935138941 CET4434971840.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:09.935230017 CET49718443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:09.941282988 CET49718443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:09.941313028 CET4434971840.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:09.942051888 CET4434971840.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:09.943202972 CET49718443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:09.943387985 CET49718443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:09.943398952 CET4434971840.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:09.943491936 CET49718443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:09.987339020 CET4434971840.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:10.018801928 CET4971980192.168.2.5199.59.243.228
                                  Jan 15, 2025 17:47:10.023631096 CET8049719199.59.243.228192.168.2.5
                                  Jan 15, 2025 17:47:10.023731947 CET4971980192.168.2.5199.59.243.228
                                  Jan 15, 2025 17:47:10.023938894 CET4971980192.168.2.5199.59.243.228
                                  Jan 15, 2025 17:47:10.028892994 CET8049719199.59.243.228192.168.2.5
                                  Jan 15, 2025 17:47:10.113739014 CET4434971840.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:10.113961935 CET4434971840.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:10.114022970 CET49718443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:10.114120960 CET49718443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:10.114136934 CET4434971840.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:10.521435976 CET8049719199.59.243.228192.168.2.5
                                  Jan 15, 2025 17:47:10.521452904 CET8049719199.59.243.228192.168.2.5
                                  Jan 15, 2025 17:47:10.521622896 CET4971980192.168.2.5199.59.243.228
                                  Jan 15, 2025 17:47:10.530143023 CET4971980192.168.2.5199.59.243.228
                                  Jan 15, 2025 17:47:10.530167103 CET4971980192.168.2.5199.59.243.228
                                  Jan 15, 2025 17:47:10.765713930 CET4972080192.168.2.5103.224.212.215
                                  Jan 15, 2025 17:47:10.770613909 CET8049720103.224.212.215192.168.2.5
                                  Jan 15, 2025 17:47:10.770695925 CET4972080192.168.2.5103.224.212.215
                                  Jan 15, 2025 17:47:10.770787954 CET4972080192.168.2.5103.224.212.215
                                  Jan 15, 2025 17:47:10.776273012 CET8049720103.224.212.215192.168.2.5
                                  Jan 15, 2025 17:47:11.364633083 CET8049720103.224.212.215192.168.2.5
                                  Jan 15, 2025 17:47:11.364701986 CET4972080192.168.2.5103.224.212.215
                                  Jan 15, 2025 17:47:11.364732027 CET8049720103.224.212.215192.168.2.5
                                  Jan 15, 2025 17:47:11.364779949 CET4972080192.168.2.5103.224.212.215
                                  Jan 15, 2025 17:47:11.368694067 CET4972080192.168.2.5103.224.212.215
                                  Jan 15, 2025 17:47:11.370827913 CET4972180192.168.2.5199.59.243.228
                                  Jan 15, 2025 17:47:11.374773979 CET8049720103.224.212.215192.168.2.5
                                  Jan 15, 2025 17:47:11.376844883 CET8049721199.59.243.228192.168.2.5
                                  Jan 15, 2025 17:47:11.376930952 CET4972180192.168.2.5199.59.243.228
                                  Jan 15, 2025 17:47:11.377120018 CET4972180192.168.2.5199.59.243.228
                                  Jan 15, 2025 17:47:11.384500980 CET8049721199.59.243.228192.168.2.5
                                  Jan 15, 2025 17:47:11.610800982 CET4972280192.168.2.5103.224.212.215
                                  Jan 15, 2025 17:47:11.615633011 CET8049722103.224.212.215192.168.2.5
                                  Jan 15, 2025 17:47:11.615701914 CET4972280192.168.2.5103.224.212.215
                                  Jan 15, 2025 17:47:11.615814924 CET4972280192.168.2.5103.224.212.215
                                  Jan 15, 2025 17:47:11.620604038 CET8049722103.224.212.215192.168.2.5
                                  Jan 15, 2025 17:47:11.840775013 CET8049721199.59.243.228192.168.2.5
                                  Jan 15, 2025 17:47:11.840790987 CET8049721199.59.243.228192.168.2.5
                                  Jan 15, 2025 17:47:11.840856075 CET4972180192.168.2.5199.59.243.228
                                  Jan 15, 2025 17:47:11.847928047 CET4972180192.168.2.5199.59.243.228
                                  Jan 15, 2025 17:47:11.847966909 CET4972180192.168.2.5199.59.243.228
                                  Jan 15, 2025 17:47:11.885294914 CET49723445192.168.2.565.166.2.92
                                  Jan 15, 2025 17:47:11.890172005 CET4454972365.166.2.92192.168.2.5
                                  Jan 15, 2025 17:47:11.890275955 CET49723445192.168.2.565.166.2.92
                                  Jan 15, 2025 17:47:11.890973091 CET49723445192.168.2.565.166.2.92
                                  Jan 15, 2025 17:47:11.891165972 CET49724445192.168.2.565.166.2.1
                                  Jan 15, 2025 17:47:11.896019936 CET4454972465.166.2.1192.168.2.5
                                  Jan 15, 2025 17:47:11.896032095 CET4454972365.166.2.92192.168.2.5
                                  Jan 15, 2025 17:47:11.896101952 CET49723445192.168.2.565.166.2.92
                                  Jan 15, 2025 17:47:11.896114111 CET49724445192.168.2.565.166.2.1
                                  Jan 15, 2025 17:47:11.896189928 CET49724445192.168.2.565.166.2.1
                                  Jan 15, 2025 17:47:11.900865078 CET49726445192.168.2.565.166.2.1
                                  Jan 15, 2025 17:47:11.901304960 CET4454972465.166.2.1192.168.2.5
                                  Jan 15, 2025 17:47:11.901371002 CET49724445192.168.2.565.166.2.1
                                  Jan 15, 2025 17:47:11.905769110 CET4454972665.166.2.1192.168.2.5
                                  Jan 15, 2025 17:47:11.905873060 CET49726445192.168.2.565.166.2.1
                                  Jan 15, 2025 17:47:11.905956984 CET49726445192.168.2.565.166.2.1
                                  Jan 15, 2025 17:47:11.910712957 CET4454972665.166.2.1192.168.2.5
                                  Jan 15, 2025 17:47:12.209203959 CET8049722103.224.212.215192.168.2.5
                                  Jan 15, 2025 17:47:12.209218979 CET8049722103.224.212.215192.168.2.5
                                  Jan 15, 2025 17:47:12.209297895 CET4972280192.168.2.5103.224.212.215
                                  Jan 15, 2025 17:47:12.210681915 CET4972280192.168.2.5103.224.212.215
                                  Jan 15, 2025 17:47:12.211540937 CET4973480192.168.2.5199.59.243.228
                                  Jan 15, 2025 17:47:12.215526104 CET8049722103.224.212.215192.168.2.5
                                  Jan 15, 2025 17:47:12.216383934 CET8049734199.59.243.228192.168.2.5
                                  Jan 15, 2025 17:47:12.217777967 CET4973480192.168.2.5199.59.243.228
                                  Jan 15, 2025 17:47:12.217854023 CET4973480192.168.2.5199.59.243.228
                                  Jan 15, 2025 17:47:12.222631931 CET8049734199.59.243.228192.168.2.5
                                  Jan 15, 2025 17:47:12.369935989 CET49737443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:12.369970083 CET4434973740.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:12.370059967 CET49737443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:12.370498896 CET49737443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:12.370511055 CET4434973740.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:12.675833941 CET8049734199.59.243.228192.168.2.5
                                  Jan 15, 2025 17:47:12.675851107 CET8049734199.59.243.228192.168.2.5
                                  Jan 15, 2025 17:47:12.675928116 CET4973480192.168.2.5199.59.243.228
                                  Jan 15, 2025 17:47:12.679147005 CET4973480192.168.2.5199.59.243.228
                                  Jan 15, 2025 17:47:12.679172993 CET4973480192.168.2.5199.59.243.228
                                  Jan 15, 2025 17:47:12.780531883 CET49674443192.168.2.523.1.237.91
                                  Jan 15, 2025 17:47:12.780544996 CET49675443192.168.2.523.1.237.91
                                  Jan 15, 2025 17:47:12.905553102 CET49673443192.168.2.523.1.237.91
                                  Jan 15, 2025 17:47:13.181185961 CET4434973740.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:13.181272030 CET49737443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:13.201366901 CET49737443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:13.201385021 CET4434973740.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:13.201773882 CET4434973740.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:13.216327906 CET49737443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:13.226475000 CET49737443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:13.226483107 CET4434973740.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:13.229710102 CET49737443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:13.271341085 CET4434973740.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:13.422638893 CET4434973740.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:13.423782110 CET49737443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:13.423799992 CET4434973740.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:13.423829079 CET49737443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:13.423855066 CET49737443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:13.891406059 CET49750445192.168.2.5194.183.238.88
                                  Jan 15, 2025 17:47:13.896301031 CET44549750194.183.238.88192.168.2.5
                                  Jan 15, 2025 17:47:13.896373987 CET49750445192.168.2.5194.183.238.88
                                  Jan 15, 2025 17:47:13.896414042 CET49750445192.168.2.5194.183.238.88
                                  Jan 15, 2025 17:47:13.896749973 CET49751445192.168.2.5194.183.238.1
                                  Jan 15, 2025 17:47:13.901582956 CET44549751194.183.238.1192.168.2.5
                                  Jan 15, 2025 17:47:13.901637077 CET49751445192.168.2.5194.183.238.1
                                  Jan 15, 2025 17:47:13.901647091 CET44549750194.183.238.88192.168.2.5
                                  Jan 15, 2025 17:47:13.901710033 CET49750445192.168.2.5194.183.238.88
                                  Jan 15, 2025 17:47:13.901798964 CET49751445192.168.2.5194.183.238.1
                                  Jan 15, 2025 17:47:13.902903080 CET49752445192.168.2.5194.183.238.1
                                  Jan 15, 2025 17:47:13.906616926 CET44549751194.183.238.1192.168.2.5
                                  Jan 15, 2025 17:47:13.906663895 CET49751445192.168.2.5194.183.238.1
                                  Jan 15, 2025 17:47:13.907665968 CET44549752194.183.238.1192.168.2.5
                                  Jan 15, 2025 17:47:13.907962084 CET49752445192.168.2.5194.183.238.1
                                  Jan 15, 2025 17:47:13.907962084 CET49752445192.168.2.5194.183.238.1
                                  Jan 15, 2025 17:47:13.912722111 CET44549752194.183.238.1192.168.2.5
                                  Jan 15, 2025 17:47:14.571979046 CET4434970823.1.237.91192.168.2.5
                                  Jan 15, 2025 17:47:14.572113037 CET49708443192.168.2.523.1.237.91
                                  Jan 15, 2025 17:47:15.907305002 CET49775445192.168.2.525.38.30.167
                                  Jan 15, 2025 17:47:15.912158966 CET4454977525.38.30.167192.168.2.5
                                  Jan 15, 2025 17:47:15.912229061 CET49775445192.168.2.525.38.30.167
                                  Jan 15, 2025 17:47:15.912261009 CET49775445192.168.2.525.38.30.167
                                  Jan 15, 2025 17:47:15.912477016 CET49776445192.168.2.525.38.30.1
                                  Jan 15, 2025 17:47:15.917325974 CET4454977525.38.30.167192.168.2.5
                                  Jan 15, 2025 17:47:15.917340040 CET4454977625.38.30.1192.168.2.5
                                  Jan 15, 2025 17:47:15.917393923 CET49775445192.168.2.525.38.30.167
                                  Jan 15, 2025 17:47:15.917437077 CET49776445192.168.2.525.38.30.1
                                  Jan 15, 2025 17:47:15.917490005 CET49776445192.168.2.525.38.30.1
                                  Jan 15, 2025 17:47:15.918410063 CET49777445192.168.2.525.38.30.1
                                  Jan 15, 2025 17:47:15.922420979 CET4454977625.38.30.1192.168.2.5
                                  Jan 15, 2025 17:47:15.922470093 CET49776445192.168.2.525.38.30.1
                                  Jan 15, 2025 17:47:15.923202991 CET4454977725.38.30.1192.168.2.5
                                  Jan 15, 2025 17:47:15.923263073 CET49777445192.168.2.525.38.30.1
                                  Jan 15, 2025 17:47:15.923322916 CET49777445192.168.2.525.38.30.1
                                  Jan 15, 2025 17:47:15.928045034 CET4454977725.38.30.1192.168.2.5
                                  Jan 15, 2025 17:47:17.922538042 CET49801445192.168.2.5218.112.212.165
                                  Jan 15, 2025 17:47:17.927375078 CET44549801218.112.212.165192.168.2.5
                                  Jan 15, 2025 17:47:17.927453041 CET49801445192.168.2.5218.112.212.165
                                  Jan 15, 2025 17:47:17.927485943 CET49801445192.168.2.5218.112.212.165
                                  Jan 15, 2025 17:47:17.927628040 CET49802445192.168.2.5218.112.212.1
                                  Jan 15, 2025 17:47:17.932384968 CET44549801218.112.212.165192.168.2.5
                                  Jan 15, 2025 17:47:17.932445049 CET49801445192.168.2.5218.112.212.165
                                  Jan 15, 2025 17:47:17.932451010 CET44549802218.112.212.1192.168.2.5
                                  Jan 15, 2025 17:47:17.932514906 CET49802445192.168.2.5218.112.212.1
                                  Jan 15, 2025 17:47:17.932570934 CET49802445192.168.2.5218.112.212.1
                                  Jan 15, 2025 17:47:17.933593988 CET49803445192.168.2.5218.112.212.1
                                  Jan 15, 2025 17:47:17.937546015 CET44549802218.112.212.1192.168.2.5
                                  Jan 15, 2025 17:47:17.937616110 CET49802445192.168.2.5218.112.212.1
                                  Jan 15, 2025 17:47:17.938338995 CET44549803218.112.212.1192.168.2.5
                                  Jan 15, 2025 17:47:17.938396931 CET49803445192.168.2.5218.112.212.1
                                  Jan 15, 2025 17:47:17.938441992 CET49803445192.168.2.5218.112.212.1
                                  Jan 15, 2025 17:47:17.943192959 CET44549803218.112.212.1192.168.2.5
                                  Jan 15, 2025 17:47:18.471529961 CET49813443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:18.471595049 CET4434981340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:18.471677065 CET49813443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:18.472507954 CET49813443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:18.472532988 CET4434981340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:19.266696930 CET4434981340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:19.266803026 CET49813443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:19.274992943 CET49813443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:19.275017023 CET4434981340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:19.275218010 CET4434981340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:19.276196003 CET49813443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:19.276263952 CET49813443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:19.276271105 CET4434981340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:19.276345968 CET49813443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:19.319325924 CET4434981340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:19.456830978 CET4434981340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:19.456924915 CET4434981340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:19.457050085 CET49813443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:19.457298994 CET49813443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:19.457319975 CET4434981340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:19.938040972 CET49840445192.168.2.577.53.16.112
                                  Jan 15, 2025 17:47:19.942945957 CET4454984077.53.16.112192.168.2.5
                                  Jan 15, 2025 17:47:19.943026066 CET49840445192.168.2.577.53.16.112
                                  Jan 15, 2025 17:47:19.943069935 CET49840445192.168.2.577.53.16.112
                                  Jan 15, 2025 17:47:19.943253040 CET49841445192.168.2.577.53.16.1
                                  Jan 15, 2025 17:47:19.948043108 CET4454984177.53.16.1192.168.2.5
                                  Jan 15, 2025 17:47:19.948148012 CET49841445192.168.2.577.53.16.1
                                  Jan 15, 2025 17:47:19.948148012 CET49841445192.168.2.577.53.16.1
                                  Jan 15, 2025 17:47:19.948159933 CET4454984077.53.16.112192.168.2.5
                                  Jan 15, 2025 17:47:19.948220015 CET49840445192.168.2.577.53.16.112
                                  Jan 15, 2025 17:47:19.949018955 CET49842445192.168.2.577.53.16.1
                                  Jan 15, 2025 17:47:19.953816891 CET4454984277.53.16.1192.168.2.5
                                  Jan 15, 2025 17:47:19.953891993 CET49842445192.168.2.577.53.16.1
                                  Jan 15, 2025 17:47:19.953903913 CET4454984177.53.16.1192.168.2.5
                                  Jan 15, 2025 17:47:19.953965902 CET49841445192.168.2.577.53.16.1
                                  Jan 15, 2025 17:47:19.954051971 CET49842445192.168.2.577.53.16.1
                                  Jan 15, 2025 17:47:19.958806038 CET4454984277.53.16.1192.168.2.5
                                  Jan 15, 2025 17:47:21.957031012 CET49875445192.168.2.513.229.164.57
                                  Jan 15, 2025 17:47:21.961947918 CET4454987513.229.164.57192.168.2.5
                                  Jan 15, 2025 17:47:21.962064028 CET49875445192.168.2.513.229.164.57
                                  Jan 15, 2025 17:47:21.965611935 CET49875445192.168.2.513.229.164.57
                                  Jan 15, 2025 17:47:21.965755939 CET49876445192.168.2.513.229.164.1
                                  Jan 15, 2025 17:47:21.970515013 CET4454987513.229.164.57192.168.2.5
                                  Jan 15, 2025 17:47:21.970554113 CET4454987613.229.164.1192.168.2.5
                                  Jan 15, 2025 17:47:21.970591068 CET49875445192.168.2.513.229.164.57
                                  Jan 15, 2025 17:47:21.970640898 CET49876445192.168.2.513.229.164.1
                                  Jan 15, 2025 17:47:21.970685959 CET49876445192.168.2.513.229.164.1
                                  Jan 15, 2025 17:47:21.975403070 CET49877445192.168.2.513.229.164.1
                                  Jan 15, 2025 17:47:21.975538969 CET4454987613.229.164.1192.168.2.5
                                  Jan 15, 2025 17:47:21.975656033 CET4454987613.229.164.1192.168.2.5
                                  Jan 15, 2025 17:47:21.975717068 CET49876445192.168.2.513.229.164.1
                                  Jan 15, 2025 17:47:21.980293989 CET4454987713.229.164.1192.168.2.5
                                  Jan 15, 2025 17:47:21.980369091 CET49877445192.168.2.513.229.164.1
                                  Jan 15, 2025 17:47:21.980448961 CET49877445192.168.2.513.229.164.1
                                  Jan 15, 2025 17:47:21.985328913 CET4454987713.229.164.1192.168.2.5
                                  Jan 15, 2025 17:47:22.210112095 CET49885443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:22.210154057 CET4434988540.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:22.210231066 CET49885443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:22.211081982 CET49885443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:22.211098909 CET4434988540.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:23.045561075 CET4434988540.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:23.045659065 CET49885443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:23.047173023 CET49885443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:23.047183990 CET4434988540.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:23.047396898 CET4434988540.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:23.048934937 CET49885443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:23.048991919 CET49885443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:23.048998117 CET4434988540.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:23.049108028 CET49885443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:23.095338106 CET4434988540.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:23.223886013 CET4434988540.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:23.224031925 CET4434988540.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:23.224247932 CET49885443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:23.224524021 CET49885443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:23.224533081 CET4434988540.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:23.224550962 CET49885443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:23.968342066 CET49917445192.168.2.5101.5.197.177
                                  Jan 15, 2025 17:47:23.973191977 CET44549917101.5.197.177192.168.2.5
                                  Jan 15, 2025 17:47:23.973283052 CET49917445192.168.2.5101.5.197.177
                                  Jan 15, 2025 17:47:23.973335028 CET49917445192.168.2.5101.5.197.177
                                  Jan 15, 2025 17:47:23.973458052 CET49918445192.168.2.5101.5.197.1
                                  Jan 15, 2025 17:47:23.978246927 CET44549917101.5.197.177192.168.2.5
                                  Jan 15, 2025 17:47:23.978305101 CET49917445192.168.2.5101.5.197.177
                                  Jan 15, 2025 17:47:23.978382111 CET44549918101.5.197.1192.168.2.5
                                  Jan 15, 2025 17:47:23.979129076 CET49918445192.168.2.5101.5.197.1
                                  Jan 15, 2025 17:47:23.979190111 CET49918445192.168.2.5101.5.197.1
                                  Jan 15, 2025 17:47:23.979393005 CET49919445192.168.2.5101.5.197.1
                                  Jan 15, 2025 17:47:23.984117031 CET44549918101.5.197.1192.168.2.5
                                  Jan 15, 2025 17:47:23.984220028 CET49918445192.168.2.5101.5.197.1
                                  Jan 15, 2025 17:47:23.984289885 CET44549919101.5.197.1192.168.2.5
                                  Jan 15, 2025 17:47:23.984529972 CET49919445192.168.2.5101.5.197.1
                                  Jan 15, 2025 17:47:23.984568119 CET49919445192.168.2.5101.5.197.1
                                  Jan 15, 2025 17:47:23.989379883 CET44549919101.5.197.1192.168.2.5
                                  Jan 15, 2025 17:47:24.782385111 CET49708443192.168.2.523.1.237.91
                                  Jan 15, 2025 17:47:24.782460928 CET49708443192.168.2.523.1.237.91
                                  Jan 15, 2025 17:47:24.782934904 CET49931443192.168.2.523.1.237.91
                                  Jan 15, 2025 17:47:24.782953978 CET4434993123.1.237.91192.168.2.5
                                  Jan 15, 2025 17:47:24.783052921 CET49931443192.168.2.523.1.237.91
                                  Jan 15, 2025 17:47:24.783298016 CET49931443192.168.2.523.1.237.91
                                  Jan 15, 2025 17:47:24.783310890 CET4434993123.1.237.91192.168.2.5
                                  Jan 15, 2025 17:47:24.787138939 CET4434970823.1.237.91192.168.2.5
                                  Jan 15, 2025 17:47:24.787167072 CET4434970823.1.237.91192.168.2.5
                                  Jan 15, 2025 17:47:25.361450911 CET4434993123.1.237.91192.168.2.5
                                  Jan 15, 2025 17:47:25.361556053 CET49931443192.168.2.523.1.237.91
                                  Jan 15, 2025 17:47:25.984050989 CET49950445192.168.2.541.240.115.69
                                  Jan 15, 2025 17:47:25.989061117 CET4454995041.240.115.69192.168.2.5
                                  Jan 15, 2025 17:47:25.989154100 CET49950445192.168.2.541.240.115.69
                                  Jan 15, 2025 17:47:25.989154100 CET49950445192.168.2.541.240.115.69
                                  Jan 15, 2025 17:47:25.989279985 CET49951445192.168.2.541.240.115.1
                                  Jan 15, 2025 17:47:25.994110107 CET4454995141.240.115.1192.168.2.5
                                  Jan 15, 2025 17:47:25.994180918 CET49951445192.168.2.541.240.115.1
                                  Jan 15, 2025 17:47:25.994216919 CET49951445192.168.2.541.240.115.1
                                  Jan 15, 2025 17:47:25.994234085 CET4454995041.240.115.69192.168.2.5
                                  Jan 15, 2025 17:47:25.994324923 CET49950445192.168.2.541.240.115.69
                                  Jan 15, 2025 17:47:25.994515896 CET49952445192.168.2.541.240.115.1
                                  Jan 15, 2025 17:47:25.999169111 CET4454995141.240.115.1192.168.2.5
                                  Jan 15, 2025 17:47:25.999228001 CET49951445192.168.2.541.240.115.1
                                  Jan 15, 2025 17:47:25.999387980 CET4454995241.240.115.1192.168.2.5
                                  Jan 15, 2025 17:47:25.999465942 CET49952445192.168.2.541.240.115.1
                                  Jan 15, 2025 17:47:25.999536991 CET49952445192.168.2.541.240.115.1
                                  Jan 15, 2025 17:47:26.004461050 CET4454995241.240.115.1192.168.2.5
                                  Jan 15, 2025 17:47:27.999962091 CET49988445192.168.2.5208.140.179.55
                                  Jan 15, 2025 17:47:28.004776001 CET44549988208.140.179.55192.168.2.5
                                  Jan 15, 2025 17:47:28.004869938 CET49988445192.168.2.5208.140.179.55
                                  Jan 15, 2025 17:47:28.004971027 CET49988445192.168.2.5208.140.179.55
                                  Jan 15, 2025 17:47:28.005160093 CET49989445192.168.2.5208.140.179.1
                                  Jan 15, 2025 17:47:28.009922028 CET44549989208.140.179.1192.168.2.5
                                  Jan 15, 2025 17:47:28.010005951 CET49989445192.168.2.5208.140.179.1
                                  Jan 15, 2025 17:47:28.010313034 CET49989445192.168.2.5208.140.179.1
                                  Jan 15, 2025 17:47:28.010437012 CET44549988208.140.179.55192.168.2.5
                                  Jan 15, 2025 17:47:28.010492086 CET49988445192.168.2.5208.140.179.55
                                  Jan 15, 2025 17:47:28.010807037 CET49990445192.168.2.5208.140.179.1
                                  Jan 15, 2025 17:47:28.015084028 CET44549989208.140.179.1192.168.2.5
                                  Jan 15, 2025 17:47:28.015158892 CET49989445192.168.2.5208.140.179.1
                                  Jan 15, 2025 17:47:28.015605927 CET44549990208.140.179.1192.168.2.5
                                  Jan 15, 2025 17:47:28.015688896 CET49990445192.168.2.5208.140.179.1
                                  Jan 15, 2025 17:47:28.015759945 CET49990445192.168.2.5208.140.179.1
                                  Jan 15, 2025 17:47:28.020524025 CET44549990208.140.179.1192.168.2.5
                                  Jan 15, 2025 17:47:30.016364098 CET50028445192.168.2.5154.83.26.1
                                  Jan 15, 2025 17:47:30.021465063 CET44550028154.83.26.1192.168.2.5
                                  Jan 15, 2025 17:47:30.024796963 CET50028445192.168.2.5154.83.26.1
                                  Jan 15, 2025 17:47:30.025895119 CET50028445192.168.2.5154.83.26.1
                                  Jan 15, 2025 17:47:30.026086092 CET50029445192.168.2.5154.83.26.1
                                  Jan 15, 2025 17:47:30.030908108 CET44550028154.83.26.1192.168.2.5
                                  Jan 15, 2025 17:47:30.031037092 CET44550029154.83.26.1192.168.2.5
                                  Jan 15, 2025 17:47:30.031131029 CET50029445192.168.2.5154.83.26.1
                                  Jan 15, 2025 17:47:30.031155109 CET50028445192.168.2.5154.83.26.1
                                  Jan 15, 2025 17:47:30.031217098 CET50029445192.168.2.5154.83.26.1
                                  Jan 15, 2025 17:47:30.031588078 CET50030445192.168.2.5154.83.26.1
                                  Jan 15, 2025 17:47:30.036286116 CET44550029154.83.26.1192.168.2.5
                                  Jan 15, 2025 17:47:30.036426067 CET44550030154.83.26.1192.168.2.5
                                  Jan 15, 2025 17:47:30.036508083 CET50029445192.168.2.5154.83.26.1
                                  Jan 15, 2025 17:47:30.036533117 CET50030445192.168.2.5154.83.26.1
                                  Jan 15, 2025 17:47:30.036597967 CET50030445192.168.2.5154.83.26.1
                                  Jan 15, 2025 17:47:30.041338921 CET44550030154.83.26.1192.168.2.5
                                  Jan 15, 2025 17:47:32.019128084 CET50063443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:32.019164085 CET4435006340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:32.019256115 CET50063443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:32.020013094 CET50063443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:32.020025015 CET4435006340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:32.034245014 CET50064445192.168.2.52.6.237.39
                                  Jan 15, 2025 17:47:32.038975954 CET445500642.6.237.39192.168.2.5
                                  Jan 15, 2025 17:47:32.039071083 CET50064445192.168.2.52.6.237.39
                                  Jan 15, 2025 17:47:32.039088964 CET50064445192.168.2.52.6.237.39
                                  Jan 15, 2025 17:47:32.039333105 CET50065445192.168.2.52.6.237.1
                                  Jan 15, 2025 17:47:32.044126987 CET445500642.6.237.39192.168.2.5
                                  Jan 15, 2025 17:47:32.044137955 CET445500652.6.237.1192.168.2.5
                                  Jan 15, 2025 17:47:32.044310093 CET50064445192.168.2.52.6.237.39
                                  Jan 15, 2025 17:47:32.044451952 CET50065445192.168.2.52.6.237.1
                                  Jan 15, 2025 17:47:32.044451952 CET50065445192.168.2.52.6.237.1
                                  Jan 15, 2025 17:47:32.044738054 CET50066445192.168.2.52.6.237.1
                                  Jan 15, 2025 17:47:32.049371004 CET445500652.6.237.1192.168.2.5
                                  Jan 15, 2025 17:47:32.049504995 CET445500662.6.237.1192.168.2.5
                                  Jan 15, 2025 17:47:32.049524069 CET50065445192.168.2.52.6.237.1
                                  Jan 15, 2025 17:47:32.049575090 CET50066445192.168.2.52.6.237.1
                                  Jan 15, 2025 17:47:32.049602985 CET50066445192.168.2.52.6.237.1
                                  Jan 15, 2025 17:47:32.054344893 CET445500662.6.237.1192.168.2.5
                                  Jan 15, 2025 17:47:32.821424961 CET4435006340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:32.821547985 CET50063443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:32.824069023 CET50063443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:32.824080944 CET4435006340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:32.824281931 CET4435006340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:32.825752974 CET50063443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:32.825834036 CET50063443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:32.825839996 CET4435006340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:32.825969934 CET50063443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:32.871330023 CET4435006340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:32.999627113 CET4435006340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:32.999782085 CET4435006340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:32.999866962 CET50063443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:33.000775099 CET50063443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:33.000785112 CET4435006340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:33.267127991 CET4454972665.166.2.1192.168.2.5
                                  Jan 15, 2025 17:47:33.267201900 CET49726445192.168.2.565.166.2.1
                                  Jan 15, 2025 17:47:33.267244101 CET49726445192.168.2.565.166.2.1
                                  Jan 15, 2025 17:47:33.267374039 CET49726445192.168.2.565.166.2.1
                                  Jan 15, 2025 17:47:33.272080898 CET4454972665.166.2.1192.168.2.5
                                  Jan 15, 2025 17:47:33.272150040 CET4454972665.166.2.1192.168.2.5
                                  Jan 15, 2025 17:47:34.047164917 CET50099445192.168.2.5126.122.68.113
                                  Jan 15, 2025 17:47:34.051969051 CET44550099126.122.68.113192.168.2.5
                                  Jan 15, 2025 17:47:34.052050114 CET50099445192.168.2.5126.122.68.113
                                  Jan 15, 2025 17:47:34.052120924 CET50099445192.168.2.5126.122.68.113
                                  Jan 15, 2025 17:47:34.052294970 CET50101445192.168.2.5126.122.68.1
                                  Jan 15, 2025 17:47:34.057117939 CET44550099126.122.68.113192.168.2.5
                                  Jan 15, 2025 17:47:34.057127953 CET44550101126.122.68.1192.168.2.5
                                  Jan 15, 2025 17:47:34.057179928 CET50099445192.168.2.5126.122.68.113
                                  Jan 15, 2025 17:47:34.057216883 CET50101445192.168.2.5126.122.68.1
                                  Jan 15, 2025 17:47:34.057302952 CET50101445192.168.2.5126.122.68.1
                                  Jan 15, 2025 17:47:34.057657003 CET50102445192.168.2.5126.122.68.1
                                  Jan 15, 2025 17:47:34.062216997 CET44550101126.122.68.1192.168.2.5
                                  Jan 15, 2025 17:47:34.062273026 CET50101445192.168.2.5126.122.68.1
                                  Jan 15, 2025 17:47:34.062684059 CET44550102126.122.68.1192.168.2.5
                                  Jan 15, 2025 17:47:34.062764883 CET50102445192.168.2.5126.122.68.1
                                  Jan 15, 2025 17:47:34.062818050 CET50102445192.168.2.5126.122.68.1
                                  Jan 15, 2025 17:47:34.067754030 CET44550102126.122.68.1192.168.2.5
                                  Jan 15, 2025 17:47:35.316050053 CET44549752194.183.238.1192.168.2.5
                                  Jan 15, 2025 17:47:35.316148996 CET49752445192.168.2.5194.183.238.1
                                  Jan 15, 2025 17:47:35.316215038 CET49752445192.168.2.5194.183.238.1
                                  Jan 15, 2025 17:47:35.316299915 CET49752445192.168.2.5194.183.238.1
                                  Jan 15, 2025 17:47:35.320919037 CET44549752194.183.238.1192.168.2.5
                                  Jan 15, 2025 17:47:35.321049929 CET44549752194.183.238.1192.168.2.5
                                  Jan 15, 2025 17:47:36.062295914 CET50136445192.168.2.540.64.79.69
                                  Jan 15, 2025 17:47:36.067137003 CET4455013640.64.79.69192.168.2.5
                                  Jan 15, 2025 17:47:36.067203999 CET50136445192.168.2.540.64.79.69
                                  Jan 15, 2025 17:47:36.067272902 CET50136445192.168.2.540.64.79.69
                                  Jan 15, 2025 17:47:36.067361116 CET50137445192.168.2.540.64.79.1
                                  Jan 15, 2025 17:47:36.072103977 CET4455013740.64.79.1192.168.2.5
                                  Jan 15, 2025 17:47:36.072163105 CET50137445192.168.2.540.64.79.1
                                  Jan 15, 2025 17:47:36.072200060 CET50137445192.168.2.540.64.79.1
                                  Jan 15, 2025 17:47:36.072412968 CET50138445192.168.2.540.64.79.1
                                  Jan 15, 2025 17:47:36.072597027 CET4455013640.64.79.69192.168.2.5
                                  Jan 15, 2025 17:47:36.072652102 CET50136445192.168.2.540.64.79.69
                                  Jan 15, 2025 17:47:36.077061892 CET4455013740.64.79.1192.168.2.5
                                  Jan 15, 2025 17:47:36.077116013 CET50137445192.168.2.540.64.79.1
                                  Jan 15, 2025 17:47:36.077156067 CET4455013840.64.79.1192.168.2.5
                                  Jan 15, 2025 17:47:36.077217102 CET50138445192.168.2.540.64.79.1
                                  Jan 15, 2025 17:47:36.077251911 CET50138445192.168.2.540.64.79.1
                                  Jan 15, 2025 17:47:36.082057953 CET4455013840.64.79.1192.168.2.5
                                  Jan 15, 2025 17:47:36.296832085 CET50141445192.168.2.565.166.2.1
                                  Jan 15, 2025 17:47:36.301667929 CET4455014165.166.2.1192.168.2.5
                                  Jan 15, 2025 17:47:36.301753044 CET50141445192.168.2.565.166.2.1
                                  Jan 15, 2025 17:47:36.302697897 CET50141445192.168.2.565.166.2.1
                                  Jan 15, 2025 17:47:36.307446957 CET4455014165.166.2.1192.168.2.5
                                  Jan 15, 2025 17:47:37.300534010 CET4454977725.38.30.1192.168.2.5
                                  Jan 15, 2025 17:47:37.300597906 CET49777445192.168.2.525.38.30.1
                                  Jan 15, 2025 17:47:37.300698996 CET49777445192.168.2.525.38.30.1
                                  Jan 15, 2025 17:47:37.300803900 CET49777445192.168.2.525.38.30.1
                                  Jan 15, 2025 17:47:37.305434942 CET4454977725.38.30.1192.168.2.5
                                  Jan 15, 2025 17:47:37.305495977 CET4454977725.38.30.1192.168.2.5
                                  Jan 15, 2025 17:47:38.078346968 CET50159445192.168.2.555.191.105.244
                                  Jan 15, 2025 17:47:38.083338022 CET4455015955.191.105.244192.168.2.5
                                  Jan 15, 2025 17:47:38.083482981 CET50159445192.168.2.555.191.105.244
                                  Jan 15, 2025 17:47:38.083594084 CET50159445192.168.2.555.191.105.244
                                  Jan 15, 2025 17:47:38.083873034 CET50160445192.168.2.555.191.105.1
                                  Jan 15, 2025 17:47:38.088735104 CET4455016055.191.105.1192.168.2.5
                                  Jan 15, 2025 17:47:38.088783979 CET4455015955.191.105.244192.168.2.5
                                  Jan 15, 2025 17:47:38.088879108 CET50159445192.168.2.555.191.105.244
                                  Jan 15, 2025 17:47:38.088924885 CET50160445192.168.2.555.191.105.1
                                  Jan 15, 2025 17:47:38.088924885 CET50160445192.168.2.555.191.105.1
                                  Jan 15, 2025 17:47:38.089359999 CET50161445192.168.2.555.191.105.1
                                  Jan 15, 2025 17:47:38.093836069 CET4455016055.191.105.1192.168.2.5
                                  Jan 15, 2025 17:47:38.093894958 CET50160445192.168.2.555.191.105.1
                                  Jan 15, 2025 17:47:38.094168901 CET4455016155.191.105.1192.168.2.5
                                  Jan 15, 2025 17:47:38.094233036 CET50161445192.168.2.555.191.105.1
                                  Jan 15, 2025 17:47:38.094257116 CET50161445192.168.2.555.191.105.1
                                  Jan 15, 2025 17:47:38.099046946 CET4455016155.191.105.1192.168.2.5
                                  Jan 15, 2025 17:47:38.327780962 CET50163445192.168.2.5194.183.238.1
                                  Jan 15, 2025 17:47:38.332612038 CET44550163194.183.238.1192.168.2.5
                                  Jan 15, 2025 17:47:38.332724094 CET50163445192.168.2.5194.183.238.1
                                  Jan 15, 2025 17:47:38.332762957 CET50163445192.168.2.5194.183.238.1
                                  Jan 15, 2025 17:47:38.337610006 CET44550163194.183.238.1192.168.2.5
                                  Jan 15, 2025 17:47:39.345009089 CET44549803218.112.212.1192.168.2.5
                                  Jan 15, 2025 17:47:39.345078945 CET49803445192.168.2.5218.112.212.1
                                  Jan 15, 2025 17:47:39.345139980 CET49803445192.168.2.5218.112.212.1
                                  Jan 15, 2025 17:47:39.345196009 CET49803445192.168.2.5218.112.212.1
                                  Jan 15, 2025 17:47:39.349994898 CET44549803218.112.212.1192.168.2.5
                                  Jan 15, 2025 17:47:39.350008965 CET44549803218.112.212.1192.168.2.5
                                  Jan 15, 2025 17:47:39.865155935 CET50174443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:39.865185022 CET4435017440.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:39.865263939 CET50174443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:39.865705967 CET50174443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:39.865730047 CET4435017440.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:40.093592882 CET50175445192.168.2.533.180.119.81
                                  Jan 15, 2025 17:47:40.099066019 CET4455017533.180.119.81192.168.2.5
                                  Jan 15, 2025 17:47:40.099144936 CET50175445192.168.2.533.180.119.81
                                  Jan 15, 2025 17:47:40.099219084 CET50175445192.168.2.533.180.119.81
                                  Jan 15, 2025 17:47:40.099428892 CET50176445192.168.2.533.180.119.1
                                  Jan 15, 2025 17:47:40.104068995 CET4455017533.180.119.81192.168.2.5
                                  Jan 15, 2025 17:47:40.104125977 CET50175445192.168.2.533.180.119.81
                                  Jan 15, 2025 17:47:40.104197979 CET4455017633.180.119.1192.168.2.5
                                  Jan 15, 2025 17:47:40.104260921 CET50176445192.168.2.533.180.119.1
                                  Jan 15, 2025 17:47:40.104275942 CET50176445192.168.2.533.180.119.1
                                  Jan 15, 2025 17:47:40.104466915 CET50177445192.168.2.533.180.119.1
                                  Jan 15, 2025 17:47:40.109318972 CET4455017633.180.119.1192.168.2.5
                                  Jan 15, 2025 17:47:40.109329939 CET4455017733.180.119.1192.168.2.5
                                  Jan 15, 2025 17:47:40.109379053 CET50176445192.168.2.533.180.119.1
                                  Jan 15, 2025 17:47:40.109395027 CET50177445192.168.2.533.180.119.1
                                  Jan 15, 2025 17:47:40.109435081 CET50177445192.168.2.533.180.119.1
                                  Jan 15, 2025 17:47:40.114193916 CET4455017733.180.119.1192.168.2.5
                                  Jan 15, 2025 17:47:40.312028885 CET50182445192.168.2.525.38.30.1
                                  Jan 15, 2025 17:47:40.316802025 CET4455018225.38.30.1192.168.2.5
                                  Jan 15, 2025 17:47:40.316857100 CET50182445192.168.2.525.38.30.1
                                  Jan 15, 2025 17:47:40.316948891 CET50182445192.168.2.525.38.30.1
                                  Jan 15, 2025 17:47:40.321715117 CET4455018225.38.30.1192.168.2.5
                                  Jan 15, 2025 17:47:40.645669937 CET4435017440.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:40.645772934 CET50174443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:40.647269964 CET50174443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:40.647279024 CET4435017440.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:40.647515059 CET4435017440.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:40.649009943 CET50174443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:40.649056911 CET50174443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:40.649065018 CET4435017440.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:40.649154902 CET50174443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:40.691332102 CET4435017440.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:40.819219112 CET4435017440.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:40.819437027 CET4435017440.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:40.819499016 CET50174443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:40.819641113 CET50174443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:40.819660902 CET4435017440.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:41.343045950 CET4454984277.53.16.1192.168.2.5
                                  Jan 15, 2025 17:47:41.343126059 CET49842445192.168.2.577.53.16.1
                                  Jan 15, 2025 17:47:41.343223095 CET49842445192.168.2.577.53.16.1
                                  Jan 15, 2025 17:47:41.343290091 CET49842445192.168.2.577.53.16.1
                                  Jan 15, 2025 17:47:41.348016977 CET4454984277.53.16.1192.168.2.5
                                  Jan 15, 2025 17:47:41.348026991 CET4454984277.53.16.1192.168.2.5
                                  Jan 15, 2025 17:47:42.109198093 CET50192445192.168.2.578.130.181.101
                                  Jan 15, 2025 17:47:42.114016056 CET4455019278.130.181.101192.168.2.5
                                  Jan 15, 2025 17:47:42.114106894 CET50192445192.168.2.578.130.181.101
                                  Jan 15, 2025 17:47:42.114141941 CET50192445192.168.2.578.130.181.101
                                  Jan 15, 2025 17:47:42.114419937 CET50193445192.168.2.578.130.181.1
                                  Jan 15, 2025 17:47:42.119052887 CET4455019278.130.181.101192.168.2.5
                                  Jan 15, 2025 17:47:42.119112015 CET50192445192.168.2.578.130.181.101
                                  Jan 15, 2025 17:47:42.119194031 CET4455019378.130.181.1192.168.2.5
                                  Jan 15, 2025 17:47:42.119267941 CET50193445192.168.2.578.130.181.1
                                  Jan 15, 2025 17:47:42.119267941 CET50193445192.168.2.578.130.181.1
                                  Jan 15, 2025 17:47:42.119448900 CET50194445192.168.2.578.130.181.1
                                  Jan 15, 2025 17:47:42.124299049 CET4455019378.130.181.1192.168.2.5
                                  Jan 15, 2025 17:47:42.124313116 CET4455019478.130.181.1192.168.2.5
                                  Jan 15, 2025 17:47:42.124380112 CET50194445192.168.2.578.130.181.1
                                  Jan 15, 2025 17:47:42.124416113 CET50194445192.168.2.578.130.181.1
                                  Jan 15, 2025 17:47:42.124449968 CET50193445192.168.2.578.130.181.1
                                  Jan 15, 2025 17:47:42.129198074 CET4455019478.130.181.1192.168.2.5
                                  Jan 15, 2025 17:47:42.358920097 CET50195445192.168.2.5218.112.212.1
                                  Jan 15, 2025 17:47:42.363759995 CET44550195218.112.212.1192.168.2.5
                                  Jan 15, 2025 17:47:42.363848925 CET50195445192.168.2.5218.112.212.1
                                  Jan 15, 2025 17:47:42.363879919 CET50195445192.168.2.5218.112.212.1
                                  Jan 15, 2025 17:47:42.368659019 CET44550195218.112.212.1192.168.2.5
                                  Jan 15, 2025 17:47:43.365151882 CET4454987713.229.164.1192.168.2.5
                                  Jan 15, 2025 17:47:43.365222931 CET49877445192.168.2.513.229.164.1
                                  Jan 15, 2025 17:47:43.365313053 CET49877445192.168.2.513.229.164.1
                                  Jan 15, 2025 17:47:43.365390062 CET49877445192.168.2.513.229.164.1
                                  Jan 15, 2025 17:47:43.370022058 CET4454987713.229.164.1192.168.2.5
                                  Jan 15, 2025 17:47:43.370125055 CET4454987713.229.164.1192.168.2.5
                                  Jan 15, 2025 17:47:43.836009026 CET4455019478.130.181.1192.168.2.5
                                  Jan 15, 2025 17:47:43.836075068 CET50194445192.168.2.578.130.181.1
                                  Jan 15, 2025 17:47:43.836119890 CET50194445192.168.2.578.130.181.1
                                  Jan 15, 2025 17:47:43.836180925 CET50194445192.168.2.578.130.181.1
                                  Jan 15, 2025 17:47:43.840925932 CET4455019478.130.181.1192.168.2.5
                                  Jan 15, 2025 17:47:43.840949059 CET4455019478.130.181.1192.168.2.5
                                  Jan 15, 2025 17:47:44.125106096 CET50210445192.168.2.563.217.137.251
                                  Jan 15, 2025 17:47:44.130004883 CET4455021063.217.137.251192.168.2.5
                                  Jan 15, 2025 17:47:44.134160042 CET50210445192.168.2.563.217.137.251
                                  Jan 15, 2025 17:47:44.134320974 CET50210445192.168.2.563.217.137.251
                                  Jan 15, 2025 17:47:44.134571075 CET50211445192.168.2.563.217.137.1
                                  Jan 15, 2025 17:47:44.139328957 CET4455021163.217.137.1192.168.2.5
                                  Jan 15, 2025 17:47:44.139439106 CET4455021063.217.137.251192.168.2.5
                                  Jan 15, 2025 17:47:44.139529943 CET50210445192.168.2.563.217.137.251
                                  Jan 15, 2025 17:47:44.139552116 CET50211445192.168.2.563.217.137.1
                                  Jan 15, 2025 17:47:44.139637947 CET50211445192.168.2.563.217.137.1
                                  Jan 15, 2025 17:47:44.140193939 CET50212445192.168.2.563.217.137.1
                                  Jan 15, 2025 17:47:44.144491911 CET4455021163.217.137.1192.168.2.5
                                  Jan 15, 2025 17:47:44.144998074 CET4455021263.217.137.1192.168.2.5
                                  Jan 15, 2025 17:47:44.145080090 CET50211445192.168.2.563.217.137.1
                                  Jan 15, 2025 17:47:44.145101070 CET50212445192.168.2.563.217.137.1
                                  Jan 15, 2025 17:47:44.145148993 CET50212445192.168.2.563.217.137.1
                                  Jan 15, 2025 17:47:44.149874926 CET4455021263.217.137.1192.168.2.5
                                  Jan 15, 2025 17:47:44.358988047 CET50214445192.168.2.577.53.16.1
                                  Jan 15, 2025 17:47:44.363780022 CET4455021477.53.16.1192.168.2.5
                                  Jan 15, 2025 17:47:44.363888025 CET50214445192.168.2.577.53.16.1
                                  Jan 15, 2025 17:47:44.364084959 CET50214445192.168.2.577.53.16.1
                                  Jan 15, 2025 17:47:44.368911028 CET4455021477.53.16.1192.168.2.5
                                  Jan 15, 2025 17:47:44.525548935 CET4434993123.1.237.91192.168.2.5
                                  Jan 15, 2025 17:47:44.528615952 CET49931443192.168.2.523.1.237.91
                                  Jan 15, 2025 17:47:45.343328953 CET44549919101.5.197.1192.168.2.5
                                  Jan 15, 2025 17:47:45.346214056 CET49919445192.168.2.5101.5.197.1
                                  Jan 15, 2025 17:47:45.349044085 CET49919445192.168.2.5101.5.197.1
                                  Jan 15, 2025 17:47:45.349098921 CET49919445192.168.2.5101.5.197.1
                                  Jan 15, 2025 17:47:45.353889942 CET44549919101.5.197.1192.168.2.5
                                  Jan 15, 2025 17:47:45.353920937 CET44549919101.5.197.1192.168.2.5
                                  Jan 15, 2025 17:47:46.140827894 CET50225445192.168.2.5144.29.150.72
                                  Jan 15, 2025 17:47:46.145765066 CET44550225144.29.150.72192.168.2.5
                                  Jan 15, 2025 17:47:46.145869970 CET50225445192.168.2.5144.29.150.72
                                  Jan 15, 2025 17:47:46.145908117 CET50225445192.168.2.5144.29.150.72
                                  Jan 15, 2025 17:47:46.146109104 CET50226445192.168.2.5144.29.150.1
                                  Jan 15, 2025 17:47:46.150991917 CET44550225144.29.150.72192.168.2.5
                                  Jan 15, 2025 17:47:46.151027918 CET44550226144.29.150.1192.168.2.5
                                  Jan 15, 2025 17:47:46.151086092 CET50225445192.168.2.5144.29.150.72
                                  Jan 15, 2025 17:47:46.151127100 CET50226445192.168.2.5144.29.150.1
                                  Jan 15, 2025 17:47:46.151215076 CET50226445192.168.2.5144.29.150.1
                                  Jan 15, 2025 17:47:46.151482105 CET50227445192.168.2.5144.29.150.1
                                  Jan 15, 2025 17:47:46.156107903 CET44550226144.29.150.1192.168.2.5
                                  Jan 15, 2025 17:47:46.156166077 CET50226445192.168.2.5144.29.150.1
                                  Jan 15, 2025 17:47:46.156322002 CET44550227144.29.150.1192.168.2.5
                                  Jan 15, 2025 17:47:46.156385899 CET50227445192.168.2.5144.29.150.1
                                  Jan 15, 2025 17:47:46.156425953 CET50227445192.168.2.5144.29.150.1
                                  Jan 15, 2025 17:47:46.161223888 CET44550227144.29.150.1192.168.2.5
                                  Jan 15, 2025 17:47:46.374672890 CET50228445192.168.2.513.229.164.1
                                  Jan 15, 2025 17:47:46.379667044 CET4455022813.229.164.1192.168.2.5
                                  Jan 15, 2025 17:47:46.379770041 CET50228445192.168.2.513.229.164.1
                                  Jan 15, 2025 17:47:46.379813910 CET50228445192.168.2.513.229.164.1
                                  Jan 15, 2025 17:47:46.384627104 CET4455022813.229.164.1192.168.2.5
                                  Jan 15, 2025 17:47:46.843199968 CET50234445192.168.2.578.130.181.1
                                  Jan 15, 2025 17:47:46.848073959 CET4455023478.130.181.1192.168.2.5
                                  Jan 15, 2025 17:47:46.848160028 CET50234445192.168.2.578.130.181.1
                                  Jan 15, 2025 17:47:46.848414898 CET50234445192.168.2.578.130.181.1
                                  Jan 15, 2025 17:47:46.853244066 CET4455023478.130.181.1192.168.2.5
                                  Jan 15, 2025 17:47:47.362766027 CET4454995241.240.115.1192.168.2.5
                                  Jan 15, 2025 17:47:47.362835884 CET49952445192.168.2.541.240.115.1
                                  Jan 15, 2025 17:47:47.362876892 CET49952445192.168.2.541.240.115.1
                                  Jan 15, 2025 17:47:47.362895966 CET49952445192.168.2.541.240.115.1
                                  Jan 15, 2025 17:47:47.367821932 CET4454995241.240.115.1192.168.2.5
                                  Jan 15, 2025 17:47:47.367842913 CET4454995241.240.115.1192.168.2.5
                                  Jan 15, 2025 17:47:48.017333984 CET50240445192.168.2.531.52.246.6
                                  Jan 15, 2025 17:47:48.022252083 CET4455024031.52.246.6192.168.2.5
                                  Jan 15, 2025 17:47:48.022356987 CET50240445192.168.2.531.52.246.6
                                  Jan 15, 2025 17:47:48.022430897 CET50240445192.168.2.531.52.246.6
                                  Jan 15, 2025 17:47:48.022566080 CET50241445192.168.2.531.52.246.1
                                  Jan 15, 2025 17:47:48.027352095 CET4455024131.52.246.1192.168.2.5
                                  Jan 15, 2025 17:47:48.027400017 CET4455024031.52.246.6192.168.2.5
                                  Jan 15, 2025 17:47:48.027441025 CET50241445192.168.2.531.52.246.1
                                  Jan 15, 2025 17:47:48.027472019 CET50240445192.168.2.531.52.246.6
                                  Jan 15, 2025 17:47:48.027478933 CET50241445192.168.2.531.52.246.1
                                  Jan 15, 2025 17:47:48.028065920 CET50242445192.168.2.531.52.246.1
                                  Jan 15, 2025 17:47:48.032368898 CET4455024131.52.246.1192.168.2.5
                                  Jan 15, 2025 17:47:48.032448053 CET50241445192.168.2.531.52.246.1
                                  Jan 15, 2025 17:47:48.032872915 CET4455024231.52.246.1192.168.2.5
                                  Jan 15, 2025 17:47:48.033411026 CET50242445192.168.2.531.52.246.1
                                  Jan 15, 2025 17:47:48.037281036 CET50242445192.168.2.531.52.246.1
                                  Jan 15, 2025 17:47:48.042151928 CET4455024231.52.246.1192.168.2.5
                                  Jan 15, 2025 17:47:48.359016895 CET50243445192.168.2.5101.5.197.1
                                  Jan 15, 2025 17:47:48.364089012 CET44550243101.5.197.1192.168.2.5
                                  Jan 15, 2025 17:47:48.364181995 CET50243445192.168.2.5101.5.197.1
                                  Jan 15, 2025 17:47:48.364207983 CET50243445192.168.2.5101.5.197.1
                                  Jan 15, 2025 17:47:48.368990898 CET44550243101.5.197.1192.168.2.5
                                  Jan 15, 2025 17:47:48.570184946 CET4455023478.130.181.1192.168.2.5
                                  Jan 15, 2025 17:47:48.570267916 CET50234445192.168.2.578.130.181.1
                                  Jan 15, 2025 17:47:48.570306063 CET50234445192.168.2.578.130.181.1
                                  Jan 15, 2025 17:47:48.570343971 CET50234445192.168.2.578.130.181.1
                                  Jan 15, 2025 17:47:48.575054884 CET4455023478.130.181.1192.168.2.5
                                  Jan 15, 2025 17:47:48.575098991 CET4455023478.130.181.1192.168.2.5
                                  Jan 15, 2025 17:47:48.624948025 CET50244445192.168.2.578.130.181.2
                                  Jan 15, 2025 17:47:48.629900932 CET4455024478.130.181.2192.168.2.5
                                  Jan 15, 2025 17:47:48.632751942 CET50244445192.168.2.578.130.181.2
                                  Jan 15, 2025 17:47:48.632930994 CET50244445192.168.2.578.130.181.2
                                  Jan 15, 2025 17:47:48.633269072 CET50245445192.168.2.578.130.181.2
                                  Jan 15, 2025 17:47:48.637733936 CET4455024478.130.181.2192.168.2.5
                                  Jan 15, 2025 17:47:48.638112068 CET4455024578.130.181.2192.168.2.5
                                  Jan 15, 2025 17:47:48.638180017 CET50244445192.168.2.578.130.181.2
                                  Jan 15, 2025 17:47:48.638221025 CET50245445192.168.2.578.130.181.2
                                  Jan 15, 2025 17:47:48.638247967 CET50245445192.168.2.578.130.181.2
                                  Jan 15, 2025 17:47:48.643157005 CET4455024578.130.181.2192.168.2.5
                                  Jan 15, 2025 17:47:49.425570011 CET44549990208.140.179.1192.168.2.5
                                  Jan 15, 2025 17:47:49.425707102 CET49990445192.168.2.5208.140.179.1
                                  Jan 15, 2025 17:47:49.425786972 CET49990445192.168.2.5208.140.179.1
                                  Jan 15, 2025 17:47:49.425786972 CET49990445192.168.2.5208.140.179.1
                                  Jan 15, 2025 17:47:49.430593014 CET44549990208.140.179.1192.168.2.5
                                  Jan 15, 2025 17:47:49.430605888 CET44549990208.140.179.1192.168.2.5
                                  Jan 15, 2025 17:47:49.765398979 CET50251445192.168.2.5216.60.73.223
                                  Jan 15, 2025 17:47:49.770340919 CET44550251216.60.73.223192.168.2.5
                                  Jan 15, 2025 17:47:49.770440102 CET50251445192.168.2.5216.60.73.223
                                  Jan 15, 2025 17:47:49.770551920 CET50251445192.168.2.5216.60.73.223
                                  Jan 15, 2025 17:47:49.770771980 CET50252445192.168.2.5216.60.73.1
                                  Jan 15, 2025 17:47:49.775420904 CET44550251216.60.73.223192.168.2.5
                                  Jan 15, 2025 17:47:49.775482893 CET50251445192.168.2.5216.60.73.223
                                  Jan 15, 2025 17:47:49.775641918 CET44550252216.60.73.1192.168.2.5
                                  Jan 15, 2025 17:47:49.775707006 CET50252445192.168.2.5216.60.73.1
                                  Jan 15, 2025 17:47:49.775749922 CET50252445192.168.2.5216.60.73.1
                                  Jan 15, 2025 17:47:49.776047945 CET50253445192.168.2.5216.60.73.1
                                  Jan 15, 2025 17:47:49.780774117 CET44550252216.60.73.1192.168.2.5
                                  Jan 15, 2025 17:47:49.780839920 CET50252445192.168.2.5216.60.73.1
                                  Jan 15, 2025 17:47:49.780843973 CET44550253216.60.73.1192.168.2.5
                                  Jan 15, 2025 17:47:49.780904055 CET50253445192.168.2.5216.60.73.1
                                  Jan 15, 2025 17:47:49.780944109 CET50253445192.168.2.5216.60.73.1
                                  Jan 15, 2025 17:47:49.785798073 CET44550253216.60.73.1192.168.2.5
                                  Jan 15, 2025 17:47:50.375977039 CET50258445192.168.2.541.240.115.1
                                  Jan 15, 2025 17:47:50.380733967 CET4455025841.240.115.1192.168.2.5
                                  Jan 15, 2025 17:47:50.380804062 CET50258445192.168.2.541.240.115.1
                                  Jan 15, 2025 17:47:50.380821943 CET50258445192.168.2.541.240.115.1
                                  Jan 15, 2025 17:47:50.385658026 CET4455025841.240.115.1192.168.2.5
                                  Jan 15, 2025 17:47:51.391984940 CET44550030154.83.26.1192.168.2.5
                                  Jan 15, 2025 17:47:51.392071962 CET50030445192.168.2.5154.83.26.1
                                  Jan 15, 2025 17:47:51.392112017 CET50030445192.168.2.5154.83.26.1
                                  Jan 15, 2025 17:47:51.392199039 CET50030445192.168.2.5154.83.26.1
                                  Jan 15, 2025 17:47:51.397521973 CET44550030154.83.26.1192.168.2.5
                                  Jan 15, 2025 17:47:51.397538900 CET44550030154.83.26.1192.168.2.5
                                  Jan 15, 2025 17:47:51.406482935 CET50265445192.168.2.5129.17.117.58
                                  Jan 15, 2025 17:47:51.411288977 CET44550265129.17.117.58192.168.2.5
                                  Jan 15, 2025 17:47:51.411659002 CET50266445192.168.2.5129.17.117.1
                                  Jan 15, 2025 17:47:51.411725998 CET50265445192.168.2.5129.17.117.58
                                  Jan 15, 2025 17:47:51.411725998 CET50265445192.168.2.5129.17.117.58
                                  Jan 15, 2025 17:47:51.416647911 CET44550266129.17.117.1192.168.2.5
                                  Jan 15, 2025 17:47:51.416728973 CET50266445192.168.2.5129.17.117.1
                                  Jan 15, 2025 17:47:51.416852951 CET50266445192.168.2.5129.17.117.1
                                  Jan 15, 2025 17:47:51.417251110 CET50267445192.168.2.5129.17.117.1
                                  Jan 15, 2025 17:47:51.422138929 CET44550267129.17.117.1192.168.2.5
                                  Jan 15, 2025 17:47:51.422219992 CET50267445192.168.2.5129.17.117.1
                                  Jan 15, 2025 17:47:51.422245026 CET50267445192.168.2.5129.17.117.1
                                  Jan 15, 2025 17:47:51.423527956 CET44550265129.17.117.58192.168.2.5
                                  Jan 15, 2025 17:47:51.423557043 CET44550266129.17.117.1192.168.2.5
                                  Jan 15, 2025 17:47:51.423762083 CET44550265129.17.117.58192.168.2.5
                                  Jan 15, 2025 17:47:51.423849106 CET50265445192.168.2.5129.17.117.58
                                  Jan 15, 2025 17:47:51.423929930 CET44550266129.17.117.1192.168.2.5
                                  Jan 15, 2025 17:47:51.423994064 CET50266445192.168.2.5129.17.117.1
                                  Jan 15, 2025 17:47:51.427172899 CET44550267129.17.117.1192.168.2.5
                                  Jan 15, 2025 17:47:52.436990976 CET50274445192.168.2.5208.140.179.1
                                  Jan 15, 2025 17:47:52.441806078 CET44550274208.140.179.1192.168.2.5
                                  Jan 15, 2025 17:47:52.441899061 CET50274445192.168.2.5208.140.179.1
                                  Jan 15, 2025 17:47:52.442025900 CET50274445192.168.2.5208.140.179.1
                                  Jan 15, 2025 17:47:52.446773052 CET44550274208.140.179.1192.168.2.5
                                  Jan 15, 2025 17:47:52.937705994 CET50279445192.168.2.5126.75.17.59
                                  Jan 15, 2025 17:47:52.942579985 CET44550279126.75.17.59192.168.2.5
                                  Jan 15, 2025 17:47:52.944232941 CET50279445192.168.2.5126.75.17.59
                                  Jan 15, 2025 17:47:52.944276094 CET50279445192.168.2.5126.75.17.59
                                  Jan 15, 2025 17:47:52.944418907 CET50280445192.168.2.5126.75.17.1
                                  Jan 15, 2025 17:47:52.949270964 CET44550279126.75.17.59192.168.2.5
                                  Jan 15, 2025 17:47:52.949282885 CET44550280126.75.17.1192.168.2.5
                                  Jan 15, 2025 17:47:52.949346066 CET50279445192.168.2.5126.75.17.59
                                  Jan 15, 2025 17:47:52.949385881 CET50280445192.168.2.5126.75.17.1
                                  Jan 15, 2025 17:47:52.949512959 CET50280445192.168.2.5126.75.17.1
                                  Jan 15, 2025 17:47:52.949803114 CET50281445192.168.2.5126.75.17.1
                                  Jan 15, 2025 17:47:52.954525948 CET44550280126.75.17.1192.168.2.5
                                  Jan 15, 2025 17:47:52.954611063 CET50280445192.168.2.5126.75.17.1
                                  Jan 15, 2025 17:47:52.954670906 CET44550281126.75.17.1192.168.2.5
                                  Jan 15, 2025 17:47:52.954745054 CET50281445192.168.2.5126.75.17.1
                                  Jan 15, 2025 17:47:52.954798937 CET50281445192.168.2.5126.75.17.1
                                  Jan 15, 2025 17:47:52.959537983 CET44550281126.75.17.1192.168.2.5
                                  Jan 15, 2025 17:47:53.315659046 CET50283443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:53.315701008 CET4435028340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:53.315798998 CET50283443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:53.316549063 CET50283443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:53.316572905 CET4435028340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:53.420239925 CET445500662.6.237.1192.168.2.5
                                  Jan 15, 2025 17:47:53.420707941 CET50066445192.168.2.52.6.237.1
                                  Jan 15, 2025 17:47:53.421055079 CET50066445192.168.2.52.6.237.1
                                  Jan 15, 2025 17:47:53.421096087 CET50066445192.168.2.52.6.237.1
                                  Jan 15, 2025 17:47:53.425786972 CET445500662.6.237.1192.168.2.5
                                  Jan 15, 2025 17:47:53.425800085 CET445500662.6.237.1192.168.2.5
                                  Jan 15, 2025 17:47:54.112627983 CET4435028340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:54.112701893 CET50283443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:54.114725113 CET50283443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:54.114738941 CET4435028340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:54.114984035 CET4435028340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:54.116408110 CET50283443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:54.116408110 CET50283443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:54.116434097 CET4435028340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:54.116533995 CET50283443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:54.163333893 CET4435028340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:54.291233063 CET4435028340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:54.291399002 CET4435028340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:54.291495085 CET50283443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:54.291640997 CET50283443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:47:54.291661978 CET4435028340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:47:54.359678984 CET50292445192.168.2.535.81.47.184
                                  Jan 15, 2025 17:47:54.364432096 CET4455029235.81.47.184192.168.2.5
                                  Jan 15, 2025 17:47:54.364496946 CET50292445192.168.2.535.81.47.184
                                  Jan 15, 2025 17:47:54.364530087 CET50292445192.168.2.535.81.47.184
                                  Jan 15, 2025 17:47:54.364700079 CET50293445192.168.2.535.81.47.1
                                  Jan 15, 2025 17:47:54.369414091 CET4455029235.81.47.184192.168.2.5
                                  Jan 15, 2025 17:47:54.369471073 CET50292445192.168.2.535.81.47.184
                                  Jan 15, 2025 17:47:54.369502068 CET4455029335.81.47.1192.168.2.5
                                  Jan 15, 2025 17:47:54.369559050 CET50293445192.168.2.535.81.47.1
                                  Jan 15, 2025 17:47:54.369580030 CET50293445192.168.2.535.81.47.1
                                  Jan 15, 2025 17:47:54.369862080 CET50295445192.168.2.535.81.47.1
                                  Jan 15, 2025 17:47:54.374475002 CET4455029335.81.47.1192.168.2.5
                                  Jan 15, 2025 17:47:54.374526024 CET50293445192.168.2.535.81.47.1
                                  Jan 15, 2025 17:47:54.374630928 CET4455029535.81.47.1192.168.2.5
                                  Jan 15, 2025 17:47:54.374702930 CET50295445192.168.2.535.81.47.1
                                  Jan 15, 2025 17:47:54.374763012 CET50295445192.168.2.535.81.47.1
                                  Jan 15, 2025 17:47:54.379509926 CET4455029535.81.47.1192.168.2.5
                                  Jan 15, 2025 17:47:54.406394005 CET50296445192.168.2.5154.83.26.1
                                  Jan 15, 2025 17:47:54.411375046 CET44550296154.83.26.1192.168.2.5
                                  Jan 15, 2025 17:47:54.411523104 CET50296445192.168.2.5154.83.26.1
                                  Jan 15, 2025 17:47:54.411523104 CET50296445192.168.2.5154.83.26.1
                                  Jan 15, 2025 17:47:54.416451931 CET44550296154.83.26.1192.168.2.5
                                  Jan 15, 2025 17:47:55.442857981 CET44550102126.122.68.1192.168.2.5
                                  Jan 15, 2025 17:47:55.442934036 CET50102445192.168.2.5126.122.68.1
                                  Jan 15, 2025 17:47:55.443125010 CET50102445192.168.2.5126.122.68.1
                                  Jan 15, 2025 17:47:55.443166018 CET50102445192.168.2.5126.122.68.1
                                  Jan 15, 2025 17:47:55.447994947 CET44550102126.122.68.1192.168.2.5
                                  Jan 15, 2025 17:47:55.448026896 CET44550102126.122.68.1192.168.2.5
                                  Jan 15, 2025 17:47:55.687211037 CET50303445192.168.2.588.125.174.20
                                  Jan 15, 2025 17:47:55.692102909 CET4455030388.125.174.20192.168.2.5
                                  Jan 15, 2025 17:47:55.692195892 CET50303445192.168.2.588.125.174.20
                                  Jan 15, 2025 17:47:55.692209005 CET50303445192.168.2.588.125.174.20
                                  Jan 15, 2025 17:47:55.692342997 CET50304445192.168.2.588.125.174.1
                                  Jan 15, 2025 17:47:55.697132111 CET4455030488.125.174.1192.168.2.5
                                  Jan 15, 2025 17:47:55.697187901 CET50304445192.168.2.588.125.174.1
                                  Jan 15, 2025 17:47:55.697218895 CET4455030388.125.174.20192.168.2.5
                                  Jan 15, 2025 17:47:55.697262049 CET50303445192.168.2.588.125.174.20
                                  Jan 15, 2025 17:47:55.697365999 CET50304445192.168.2.588.125.174.1
                                  Jan 15, 2025 17:47:55.697691917 CET50305445192.168.2.588.125.174.1
                                  Jan 15, 2025 17:47:55.702199936 CET4455030488.125.174.1192.168.2.5
                                  Jan 15, 2025 17:47:55.702260017 CET50304445192.168.2.588.125.174.1
                                  Jan 15, 2025 17:47:55.702543020 CET4455030588.125.174.1192.168.2.5
                                  Jan 15, 2025 17:47:55.702613115 CET50305445192.168.2.588.125.174.1
                                  Jan 15, 2025 17:47:55.702651024 CET50305445192.168.2.588.125.174.1
                                  Jan 15, 2025 17:47:55.707449913 CET4455030588.125.174.1192.168.2.5
                                  Jan 15, 2025 17:47:56.563946009 CET50311445192.168.2.52.6.237.1
                                  Jan 15, 2025 17:47:56.569708109 CET445503112.6.237.1192.168.2.5
                                  Jan 15, 2025 17:47:56.569768906 CET50311445192.168.2.52.6.237.1
                                  Jan 15, 2025 17:47:56.569797993 CET50311445192.168.2.52.6.237.1
                                  Jan 15, 2025 17:47:56.574551105 CET445503112.6.237.1192.168.2.5
                                  Jan 15, 2025 17:47:56.921608925 CET50316445192.168.2.588.23.242.224
                                  Jan 15, 2025 17:47:56.926383018 CET4455031688.23.242.224192.168.2.5
                                  Jan 15, 2025 17:47:56.926474094 CET50316445192.168.2.588.23.242.224
                                  Jan 15, 2025 17:47:56.926501989 CET50316445192.168.2.588.23.242.224
                                  Jan 15, 2025 17:47:56.926594019 CET50317445192.168.2.588.23.242.1
                                  Jan 15, 2025 17:47:56.931346893 CET4455031788.23.242.1192.168.2.5
                                  Jan 15, 2025 17:47:56.931404114 CET50317445192.168.2.588.23.242.1
                                  Jan 15, 2025 17:47:56.931435108 CET50317445192.168.2.588.23.242.1
                                  Jan 15, 2025 17:47:56.931452990 CET4455031688.23.242.224192.168.2.5
                                  Jan 15, 2025 17:47:56.931502104 CET50316445192.168.2.588.23.242.224
                                  Jan 15, 2025 17:47:56.931679964 CET50318445192.168.2.588.23.242.1
                                  Jan 15, 2025 17:47:56.936346054 CET4455031788.23.242.1192.168.2.5
                                  Jan 15, 2025 17:47:56.936417103 CET50317445192.168.2.588.23.242.1
                                  Jan 15, 2025 17:47:56.936443090 CET4455031888.23.242.1192.168.2.5
                                  Jan 15, 2025 17:47:56.936506987 CET50318445192.168.2.588.23.242.1
                                  Jan 15, 2025 17:47:56.936520100 CET50318445192.168.2.588.23.242.1
                                  Jan 15, 2025 17:47:56.941750050 CET4455031888.23.242.1192.168.2.5
                                  Jan 15, 2025 17:47:57.455033064 CET4455013840.64.79.1192.168.2.5
                                  Jan 15, 2025 17:47:57.455148935 CET50138445192.168.2.540.64.79.1
                                  Jan 15, 2025 17:47:57.455188036 CET50138445192.168.2.540.64.79.1
                                  Jan 15, 2025 17:47:57.455244064 CET50138445192.168.2.540.64.79.1
                                  Jan 15, 2025 17:47:57.460062981 CET4455013840.64.79.1192.168.2.5
                                  Jan 15, 2025 17:47:57.460084915 CET4455013840.64.79.1192.168.2.5
                                  Jan 15, 2025 17:47:57.662436962 CET4455014165.166.2.1192.168.2.5
                                  Jan 15, 2025 17:47:57.662600994 CET50141445192.168.2.565.166.2.1
                                  Jan 15, 2025 17:47:57.662662029 CET50141445192.168.2.565.166.2.1
                                  Jan 15, 2025 17:47:57.662708998 CET50141445192.168.2.565.166.2.1
                                  Jan 15, 2025 17:47:57.667416096 CET4455014165.166.2.1192.168.2.5
                                  Jan 15, 2025 17:47:57.667493105 CET4455014165.166.2.1192.168.2.5
                                  Jan 15, 2025 17:47:57.718497992 CET50324445192.168.2.565.166.2.2
                                  Jan 15, 2025 17:47:57.724176884 CET4455032465.166.2.2192.168.2.5
                                  Jan 15, 2025 17:47:57.724265099 CET50324445192.168.2.565.166.2.2
                                  Jan 15, 2025 17:47:57.724303961 CET50324445192.168.2.565.166.2.2
                                  Jan 15, 2025 17:47:57.724736929 CET50325445192.168.2.565.166.2.2
                                  Jan 15, 2025 17:47:57.730515003 CET4455032565.166.2.2192.168.2.5
                                  Jan 15, 2025 17:47:57.730597973 CET50325445192.168.2.565.166.2.2
                                  Jan 15, 2025 17:47:57.730635881 CET50325445192.168.2.565.166.2.2
                                  Jan 15, 2025 17:47:57.731115103 CET4455032465.166.2.2192.168.2.5
                                  Jan 15, 2025 17:47:57.731173992 CET50324445192.168.2.565.166.2.2
                                  Jan 15, 2025 17:47:57.736824989 CET4455032565.166.2.2192.168.2.5
                                  Jan 15, 2025 17:47:58.077896118 CET50327445192.168.2.5116.101.184.130
                                  Jan 15, 2025 17:47:58.082819939 CET44550327116.101.184.130192.168.2.5
                                  Jan 15, 2025 17:47:58.082933903 CET50327445192.168.2.5116.101.184.130
                                  Jan 15, 2025 17:47:58.082933903 CET50327445192.168.2.5116.101.184.130
                                  Jan 15, 2025 17:47:58.083045959 CET50328445192.168.2.5116.101.184.1
                                  Jan 15, 2025 17:47:58.087840080 CET44550328116.101.184.1192.168.2.5
                                  Jan 15, 2025 17:47:58.088006973 CET50328445192.168.2.5116.101.184.1
                                  Jan 15, 2025 17:47:58.088006973 CET50328445192.168.2.5116.101.184.1
                                  Jan 15, 2025 17:47:58.088164091 CET44550327116.101.184.130192.168.2.5
                                  Jan 15, 2025 17:47:58.088301897 CET50329445192.168.2.5116.101.184.1
                                  Jan 15, 2025 17:47:58.088323116 CET50327445192.168.2.5116.101.184.130
                                  Jan 15, 2025 17:47:58.092995882 CET44550328116.101.184.1192.168.2.5
                                  Jan 15, 2025 17:47:58.093058109 CET50328445192.168.2.5116.101.184.1
                                  Jan 15, 2025 17:47:58.093080997 CET44550329116.101.184.1192.168.2.5
                                  Jan 15, 2025 17:47:58.093153954 CET50329445192.168.2.5116.101.184.1
                                  Jan 15, 2025 17:47:58.093178988 CET50329445192.168.2.5116.101.184.1
                                  Jan 15, 2025 17:47:58.098021984 CET44550329116.101.184.1192.168.2.5
                                  Jan 15, 2025 17:47:58.452603102 CET50334445192.168.2.5126.122.68.1
                                  Jan 15, 2025 17:47:58.457458973 CET44550334126.122.68.1192.168.2.5
                                  Jan 15, 2025 17:47:58.457531929 CET50334445192.168.2.5126.122.68.1
                                  Jan 15, 2025 17:47:58.457583904 CET50334445192.168.2.5126.122.68.1
                                  Jan 15, 2025 17:47:58.462383986 CET44550334126.122.68.1192.168.2.5
                                  Jan 15, 2025 17:47:59.156188011 CET50338445192.168.2.5193.204.71.168
                                  Jan 15, 2025 17:47:59.161042929 CET44550338193.204.71.168192.168.2.5
                                  Jan 15, 2025 17:47:59.161139965 CET50338445192.168.2.5193.204.71.168
                                  Jan 15, 2025 17:47:59.161184072 CET50338445192.168.2.5193.204.71.168
                                  Jan 15, 2025 17:47:59.161305904 CET50339445192.168.2.5193.204.71.1
                                  Jan 15, 2025 17:47:59.166129112 CET44550339193.204.71.1192.168.2.5
                                  Jan 15, 2025 17:47:59.166157007 CET44550338193.204.71.168192.168.2.5
                                  Jan 15, 2025 17:47:59.166212082 CET50339445192.168.2.5193.204.71.1
                                  Jan 15, 2025 17:47:59.166212082 CET50339445192.168.2.5193.204.71.1
                                  Jan 15, 2025 17:47:59.166241884 CET50338445192.168.2.5193.204.71.168
                                  Jan 15, 2025 17:47:59.166527033 CET50342445192.168.2.5193.204.71.1
                                  Jan 15, 2025 17:47:59.171180964 CET44550339193.204.71.1192.168.2.5
                                  Jan 15, 2025 17:47:59.171233892 CET50339445192.168.2.5193.204.71.1
                                  Jan 15, 2025 17:47:59.171360016 CET44550342193.204.71.1192.168.2.5
                                  Jan 15, 2025 17:47:59.171433926 CET50342445192.168.2.5193.204.71.1
                                  Jan 15, 2025 17:47:59.171478033 CET50342445192.168.2.5193.204.71.1
                                  Jan 15, 2025 17:47:59.176212072 CET44550342193.204.71.1192.168.2.5
                                  Jan 15, 2025 17:47:59.454546928 CET4455016155.191.105.1192.168.2.5
                                  Jan 15, 2025 17:47:59.454607964 CET50161445192.168.2.555.191.105.1
                                  Jan 15, 2025 17:47:59.454653025 CET50161445192.168.2.555.191.105.1
                                  Jan 15, 2025 17:47:59.454698086 CET50161445192.168.2.555.191.105.1
                                  Jan 15, 2025 17:47:59.459469080 CET4455016155.191.105.1192.168.2.5
                                  Jan 15, 2025 17:47:59.459482908 CET4455016155.191.105.1192.168.2.5
                                  Jan 15, 2025 17:47:59.703497887 CET44550163194.183.238.1192.168.2.5
                                  Jan 15, 2025 17:47:59.704997063 CET50163445192.168.2.5194.183.238.1
                                  Jan 15, 2025 17:47:59.705099106 CET50163445192.168.2.5194.183.238.1
                                  Jan 15, 2025 17:47:59.705099106 CET50163445192.168.2.5194.183.238.1
                                  Jan 15, 2025 17:47:59.709904909 CET44550163194.183.238.1192.168.2.5
                                  Jan 15, 2025 17:47:59.709918976 CET44550163194.183.238.1192.168.2.5
                                  Jan 15, 2025 17:47:59.765459061 CET50345445192.168.2.5194.183.238.2
                                  Jan 15, 2025 17:47:59.770523071 CET44550345194.183.238.2192.168.2.5
                                  Jan 15, 2025 17:47:59.770901918 CET50345445192.168.2.5194.183.238.2
                                  Jan 15, 2025 17:47:59.770942926 CET50345445192.168.2.5194.183.238.2
                                  Jan 15, 2025 17:47:59.771303892 CET50346445192.168.2.5194.183.238.2
                                  Jan 15, 2025 17:47:59.775949001 CET44550345194.183.238.2192.168.2.5
                                  Jan 15, 2025 17:47:59.776015997 CET50345445192.168.2.5194.183.238.2
                                  Jan 15, 2025 17:47:59.776115894 CET44550346194.183.238.2192.168.2.5
                                  Jan 15, 2025 17:47:59.776185036 CET50346445192.168.2.5194.183.238.2
                                  Jan 15, 2025 17:47:59.776220083 CET50346445192.168.2.5194.183.238.2
                                  Jan 15, 2025 17:47:59.780996084 CET44550346194.183.238.2192.168.2.5
                                  Jan 15, 2025 17:48:00.171715021 CET50350445192.168.2.5116.74.169.95
                                  Jan 15, 2025 17:48:00.176625967 CET44550350116.74.169.95192.168.2.5
                                  Jan 15, 2025 17:48:00.176822901 CET50350445192.168.2.5116.74.169.95
                                  Jan 15, 2025 17:48:00.176822901 CET50350445192.168.2.5116.74.169.95
                                  Jan 15, 2025 17:48:00.176865101 CET50351445192.168.2.5116.74.169.1
                                  Jan 15, 2025 17:48:00.181698084 CET44550351116.74.169.1192.168.2.5
                                  Jan 15, 2025 17:48:00.181785107 CET50351445192.168.2.5116.74.169.1
                                  Jan 15, 2025 17:48:00.181786060 CET50351445192.168.2.5116.74.169.1
                                  Jan 15, 2025 17:48:00.181833029 CET44550350116.74.169.95192.168.2.5
                                  Jan 15, 2025 17:48:00.182044983 CET50350445192.168.2.5116.74.169.95
                                  Jan 15, 2025 17:48:00.182096958 CET50352445192.168.2.5116.74.169.1
                                  Jan 15, 2025 17:48:00.186719894 CET44550351116.74.169.1192.168.2.5
                                  Jan 15, 2025 17:48:00.186796904 CET50351445192.168.2.5116.74.169.1
                                  Jan 15, 2025 17:48:00.186937094 CET44550352116.74.169.1192.168.2.5
                                  Jan 15, 2025 17:48:00.187021017 CET50352445192.168.2.5116.74.169.1
                                  Jan 15, 2025 17:48:00.187021017 CET50352445192.168.2.5116.74.169.1
                                  Jan 15, 2025 17:48:00.191848993 CET44550352116.74.169.1192.168.2.5
                                  Jan 15, 2025 17:48:00.468319893 CET50354445192.168.2.540.64.79.1
                                  Jan 15, 2025 17:48:00.523458958 CET4455035440.64.79.1192.168.2.5
                                  Jan 15, 2025 17:48:00.524501085 CET50354445192.168.2.540.64.79.1
                                  Jan 15, 2025 17:48:00.524557114 CET50354445192.168.2.540.64.79.1
                                  Jan 15, 2025 17:48:00.529336929 CET4455035440.64.79.1192.168.2.5
                                  Jan 15, 2025 17:48:01.109252930 CET50361445192.168.2.5170.97.32.147
                                  Jan 15, 2025 17:48:01.114039898 CET44550361170.97.32.147192.168.2.5
                                  Jan 15, 2025 17:48:01.114124060 CET50361445192.168.2.5170.97.32.147
                                  Jan 15, 2025 17:48:01.114195108 CET50361445192.168.2.5170.97.32.147
                                  Jan 15, 2025 17:48:01.114356995 CET50362445192.168.2.5170.97.32.1
                                  Jan 15, 2025 17:48:01.119081020 CET44550361170.97.32.147192.168.2.5
                                  Jan 15, 2025 17:48:01.119148970 CET44550362170.97.32.1192.168.2.5
                                  Jan 15, 2025 17:48:01.119151115 CET50361445192.168.2.5170.97.32.147
                                  Jan 15, 2025 17:48:01.119213104 CET50362445192.168.2.5170.97.32.1
                                  Jan 15, 2025 17:48:01.119306087 CET50362445192.168.2.5170.97.32.1
                                  Jan 15, 2025 17:48:01.119613886 CET50363445192.168.2.5170.97.32.1
                                  Jan 15, 2025 17:48:01.124131918 CET44550362170.97.32.1192.168.2.5
                                  Jan 15, 2025 17:48:01.124203920 CET50362445192.168.2.5170.97.32.1
                                  Jan 15, 2025 17:48:01.124466896 CET44550363170.97.32.1192.168.2.5
                                  Jan 15, 2025 17:48:01.124562979 CET50363445192.168.2.5170.97.32.1
                                  Jan 15, 2025 17:48:01.124563932 CET50363445192.168.2.5170.97.32.1
                                  Jan 15, 2025 17:48:01.129317999 CET44550363170.97.32.1192.168.2.5
                                  Jan 15, 2025 17:48:01.469249010 CET4455017733.180.119.1192.168.2.5
                                  Jan 15, 2025 17:48:01.469326019 CET50177445192.168.2.533.180.119.1
                                  Jan 15, 2025 17:48:01.469388008 CET50177445192.168.2.533.180.119.1
                                  Jan 15, 2025 17:48:01.469434023 CET50177445192.168.2.533.180.119.1
                                  Jan 15, 2025 17:48:01.474580050 CET4455017733.180.119.1192.168.2.5
                                  Jan 15, 2025 17:48:01.474595070 CET4455017733.180.119.1192.168.2.5
                                  Jan 15, 2025 17:48:01.704745054 CET4455018225.38.30.1192.168.2.5
                                  Jan 15, 2025 17:48:01.704839945 CET50182445192.168.2.525.38.30.1
                                  Jan 15, 2025 17:48:01.705066919 CET50182445192.168.2.525.38.30.1
                                  Jan 15, 2025 17:48:01.705142021 CET50182445192.168.2.525.38.30.1
                                  Jan 15, 2025 17:48:01.709849119 CET4455018225.38.30.1192.168.2.5
                                  Jan 15, 2025 17:48:01.709873915 CET4455018225.38.30.1192.168.2.5
                                  Jan 15, 2025 17:48:01.765399933 CET50364445192.168.2.525.38.30.2
                                  Jan 15, 2025 17:48:01.770193100 CET4455036425.38.30.2192.168.2.5
                                  Jan 15, 2025 17:48:01.770425081 CET50364445192.168.2.525.38.30.2
                                  Jan 15, 2025 17:48:01.770461082 CET50364445192.168.2.525.38.30.2
                                  Jan 15, 2025 17:48:01.770776987 CET50365445192.168.2.525.38.30.2
                                  Jan 15, 2025 17:48:01.775396109 CET4455036425.38.30.2192.168.2.5
                                  Jan 15, 2025 17:48:01.775490046 CET50364445192.168.2.525.38.30.2
                                  Jan 15, 2025 17:48:01.775592089 CET4455036525.38.30.2192.168.2.5
                                  Jan 15, 2025 17:48:01.775690079 CET50365445192.168.2.525.38.30.2
                                  Jan 15, 2025 17:48:01.775719881 CET50365445192.168.2.525.38.30.2
                                  Jan 15, 2025 17:48:01.780451059 CET4455036525.38.30.2192.168.2.5
                                  Jan 15, 2025 17:48:01.984972000 CET50366445192.168.2.594.215.143.221
                                  Jan 15, 2025 17:48:01.989859104 CET4455036694.215.143.221192.168.2.5
                                  Jan 15, 2025 17:48:01.989943027 CET50366445192.168.2.594.215.143.221
                                  Jan 15, 2025 17:48:01.990017891 CET50366445192.168.2.594.215.143.221
                                  Jan 15, 2025 17:48:01.990200996 CET50367445192.168.2.594.215.143.1
                                  Jan 15, 2025 17:48:01.994921923 CET4455036694.215.143.221192.168.2.5
                                  Jan 15, 2025 17:48:01.995141983 CET4455036794.215.143.1192.168.2.5
                                  Jan 15, 2025 17:48:01.995213985 CET50366445192.168.2.594.215.143.221
                                  Jan 15, 2025 17:48:01.995280027 CET50367445192.168.2.594.215.143.1
                                  Jan 15, 2025 17:48:01.997550011 CET50367445192.168.2.594.215.143.1
                                  Jan 15, 2025 17:48:01.997936010 CET50368445192.168.2.594.215.143.1
                                  Jan 15, 2025 17:48:02.002814054 CET4455036794.215.143.1192.168.2.5
                                  Jan 15, 2025 17:48:02.002844095 CET4455036894.215.143.1192.168.2.5
                                  Jan 15, 2025 17:48:02.002890110 CET50367445192.168.2.594.215.143.1
                                  Jan 15, 2025 17:48:02.002926111 CET50368445192.168.2.594.215.143.1
                                  Jan 15, 2025 17:48:02.002952099 CET50368445192.168.2.594.215.143.1
                                  Jan 15, 2025 17:48:02.007772923 CET4455036894.215.143.1192.168.2.5
                                  Jan 15, 2025 17:48:02.468420982 CET50369445192.168.2.555.191.105.1
                                  Jan 15, 2025 17:48:02.473344088 CET4455036955.191.105.1192.168.2.5
                                  Jan 15, 2025 17:48:02.473462105 CET50369445192.168.2.555.191.105.1
                                  Jan 15, 2025 17:48:02.473539114 CET50369445192.168.2.555.191.105.1
                                  Jan 15, 2025 17:48:02.480073929 CET4455036955.191.105.1192.168.2.5
                                  Jan 15, 2025 17:48:02.812591076 CET50370445192.168.2.576.82.8.189
                                  Jan 15, 2025 17:48:02.817404985 CET4455037076.82.8.189192.168.2.5
                                  Jan 15, 2025 17:48:02.818089962 CET50370445192.168.2.576.82.8.189
                                  Jan 15, 2025 17:48:02.818170071 CET50370445192.168.2.576.82.8.189
                                  Jan 15, 2025 17:48:02.818337917 CET50371445192.168.2.576.82.8.1
                                  Jan 15, 2025 17:48:02.823079109 CET4455037076.82.8.189192.168.2.5
                                  Jan 15, 2025 17:48:02.823139906 CET4455037176.82.8.1192.168.2.5
                                  Jan 15, 2025 17:48:02.823220015 CET50370445192.168.2.576.82.8.189
                                  Jan 15, 2025 17:48:02.823246002 CET50371445192.168.2.576.82.8.1
                                  Jan 15, 2025 17:48:02.823331118 CET50371445192.168.2.576.82.8.1
                                  Jan 15, 2025 17:48:02.823628902 CET50372445192.168.2.576.82.8.1
                                  Jan 15, 2025 17:48:02.828381062 CET4455037276.82.8.1192.168.2.5
                                  Jan 15, 2025 17:48:02.828461885 CET50372445192.168.2.576.82.8.1
                                  Jan 15, 2025 17:48:02.828475952 CET4455037176.82.8.1192.168.2.5
                                  Jan 15, 2025 17:48:02.828496933 CET50372445192.168.2.576.82.8.1
                                  Jan 15, 2025 17:48:02.828528881 CET50371445192.168.2.576.82.8.1
                                  Jan 15, 2025 17:48:02.833271027 CET4455037276.82.8.1192.168.2.5
                                  Jan 15, 2025 17:48:03.271970034 CET50373443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:03.272042036 CET4435037340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:03.272114992 CET50373443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:03.272658110 CET50373443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:03.272686958 CET4435037340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:03.577914953 CET50374445192.168.2.52.139.197.109
                                  Jan 15, 2025 17:48:03.582874060 CET445503742.139.197.109192.168.2.5
                                  Jan 15, 2025 17:48:03.582952976 CET50374445192.168.2.52.139.197.109
                                  Jan 15, 2025 17:48:03.582983017 CET50374445192.168.2.52.139.197.109
                                  Jan 15, 2025 17:48:03.583199024 CET50375445192.168.2.52.139.197.1
                                  Jan 15, 2025 17:48:03.587925911 CET445503742.139.197.109192.168.2.5
                                  Jan 15, 2025 17:48:03.587986946 CET50374445192.168.2.52.139.197.109
                                  Jan 15, 2025 17:48:03.588032007 CET445503752.139.197.1192.168.2.5
                                  Jan 15, 2025 17:48:03.588105917 CET50375445192.168.2.52.139.197.1
                                  Jan 15, 2025 17:48:03.588265896 CET50375445192.168.2.52.139.197.1
                                  Jan 15, 2025 17:48:03.588488102 CET50376445192.168.2.52.139.197.1
                                  Jan 15, 2025 17:48:03.593074083 CET445503752.139.197.1192.168.2.5
                                  Jan 15, 2025 17:48:03.593127966 CET50375445192.168.2.52.139.197.1
                                  Jan 15, 2025 17:48:03.593257904 CET445503762.139.197.1192.168.2.5
                                  Jan 15, 2025 17:48:03.593314886 CET50376445192.168.2.52.139.197.1
                                  Jan 15, 2025 17:48:03.593425989 CET50376445192.168.2.52.139.197.1
                                  Jan 15, 2025 17:48:03.598176003 CET445503762.139.197.1192.168.2.5
                                  Jan 15, 2025 17:48:03.682998896 CET4455036894.215.143.1192.168.2.5
                                  Jan 15, 2025 17:48:03.683073997 CET50368445192.168.2.594.215.143.1
                                  Jan 15, 2025 17:48:03.683120012 CET50368445192.168.2.594.215.143.1
                                  Jan 15, 2025 17:48:03.683131933 CET50368445192.168.2.594.215.143.1
                                  Jan 15, 2025 17:48:03.687973976 CET4455036894.215.143.1192.168.2.5
                                  Jan 15, 2025 17:48:03.687995911 CET4455036894.215.143.1192.168.2.5
                                  Jan 15, 2025 17:48:03.738147020 CET44550195218.112.212.1192.168.2.5
                                  Jan 15, 2025 17:48:03.738234043 CET50195445192.168.2.5218.112.212.1
                                  Jan 15, 2025 17:48:03.738276005 CET50195445192.168.2.5218.112.212.1
                                  Jan 15, 2025 17:48:03.738389969 CET50195445192.168.2.5218.112.212.1
                                  Jan 15, 2025 17:48:03.743128061 CET44550195218.112.212.1192.168.2.5
                                  Jan 15, 2025 17:48:03.743169069 CET44550195218.112.212.1192.168.2.5
                                  Jan 15, 2025 17:48:03.796492100 CET50377445192.168.2.5218.112.212.2
                                  Jan 15, 2025 17:48:03.801381111 CET44550377218.112.212.2192.168.2.5
                                  Jan 15, 2025 17:48:03.801460981 CET50377445192.168.2.5218.112.212.2
                                  Jan 15, 2025 17:48:03.801538944 CET50377445192.168.2.5218.112.212.2
                                  Jan 15, 2025 17:48:03.801872969 CET50378445192.168.2.5218.112.212.2
                                  Jan 15, 2025 17:48:03.806513071 CET44550377218.112.212.2192.168.2.5
                                  Jan 15, 2025 17:48:03.806612968 CET50377445192.168.2.5218.112.212.2
                                  Jan 15, 2025 17:48:03.806664944 CET44550378218.112.212.2192.168.2.5
                                  Jan 15, 2025 17:48:03.806910038 CET50378445192.168.2.5218.112.212.2
                                  Jan 15, 2025 17:48:03.806947947 CET50378445192.168.2.5218.112.212.2
                                  Jan 15, 2025 17:48:03.811672926 CET44550378218.112.212.2192.168.2.5
                                  Jan 15, 2025 17:48:04.253289938 CET4435037340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:04.253412962 CET50373443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:04.255666971 CET50373443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:04.255697012 CET4435037340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:04.259295940 CET4435037340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:04.261310101 CET50373443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:04.261401892 CET50373443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:04.261415005 CET4435037340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:04.261554956 CET50373443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:04.307333946 CET4435037340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:04.431616068 CET4435037340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:04.431727886 CET4435037340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:04.431926966 CET50373443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:04.432018042 CET50373443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:04.432063103 CET4435037340.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:04.484061956 CET50380445192.168.2.533.180.119.1
                                  Jan 15, 2025 17:48:04.489181042 CET4455038033.180.119.1192.168.2.5
                                  Jan 15, 2025 17:48:04.489291906 CET50380445192.168.2.533.180.119.1
                                  Jan 15, 2025 17:48:04.489335060 CET50380445192.168.2.533.180.119.1
                                  Jan 15, 2025 17:48:04.495589018 CET4455038033.180.119.1192.168.2.5
                                  Jan 15, 2025 17:48:05.519788027 CET4455021263.217.137.1192.168.2.5
                                  Jan 15, 2025 17:48:05.519869089 CET50212445192.168.2.563.217.137.1
                                  Jan 15, 2025 17:48:05.519895077 CET50212445192.168.2.563.217.137.1
                                  Jan 15, 2025 17:48:05.519926071 CET50212445192.168.2.563.217.137.1
                                  Jan 15, 2025 17:48:05.524645090 CET4455021263.217.137.1192.168.2.5
                                  Jan 15, 2025 17:48:05.524707079 CET4455021263.217.137.1192.168.2.5
                                  Jan 15, 2025 17:48:05.718749046 CET4455021477.53.16.1192.168.2.5
                                  Jan 15, 2025 17:48:05.718920946 CET50214445192.168.2.577.53.16.1
                                  Jan 15, 2025 17:48:05.719095945 CET50214445192.168.2.577.53.16.1
                                  Jan 15, 2025 17:48:05.719095945 CET50214445192.168.2.577.53.16.1
                                  Jan 15, 2025 17:48:05.723979950 CET4455021477.53.16.1192.168.2.5
                                  Jan 15, 2025 17:48:05.724003077 CET4455021477.53.16.1192.168.2.5
                                  Jan 15, 2025 17:48:05.780869961 CET50384445192.168.2.577.53.16.2
                                  Jan 15, 2025 17:48:05.785921097 CET4455038477.53.16.2192.168.2.5
                                  Jan 15, 2025 17:48:05.786098003 CET50384445192.168.2.577.53.16.2
                                  Jan 15, 2025 17:48:05.786185980 CET50384445192.168.2.577.53.16.2
                                  Jan 15, 2025 17:48:05.786675930 CET50385445192.168.2.577.53.16.2
                                  Jan 15, 2025 17:48:05.791109085 CET4455038477.53.16.2192.168.2.5
                                  Jan 15, 2025 17:48:05.791230917 CET50384445192.168.2.577.53.16.2
                                  Jan 15, 2025 17:48:05.791474104 CET4455038577.53.16.2192.168.2.5
                                  Jan 15, 2025 17:48:05.791554928 CET50385445192.168.2.577.53.16.2
                                  Jan 15, 2025 17:48:05.791599989 CET50385445192.168.2.577.53.16.2
                                  Jan 15, 2025 17:48:05.796416998 CET4455038577.53.16.2192.168.2.5
                                  Jan 15, 2025 17:48:06.687073946 CET50389445192.168.2.594.215.143.1
                                  Jan 15, 2025 17:48:06.692586899 CET4455038994.215.143.1192.168.2.5
                                  Jan 15, 2025 17:48:06.692743063 CET50389445192.168.2.594.215.143.1
                                  Jan 15, 2025 17:48:06.692785025 CET50389445192.168.2.594.215.143.1
                                  Jan 15, 2025 17:48:06.697635889 CET4455038994.215.143.1192.168.2.5
                                  Jan 15, 2025 17:48:07.532294035 CET44550227144.29.150.1192.168.2.5
                                  Jan 15, 2025 17:48:07.532454967 CET50227445192.168.2.5144.29.150.1
                                  Jan 15, 2025 17:48:07.532565117 CET50227445192.168.2.5144.29.150.1
                                  Jan 15, 2025 17:48:07.532566071 CET50227445192.168.2.5144.29.150.1
                                  Jan 15, 2025 17:48:07.537427902 CET44550227144.29.150.1192.168.2.5
                                  Jan 15, 2025 17:48:07.537445068 CET44550227144.29.150.1192.168.2.5
                                  Jan 15, 2025 17:48:07.753963947 CET4455022813.229.164.1192.168.2.5
                                  Jan 15, 2025 17:48:07.754081011 CET50228445192.168.2.513.229.164.1
                                  Jan 15, 2025 17:48:07.754153967 CET50228445192.168.2.513.229.164.1
                                  Jan 15, 2025 17:48:07.754221916 CET50228445192.168.2.513.229.164.1
                                  Jan 15, 2025 17:48:07.759146929 CET4455022813.229.164.1192.168.2.5
                                  Jan 15, 2025 17:48:07.759160042 CET4455022813.229.164.1192.168.2.5
                                  Jan 15, 2025 17:48:07.816736937 CET50397445192.168.2.513.229.164.2
                                  Jan 15, 2025 17:48:07.821760893 CET4455039713.229.164.2192.168.2.5
                                  Jan 15, 2025 17:48:07.821912050 CET50397445192.168.2.513.229.164.2
                                  Jan 15, 2025 17:48:07.821928024 CET50397445192.168.2.513.229.164.2
                                  Jan 15, 2025 17:48:07.822304010 CET50398445192.168.2.513.229.164.2
                                  Jan 15, 2025 17:48:07.826951981 CET4455039713.229.164.2192.168.2.5
                                  Jan 15, 2025 17:48:07.827023983 CET50397445192.168.2.513.229.164.2
                                  Jan 15, 2025 17:48:07.827260017 CET4455039813.229.164.2192.168.2.5
                                  Jan 15, 2025 17:48:07.827352047 CET50398445192.168.2.513.229.164.2
                                  Jan 15, 2025 17:48:07.830127001 CET50398445192.168.2.513.229.164.2
                                  Jan 15, 2025 17:48:07.832295895 CET4455039813.229.164.2192.168.2.5
                                  Jan 15, 2025 17:48:07.835026026 CET4455039813.229.164.2192.168.2.5
                                  Jan 15, 2025 17:48:08.323472023 CET4455038994.215.143.1192.168.2.5
                                  Jan 15, 2025 17:48:08.323606968 CET50389445192.168.2.594.215.143.1
                                  Jan 15, 2025 17:48:08.323642015 CET50389445192.168.2.594.215.143.1
                                  Jan 15, 2025 17:48:08.323648930 CET50389445192.168.2.594.215.143.1
                                  Jan 15, 2025 17:48:08.328552008 CET4455038994.215.143.1192.168.2.5
                                  Jan 15, 2025 17:48:08.328566074 CET4455038994.215.143.1192.168.2.5
                                  Jan 15, 2025 17:48:08.374610901 CET50404445192.168.2.594.215.143.2
                                  Jan 15, 2025 17:48:08.379585981 CET4455040494.215.143.2192.168.2.5
                                  Jan 15, 2025 17:48:08.379693031 CET50404445192.168.2.594.215.143.2
                                  Jan 15, 2025 17:48:08.379790068 CET50404445192.168.2.594.215.143.2
                                  Jan 15, 2025 17:48:08.380182981 CET50405445192.168.2.594.215.143.2
                                  Jan 15, 2025 17:48:08.384792089 CET4455040494.215.143.2192.168.2.5
                                  Jan 15, 2025 17:48:08.384886980 CET50404445192.168.2.594.215.143.2
                                  Jan 15, 2025 17:48:08.385008097 CET4455040594.215.143.2192.168.2.5
                                  Jan 15, 2025 17:48:08.385080099 CET50405445192.168.2.594.215.143.2
                                  Jan 15, 2025 17:48:08.385123014 CET50405445192.168.2.594.215.143.2
                                  Jan 15, 2025 17:48:08.389939070 CET4455040594.215.143.2192.168.2.5
                                  Jan 15, 2025 17:48:08.531152964 CET50407445192.168.2.563.217.137.1
                                  Jan 15, 2025 17:48:08.536113024 CET4455040763.217.137.1192.168.2.5
                                  Jan 15, 2025 17:48:08.536251068 CET50407445192.168.2.563.217.137.1
                                  Jan 15, 2025 17:48:08.536315918 CET50407445192.168.2.563.217.137.1
                                  Jan 15, 2025 17:48:08.541120052 CET4455040763.217.137.1192.168.2.5
                                  Jan 15, 2025 17:48:09.422535896 CET4455024231.52.246.1192.168.2.5
                                  Jan 15, 2025 17:48:09.422800064 CET50242445192.168.2.531.52.246.1
                                  Jan 15, 2025 17:48:09.422857046 CET50242445192.168.2.531.52.246.1
                                  Jan 15, 2025 17:48:09.422857046 CET50242445192.168.2.531.52.246.1
                                  Jan 15, 2025 17:48:09.427728891 CET4455024231.52.246.1192.168.2.5
                                  Jan 15, 2025 17:48:09.427740097 CET4455024231.52.246.1192.168.2.5
                                  Jan 15, 2025 17:48:09.735037088 CET44550243101.5.197.1192.168.2.5
                                  Jan 15, 2025 17:48:09.735265970 CET50243445192.168.2.5101.5.197.1
                                  Jan 15, 2025 17:48:09.735265970 CET50243445192.168.2.5101.5.197.1
                                  Jan 15, 2025 17:48:09.735265970 CET50243445192.168.2.5101.5.197.1
                                  Jan 15, 2025 17:48:09.740737915 CET44550243101.5.197.1192.168.2.5
                                  Jan 15, 2025 17:48:09.740747929 CET44550243101.5.197.1192.168.2.5
                                  Jan 15, 2025 17:48:09.796523094 CET50421445192.168.2.5101.5.197.2
                                  Jan 15, 2025 17:48:09.801575899 CET44550421101.5.197.2192.168.2.5
                                  Jan 15, 2025 17:48:09.801649094 CET50421445192.168.2.5101.5.197.2
                                  Jan 15, 2025 17:48:09.801678896 CET50421445192.168.2.5101.5.197.2
                                  Jan 15, 2025 17:48:09.801944017 CET50422445192.168.2.5101.5.197.2
                                  Jan 15, 2025 17:48:09.806772947 CET44550422101.5.197.2192.168.2.5
                                  Jan 15, 2025 17:48:09.806783915 CET44550421101.5.197.2192.168.2.5
                                  Jan 15, 2025 17:48:09.806853056 CET50422445192.168.2.5101.5.197.2
                                  Jan 15, 2025 17:48:09.806853056 CET50421445192.168.2.5101.5.197.2
                                  Jan 15, 2025 17:48:09.806920052 CET50422445192.168.2.5101.5.197.2
                                  Jan 15, 2025 17:48:09.811758995 CET44550422101.5.197.2192.168.2.5
                                  Jan 15, 2025 17:48:10.002279043 CET4455024578.130.181.2192.168.2.5
                                  Jan 15, 2025 17:48:10.002405882 CET50245445192.168.2.578.130.181.2
                                  Jan 15, 2025 17:48:10.002444029 CET50245445192.168.2.578.130.181.2
                                  Jan 15, 2025 17:48:10.002624035 CET50245445192.168.2.578.130.181.2
                                  Jan 15, 2025 17:48:10.007196903 CET4455024578.130.181.2192.168.2.5
                                  Jan 15, 2025 17:48:10.007396936 CET4455024578.130.181.2192.168.2.5
                                  Jan 15, 2025 17:48:10.546401024 CET50432445192.168.2.5144.29.150.1
                                  Jan 15, 2025 17:48:10.551413059 CET44550432144.29.150.1192.168.2.5
                                  Jan 15, 2025 17:48:10.551492929 CET50432445192.168.2.5144.29.150.1
                                  Jan 15, 2025 17:48:10.551517963 CET50432445192.168.2.5144.29.150.1
                                  Jan 15, 2025 17:48:10.556299925 CET44550432144.29.150.1192.168.2.5
                                  Jan 15, 2025 17:48:11.125195026 CET44550253216.60.73.1192.168.2.5
                                  Jan 15, 2025 17:48:11.125344038 CET50253445192.168.2.5216.60.73.1
                                  Jan 15, 2025 17:48:11.125396967 CET50253445192.168.2.5216.60.73.1
                                  Jan 15, 2025 17:48:11.125396967 CET50253445192.168.2.5216.60.73.1
                                  Jan 15, 2025 17:48:11.130294085 CET44550253216.60.73.1192.168.2.5
                                  Jan 15, 2025 17:48:11.130352020 CET44550253216.60.73.1192.168.2.5
                                  Jan 15, 2025 17:48:11.734688997 CET4455025841.240.115.1192.168.2.5
                                  Jan 15, 2025 17:48:11.734972000 CET50258445192.168.2.541.240.115.1
                                  Jan 15, 2025 17:48:11.734972000 CET50258445192.168.2.541.240.115.1
                                  Jan 15, 2025 17:48:11.734972000 CET50258445192.168.2.541.240.115.1
                                  Jan 15, 2025 17:48:11.740160942 CET4455025841.240.115.1192.168.2.5
                                  Jan 15, 2025 17:48:11.740191936 CET4455025841.240.115.1192.168.2.5
                                  Jan 15, 2025 17:48:11.796320915 CET50456445192.168.2.541.240.115.2
                                  Jan 15, 2025 17:48:11.801465988 CET4455045641.240.115.2192.168.2.5
                                  Jan 15, 2025 17:48:11.801624060 CET50456445192.168.2.541.240.115.2
                                  Jan 15, 2025 17:48:11.801798105 CET50456445192.168.2.541.240.115.2
                                  Jan 15, 2025 17:48:11.802243948 CET50458445192.168.2.541.240.115.2
                                  Jan 15, 2025 17:48:11.806731939 CET4455045641.240.115.2192.168.2.5
                                  Jan 15, 2025 17:48:11.806793928 CET50456445192.168.2.541.240.115.2
                                  Jan 15, 2025 17:48:11.807065010 CET4455045841.240.115.2192.168.2.5
                                  Jan 15, 2025 17:48:11.807123899 CET50458445192.168.2.541.240.115.2
                                  Jan 15, 2025 17:48:11.807162046 CET50458445192.168.2.541.240.115.2
                                  Jan 15, 2025 17:48:11.811963081 CET4455045841.240.115.2192.168.2.5
                                  Jan 15, 2025 17:48:12.437015057 CET50473445192.168.2.531.52.246.1
                                  Jan 15, 2025 17:48:12.442262888 CET4455047331.52.246.1192.168.2.5
                                  Jan 15, 2025 17:48:12.442361116 CET50473445192.168.2.531.52.246.1
                                  Jan 15, 2025 17:48:12.442387104 CET50473445192.168.2.531.52.246.1
                                  Jan 15, 2025 17:48:12.447205067 CET4455047331.52.246.1192.168.2.5
                                  Jan 15, 2025 17:48:12.832026958 CET44550267129.17.117.1192.168.2.5
                                  Jan 15, 2025 17:48:12.832109928 CET50267445192.168.2.5129.17.117.1
                                  Jan 15, 2025 17:48:12.832145929 CET50267445192.168.2.5129.17.117.1
                                  Jan 15, 2025 17:48:12.832217932 CET50267445192.168.2.5129.17.117.1
                                  Jan 15, 2025 17:48:12.837069988 CET44550267129.17.117.1192.168.2.5
                                  Jan 15, 2025 17:48:12.837105989 CET44550267129.17.117.1192.168.2.5
                                  Jan 15, 2025 17:48:13.015163898 CET50488445192.168.2.578.130.181.2
                                  Jan 15, 2025 17:48:13.020389080 CET4455048878.130.181.2192.168.2.5
                                  Jan 15, 2025 17:48:13.020494938 CET50488445192.168.2.578.130.181.2
                                  Jan 15, 2025 17:48:13.023334980 CET50488445192.168.2.578.130.181.2
                                  Jan 15, 2025 17:48:13.028255939 CET4455048878.130.181.2192.168.2.5
                                  Jan 15, 2025 17:48:13.832571030 CET44550274208.140.179.1192.168.2.5
                                  Jan 15, 2025 17:48:13.832649946 CET50274445192.168.2.5208.140.179.1
                                  Jan 15, 2025 17:48:13.832679987 CET50274445192.168.2.5208.140.179.1
                                  Jan 15, 2025 17:48:13.832710028 CET50274445192.168.2.5208.140.179.1
                                  Jan 15, 2025 17:48:13.837620974 CET44550274208.140.179.1192.168.2.5
                                  Jan 15, 2025 17:48:13.837635994 CET44550274208.140.179.1192.168.2.5
                                  Jan 15, 2025 17:48:13.890286922 CET50521445192.168.2.5208.140.179.2
                                  Jan 15, 2025 17:48:13.895349979 CET44550521208.140.179.2192.168.2.5
                                  Jan 15, 2025 17:48:13.895474911 CET50521445192.168.2.5208.140.179.2
                                  Jan 15, 2025 17:48:13.895514965 CET50521445192.168.2.5208.140.179.2
                                  Jan 15, 2025 17:48:13.895821095 CET50522445192.168.2.5208.140.179.2
                                  Jan 15, 2025 17:48:13.900506020 CET44550521208.140.179.2192.168.2.5
                                  Jan 15, 2025 17:48:13.900587082 CET50521445192.168.2.5208.140.179.2
                                  Jan 15, 2025 17:48:13.900734901 CET44550522208.140.179.2192.168.2.5
                                  Jan 15, 2025 17:48:13.900811911 CET50522445192.168.2.5208.140.179.2
                                  Jan 15, 2025 17:48:13.900851011 CET50522445192.168.2.5208.140.179.2
                                  Jan 15, 2025 17:48:13.905657053 CET44550522208.140.179.2192.168.2.5
                                  Jan 15, 2025 17:48:14.140188932 CET50535445192.168.2.5216.60.73.1
                                  Jan 15, 2025 17:48:14.145436049 CET44550535216.60.73.1192.168.2.5
                                  Jan 15, 2025 17:48:14.145600080 CET50535445192.168.2.5216.60.73.1
                                  Jan 15, 2025 17:48:14.145644903 CET50535445192.168.2.5216.60.73.1
                                  Jan 15, 2025 17:48:14.150485992 CET44550535216.60.73.1192.168.2.5
                                  Jan 15, 2025 17:48:14.334319115 CET44550281126.75.17.1192.168.2.5
                                  Jan 15, 2025 17:48:14.334459066 CET50281445192.168.2.5126.75.17.1
                                  Jan 15, 2025 17:48:14.334518909 CET50281445192.168.2.5126.75.17.1
                                  Jan 15, 2025 17:48:14.334518909 CET50281445192.168.2.5126.75.17.1
                                  Jan 15, 2025 17:48:14.339418888 CET44550281126.75.17.1192.168.2.5
                                  Jan 15, 2025 17:48:14.339431047 CET44550281126.75.17.1192.168.2.5
                                  Jan 15, 2025 17:48:15.719032049 CET4455029535.81.47.1192.168.2.5
                                  Jan 15, 2025 17:48:15.719141006 CET50295445192.168.2.535.81.47.1
                                  Jan 15, 2025 17:48:15.796910048 CET44550296154.83.26.1192.168.2.5
                                  Jan 15, 2025 17:48:15.796991110 CET50296445192.168.2.5154.83.26.1
                                  Jan 15, 2025 17:48:16.191873074 CET50385445192.168.2.577.53.16.2
                                  Jan 15, 2025 17:48:16.191926956 CET50295445192.168.2.535.81.47.1
                                  Jan 15, 2025 17:48:16.191940069 CET50346445192.168.2.5194.183.238.2
                                  Jan 15, 2025 17:48:16.191968918 CET50365445192.168.2.525.38.30.2
                                  Jan 15, 2025 17:48:16.191997051 CET50378445192.168.2.5218.112.212.2
                                  Jan 15, 2025 17:48:16.192033052 CET50473445192.168.2.531.52.246.1
                                  Jan 15, 2025 17:48:16.192084074 CET50325445192.168.2.565.166.2.2
                                  Jan 15, 2025 17:48:16.192137003 CET50296445192.168.2.5154.83.26.1
                                  Jan 15, 2025 17:48:16.192168951 CET50305445192.168.2.588.125.174.1
                                  Jan 15, 2025 17:48:16.192183971 CET50311445192.168.2.52.6.237.1
                                  Jan 15, 2025 17:48:16.192214966 CET50318445192.168.2.588.23.242.1
                                  Jan 15, 2025 17:48:16.192245960 CET50329445192.168.2.5116.101.184.1
                                  Jan 15, 2025 17:48:16.192269087 CET50334445192.168.2.5126.122.68.1
                                  Jan 15, 2025 17:48:16.192312956 CET50342445192.168.2.5193.204.71.1
                                  Jan 15, 2025 17:48:16.192403078 CET50352445192.168.2.5116.74.169.1
                                  Jan 15, 2025 17:48:16.192449093 CET50354445192.168.2.540.64.79.1
                                  Jan 15, 2025 17:48:16.192497015 CET50363445192.168.2.5170.97.32.1
                                  Jan 15, 2025 17:48:16.192526102 CET50369445192.168.2.555.191.105.1
                                  Jan 15, 2025 17:48:16.192553043 CET50372445192.168.2.576.82.8.1
                                  Jan 15, 2025 17:48:16.192645073 CET50380445192.168.2.533.180.119.1
                                  Jan 15, 2025 17:48:16.192672968 CET50405445192.168.2.594.215.143.2
                                  Jan 15, 2025 17:48:16.192676067 CET50376445192.168.2.52.139.197.1
                                  Jan 15, 2025 17:48:16.192701101 CET50398445192.168.2.513.229.164.2
                                  Jan 15, 2025 17:48:16.192728043 CET50407445192.168.2.563.217.137.1
                                  Jan 15, 2025 17:48:16.192760944 CET50422445192.168.2.5101.5.197.2
                                  Jan 15, 2025 17:48:16.192780972 CET50458445192.168.2.541.240.115.2
                                  Jan 15, 2025 17:48:16.192805052 CET50432445192.168.2.5144.29.150.1
                                  Jan 15, 2025 17:48:16.192884922 CET50488445192.168.2.578.130.181.2
                                  Jan 15, 2025 17:48:16.193022966 CET50522445192.168.2.5208.140.179.2
                                  Jan 15, 2025 17:48:16.193078041 CET50535445192.168.2.5216.60.73.1
                                  Jan 15, 2025 17:48:23.636367083 CET50638443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:23.636471987 CET4435063840.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:23.636550903 CET50638443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:23.637171984 CET50638443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:23.637209892 CET4435063840.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:24.602288961 CET4435063840.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:24.602408886 CET50638443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:24.604413986 CET50638443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:24.604430914 CET4435063840.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:24.604646921 CET4435063840.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:24.606051922 CET50638443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:24.606113911 CET50638443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:24.606120110 CET4435063840.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:24.606211901 CET50638443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:24.647336960 CET4435063840.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:24.782958984 CET4435063840.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:24.783668995 CET4435063840.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:24.783735037 CET50638443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:24.783926010 CET50638443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:24.783972979 CET4435063840.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:24.784003973 CET50638443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:35.803148985 CET50639443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:35.803225994 CET4435063940.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:35.803348064 CET50639443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:35.803863049 CET50639443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:35.803884983 CET4435063940.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:36.597363949 CET4435063940.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:36.597512007 CET50639443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:36.599288940 CET50639443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:36.599301100 CET4435063940.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:36.599528074 CET4435063940.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:36.600969076 CET50639443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:36.601008892 CET50639443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:36.601013899 CET4435063940.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:36.601150036 CET50639443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:36.643326998 CET4435063940.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:36.771465063 CET4435063940.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:36.771562099 CET4435063940.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:36.771621943 CET50639443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:36.771785975 CET50639443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:48:36.771809101 CET4435063940.115.3.253192.168.2.5
                                  Jan 15, 2025 17:48:43.124310017 CET49710443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:48:43.124376059 CET49706443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:48:43.124485970 CET4970780192.168.2.5199.232.210.172
                                  Jan 15, 2025 17:48:43.129554033 CET4434971040.126.32.133192.168.2.5
                                  Jan 15, 2025 17:48:43.129663944 CET49710443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:48:43.129914045 CET4434970640.126.32.133192.168.2.5
                                  Jan 15, 2025 17:48:43.129977942 CET49706443192.168.2.540.126.32.133
                                  Jan 15, 2025 17:48:43.130024910 CET8049707199.232.210.172192.168.2.5
                                  Jan 15, 2025 17:48:43.130084038 CET4970780192.168.2.5199.232.210.172
                                  Jan 15, 2025 17:49:03.659235954 CET50640443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:49:03.659277916 CET4435064040.115.3.253192.168.2.5
                                  Jan 15, 2025 17:49:03.659406900 CET50640443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:49:03.660096884 CET50640443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:49:03.660111904 CET4435064040.115.3.253192.168.2.5
                                  Jan 15, 2025 17:49:04.470436096 CET4435064040.115.3.253192.168.2.5
                                  Jan 15, 2025 17:49:04.470529079 CET50640443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:49:04.472454071 CET50640443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:49:04.472465992 CET4435064040.115.3.253192.168.2.5
                                  Jan 15, 2025 17:49:04.472671986 CET4435064040.115.3.253192.168.2.5
                                  Jan 15, 2025 17:49:04.474419117 CET50640443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:49:04.474493027 CET50640443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:49:04.474498034 CET4435064040.115.3.253192.168.2.5
                                  Jan 15, 2025 17:49:04.474605083 CET50640443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:49:04.519326925 CET4435064040.115.3.253192.168.2.5
                                  Jan 15, 2025 17:49:04.655123949 CET4435064040.115.3.253192.168.2.5
                                  Jan 15, 2025 17:49:04.655200958 CET4435064040.115.3.253192.168.2.5
                                  Jan 15, 2025 17:49:04.655539989 CET50640443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:49:04.655698061 CET50640443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:49:04.655716896 CET4435064040.115.3.253192.168.2.5
                                  Jan 15, 2025 17:49:09.663239956 CET50641443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:49:09.663356066 CET4435064140.115.3.253192.168.2.5
                                  Jan 15, 2025 17:49:09.663454056 CET50641443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:49:09.664192915 CET50641443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:49:09.664230108 CET4435064140.115.3.253192.168.2.5
                                  Jan 15, 2025 17:49:10.477025986 CET4435064140.115.3.253192.168.2.5
                                  Jan 15, 2025 17:49:10.477189064 CET50641443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:49:10.478678942 CET50641443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:49:10.478714943 CET4435064140.115.3.253192.168.2.5
                                  Jan 15, 2025 17:49:10.478956938 CET4435064140.115.3.253192.168.2.5
                                  Jan 15, 2025 17:49:10.480289936 CET50641443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:49:10.480348110 CET50641443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:49:10.480360985 CET4435064140.115.3.253192.168.2.5
                                  Jan 15, 2025 17:49:10.480478048 CET50641443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:49:10.527342081 CET4435064140.115.3.253192.168.2.5
                                  Jan 15, 2025 17:49:10.698990107 CET4435064140.115.3.253192.168.2.5
                                  Jan 15, 2025 17:49:10.699073076 CET4435064140.115.3.253192.168.2.5
                                  Jan 15, 2025 17:49:10.699157953 CET50641443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:49:10.699367046 CET50641443192.168.2.540.115.3.253
                                  Jan 15, 2025 17:49:10.699408054 CET4435064140.115.3.253192.168.2.5
                                  TimestampSource PortDest PortSource IPDest IP
                                  Jan 15, 2025 17:47:08.760607958 CET6547853192.168.2.51.1.1.1
                                  Jan 15, 2025 17:47:09.070542097 CET53654781.1.1.1192.168.2.5
                                  Jan 15, 2025 17:47:09.684875965 CET6320153192.168.2.51.1.1.1
                                  Jan 15, 2025 17:47:10.017946005 CET53632011.1.1.1192.168.2.5
                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                  Jan 15, 2025 17:47:08.760607958 CET192.168.2.51.1.1.10x6a21Standard query (0)www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comA (IP address)IN (0x0001)false
                                  Jan 15, 2025 17:47:09.684875965 CET192.168.2.51.1.1.10x3af9Standard query (0)ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.comA (IP address)IN (0x0001)false
                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                  Jan 15, 2025 17:47:06.137216091 CET1.1.1.1192.168.2.50x70d8No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                                  Jan 15, 2025 17:47:06.137216091 CET1.1.1.1192.168.2.50x70d8No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                                  Jan 15, 2025 17:47:09.070542097 CET1.1.1.1192.168.2.50x6a21No error (0)www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com103.224.212.215A (IP address)IN (0x0001)false
                                  Jan 15, 2025 17:47:10.017946005 CET1.1.1.1192.168.2.50x3af9No error (0)ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com77026.bodis.comCNAME (Canonical name)IN (0x0001)false
                                  Jan 15, 2025 17:47:10.017946005 CET1.1.1.1192.168.2.50x3af9No error (0)77026.bodis.com199.59.243.228A (IP address)IN (0x0001)false
                                  • www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                  • ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  0192.168.2.549717103.224.212.215803292C:\Windows\mssecsvr.exe
                                  TimestampBytes transferredDirectionData
                                  Jan 15, 2025 17:47:09.082789898 CET100OUTGET / HTTP/1.1
                                  Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                  Cache-Control: no-cache
                                  Jan 15, 2025 17:47:09.680531025 CET365INHTTP/1.1 302 Found
                                  date: Wed, 15 Jan 2025 16:47:09 GMT
                                  server: Apache
                                  set-cookie: __tad=1736959629.6434080; expires=Sat, 13-Jan-2035 16:47:09 GMT; Max-Age=315360000
                                  location: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250116-0347-098f-a7ce-9f0e9ab6a8f5
                                  content-length: 2
                                  content-type: text/html; charset=UTF-8
                                  connection: close
                                  Data Raw: 0a 0a
                                  Data Ascii:


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  1192.168.2.549719199.59.243.228803292C:\Windows\mssecsvr.exe
                                  TimestampBytes transferredDirectionData
                                  Jan 15, 2025 17:47:10.023938894 CET169OUTGET /?subid1=20250116-0347-098f-a7ce-9f0e9ab6a8f5 HTTP/1.1
                                  Cache-Control: no-cache
                                  Host: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                  Connection: Keep-Alive
                                  Jan 15, 2025 17:47:10.521435976 CET1236INHTTP/1.1 200 OK
                                  date: Wed, 15 Jan 2025 16:47:10 GMT
                                  content-type: text/html; charset=utf-8
                                  content-length: 1262
                                  x-request-id: 16b7b141-0abf-4f9e-8c4f-1c3090e5ffce
                                  cache-control: no-store, max-age=0
                                  accept-ch: sec-ch-prefers-color-scheme
                                  critical-ch: sec-ch-prefers-color-scheme
                                  vary: sec-ch-prefers-color-scheme
                                  x-adblock-key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_VykpxZ409fFQw1xIZg05V+iNG10Gq/Bl2hfVcqvuD11/yDInZKr8UwiNhOy/Epe+3ux+Pac6dpZ+QPzq5mX8Qg==
                                  set-cookie: parking_session=16b7b141-0abf-4f9e-8c4f-1c3090e5ffce; expires=Wed, 15 Jan 2025 17:02:10 GMT; path=/
                                  Data Raw: 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 64 61 74 61 2d 61 64 62 6c 6f 63 6b 6b 65 79 3d 22 4d 46 77 77 44 51 59 4a 4b 6f 5a 49 68 76 63 4e 41 51 45 42 42 51 41 44 53 77 41 77 53 41 4a 42 41 4e 44 72 70 32 6c 7a 37 41 4f 6d 41 44 61 4e 38 74 41 35 30 4c 73 57 63 6a 4c 46 79 51 46 63 62 2f 50 32 54 78 63 35 38 6f 59 4f 65 49 4c 62 33 76 42 77 37 4a 36 66 34 70 61 6d 6b 41 51 56 53 51 75 71 59 73 4b 78 33 59 7a 64 55 48 43 76 62 56 5a 76 46 55 73 43 41 77 45 41 41 51 3d 3d 5f 56 79 6b 70 78 5a 34 30 39 66 46 51 77 31 78 49 5a 67 30 35 56 2b 69 4e 47 31 30 47 71 2f 42 6c 32 68 66 56 63 71 76 75 44 31 31 2f 79 44 49 6e 5a 4b 72 38 55 77 69 4e 68 4f 79 2f 45 70 65 2b 33 75 78 2b 50 61 63 36 64 70 5a 2b 51 50 7a 71 35 6d 58 38 51 67 3d 3d 22 20 6c 61 6e 67 3d 22 65 6e 22 20 73 74 79 6c 65 3d 22 62 61 63 6b 67 72 6f 75 6e 64 3a 20 23 32 42 32 42 32 42 3b 22 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 6d [TRUNCATED]
                                  Data Ascii: <!doctype html><html data-adblockkey="MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_VykpxZ409fFQw1xIZg05V+iNG10Gq/Bl2hfVcqvuD11/yDInZKr8UwiNhOy/Epe+3ux+Pac6dpZ+QPzq5mX8Qg==" lang="en" style="background: #2B2B2B;"><head> <meta charset="utf-8"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link rel="icon" href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAIAAACQd1PeAAAADElEQVQI12P4//8/AAX+Av7czFnnAAAAAElFTkSuQmCC"> <link rel="pr
                                  Jan 15, 2025 17:47:10.521452904 CET696INData Raw: 65 63 6f 6e 6e 65 63 74 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 64 69 76 20 69 64 3d 22 74 61 72 67 65
                                  Data Ascii: econnect" href="https://www.google.com" crossorigin></head><body><div id="target" style="opacity: 0"></div><script>window.park = "eyJ1dWlkIjoiMTZiN2IxNDEtMGFiZi00ZjllLThjNGYtMWMzMDkwZTVmZmNlIiwicGFnZV90aW1lIjoxNzM2OTU5NjMwLCJwYWdlX3VybCI6I


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  2192.168.2.549720103.224.212.215806640C:\Windows\mssecsvr.exe
                                  TimestampBytes transferredDirectionData
                                  Jan 15, 2025 17:47:10.770787954 CET100OUTGET / HTTP/1.1
                                  Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                  Cache-Control: no-cache
                                  Jan 15, 2025 17:47:11.364633083 CET365INHTTP/1.1 302 Found
                                  date: Wed, 15 Jan 2025 16:47:11 GMT
                                  server: Apache
                                  set-cookie: __tad=1736959631.7349370; expires=Sat, 13-Jan-2035 16:47:11 GMT; Max-Age=315360000
                                  location: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250116-0347-119b-90f6-837dd48231ad
                                  content-length: 2
                                  content-type: text/html; charset=UTF-8
                                  connection: close
                                  Data Raw: 0a 0a
                                  Data Ascii:


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  3192.168.2.549721199.59.243.228806640C:\Windows\mssecsvr.exe
                                  TimestampBytes transferredDirectionData
                                  Jan 15, 2025 17:47:11.377120018 CET169OUTGET /?subid1=20250116-0347-119b-90f6-837dd48231ad HTTP/1.1
                                  Cache-Control: no-cache
                                  Host: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                  Connection: Keep-Alive
                                  Jan 15, 2025 17:47:11.840775013 CET1236INHTTP/1.1 200 OK
                                  date: Wed, 15 Jan 2025 16:47:11 GMT
                                  content-type: text/html; charset=utf-8
                                  content-length: 1262
                                  x-request-id: 76cd02e5-be51-46c7-bf9d-ed2841b01ee7
                                  cache-control: no-store, max-age=0
                                  accept-ch: sec-ch-prefers-color-scheme
                                  critical-ch: sec-ch-prefers-color-scheme
                                  vary: sec-ch-prefers-color-scheme
                                  x-adblock-key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_XKhAs+dmRJFmIXAJnc7hv0FuEttwIWTZf5ULe7v8qTntP+3TuZ3qh/UuqW5pySY3R7lPiF5AWHUss8opPFKYdg==
                                  set-cookie: parking_session=76cd02e5-be51-46c7-bf9d-ed2841b01ee7; expires=Wed, 15 Jan 2025 17:02:11 GMT; path=/
                                  Data Raw: 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 64 61 74 61 2d 61 64 62 6c 6f 63 6b 6b 65 79 3d 22 4d 46 77 77 44 51 59 4a 4b 6f 5a 49 68 76 63 4e 41 51 45 42 42 51 41 44 53 77 41 77 53 41 4a 42 41 4e 44 72 70 32 6c 7a 37 41 4f 6d 41 44 61 4e 38 74 41 35 30 4c 73 57 63 6a 4c 46 79 51 46 63 62 2f 50 32 54 78 63 35 38 6f 59 4f 65 49 4c 62 33 76 42 77 37 4a 36 66 34 70 61 6d 6b 41 51 56 53 51 75 71 59 73 4b 78 33 59 7a 64 55 48 43 76 62 56 5a 76 46 55 73 43 41 77 45 41 41 51 3d 3d 5f 58 4b 68 41 73 2b 64 6d 52 4a 46 6d 49 58 41 4a 6e 63 37 68 76 30 46 75 45 74 74 77 49 57 54 5a 66 35 55 4c 65 37 76 38 71 54 6e 74 50 2b 33 54 75 5a 33 71 68 2f 55 75 71 57 35 70 79 53 59 33 52 37 6c 50 69 46 35 41 57 48 55 73 73 38 6f 70 50 46 4b 59 64 67 3d 3d 22 20 6c 61 6e 67 3d 22 65 6e 22 20 73 74 79 6c 65 3d 22 62 61 63 6b 67 72 6f 75 6e 64 3a 20 23 32 42 32 42 32 42 3b 22 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 6d [TRUNCATED]
                                  Data Ascii: <!doctype html><html data-adblockkey="MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_XKhAs+dmRJFmIXAJnc7hv0FuEttwIWTZf5ULe7v8qTntP+3TuZ3qh/UuqW5pySY3R7lPiF5AWHUss8opPFKYdg==" lang="en" style="background: #2B2B2B;"><head> <meta charset="utf-8"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link rel="icon" href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAIAAACQd1PeAAAADElEQVQI12P4//8/AAX+Av7czFnnAAAAAElFTkSuQmCC"> <link rel="pr
                                  Jan 15, 2025 17:47:11.840790987 CET696INData Raw: 65 63 6f 6e 6e 65 63 74 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 64 69 76 20 69 64 3d 22 74 61 72 67 65
                                  Data Ascii: econnect" href="https://www.google.com" crossorigin></head><body><div id="target" style="opacity: 0"></div><script>window.park = "eyJ1dWlkIjoiNzZjZDAyZTUtYmU1MS00NmM3LWJmOWQtZWQyODQxYjAxZWU3IiwicGFnZV90aW1lIjoxNzM2OTU5NjMxLCJwYWdlX3VybCI6I


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  4192.168.2.549722103.224.212.215802380C:\Windows\mssecsvr.exe
                                  TimestampBytes transferredDirectionData
                                  Jan 15, 2025 17:47:11.615814924 CET134OUTGET / HTTP/1.1
                                  Host: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                  Cache-Control: no-cache
                                  Cookie: __tad=1736959629.6434080
                                  Jan 15, 2025 17:47:12.209203959 CET269INHTTP/1.1 302 Found
                                  date: Wed, 15 Jan 2025 16:47:12 GMT
                                  server: Apache
                                  location: http://ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/?subid1=20250116-0347-12c5-b838-b08634650efc
                                  content-length: 2
                                  content-type: text/html; charset=UTF-8
                                  connection: close
                                  Data Raw: 0a 0a
                                  Data Ascii:


                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                  5192.168.2.549734199.59.243.228802380C:\Windows\mssecsvr.exe
                                  TimestampBytes transferredDirectionData
                                  Jan 15, 2025 17:47:12.217854023 CET231OUTGET /?subid1=20250116-0347-12c5-b838-b08634650efc HTTP/1.1
                                  Cache-Control: no-cache
                                  Host: ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                  Connection: Keep-Alive
                                  Cookie: parking_session=16b7b141-0abf-4f9e-8c4f-1c3090e5ffce
                                  Jan 15, 2025 17:47:12.675833941 CET1236INHTTP/1.1 200 OK
                                  date: Wed, 15 Jan 2025 16:47:11 GMT
                                  content-type: text/html; charset=utf-8
                                  content-length: 1262
                                  x-request-id: 110f454e-bcdf-430f-b591-5c92798fe0ad
                                  cache-control: no-store, max-age=0
                                  accept-ch: sec-ch-prefers-color-scheme
                                  critical-ch: sec-ch-prefers-color-scheme
                                  vary: sec-ch-prefers-color-scheme
                                  x-adblock-key: MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_TFHPoQ09XhNUFqA8z9JCYW4zFuYAdH5PPDSLqrcqUmyw9eTaXBsoDPX25sWCFF2imdvS920XaIwtRzyXMX4shg==
                                  set-cookie: parking_session=16b7b141-0abf-4f9e-8c4f-1c3090e5ffce; expires=Wed, 15 Jan 2025 17:02:12 GMT
                                  Data Raw: 3c 21 64 6f 63 74 79 70 65 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 64 61 74 61 2d 61 64 62 6c 6f 63 6b 6b 65 79 3d 22 4d 46 77 77 44 51 59 4a 4b 6f 5a 49 68 76 63 4e 41 51 45 42 42 51 41 44 53 77 41 77 53 41 4a 42 41 4e 44 72 70 32 6c 7a 37 41 4f 6d 41 44 61 4e 38 74 41 35 30 4c 73 57 63 6a 4c 46 79 51 46 63 62 2f 50 32 54 78 63 35 38 6f 59 4f 65 49 4c 62 33 76 42 77 37 4a 36 66 34 70 61 6d 6b 41 51 56 53 51 75 71 59 73 4b 78 33 59 7a 64 55 48 43 76 62 56 5a 76 46 55 73 43 41 77 45 41 41 51 3d 3d 5f 54 46 48 50 6f 51 30 39 58 68 4e 55 46 71 41 38 7a 39 4a 43 59 57 34 7a 46 75 59 41 64 48 35 50 50 44 53 4c 71 72 63 71 55 6d 79 77 39 65 54 61 58 42 73 6f 44 50 58 32 35 73 57 43 46 46 32 69 6d 64 76 53 39 32 30 58 61 49 77 74 52 7a 79 58 4d 58 34 73 68 67 3d 3d 22 20 6c 61 6e 67 3d 22 65 6e 22 20 73 74 79 6c 65 3d 22 62 61 63 6b 67 72 6f 75 6e 64 3a 20 23 32 42 32 42 32 42 3b 22 3e 0a 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 6d [TRUNCATED]
                                  Data Ascii: <!doctype html><html data-adblockkey="MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDrp2lz7AOmADaN8tA50LsWcjLFyQFcb/P2Txc58oYOeILb3vBw7J6f4pamkAQVSQuqYsKx3YzdUHCvbVZvFUsCAwEAAQ==_TFHPoQ09XhNUFqA8z9JCYW4zFuYAdH5PPDSLqrcqUmyw9eTaXBsoDPX25sWCFF2imdvS920XaIwtRzyXMX4shg==" lang="en" style="background: #2B2B2B;"><head> <meta charset="utf-8"> <meta name="viewport" content="width=device-width, initial-scale=1"> <link rel="icon" href="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAAEAAAABCAIAAACQd1PeAAAADElEQVQI12P4//8/AAX+Av7czFnnAAAAAElFTkSuQmCC"> <link rel="preconnect
                                  Jan 15, 2025 17:47:12.675851107 CET688INData Raw: 22 20 68 72 65 66 3d 22 68 74 74 70 73 3a 2f 2f 77 77 77 2e 67 6f 6f 67 6c 65 2e 63 6f 6d 22 20 63 72 6f 73 73 6f 72 69 67 69 6e 3e 0a 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 64 69 76 20 69 64 3d 22 74 61 72 67 65 74 22 20 73 74 79 6c 65
                                  Data Ascii: " href="https://www.google.com" crossorigin></head><body><div id="target" style="opacity: 0"></div><script>window.park = "eyJ1dWlkIjoiMTZiN2IxNDEtMGFiZi00ZjllLThjNGYtMWMzMDkwZTVmZmNlIiwicGFnZV90aW1lIjoxNzM2OTU5NjMyLCJwYWdlX3VybCI6Imh0dHA6L


                                  Session IDSource IPSource PortDestination IPDestination Port
                                  0192.168.2.54971240.115.3.253443
                                  TimestampBytes transferredDirectionData
                                  2025-01-15 16:47:05 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 33 33 61 36 69 37 39 66 4b 55 57 68 39 45 56 49 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 39 33 65 39 30 39 30 33 30 36 63 33 62 35 33 65 0d 0a 0d 0a
                                  Data Ascii: CNT 1 CON 305MS-CV: 33a6i79fKUWh9EVI.1Context: 93e9090306c3b53e
                                  2025-01-15 16:47:05 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                                  Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                                  2025-01-15 16:47:05 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 33 33 61 36 69 37 39 66 4b 55 57 68 39 45 56 49 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 39 33 65 39 30 39 30 33 30 36 63 33 62 35 33 65 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 62 63 54 4c 76 42 36 55 4b 4b 61 52 6d 72 48 6e 76 55 58 6c 39 77 4c 53 63 61 76 49 64 44 78 6d 2f 4e 42 42 53 39 34 39 43 43 71 32 4c 72 6f 71 57 6c 34 6a 6c 64 45 31 79 4b 30 37 63 34 6b 70 48 37 30 73 52 4c 48 36 34 36 55 34 77 61 4f 70 65 4c 75 74 51 38 6a 6a 50 59 56 50 70 61 6d 6d 6c 4f 4e 6e 6e 64 4f 31 70 4c 4c 44 51
                                  Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: 33a6i79fKUWh9EVI.2Context: 93e9090306c3b53e<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAbcTLvB6UKKaRmrHnvUXl9wLScavIdDxm/NBBS949CCq2LroqWl4jldE1yK07c4kpH70sRLH646U4waOpeLutQ8jjPYVPpammlONnndO1pLLDQ
                                  2025-01-15 16:47:05 UTC74OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 51 4f 53 20 35 36 0d 0a 4d 53 2d 43 56 3a 20 33 33 61 36 69 37 39 66 4b 55 57 68 39 45 56 49 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 39 33 65 39 30 39 30 33 30 36 63 33 62 35 33 65 0d 0a 0d 0a
                                  Data Ascii: BND 3 CON\QOS 56MS-CV: 33a6i79fKUWh9EVI.3Context: 93e9090306c3b53e
                                  2025-01-15 16:47:05 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                  Data Ascii: 202 1 CON 58
                                  2025-01-15 16:47:05 UTC58INData Raw: 4d 53 2d 43 56 3a 20 35 78 72 36 4e 2f 38 42 4f 55 32 30 6a 73 34 78 68 78 30 64 71 67 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                  Data Ascii: MS-CV: 5xr6N/8BOU20js4xhx0dqg.0Payload parsing failed.


                                  Session IDSource IPSource PortDestination IPDestination Port
                                  1192.168.2.54971840.115.3.253443
                                  TimestampBytes transferredDirectionData
                                  2025-01-15 16:47:09 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 4a 76 43 76 2b 77 63 70 7a 30 65 58 64 50 50 7a 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 64 33 66 66 65 38 38 35 31 66 62 30 31 65 34 35 0d 0a 0d 0a
                                  Data Ascii: CNT 1 CON 305MS-CV: JvCv+wcpz0eXdPPz.1Context: d3ffe8851fb01e45
                                  2025-01-15 16:47:09 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                                  Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                                  2025-01-15 16:47:09 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 4a 76 43 76 2b 77 63 70 7a 30 65 58 64 50 50 7a 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 64 33 66 66 65 38 38 35 31 66 62 30 31 65 34 35 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 62 63 54 4c 76 42 36 55 4b 4b 61 52 6d 72 48 6e 76 55 58 6c 39 77 4c 53 63 61 76 49 64 44 78 6d 2f 4e 42 42 53 39 34 39 43 43 71 32 4c 72 6f 71 57 6c 34 6a 6c 64 45 31 79 4b 30 37 63 34 6b 70 48 37 30 73 52 4c 48 36 34 36 55 34 77 61 4f 70 65 4c 75 74 51 38 6a 6a 50 59 56 50 70 61 6d 6d 6c 4f 4e 6e 6e 64 4f 31 70 4c 4c 44 51
                                  Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: JvCv+wcpz0eXdPPz.2Context: d3ffe8851fb01e45<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAbcTLvB6UKKaRmrHnvUXl9wLScavIdDxm/NBBS949CCq2LroqWl4jldE1yK07c4kpH70sRLH646U4waOpeLutQ8jjPYVPpammlONnndO1pLLDQ
                                  2025-01-15 16:47:09 UTC74OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 51 4f 53 20 35 36 0d 0a 4d 53 2d 43 56 3a 20 4a 76 43 76 2b 77 63 70 7a 30 65 58 64 50 50 7a 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 64 33 66 66 65 38 38 35 31 66 62 30 31 65 34 35 0d 0a 0d 0a
                                  Data Ascii: BND 3 CON\QOS 56MS-CV: JvCv+wcpz0eXdPPz.3Context: d3ffe8851fb01e45
                                  2025-01-15 16:47:10 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                  Data Ascii: 202 1 CON 58
                                  2025-01-15 16:47:10 UTC58INData Raw: 4d 53 2d 43 56 3a 20 59 31 53 5a 58 51 6f 57 62 6b 47 53 4f 35 57 4b 79 67 4b 47 53 51 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                  Data Ascii: MS-CV: Y1SZXQoWbkGSO5WKygKGSQ.0Payload parsing failed.


                                  Session IDSource IPSource PortDestination IPDestination Port
                                  2192.168.2.54973740.115.3.253443
                                  TimestampBytes transferredDirectionData
                                  2025-01-15 16:47:13 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 6c 36 70 34 73 4e 6e 6b 54 45 57 31 31 6a 38 58 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 38 31 64 39 64 34 37 66 62 35 31 62 65 33 31 39 0d 0a 0d 0a
                                  Data Ascii: CNT 1 CON 305MS-CV: l6p4sNnkTEW11j8X.1Context: 81d9d47fb51be319
                                  2025-01-15 16:47:13 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                                  Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                                  2025-01-15 16:47:13 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 6c 36 70 34 73 4e 6e 6b 54 45 57 31 31 6a 38 58 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 38 31 64 39 64 34 37 66 62 35 31 62 65 33 31 39 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 62 63 54 4c 76 42 36 55 4b 4b 61 52 6d 72 48 6e 76 55 58 6c 39 77 4c 53 63 61 76 49 64 44 78 6d 2f 4e 42 42 53 39 34 39 43 43 71 32 4c 72 6f 71 57 6c 34 6a 6c 64 45 31 79 4b 30 37 63 34 6b 70 48 37 30 73 52 4c 48 36 34 36 55 34 77 61 4f 70 65 4c 75 74 51 38 6a 6a 50 59 56 50 70 61 6d 6d 6c 4f 4e 6e 6e 64 4f 31 70 4c 4c 44 51
                                  Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: l6p4sNnkTEW11j8X.2Context: 81d9d47fb51be319<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAbcTLvB6UKKaRmrHnvUXl9wLScavIdDxm/NBBS949CCq2LroqWl4jldE1yK07c4kpH70sRLH646U4waOpeLutQ8jjPYVPpammlONnndO1pLLDQ
                                  2025-01-15 16:47:13 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 6c 36 70 34 73 4e 6e 6b 54 45 57 31 31 6a 38 58 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 38 31 64 39 64 34 37 66 62 35 31 62 65 33 31 39 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                                  Data Ascii: BND 3 CON\WNS 0 197MS-CV: l6p4sNnkTEW11j8X.3Context: 81d9d47fb51be319<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                                  2025-01-15 16:47:13 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                  Data Ascii: 202 1 CON 58
                                  2025-01-15 16:47:13 UTC58INData Raw: 4d 53 2d 43 56 3a 20 36 6f 68 62 49 4d 38 70 38 45 2b 55 71 34 42 4a 70 6d 76 4f 57 51 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                  Data Ascii: MS-CV: 6ohbIM8p8E+Uq4BJpmvOWQ.0Payload parsing failed.


                                  Session IDSource IPSource PortDestination IPDestination Port
                                  3192.168.2.54981340.115.3.253443
                                  TimestampBytes transferredDirectionData
                                  2025-01-15 16:47:19 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 70 6d 43 63 6a 45 6b 36 59 45 2b 4d 31 79 32 7a 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 61 31 39 39 61 64 36 63 30 65 63 37 34 32 32 66 0d 0a 0d 0a
                                  Data Ascii: CNT 1 CON 305MS-CV: pmCcjEk6YE+M1y2z.1Context: a199ad6c0ec7422f
                                  2025-01-15 16:47:19 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                                  Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                                  2025-01-15 16:47:19 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 70 6d 43 63 6a 45 6b 36 59 45 2b 4d 31 79 32 7a 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 61 31 39 39 61 64 36 63 30 65 63 37 34 32 32 66 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 62 63 54 4c 76 42 36 55 4b 4b 61 52 6d 72 48 6e 76 55 58 6c 39 77 4c 53 63 61 76 49 64 44 78 6d 2f 4e 42 42 53 39 34 39 43 43 71 32 4c 72 6f 71 57 6c 34 6a 6c 64 45 31 79 4b 30 37 63 34 6b 70 48 37 30 73 52 4c 48 36 34 36 55 34 77 61 4f 70 65 4c 75 74 51 38 6a 6a 50 59 56 50 70 61 6d 6d 6c 4f 4e 6e 6e 64 4f 31 70 4c 4c 44 51
                                  Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: pmCcjEk6YE+M1y2z.2Context: a199ad6c0ec7422f<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAbcTLvB6UKKaRmrHnvUXl9wLScavIdDxm/NBBS949CCq2LroqWl4jldE1yK07c4kpH70sRLH646U4waOpeLutQ8jjPYVPpammlONnndO1pLLDQ
                                  2025-01-15 16:47:19 UTC74OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 51 4f 53 20 35 36 0d 0a 4d 53 2d 43 56 3a 20 70 6d 43 63 6a 45 6b 36 59 45 2b 4d 31 79 32 7a 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 61 31 39 39 61 64 36 63 30 65 63 37 34 32 32 66 0d 0a 0d 0a
                                  Data Ascii: BND 3 CON\QOS 56MS-CV: pmCcjEk6YE+M1y2z.3Context: a199ad6c0ec7422f
                                  2025-01-15 16:47:19 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                  Data Ascii: 202 1 CON 58
                                  2025-01-15 16:47:19 UTC58INData Raw: 4d 53 2d 43 56 3a 20 46 37 55 35 36 44 37 49 76 30 53 44 77 45 71 32 44 61 44 48 7a 67 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                  Data Ascii: MS-CV: F7U56D7Iv0SDwEq2DaDHzg.0Payload parsing failed.


                                  Session IDSource IPSource PortDestination IPDestination Port
                                  4192.168.2.54988540.115.3.253443
                                  TimestampBytes transferredDirectionData
                                  2025-01-15 16:47:23 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 6c 46 62 45 67 4a 65 54 78 6b 79 36 41 52 78 6d 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 33 66 63 31 64 36 38 38 37 39 36 35 36 31 62 64 0d 0a 0d 0a
                                  Data Ascii: CNT 1 CON 305MS-CV: lFbEgJeTxky6ARxm.1Context: 3fc1d688796561bd
                                  2025-01-15 16:47:23 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                                  Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                                  2025-01-15 16:47:23 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 6c 46 62 45 67 4a 65 54 78 6b 79 36 41 52 78 6d 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 33 66 63 31 64 36 38 38 37 39 36 35 36 31 62 64 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 62 63 54 4c 76 42 36 55 4b 4b 61 52 6d 72 48 6e 76 55 58 6c 39 77 4c 53 63 61 76 49 64 44 78 6d 2f 4e 42 42 53 39 34 39 43 43 71 32 4c 72 6f 71 57 6c 34 6a 6c 64 45 31 79 4b 30 37 63 34 6b 70 48 37 30 73 52 4c 48 36 34 36 55 34 77 61 4f 70 65 4c 75 74 51 38 6a 6a 50 59 56 50 70 61 6d 6d 6c 4f 4e 6e 6e 64 4f 31 70 4c 4c 44 51
                                  Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: lFbEgJeTxky6ARxm.2Context: 3fc1d688796561bd<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAbcTLvB6UKKaRmrHnvUXl9wLScavIdDxm/NBBS949CCq2LroqWl4jldE1yK07c4kpH70sRLH646U4waOpeLutQ8jjPYVPpammlONnndO1pLLDQ
                                  2025-01-15 16:47:23 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 6c 46 62 45 67 4a 65 54 78 6b 79 36 41 52 78 6d 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 33 66 63 31 64 36 38 38 37 39 36 35 36 31 62 64 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                                  Data Ascii: BND 3 CON\WNS 0 197MS-CV: lFbEgJeTxky6ARxm.3Context: 3fc1d688796561bd<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                                  2025-01-15 16:47:23 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                  Data Ascii: 202 1 CON 58
                                  2025-01-15 16:47:23 UTC58INData Raw: 4d 53 2d 43 56 3a 20 78 33 33 2b 52 44 6f 56 48 45 61 6a 7a 51 35 59 4d 66 58 49 62 67 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                  Data Ascii: MS-CV: x33+RDoVHEajzQ5YMfXIbg.0Payload parsing failed.


                                  Session IDSource IPSource PortDestination IPDestination Port
                                  5192.168.2.55006340.115.3.253443
                                  TimestampBytes transferredDirectionData
                                  2025-01-15 16:47:32 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 75 2f 6a 44 64 62 41 71 41 45 4f 44 43 77 47 6c 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 32 65 36 34 62 36 39 32 61 66 35 37 38 31 39 66 0d 0a 0d 0a
                                  Data Ascii: CNT 1 CON 305MS-CV: u/jDdbAqAEODCwGl.1Context: 2e64b692af57819f
                                  2025-01-15 16:47:32 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                                  Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                                  2025-01-15 16:47:32 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 75 2f 6a 44 64 62 41 71 41 45 4f 44 43 77 47 6c 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 32 65 36 34 62 36 39 32 61 66 35 37 38 31 39 66 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 62 63 54 4c 76 42 36 55 4b 4b 61 52 6d 72 48 6e 76 55 58 6c 39 77 4c 53 63 61 76 49 64 44 78 6d 2f 4e 42 42 53 39 34 39 43 43 71 32 4c 72 6f 71 57 6c 34 6a 6c 64 45 31 79 4b 30 37 63 34 6b 70 48 37 30 73 52 4c 48 36 34 36 55 34 77 61 4f 70 65 4c 75 74 51 38 6a 6a 50 59 56 50 70 61 6d 6d 6c 4f 4e 6e 6e 64 4f 31 70 4c 4c 44 51
                                  Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: u/jDdbAqAEODCwGl.2Context: 2e64b692af57819f<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAbcTLvB6UKKaRmrHnvUXl9wLScavIdDxm/NBBS949CCq2LroqWl4jldE1yK07c4kpH70sRLH646U4waOpeLutQ8jjPYVPpammlONnndO1pLLDQ
                                  2025-01-15 16:47:32 UTC74OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 51 4f 53 20 35 36 0d 0a 4d 53 2d 43 56 3a 20 75 2f 6a 44 64 62 41 71 41 45 4f 44 43 77 47 6c 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 32 65 36 34 62 36 39 32 61 66 35 37 38 31 39 66 0d 0a 0d 0a
                                  Data Ascii: BND 3 CON\QOS 56MS-CV: u/jDdbAqAEODCwGl.3Context: 2e64b692af57819f
                                  2025-01-15 16:47:32 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                  Data Ascii: 202 1 CON 58
                                  2025-01-15 16:47:32 UTC58INData Raw: 4d 53 2d 43 56 3a 20 61 50 59 6c 37 46 6b 38 48 45 79 32 75 62 79 63 44 43 49 36 38 77 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                  Data Ascii: MS-CV: aPYl7Fk8HEy2ubycDCI68w.0Payload parsing failed.


                                  Session IDSource IPSource PortDestination IPDestination Port
                                  6192.168.2.55017440.115.3.253443
                                  TimestampBytes transferredDirectionData
                                  2025-01-15 16:47:40 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 50 33 55 2b 4d 47 70 4b 4d 45 32 65 42 47 2f 56 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 35 35 62 32 30 32 65 61 38 32 30 32 35 65 33 64 0d 0a 0d 0a
                                  Data Ascii: CNT 1 CON 305MS-CV: P3U+MGpKME2eBG/V.1Context: 55b202ea82025e3d
                                  2025-01-15 16:47:40 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                                  Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                                  2025-01-15 16:47:40 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 50 33 55 2b 4d 47 70 4b 4d 45 32 65 42 47 2f 56 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 35 35 62 32 30 32 65 61 38 32 30 32 35 65 33 64 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 62 63 54 4c 76 42 36 55 4b 4b 61 52 6d 72 48 6e 76 55 58 6c 39 77 4c 53 63 61 76 49 64 44 78 6d 2f 4e 42 42 53 39 34 39 43 43 71 32 4c 72 6f 71 57 6c 34 6a 6c 64 45 31 79 4b 30 37 63 34 6b 70 48 37 30 73 52 4c 48 36 34 36 55 34 77 61 4f 70 65 4c 75 74 51 38 6a 6a 50 59 56 50 70 61 6d 6d 6c 4f 4e 6e 6e 64 4f 31 70 4c 4c 44 51
                                  Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: P3U+MGpKME2eBG/V.2Context: 55b202ea82025e3d<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAbcTLvB6UKKaRmrHnvUXl9wLScavIdDxm/NBBS949CCq2LroqWl4jldE1yK07c4kpH70sRLH646U4waOpeLutQ8jjPYVPpammlONnndO1pLLDQ
                                  2025-01-15 16:47:40 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 50 33 55 2b 4d 47 70 4b 4d 45 32 65 42 47 2f 56 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 35 35 62 32 30 32 65 61 38 32 30 32 35 65 33 64 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                                  Data Ascii: BND 3 CON\WNS 0 197MS-CV: P3U+MGpKME2eBG/V.3Context: 55b202ea82025e3d<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                                  2025-01-15 16:47:40 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                  Data Ascii: 202 1 CON 58
                                  2025-01-15 16:47:40 UTC58INData Raw: 4d 53 2d 43 56 3a 20 4a 43 4e 50 49 36 4d 58 5a 30 6d 58 6d 4c 2b 37 78 75 4f 79 30 41 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                  Data Ascii: MS-CV: JCNPI6MXZ0mXmL+7xuOy0A.0Payload parsing failed.


                                  Session IDSource IPSource PortDestination IPDestination Port
                                  7192.168.2.55028340.115.3.253443
                                  TimestampBytes transferredDirectionData
                                  2025-01-15 16:47:54 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 4e 4e 54 4f 6b 46 65 5a 4c 30 47 70 70 38 41 4f 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 35 65 38 62 36 33 32 61 64 34 62 32 39 35 39 37 0d 0a 0d 0a
                                  Data Ascii: CNT 1 CON 305MS-CV: NNTOkFeZL0Gpp8AO.1Context: 5e8b632ad4b29597
                                  2025-01-15 16:47:54 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                                  Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                                  2025-01-15 16:47:54 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 4e 4e 54 4f 6b 46 65 5a 4c 30 47 70 70 38 41 4f 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 35 65 38 62 36 33 32 61 64 34 62 32 39 35 39 37 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 62 63 54 4c 76 42 36 55 4b 4b 61 52 6d 72 48 6e 76 55 58 6c 39 77 4c 53 63 61 76 49 64 44 78 6d 2f 4e 42 42 53 39 34 39 43 43 71 32 4c 72 6f 71 57 6c 34 6a 6c 64 45 31 79 4b 30 37 63 34 6b 70 48 37 30 73 52 4c 48 36 34 36 55 34 77 61 4f 70 65 4c 75 74 51 38 6a 6a 50 59 56 50 70 61 6d 6d 6c 4f 4e 6e 6e 64 4f 31 70 4c 4c 44 51
                                  Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: NNTOkFeZL0Gpp8AO.2Context: 5e8b632ad4b29597<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAbcTLvB6UKKaRmrHnvUXl9wLScavIdDxm/NBBS949CCq2LroqWl4jldE1yK07c4kpH70sRLH646U4waOpeLutQ8jjPYVPpammlONnndO1pLLDQ
                                  2025-01-15 16:47:54 UTC74OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 51 4f 53 20 35 36 0d 0a 4d 53 2d 43 56 3a 20 4e 4e 54 4f 6b 46 65 5a 4c 30 47 70 70 38 41 4f 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 35 65 38 62 36 33 32 61 64 34 62 32 39 35 39 37 0d 0a 0d 0a
                                  Data Ascii: BND 3 CON\QOS 56MS-CV: NNTOkFeZL0Gpp8AO.3Context: 5e8b632ad4b29597
                                  2025-01-15 16:47:54 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                  Data Ascii: 202 1 CON 58
                                  2025-01-15 16:47:54 UTC58INData Raw: 4d 53 2d 43 56 3a 20 41 64 63 67 58 31 52 6d 72 55 43 79 37 44 54 7a 7a 42 2f 34 2f 41 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                  Data Ascii: MS-CV: AdcgX1RmrUCy7DTzzB/4/A.0Payload parsing failed.


                                  Session IDSource IPSource PortDestination IPDestination Port
                                  8192.168.2.55037340.115.3.253443
                                  TimestampBytes transferredDirectionData
                                  2025-01-15 16:48:04 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 5a 36 70 41 66 51 66 6d 66 55 61 38 35 6d 6e 57 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 39 38 38 64 65 30 30 66 39 32 65 61 39 32 33 33 0d 0a 0d 0a
                                  Data Ascii: CNT 1 CON 305MS-CV: Z6pAfQfmfUa85mnW.1Context: 988de00f92ea9233
                                  2025-01-15 16:48:04 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                                  Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                                  2025-01-15 16:48:04 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 5a 36 70 41 66 51 66 6d 66 55 61 38 35 6d 6e 57 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 39 38 38 64 65 30 30 66 39 32 65 61 39 32 33 33 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 62 63 54 4c 76 42 36 55 4b 4b 61 52 6d 72 48 6e 76 55 58 6c 39 77 4c 53 63 61 76 49 64 44 78 6d 2f 4e 42 42 53 39 34 39 43 43 71 32 4c 72 6f 71 57 6c 34 6a 6c 64 45 31 79 4b 30 37 63 34 6b 70 48 37 30 73 52 4c 48 36 34 36 55 34 77 61 4f 70 65 4c 75 74 51 38 6a 6a 50 59 56 50 70 61 6d 6d 6c 4f 4e 6e 6e 64 4f 31 70 4c 4c 44 51
                                  Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: Z6pAfQfmfUa85mnW.2Context: 988de00f92ea9233<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAbcTLvB6UKKaRmrHnvUXl9wLScavIdDxm/NBBS949CCq2LroqWl4jldE1yK07c4kpH70sRLH646U4waOpeLutQ8jjPYVPpammlONnndO1pLLDQ
                                  2025-01-15 16:48:04 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 5a 36 70 41 66 51 66 6d 66 55 61 38 35 6d 6e 57 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 39 38 38 64 65 30 30 66 39 32 65 61 39 32 33 33 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                                  Data Ascii: BND 3 CON\WNS 0 197MS-CV: Z6pAfQfmfUa85mnW.3Context: 988de00f92ea9233<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                                  2025-01-15 16:48:04 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                  Data Ascii: 202 1 CON 58
                                  2025-01-15 16:48:04 UTC58INData Raw: 4d 53 2d 43 56 3a 20 55 5a 58 6e 76 6a 4c 64 53 55 57 2b 6c 37 6e 54 46 4f 6c 46 56 41 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                  Data Ascii: MS-CV: UZXnvjLdSUW+l7nTFOlFVA.0Payload parsing failed.


                                  Session IDSource IPSource PortDestination IPDestination Port
                                  9192.168.2.55063840.115.3.253443
                                  TimestampBytes transferredDirectionData
                                  2025-01-15 16:48:24 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 32 48 48 5a 6f 4c 6b 47 72 55 65 6a 68 74 4e 49 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 33 35 65 32 36 65 66 32 64 64 36 33 35 30 64 65 0d 0a 0d 0a
                                  Data Ascii: CNT 1 CON 305MS-CV: 2HHZoLkGrUejhtNI.1Context: 35e26ef2dd6350de
                                  2025-01-15 16:48:24 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                                  Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                                  2025-01-15 16:48:24 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 32 48 48 5a 6f 4c 6b 47 72 55 65 6a 68 74 4e 49 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 33 35 65 32 36 65 66 32 64 64 36 33 35 30 64 65 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 62 63 54 4c 76 42 36 55 4b 4b 61 52 6d 72 48 6e 76 55 58 6c 39 77 4c 53 63 61 76 49 64 44 78 6d 2f 4e 42 42 53 39 34 39 43 43 71 32 4c 72 6f 71 57 6c 34 6a 6c 64 45 31 79 4b 30 37 63 34 6b 70 48 37 30 73 52 4c 48 36 34 36 55 34 77 61 4f 70 65 4c 75 74 51 38 6a 6a 50 59 56 50 70 61 6d 6d 6c 4f 4e 6e 6e 64 4f 31 70 4c 4c 44 51
                                  Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: 2HHZoLkGrUejhtNI.2Context: 35e26ef2dd6350de<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAbcTLvB6UKKaRmrHnvUXl9wLScavIdDxm/NBBS949CCq2LroqWl4jldE1yK07c4kpH70sRLH646U4waOpeLutQ8jjPYVPpammlONnndO1pLLDQ
                                  2025-01-15 16:48:24 UTC74OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 51 4f 53 20 35 36 0d 0a 4d 53 2d 43 56 3a 20 32 48 48 5a 6f 4c 6b 47 72 55 65 6a 68 74 4e 49 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 33 35 65 32 36 65 66 32 64 64 36 33 35 30 64 65 0d 0a 0d 0a
                                  Data Ascii: BND 3 CON\QOS 56MS-CV: 2HHZoLkGrUejhtNI.3Context: 35e26ef2dd6350de
                                  2025-01-15 16:48:24 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                  Data Ascii: 202 1 CON 58
                                  2025-01-15 16:48:24 UTC58INData Raw: 4d 53 2d 43 56 3a 20 49 55 68 59 79 64 7a 35 37 55 53 75 58 56 2b 68 45 37 6d 66 2b 51 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                  Data Ascii: MS-CV: IUhYydz57USuXV+hE7mf+Q.0Payload parsing failed.


                                  Session IDSource IPSource PortDestination IPDestination Port
                                  10192.168.2.55063940.115.3.253443
                                  TimestampBytes transferredDirectionData
                                  2025-01-15 16:48:36 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 4c 72 30 4c 4a 76 56 4b 57 6b 75 57 49 6b 31 39 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 66 39 63 31 36 61 33 61 32 64 39 31 37 65 30 65 0d 0a 0d 0a
                                  Data Ascii: CNT 1 CON 305MS-CV: Lr0LJvVKWkuWIk19.1Context: f9c16a3a2d917e0e
                                  2025-01-15 16:48:36 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                                  Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                                  2025-01-15 16:48:36 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 4c 72 30 4c 4a 76 56 4b 57 6b 75 57 49 6b 31 39 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 66 39 63 31 36 61 33 61 32 64 39 31 37 65 30 65 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 62 63 54 4c 76 42 36 55 4b 4b 61 52 6d 72 48 6e 76 55 58 6c 39 77 4c 53 63 61 76 49 64 44 78 6d 2f 4e 42 42 53 39 34 39 43 43 71 32 4c 72 6f 71 57 6c 34 6a 6c 64 45 31 79 4b 30 37 63 34 6b 70 48 37 30 73 52 4c 48 36 34 36 55 34 77 61 4f 70 65 4c 75 74 51 38 6a 6a 50 59 56 50 70 61 6d 6d 6c 4f 4e 6e 6e 64 4f 31 70 4c 4c 44 51
                                  Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: Lr0LJvVKWkuWIk19.2Context: f9c16a3a2d917e0e<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAbcTLvB6UKKaRmrHnvUXl9wLScavIdDxm/NBBS949CCq2LroqWl4jldE1yK07c4kpH70sRLH646U4waOpeLutQ8jjPYVPpammlONnndO1pLLDQ
                                  2025-01-15 16:48:36 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 4c 72 30 4c 4a 76 56 4b 57 6b 75 57 49 6b 31 39 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 66 39 63 31 36 61 33 61 32 64 39 31 37 65 30 65 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                                  Data Ascii: BND 3 CON\WNS 0 197MS-CV: Lr0LJvVKWkuWIk19.3Context: f9c16a3a2d917e0e<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                                  2025-01-15 16:48:36 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                  Data Ascii: 202 1 CON 58
                                  2025-01-15 16:48:36 UTC58INData Raw: 4d 53 2d 43 56 3a 20 2f 73 62 4e 62 32 73 6d 52 30 79 68 68 79 4b 34 33 48 55 2f 46 67 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                  Data Ascii: MS-CV: /sbNb2smR0yhhyK43HU/Fg.0Payload parsing failed.


                                  Session IDSource IPSource PortDestination IPDestination Port
                                  11192.168.2.55064040.115.3.253443
                                  TimestampBytes transferredDirectionData
                                  2025-01-15 16:49:04 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 4e 4d 41 61 37 33 4d 67 4c 45 53 38 79 50 47 6d 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 35 37 36 38 66 64 63 32 64 32 33 36 37 66 35 64 0d 0a 0d 0a
                                  Data Ascii: CNT 1 CON 305MS-CV: NMAa73MgLES8yPGm.1Context: 5768fdc2d2367f5d
                                  2025-01-15 16:49:04 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                                  Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                                  2025-01-15 16:49:04 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 4e 4d 41 61 37 33 4d 67 4c 45 53 38 79 50 47 6d 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 35 37 36 38 66 64 63 32 64 32 33 36 37 66 35 64 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 62 63 54 4c 76 42 36 55 4b 4b 61 52 6d 72 48 6e 76 55 58 6c 39 77 4c 53 63 61 76 49 64 44 78 6d 2f 4e 42 42 53 39 34 39 43 43 71 32 4c 72 6f 71 57 6c 34 6a 6c 64 45 31 79 4b 30 37 63 34 6b 70 48 37 30 73 52 4c 48 36 34 36 55 34 77 61 4f 70 65 4c 75 74 51 38 6a 6a 50 59 56 50 70 61 6d 6d 6c 4f 4e 6e 6e 64 4f 31 70 4c 4c 44 51
                                  Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: NMAa73MgLES8yPGm.2Context: 5768fdc2d2367f5d<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAbcTLvB6UKKaRmrHnvUXl9wLScavIdDxm/NBBS949CCq2LroqWl4jldE1yK07c4kpH70sRLH646U4waOpeLutQ8jjPYVPpammlONnndO1pLLDQ
                                  2025-01-15 16:49:04 UTC74OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 51 4f 53 20 35 36 0d 0a 4d 53 2d 43 56 3a 20 4e 4d 41 61 37 33 4d 67 4c 45 53 38 79 50 47 6d 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 35 37 36 38 66 64 63 32 64 32 33 36 37 66 35 64 0d 0a 0d 0a
                                  Data Ascii: BND 3 CON\QOS 56MS-CV: NMAa73MgLES8yPGm.3Context: 5768fdc2d2367f5d
                                  2025-01-15 16:49:04 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                  Data Ascii: 202 1 CON 58
                                  2025-01-15 16:49:04 UTC58INData Raw: 4d 53 2d 43 56 3a 20 44 5a 44 39 37 41 46 50 35 30 53 46 78 4c 7a 5a 42 44 67 34 54 67 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                  Data Ascii: MS-CV: DZD97AFP50SFxLzZBDg4Tg.0Payload parsing failed.


                                  Session IDSource IPSource PortDestination IPDestination Port
                                  12192.168.2.55064140.115.3.253443
                                  TimestampBytes transferredDirectionData
                                  2025-01-15 16:49:10 UTC71OUTData Raw: 43 4e 54 20 31 20 43 4f 4e 20 33 30 35 0d 0a 4d 53 2d 43 56 3a 20 68 4d 69 41 56 49 58 6c 36 45 79 34 30 51 2f 44 2e 31 0d 0a 43 6f 6e 74 65 78 74 3a 20 33 35 62 35 65 31 30 31 37 39 62 36 62 35 34 61 0d 0a 0d 0a
                                  Data Ascii: CNT 1 CON 305MS-CV: hMiAVIXl6Ey40Q/D.1Context: 35b5e10179b6b54a
                                  2025-01-15 16:49:10 UTC249OUTData Raw: 3c 63 6f 6e 6e 65 63 74 3e 3c 76 65 72 3e 32 3c 2f 76 65 72 3e 3c 61 67 65 6e 74 3e 3c 6f 73 3e 57 69 6e 64 6f 77 73 3c 2f 6f 73 3e 3c 6f 73 56 65 72 3e 31 30 2e 30 2e 30 2e 30 2e 31 39 30 34 35 3c 2f 6f 73 56 65 72 3e 3c 70 72 6f 63 3e 78 36 34 3c 2f 70 72 6f 63 3e 3c 6c 63 69 64 3e 65 6e 2d 43 48 3c 2f 6c 63 69 64 3e 3c 67 65 6f 49 64 3e 32 32 33 3c 2f 67 65 6f 49 64 3e 3c 61 6f 61 63 3e 30 3c 2f 61 6f 61 63 3e 3c 64 65 76 69 63 65 54 79 70 65 3e 31 3c 2f 64 65 76 69 63 65 54 79 70 65 3e 3c 64 65 76 69 63 65 4e 61 6d 65 3e 56 4d 77 61 72 65 32 30 2c 31 3c 2f 64 65 76 69 63 65 4e 61 6d 65 3e 3c 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 74 72 75 65 3c 2f 66 6f 6c 6c 6f 77 52 65 74 72 79 3e 3c 2f 61 67 65 6e 74 3e 3c 2f 63 6f 6e 6e 65 63 74 3e
                                  Data Ascii: <connect><ver>2</ver><agent><os>Windows</os><osVer>10.0.0.0.19045</osVer><proc>x64</proc><lcid>en-CH</lcid><geoId>223</geoId><aoac>0</aoac><deviceType>1</deviceType><deviceName>VMware20,1</deviceName><followRetry>true</followRetry></agent></connect>
                                  2025-01-15 16:49:10 UTC1084OUTData Raw: 41 54 48 20 32 20 43 4f 4e 5c 44 45 56 49 43 45 20 31 30 36 31 0d 0a 4d 53 2d 43 56 3a 20 68 4d 69 41 56 49 58 6c 36 45 79 34 30 51 2f 44 2e 32 0d 0a 43 6f 6e 74 65 78 74 3a 20 33 35 62 35 65 31 30 31 37 39 62 36 62 35 34 61 0d 0a 0d 0a 3c 64 65 76 69 63 65 3e 3c 63 6f 6d 70 61 63 74 2d 74 69 63 6b 65 74 3e 74 3d 45 77 43 34 41 75 70 49 42 41 41 55 31 62 44 47 66 64 61 7a 69 44 66 58 70 6a 4e 35 4e 36 63 59 68 54 31 77 62 6d 51 41 41 62 63 54 4c 76 42 36 55 4b 4b 61 52 6d 72 48 6e 76 55 58 6c 39 77 4c 53 63 61 76 49 64 44 78 6d 2f 4e 42 42 53 39 34 39 43 43 71 32 4c 72 6f 71 57 6c 34 6a 6c 64 45 31 79 4b 30 37 63 34 6b 70 48 37 30 73 52 4c 48 36 34 36 55 34 77 61 4f 70 65 4c 75 74 51 38 6a 6a 50 59 56 50 70 61 6d 6d 6c 4f 4e 6e 6e 64 4f 31 70 4c 4c 44 51
                                  Data Ascii: ATH 2 CON\DEVICE 1061MS-CV: hMiAVIXl6Ey40Q/D.2Context: 35b5e10179b6b54a<device><compact-ticket>t=EwC4AupIBAAU1bDGfdaziDfXpjN5N6cYhT1wbmQAAbcTLvB6UKKaRmrHnvUXl9wLScavIdDxm/NBBS949CCq2LroqWl4jldE1yK07c4kpH70sRLH646U4waOpeLutQ8jjPYVPpammlONnndO1pLLDQ
                                  2025-01-15 16:49:10 UTC218OUTData Raw: 42 4e 44 20 33 20 43 4f 4e 5c 57 4e 53 20 30 20 31 39 37 0d 0a 4d 53 2d 43 56 3a 20 68 4d 69 41 56 49 58 6c 36 45 79 34 30 51 2f 44 2e 33 0d 0a 43 6f 6e 74 65 78 74 3a 20 33 35 62 35 65 31 30 31 37 39 62 36 62 35 34 61 0d 0a 0d 0a 3c 77 6e 73 3e 3c 76 65 72 3e 31 3c 2f 76 65 72 3e 3c 63 6c 69 65 6e 74 3e 3c 6e 61 6d 65 3e 57 50 4e 3c 2f 6e 61 6d 65 3e 3c 76 65 72 3e 31 2e 30 3c 2f 76 65 72 3e 3c 2f 63 6c 69 65 6e 74 3e 3c 6f 70 74 69 6f 6e 73 3e 3c 70 77 72 6d 6f 64 65 20 6d 6f 64 65 3d 22 30 22 3e 3c 2f 70 77 72 6d 6f 64 65 3e 3c 2f 6f 70 74 69 6f 6e 73 3e 3c 6c 61 73 74 4d 73 67 49 64 3e 30 3c 2f 6c 61 73 74 4d 73 67 49 64 3e 3c 2f 77 6e 73 3e
                                  Data Ascii: BND 3 CON\WNS 0 197MS-CV: hMiAVIXl6Ey40Q/D.3Context: 35b5e10179b6b54a<wns><ver>1</ver><client><name>WPN</name><ver>1.0</ver></client><options><pwrmode mode="0"></pwrmode></options><lastMsgId>0</lastMsgId></wns>
                                  2025-01-15 16:49:10 UTC14INData Raw: 32 30 32 20 31 20 43 4f 4e 20 35 38 0d 0a
                                  Data Ascii: 202 1 CON 58
                                  2025-01-15 16:49:10 UTC58INData Raw: 4d 53 2d 43 56 3a 20 52 6c 70 39 72 76 41 56 44 45 69 56 43 57 4f 6d 49 71 66 43 6f 67 2e 30 0d 0a 0d 0a 50 61 79 6c 6f 61 64 20 70 61 72 73 69 6e 67 20 66 61 69 6c 65 64 2e
                                  Data Ascii: MS-CV: Rlp9rvAVDEiVCWOmIqfCog.0Payload parsing failed.


                                  Click to jump to process

                                  Click to jump to process

                                  Click to dive into process behavior distribution

                                  Click to jump to process

                                  Target ID:0
                                  Start time:11:47:07
                                  Start date:15/01/2025
                                  Path:C:\Windows\System32\loaddll32.exe
                                  Wow64 process (32bit):true
                                  Commandline:loaddll32.exe "C:\Users\user\Desktop\hNgIvHRuTU.dll"
                                  Imagebase:0x4a0000
                                  File size:126'464 bytes
                                  MD5 hash:51E6071F9CBA48E79F10C84515AAE618
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high
                                  Has exited:true

                                  Target ID:1
                                  Start time:11:47:07
                                  Start date:15/01/2025
                                  Path:C:\Windows\System32\conhost.exe
                                  Wow64 process (32bit):false
                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                  Imagebase:0x7ff6d64d0000
                                  File size:862'208 bytes
                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high
                                  Has exited:true

                                  Target ID:2
                                  Start time:11:47:07
                                  Start date:15/01/2025
                                  Path:C:\Windows\SysWOW64\cmd.exe
                                  Wow64 process (32bit):true
                                  Commandline:cmd.exe /C rundll32.exe "C:\Users\user\Desktop\hNgIvHRuTU.dll",#1
                                  Imagebase:0x790000
                                  File size:236'544 bytes
                                  MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high
                                  Has exited:true

                                  Target ID:3
                                  Start time:11:47:07
                                  Start date:15/01/2025
                                  Path:C:\Windows\SysWOW64\rundll32.exe
                                  Wow64 process (32bit):true
                                  Commandline:rundll32.exe C:\Users\user\Desktop\hNgIvHRuTU.dll,PlayGame
                                  Imagebase:0x870000
                                  File size:61'440 bytes
                                  MD5 hash:889B99C52A60DD49227C5E485A016679
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high
                                  Has exited:true

                                  Target ID:4
                                  Start time:11:47:07
                                  Start date:15/01/2025
                                  Path:C:\Windows\SysWOW64\rundll32.exe
                                  Wow64 process (32bit):true
                                  Commandline:rundll32.exe "C:\Users\user\Desktop\hNgIvHRuTU.dll",#1
                                  Imagebase:0x870000
                                  File size:61'440 bytes
                                  MD5 hash:889B99C52A60DD49227C5E485A016679
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high
                                  Has exited:true

                                  Target ID:5
                                  Start time:11:47:07
                                  Start date:15/01/2025
                                  Path:C:\Windows\mssecsvr.exe
                                  Wow64 process (32bit):true
                                  Commandline:C:\WINDOWS\mssecsvr.exe
                                  Imagebase:0x400000
                                  File size:2'281'472 bytes
                                  MD5 hash:526B41F0EBCFED2206ED1C567D79D1FD
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Yara matches:
                                  • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000005.00000000.2135064930.000000000040F000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                                  • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000005.00000002.2168405539.000000000040F000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                                  • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000005.00000002.2168553618.0000000000710000.00000002.00000001.01000000.00000004.sdmp, Author: Joe Security
                                  • Rule: wanna_cry_ransomware_generic, Description: detects wannacry ransomware on disk and in virtual page, Source: 00000005.00000002.2168553618.0000000000710000.00000002.00000001.01000000.00000004.sdmp, Author: us-cert code analysis team
                                  • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000005.00000000.2135200599.0000000000710000.00000002.00000001.01000000.00000004.sdmp, Author: Joe Security
                                  • Rule: wanna_cry_ransomware_generic, Description: detects wannacry ransomware on disk and in virtual page, Source: 00000005.00000000.2135200599.0000000000710000.00000002.00000001.01000000.00000004.sdmp, Author: us-cert code analysis team
                                  Reputation:low
                                  Has exited:true

                                  Target ID:7
                                  Start time:11:47:09
                                  Start date:15/01/2025
                                  Path:C:\Windows\mssecsvr.exe
                                  Wow64 process (32bit):true
                                  Commandline:C:\WINDOWS\mssecsvr.exe -m security
                                  Imagebase:0x400000
                                  File size:2'281'472 bytes
                                  MD5 hash:526B41F0EBCFED2206ED1C567D79D1FD
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Yara matches:
                                  • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000007.00000002.2802226931.000000000042E000.00000004.00000001.01000000.00000004.sdmp, Author: Joe Security
                                  • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000007.00000000.2156076914.000000000040F000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                                  • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000007.00000000.2156180423.0000000000710000.00000002.00000001.01000000.00000004.sdmp, Author: Joe Security
                                  • Rule: wanna_cry_ransomware_generic, Description: detects wannacry ransomware on disk and in virtual page, Source: 00000007.00000000.2156180423.0000000000710000.00000002.00000001.01000000.00000004.sdmp, Author: us-cert code analysis team
                                  • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000007.00000002.2803344917.0000000002282000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                  • Rule: wanna_cry_ransomware_generic, Description: detects wannacry ransomware on disk and in virtual page, Source: 00000007.00000002.2803344917.0000000002282000.00000004.00000020.00020000.00000000.sdmp, Author: us-cert code analysis team
                                  • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000007.00000002.2803025512.0000000001D5C000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                  • Rule: wanna_cry_ransomware_generic, Description: detects wannacry ransomware on disk and in virtual page, Source: 00000007.00000002.2803025512.0000000001D5C000.00000004.00000020.00020000.00000000.sdmp, Author: us-cert code analysis team
                                  • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000007.00000002.2802339283.0000000000710000.00000002.00000001.01000000.00000004.sdmp, Author: Joe Security
                                  • Rule: wanna_cry_ransomware_generic, Description: detects wannacry ransomware on disk and in virtual page, Source: 00000007.00000002.2802339283.0000000000710000.00000002.00000001.01000000.00000004.sdmp, Author: us-cert code analysis team
                                  Reputation:low
                                  Has exited:true

                                  Target ID:8
                                  Start time:11:47:10
                                  Start date:15/01/2025
                                  Path:C:\Windows\SysWOW64\rundll32.exe
                                  Wow64 process (32bit):true
                                  Commandline:rundll32.exe "C:\Users\user\Desktop\hNgIvHRuTU.dll",PlayGame
                                  Imagebase:0x870000
                                  File size:61'440 bytes
                                  MD5 hash:889B99C52A60DD49227C5E485A016679
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Reputation:high
                                  Has exited:true

                                  Target ID:9
                                  Start time:11:47:10
                                  Start date:15/01/2025
                                  Path:C:\Windows\mssecsvr.exe
                                  Wow64 process (32bit):true
                                  Commandline:C:\WINDOWS\mssecsvr.exe
                                  Imagebase:0x400000
                                  File size:2'281'472 bytes
                                  MD5 hash:526B41F0EBCFED2206ED1C567D79D1FD
                                  Has elevated privileges:true
                                  Has administrator privileges:true
                                  Programmed in:C, C++ or other language
                                  Yara matches:
                                  • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000009.00000000.2164308144.000000000040F000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                                  • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000009.00000002.2177053960.0000000000710000.00000002.00000001.01000000.00000004.sdmp, Author: Joe Security
                                  • Rule: wanna_cry_ransomware_generic, Description: detects wannacry ransomware on disk and in virtual page, Source: 00000009.00000002.2177053960.0000000000710000.00000002.00000001.01000000.00000004.sdmp, Author: us-cert code analysis team
                                  • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000009.00000000.2164431927.0000000000710000.00000002.00000001.01000000.00000004.sdmp, Author: Joe Security
                                  • Rule: wanna_cry_ransomware_generic, Description: detects wannacry ransomware on disk and in virtual page, Source: 00000009.00000000.2164431927.0000000000710000.00000002.00000001.01000000.00000004.sdmp, Author: us-cert code analysis team
                                  • Rule: JoeSecurity_Wannacry, Description: Yara detected Wannacry ransomware, Source: 00000009.00000002.2176853198.000000000040F000.00000008.00000001.01000000.00000004.sdmp, Author: Joe Security
                                  Reputation:low
                                  Has exited:true

                                  Reset < >

                                    Execution Graph

                                    Execution Coverage:71.7%
                                    Dynamic/Decrypted Code Coverage:0%
                                    Signature Coverage:63.2%
                                    Total number of Nodes:38
                                    Total number of Limit Nodes:9
                                    execution_graph 63 409a16 __set_app_type __p__fmode __p__commode 64 409a85 63->64 65 409a99 64->65 66 409a8d __setusermatherr 64->66 75 409b8c _controlfp 65->75 66->65 68 409a9e _initterm __getmainargs _initterm 69 409af2 GetStartupInfoA 68->69 71 409b26 GetModuleHandleA 69->71 76 408140 InternetOpenA InternetOpenUrlA 71->76 75->68 77 4081a7 InternetCloseHandle InternetCloseHandle 76->77 80 408090 GetModuleFileNameA __p___argc 77->80 79 4081b2 exit _XcptFilter 81 4080b0 80->81 82 4080b9 OpenSCManagerA 80->82 91 407f20 81->91 83 408101 StartServiceCtrlDispatcherA 82->83 84 4080cf OpenServiceA 82->84 83->79 86 4080fc CloseServiceHandle 84->86 87 4080ee 84->87 86->83 96 407fa0 ChangeServiceConfig2A 87->96 90 4080f6 CloseServiceHandle 90->86 108 407c40 sprintf OpenSCManagerA 91->108 93 407f25 97 407ce0 GetModuleHandleW 93->97 96->90 98 407d01 GetProcAddress GetProcAddress GetProcAddress GetProcAddress 97->98 99 407f08 97->99 98->99 100 407d49 98->100 99->79 100->99 101 407d69 FindResourceA 100->101 101->99 102 407d84 LoadResource 101->102 102->99 103 407d94 LockResource 102->103 103->99 104 407da7 SizeofResource 103->104 104->99 105 407db9 sprintf sprintf MoveFileExA CreateFileA 104->105 105->99 106 407e54 WriteFile CloseHandle CreateProcessA 105->106 106->99 107 407ef2 CloseHandle CloseHandle 106->107 107->99 109 407c74 CreateServiceA 108->109 110 407cca 108->110 111 407cbb CloseServiceHandle 109->111 112 407cad StartServiceA CloseServiceHandle 109->112 110->93 111->93 112->111

                                    Callgraph

                                    Control-flow Graph

                                    APIs
                                    • GetModuleHandleW.KERNEL32(kernel32.dll,00000000,6F370EF0,?,00000000), ref: 00407CEF
                                    • GetProcAddress.KERNEL32(00000000,CreateProcessA), ref: 00407D0D
                                    • GetProcAddress.KERNEL32(00000000,CreateFileA), ref: 00407D1A
                                    • GetProcAddress.KERNEL32(00000000,WriteFile), ref: 00407D27
                                    • GetProcAddress.KERNEL32(00000000,CloseHandle), ref: 00407D34
                                    • FindResourceA.KERNEL32(00000000,00000727,0043137C), ref: 00407D74
                                    • LoadResource.KERNEL32(00000000,00000000,?,00000000), ref: 00407D86
                                    • LockResource.KERNEL32(00000000,?,00000000), ref: 00407D95
                                    • SizeofResource.KERNEL32(00000000,00000000,?,00000000), ref: 00407DA9
                                    • sprintf.MSVCRT ref: 00407E01
                                    • sprintf.MSVCRT ref: 00407E18
                                    • MoveFileExA.KERNEL32(?,?,00000001(MOVEFILE_REPLACE_EXISTING)), ref: 00407E2C
                                    • CreateFileA.KERNELBASE(?,40000000,00000000,00000000,00000002,00000004,00000000), ref: 00407E43
                                    • WriteFile.KERNELBASE(00000000,?,00000000,?,00000000), ref: 00407E61
                                    • CloseHandle.KERNELBASE(00000000), ref: 00407E68
                                    • CreateProcessA.KERNELBASE ref: 00407EE8
                                    • CloseHandle.KERNEL32(00000000), ref: 00407EF7
                                    • CloseHandle.KERNEL32(08000000), ref: 00407F02
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000005.00000002.2168364904.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000005.00000002.2168344272.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2168387234.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2168405539.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2168405539.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2168456694.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2168553618.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_5_2_400000_mssecsvr.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: AddressHandleProcResource$CloseFile$Createsprintf$FindLoadLockModuleMoveProcessSizeofWrite
                                    • String ID: /i$C:\%s\%s$C:\%s\qeriuwjhrf$CloseHandle$CreateFileA$CreateProcessA$D$WINDOWS$WriteFile$kernel32.dll$tasksche.exe
                                    • API String ID: 4281112323-1507730452
                                    • Opcode ID: fb819ea0bbfac7cba45177718834bfaea6ecb5a57a4692884010a03d6946efb9
                                    • Instruction ID: 13a48b3e7e70fc1f7524b3ea2ca00aec236584d0bbebcf852995d03268f4a9c8
                                    • Opcode Fuzzy Hash: fb819ea0bbfac7cba45177718834bfaea6ecb5a57a4692884010a03d6946efb9
                                    • Instruction Fuzzy Hash: B15197715043496FE7109F74DC84AAB7B98EB88354F14493EF651A32E0DA7898088BAA

                                    Control-flow Graph

                                    APIs
                                    Memory Dump Source
                                    • Source File: 00000005.00000002.2168364904.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000005.00000002.2168344272.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2168387234.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2168405539.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2168405539.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2168456694.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2168553618.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_5_2_400000_mssecsvr.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: _initterm$FilterHandleInfoModuleStartupXcpt__getmainargs__p__commode__p__fmode__set_app_type__setusermatherrexit
                                    • String ID:
                                    • API String ID: 801014965-0
                                    • Opcode ID: e3007c8091b935f0f6e9b16d849c1c27a397ab206965397834d54df9927598b6
                                    • Instruction ID: f220c78e044b43db95b39954543cb8470338bddc8e57b6bf74c51ec52977e19a
                                    • Opcode Fuzzy Hash: e3007c8091b935f0f6e9b16d849c1c27a397ab206965397834d54df9927598b6
                                    • Instruction Fuzzy Hash: AF415E71800348EFDB24DFA4ED45AAA7BB8FB09720F20413BE451A72D2D7786841CB59

                                    Control-flow Graph

                                    APIs
                                    • InternetOpenA.WININET(00000000,00000001,00000000,00000000,00000000), ref: 0040817B
                                    • InternetOpenUrlA.WININET(00000000,00000000,00000000,00000000,84000000,00000000), ref: 00408194
                                    • InternetCloseHandle.WININET(00000000), ref: 004081A7
                                    • InternetCloseHandle.WININET(00000000), ref: 004081AB
                                      • Part of subcall function 00408090: GetModuleFileNameA.KERNEL32(00000000,0070F760,00000104,?,004081B2), ref: 0040809F
                                      • Part of subcall function 00408090: __p___argc.MSVCRT ref: 004080A5
                                    Strings
                                    • http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com, xrefs: 0040814A
                                    Memory Dump Source
                                    • Source File: 00000005.00000002.2168364904.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000005.00000002.2168344272.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2168387234.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2168405539.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2168405539.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2168456694.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2168553618.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_5_2_400000_mssecsvr.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: Internet$CloseHandleOpen$FileModuleName__p___argc
                                    • String ID: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                    • API String ID: 774561529-2614457033
                                    • Opcode ID: 0bbc0dabe610ff42f1f9ad6e85cc21407dd9b1b68127969cd029bea3a518856a
                                    • Instruction ID: 3b8a91e0baa4f3639afdb349cfc438007093f0a6557163af6b5eb03d237fc32a
                                    • Opcode Fuzzy Hash: 0bbc0dabe610ff42f1f9ad6e85cc21407dd9b1b68127969cd029bea3a518856a
                                    • Instruction Fuzzy Hash: B3018671548310AEE310DF748D01B6B7BE9EF85710F01082EF984F72C0EAB59804876B

                                    Control-flow Graph

                                    APIs
                                    • sprintf.MSVCRT ref: 00407C56
                                    • OpenSCManagerA.ADVAPI32(00000000,00000000,000F003F), ref: 00407C68
                                    • CreateServiceA.ADVAPI32(00000000,mssecsvc2.1,Microsoft Security Center (2.1) Service,000F01FF,00000010,00000002,00000001,?,00000000,00000000,00000000,00000000,00000000,6F370EF0,00000000), ref: 00407C9B
                                    • StartServiceA.ADVAPI32(00000000,00000000,00000000), ref: 00407CB2
                                    • CloseServiceHandle.ADVAPI32(00000000), ref: 00407CB9
                                    • CloseServiceHandle.ADVAPI32(00000000), ref: 00407CBC
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000005.00000002.2168364904.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000005.00000002.2168344272.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2168387234.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2168405539.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2168405539.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2168456694.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2168553618.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_5_2_400000_mssecsvr.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: Service$CloseHandle$CreateManagerOpenStartsprintf
                                    • String ID: %s -m security$Microsoft Security Center (2.1) Service$mssecsvc2.1
                                    • API String ID: 3340711343-2450984573
                                    • Opcode ID: c3592d809756ac94f014d34e1e4fa0c14de5620095203194e3f9233ad68c92ee
                                    • Instruction ID: 2288e5cc66680fabefb91112cf05624c6df81315eb9d87428618c258e2ee617f
                                    • Opcode Fuzzy Hash: c3592d809756ac94f014d34e1e4fa0c14de5620095203194e3f9233ad68c92ee
                                    • Instruction Fuzzy Hash: AD01D1717C43043BF2305B149D8BFEB3658AB84F01F500025FB44B92D0DAF9A81491AF

                                    Control-flow Graph

                                    APIs
                                    • GetModuleFileNameA.KERNEL32(00000000,0070F760,00000104,?,004081B2), ref: 0040809F
                                    • __p___argc.MSVCRT ref: 004080A5
                                    • OpenSCManagerA.ADVAPI32(00000000,00000000,000F003F,00000000,?,004081B2), ref: 004080C3
                                    • OpenServiceA.ADVAPI32(00000000,mssecsvc2.1,000F01FF,6F370EF0,00000000,?,004081B2), ref: 004080DC
                                    • CloseServiceHandle.ADVAPI32(00000000,?,?,?,004081B2), ref: 004080FA
                                    • CloseServiceHandle.ADVAPI32(00000000,?,004081B2), ref: 004080FD
                                    • StartServiceCtrlDispatcherA.ADVAPI32(?,?,?), ref: 00408126
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000005.00000002.2168364904.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000005.00000002.2168344272.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2168387234.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2168405539.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2168405539.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2168456694.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000005.00000002.2168553618.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_5_2_400000_mssecsvr.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: Service$CloseHandleOpen$CtrlDispatcherFileManagerModuleNameStart__p___argc
                                    • String ID: mssecsvc2.1
                                    • API String ID: 4274534310-2839763450
                                    • Opcode ID: 14f2d0f9cf239aa653f070f930b60ae04978eb0b591616557438e437b3700a6a
                                    • Instruction ID: 0eddf8d8cc97b5ba853ece0b0f9ce4fe0dc31dc3004373c78c05f92e851b2f94
                                    • Opcode Fuzzy Hash: 14f2d0f9cf239aa653f070f930b60ae04978eb0b591616557438e437b3700a6a
                                    • Instruction Fuzzy Hash: 4A014775640315BBE3117F149E4AF6F3AA4EF80B19F404429F544762D2DFB888188AAF

                                    Execution Graph

                                    Execution Coverage:34.8%
                                    Dynamic/Decrypted Code Coverage:0%
                                    Signature Coverage:0%
                                    Total number of Nodes:36
                                    Total number of Limit Nodes:2

                                    Callgraph

                                    Control-flow Graph

                                    APIs
                                    • GetModuleFileNameA.KERNEL32(00000000,0070F760,00000104,?,004081B2), ref: 0040809F
                                    • __p___argc.MSVCRT ref: 004080A5
                                    • OpenSCManagerA.ADVAPI32(00000000,00000000,000F003F,00000000,?,004081B2), ref: 004080C3
                                    • OpenServiceA.ADVAPI32(00000000,mssecsvc2.1,000F01FF,6F370EF0,00000000,?,004081B2), ref: 004080DC
                                    • CloseServiceHandle.ADVAPI32(00000000,?,?,?,004081B2), ref: 004080FA
                                    • CloseServiceHandle.ADVAPI32(00000000,?,004081B2), ref: 004080FD
                                    • StartServiceCtrlDispatcherA.ADVAPI32(?,?,?), ref: 00408126
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000007.00000002.2802160479.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000007.00000002.2802127619.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802179594.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802192389.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802192389.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802226931.000000000042E000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802240159.000000000042F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802254528.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802339283.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_7_2_400000_mssecsvr.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: Service$CloseHandleOpen$CtrlDispatcherFileManagerModuleNameStart__p___argc
                                    • String ID: mssecsvc2.1
                                    • API String ID: 4274534310-2839763450
                                    • Opcode ID: 14f2d0f9cf239aa653f070f930b60ae04978eb0b591616557438e437b3700a6a
                                    • Instruction ID: 0eddf8d8cc97b5ba853ece0b0f9ce4fe0dc31dc3004373c78c05f92e851b2f94
                                    • Opcode Fuzzy Hash: 14f2d0f9cf239aa653f070f930b60ae04978eb0b591616557438e437b3700a6a
                                    • Instruction Fuzzy Hash: 4A014775640315BBE3117F149E4AF6F3AA4EF80B19F404429F544762D2DFB888188AAF

                                    Control-flow Graph

                                    APIs
                                    • InternetOpenA.WININET(00000000,00000001,00000000,00000000,00000000), ref: 0040817B
                                    • InternetOpenUrlA.WININET(00000000,00000000,00000000,00000000,84000000,00000000), ref: 00408194
                                    • InternetCloseHandle.WININET(00000000), ref: 004081A7
                                    • InternetCloseHandle.WININET(00000000), ref: 004081AB
                                      • Part of subcall function 00408090: GetModuleFileNameA.KERNEL32(00000000,0070F760,00000104,?,004081B2), ref: 0040809F
                                      • Part of subcall function 00408090: __p___argc.MSVCRT ref: 004080A5
                                    Strings
                                    • http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com, xrefs: 0040814A
                                    Memory Dump Source
                                    • Source File: 00000007.00000002.2802160479.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000007.00000002.2802127619.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802179594.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802192389.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802192389.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802226931.000000000042E000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802240159.000000000042F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802254528.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802339283.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_7_2_400000_mssecsvr.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: Internet$CloseHandleOpen$FileModuleName__p___argc
                                    • String ID: http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com
                                    • API String ID: 774561529-2614457033
                                    • Opcode ID: 0bbc0dabe610ff42f1f9ad6e85cc21407dd9b1b68127969cd029bea3a518856a
                                    • Instruction ID: 3b8a91e0baa4f3639afdb349cfc438007093f0a6557163af6b5eb03d237fc32a
                                    • Opcode Fuzzy Hash: 0bbc0dabe610ff42f1f9ad6e85cc21407dd9b1b68127969cd029bea3a518856a
                                    • Instruction Fuzzy Hash: B3018671548310AEE310DF748D01B6B7BE9EF85710F01082EF984F72C0EAB59804876B

                                    Control-flow Graph

                                    APIs
                                    • sprintf.MSVCRT ref: 00407C56
                                    • OpenSCManagerA.ADVAPI32(00000000,00000000,000F003F), ref: 00407C68
                                    • CreateServiceA.ADVAPI32(00000000,mssecsvc2.1,Microsoft Security Center (2.1) Service,000F01FF,00000010,00000002,00000001,?,00000000,00000000,00000000,00000000,00000000,6F370EF0,00000000), ref: 00407C9B
                                    • StartServiceA.ADVAPI32(00000000,00000000,00000000), ref: 00407CB2
                                    • CloseServiceHandle.ADVAPI32(00000000), ref: 00407CB9
                                    • CloseServiceHandle.ADVAPI32(00000000), ref: 00407CBC
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000007.00000002.2802160479.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000007.00000002.2802127619.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802179594.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802192389.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802192389.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802226931.000000000042E000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802240159.000000000042F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802254528.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802339283.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_7_2_400000_mssecsvr.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: Service$CloseHandle$CreateManagerOpenStartsprintf
                                    • String ID: %s -m security$Microsoft Security Center (2.1) Service$mssecsvc2.1
                                    • API String ID: 3340711343-2450984573
                                    • Opcode ID: c3592d809756ac94f014d34e1e4fa0c14de5620095203194e3f9233ad68c92ee
                                    • Instruction ID: 2288e5cc66680fabefb91112cf05624c6df81315eb9d87428618c258e2ee617f
                                    • Opcode Fuzzy Hash: c3592d809756ac94f014d34e1e4fa0c14de5620095203194e3f9233ad68c92ee
                                    • Instruction Fuzzy Hash: AD01D1717C43043BF2305B149D8BFEB3658AB84F01F500025FB44B92D0DAF9A81491AF

                                    Control-flow Graph

                                    • Executed
                                    • Not Executed
                                    control_flow_graph 15 407ce0-407cfb GetModuleHandleW 16 407d01-407d43 GetProcAddress * 4 15->16 17 407f08-407f14 15->17 16->17 18 407d49-407d4f 16->18 18->17 19 407d55-407d5b 18->19 19->17 20 407d61-407d63 19->20 20->17 21 407d69-407d7e FindResourceA 20->21 21->17 22 407d84-407d8e LoadResource 21->22 22->17 23 407d94-407da1 LockResource 22->23 23->17 24 407da7-407db3 SizeofResource 23->24 24->17 25 407db9-407e4e sprintf * 2 MoveFileExA 24->25 25->17 27 407e54-407ef0 25->27 27->17 31 407ef2-407f01 27->31 31->17
                                    APIs
                                    • GetModuleHandleW.KERNEL32(kernel32.dll,00000000,6F370EF0,?,00000000), ref: 00407CEF
                                    • GetProcAddress.KERNEL32(00000000,CreateProcessA), ref: 00407D0D
                                    • GetProcAddress.KERNEL32(00000000,CreateFileA), ref: 00407D1A
                                    • GetProcAddress.KERNEL32(00000000,WriteFile), ref: 00407D27
                                    • GetProcAddress.KERNEL32(00000000,CloseHandle), ref: 00407D34
                                    • FindResourceA.KERNEL32(00000000,00000727,0043137C), ref: 00407D74
                                    • LoadResource.KERNEL32(00000000,00000000,?,00000000), ref: 00407D86
                                    • LockResource.KERNEL32(00000000,?,00000000), ref: 00407D95
                                    • SizeofResource.KERNEL32(00000000,00000000,?,00000000), ref: 00407DA9
                                    • sprintf.MSVCRT ref: 00407E01
                                    • sprintf.MSVCRT ref: 00407E18
                                    • MoveFileExA.KERNEL32(?,?,00000001(MOVEFILE_REPLACE_EXISTING)), ref: 00407E2C
                                    Strings
                                    Memory Dump Source
                                    • Source File: 00000007.00000002.2802160479.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000007.00000002.2802127619.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802179594.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802192389.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802192389.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802226931.000000000042E000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802240159.000000000042F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802254528.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802339283.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_7_2_400000_mssecsvr.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: AddressProcResource$sprintf$FileFindHandleLoadLockModuleMoveSizeof
                                    • String ID: /i$C:\%s\%s$C:\%s\qeriuwjhrf$CloseHandle$CreateFileA$CreateProcessA$D$WINDOWS$WriteFile$kernel32.dll$tasksche.exe
                                    • API String ID: 4072214828-1507730452
                                    • Opcode ID: fb819ea0bbfac7cba45177718834bfaea6ecb5a57a4692884010a03d6946efb9
                                    • Instruction ID: 13a48b3e7e70fc1f7524b3ea2ca00aec236584d0bbebcf852995d03268f4a9c8
                                    • Opcode Fuzzy Hash: fb819ea0bbfac7cba45177718834bfaea6ecb5a57a4692884010a03d6946efb9
                                    • Instruction Fuzzy Hash: B15197715043496FE7109F74DC84AAB7B98EB88354F14493EF651A32E0DA7898088BAA

                                    Control-flow Graph

                                    APIs
                                    Memory Dump Source
                                    • Source File: 00000007.00000002.2802160479.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Offset: 00400000, based on PE: true
                                    • Associated: 00000007.00000002.2802127619.0000000000400000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802179594.000000000040A000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802192389.000000000040B000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802192389.000000000040F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802226931.000000000042E000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802240159.000000000042F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802254528.0000000000431000.00000004.00000001.01000000.00000004.sdmpDownload File
                                    • Associated: 00000007.00000002.2802339283.0000000000710000.00000002.00000001.01000000.00000004.sdmpDownload File
                                    Joe Sandbox IDA Plugin
                                    • Snapshot File: hcaresult_7_2_400000_mssecsvr.jbxd
                                    Yara matches
                                    Similarity
                                    • API ID: _initterm$FilterHandleInfoModuleStartupXcpt__getmainargs__p__commode__p__fmode__set_app_type__setusermatherrexit
                                    • String ID:
                                    • API String ID: 801014965-0
                                    • Opcode ID: e3007c8091b935f0f6e9b16d849c1c27a397ab206965397834d54df9927598b6
                                    • Instruction ID: f220c78e044b43db95b39954543cb8470338bddc8e57b6bf74c51ec52977e19a
                                    • Opcode Fuzzy Hash: e3007c8091b935f0f6e9b16d849c1c27a397ab206965397834d54df9927598b6
                                    • Instruction Fuzzy Hash: AF415E71800348EFDB24DFA4ED45AAA7BB8FB09720F20413BE451A72D2D7786841CB59