Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
xkzdRi6nGpg3.exe

Overview

General Information

Sample name:xkzdRi6nGpg3.exe
Analysis ID:1431189
MD5:12d3e11ae0227e8182db020a1f875b67
SHA1:ec4525cf7bd7b85e9fbd3101faf7dafaeb83424e
SHA256:ba1c1884ec9bc5326e183aa6a6f31a7f0f3a78f0ae04a5d13aba1eba1ac3448e
Tags:exenjRat
Infos:

Detection

Njrat
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Found malware configuration
Snort IDS alert for network traffic
Yara detected Njrat
.NET source code contains potential unpacker
.NET source code references suspicious native API functions
C2 URLs / IPs found in malware configuration
Contains functionality to log keystrokes (.Net Source)
Machine Learning detection for sample
Self deletion via cmd or bat file
Uses dynamic DNS services
Allocates memory with a write watch (potentially for evading sandboxes)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Uses 32bit PE files

Classification

  • System is w10x64
  • xkzdRi6nGpg3.exe (PID: 5980 cmdline: "C:\Users\user\Desktop\xkzdRi6nGpg3.exe" MD5: 12D3E11AE0227E8182DB020A1F875B67)
    • cmd.exe (PID: 3248 cmdline: cmd.exe /C Y /N /D Y /T 1 & Del "C:\Users\user\Desktop\xkzdRi6nGpg3.exe" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • conhost.exe (PID: 3476 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
NjRATRedPacket Security describes NJRat as "a remote access trojan (RAT) has capabilities to log keystrokes, access the victim's camera, steal credentials stored in browsers, open a reverse shell, upload/download files, view the victim's desktop, perform process, file, and registry manipulations, and capabilities to let the attacker update, uninstall, restart, close, disconnect the RAT and rename its campaign ID. Through the Command & Control (CnC) server software, the attacker has capabilities to create and configure the malware to spread through USB drives."It is supposedly popular with actors in the Middle East. Similar to other RATs, many leaked builders may be backdoored.
  • AQUATIC PANDA
  • Earth Lusca
  • Operation C-Major
  • The Gorgon Group
https://malpedia.caad.fkie.fraunhofer.de/details/win.njrat
{"Host": "rusia.duckdns.org", "Port": "1994", "Campaign ID": "NYAN CAT", "Network Seprator": "@!#&^%$", "Registry": "5e13091123"}
SourceRuleDescriptionAuthorStrings
xkzdRi6nGpg3.exeJoeSecurity_NjratYara detected NjratJoe Security
    SourceRuleDescriptionAuthorStrings
    00000001.00000000.1272554302.0000000000CA2000.00000002.00000001.01000000.00000003.sdmpJoeSecurity_NjratYara detected NjratJoe Security
      Process Memory Space: xkzdRi6nGpg3.exe PID: 5980JoeSecurity_NjratYara detected NjratJoe Security
        SourceRuleDescriptionAuthorStrings
        1.0.xkzdRi6nGpg3.exe.ca0000.0.unpackJoeSecurity_NjratYara detected NjratJoe Security
          No Sigma rule has matched
          Timestamp:04/24/24-17:06:01.844441
          SID:2825563
          Source Port:49706
          Destination Port:1994
          Protocol:TCP
          Classtype:A Network Trojan was detected
          Timestamp:04/24/24-17:08:27.238731
          SID:2825564
          Source Port:49706
          Destination Port:1994
          Protocol:TCP
          Classtype:A Network Trojan was detected
          Timestamp:04/24/24-17:06:01.270296
          SID:2033132
          Source Port:49706
          Destination Port:1994
          Protocol:TCP
          Classtype:A Network Trojan was detected

          Click to jump to signature section

          Show All Signature Results

          AV Detection

          barindex
          Source: xkzdRi6nGpg3.exeAvira: detected
          Source: rusia.duckdns.orgAvira URL Cloud: Label: malware
          Source: 00000001.00000000.1272554302.0000000000CA2000.00000002.00000001.01000000.00000003.sdmpMalware Configuration Extractor: Njrat {"Host": "rusia.duckdns.org", "Port": "1994", "Campaign ID": "NYAN CAT", "Network Seprator": "@!#&^%$", "Registry": "5e13091123"}
          Source: Yara matchFile source: xkzdRi6nGpg3.exe, type: SAMPLE
          Source: Yara matchFile source: 1.0.xkzdRi6nGpg3.exe.ca0000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000001.00000000.1272554302.0000000000CA2000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: xkzdRi6nGpg3.exe PID: 5980, type: MEMORYSTR
          Source: xkzdRi6nGpg3.exeJoe Sandbox ML: detected
          Source: xkzdRi6nGpg3.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeFile opened: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_d08f9da24428a513\MSVCR80.dllJump to behavior
          Source: xkzdRi6nGpg3.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE

          Networking

          barindex
          Source: TrafficSnort IDS: 2033132 ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) 192.168.2.9:49706 -> 46.246.84.12:1994
          Source: TrafficSnort IDS: 2825563 ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (inf) 192.168.2.9:49706 -> 46.246.84.12:1994
          Source: TrafficSnort IDS: 2825564 ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) 192.168.2.9:49706 -> 46.246.84.12:1994
          Source: Malware configuration extractorURLs: rusia.duckdns.org
          Source: unknownDNS query: name: rusia.duckdns.org
          Source: global trafficTCP traffic: 192.168.2.9:49706 -> 46.246.84.12:1994
          Source: Joe Sandbox ViewIP Address: 46.246.84.12 46.246.84.12
          Source: Joe Sandbox ViewASN Name: PORTLANEwwwportlanecomSE PORTLANEwwwportlanecomSE
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeCode function: 1_2_0136A186 recv,1_2_0136A186
          Source: global trafficDNS traffic detected: DNS query: rusia.duckdns.org

          Key, Mouse, Clipboard, Microphone and Screen Capturing

          barindex
          Source: xkzdRi6nGpg3.exe, Keylogger.cs.Net Code: VKCodeToUnicode

          E-Banking Fraud

          barindex
          Source: Yara matchFile source: xkzdRi6nGpg3.exe, type: SAMPLE
          Source: Yara matchFile source: 1.0.xkzdRi6nGpg3.exe.ca0000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000001.00000000.1272554302.0000000000CA2000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: xkzdRi6nGpg3.exe PID: 5980, type: MEMORYSTR
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeCode function: 1_2_018619F01_2_018619F0
          Source: xkzdRi6nGpg3.exe, 00000001.00000000.1272570021.0000000000CA8000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameClient.exe4 vs xkzdRi6nGpg3.exe
          Source: xkzdRi6nGpg3.exeBinary or memory string: OriginalFilenameClient.exe4 vs xkzdRi6nGpg3.exe
          Source: xkzdRi6nGpg3.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
          Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@4/1@2/1
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeCode function: 1_2_055E22AA AdjustTokenPrivileges,1_2_055E22AA
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeCode function: 1_2_055E2273 AdjustTokenPrivileges,1_2_055E2273
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeFile created: C:\Users\user\AppData\Local\Microsoft\CLR_v2.0_32\UsageLogs\xkzdRi6nGpg3.exe.logJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeMutant created: NULL
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeMutant created: \Sessions\1\BaseNamedObjects\Global\.net clr networking
          Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3476:120:WilError_03
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeMutant created: \Sessions\1\BaseNamedObjects\5e13091123
          Source: xkzdRi6nGpg3.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
          Source: xkzdRi6nGpg3.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.79%
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
          Source: unknownProcess created: C:\Users\user\Desktop\xkzdRi6nGpg3.exe "C:\Users\user\Desktop\xkzdRi6nGpg3.exe"
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C Y /N /D Y /T 1 & Del "C:\Users\user\Desktop\xkzdRi6nGpg3.exe"
          Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C Y /N /D Y /T 1 & Del "C:\Users\user\Desktop\xkzdRi6nGpg3.exe"Jump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeSection loaded: mscoree.dllJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeSection loaded: apphelp.dllJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeSection loaded: kernel.appcore.dllJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeSection loaded: version.dllJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeSection loaded: windows.storage.dllJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeSection loaded: wldp.dllJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeSection loaded: profapi.dllJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeSection loaded: uxtheme.dllJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeSection loaded: cryptsp.dllJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeSection loaded: rsaenh.dllJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeSection loaded: cryptbase.dllJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeSection loaded: mswsock.dllJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeSection loaded: dnsapi.dllJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeSection loaded: iphlpapi.dllJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeSection loaded: rasadhlp.dllJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeSection loaded: fwpuclnt.dllJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeSection loaded: sspicli.dllJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeSection loaded: wbemcomn.dllJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeSection loaded: amsi.dllJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeSection loaded: userenv.dllJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeSection loaded: shfolder.dllJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeSection loaded: avicap32.dllJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeSection loaded: msvfw32.dllJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeSection loaded: winmm.dllJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeSection loaded: windowscodecs.dllJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{CF4CC405-E2C5-4DDD-B3CE-5E7582D8C9FA}\InprocServer32Jump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeFile opened: C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dllJump to behavior
          Source: xkzdRi6nGpg3.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeFile opened: C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_d08f9da24428a513\MSVCR80.dllJump to behavior
          Source: xkzdRi6nGpg3.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE

          Data Obfuscation

          barindex
          Source: xkzdRi6nGpg3.exe, Program.cs.Net Code: Plugin System.Reflection.Assembly.Load(byte[])

          Hooking and other Techniques for Hiding and Protection

          barindex
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess created: cmd.exe /C Y /N /D Y /T 1 & Del "C:\Users\user\Desktop\xkzdRi6nGpg3.exe"
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess created: cmd.exe /C Y /N /D Y /T 1 & Del "C:\Users\user\Desktop\xkzdRi6nGpg3.exe"Jump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeMemory allocated: 13F0000 memory reserve | memory write watchJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeMemory allocated: 3410000 memory reserve | memory write watchJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeMemory allocated: 1640000 memory commit | memory reserve | memory write watchJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeWindow / User API: threadDelayed 417Jump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeWindow / User API: threadDelayed 3654Jump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeWindow / User API: threadDelayed 5455Jump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeWindow / User API: foregroundWindowGot 1765Jump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exe TID: 6696Thread sleep time: -417000s >= -30000sJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exe TID: 6696Thread sleep time: -5455000s >= -30000sJump to behavior
          Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
          Source: xkzdRi6nGpg3.exe, 00000001.00000002.2851240205.0000000001489000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW/>
          Source: xkzdRi6nGpg3.exe, 00000001.00000002.2851240205.0000000001489000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeProcess token adjusted: DebugJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeMemory allocated: page read and write | page guardJump to behavior

          HIPS / PFW / Operating System Protection Evasion

          barindex
          Source: xkzdRi6nGpg3.exe, Program.csReference to suspicious API methods: capGetDriverDescriptionA(wDriver, ref lpszName, cbName, ref lpszVer, 100)
          Source: xkzdRi6nGpg3.exe, Keylogger.csReference to suspicious API methods: MapVirtualKey(a, 0u)
          Source: xkzdRi6nGpg3.exe, Keylogger.csReference to suspicious API methods: GetAsyncKeyState(num2)
          Source: xkzdRi6nGpg3.exe, 00000001.00000002.2851642273.00000000034BA000.00000004.00000800.00020000.00000000.sdmp, xkzdRi6nGpg3.exe, 00000001.00000002.2851642273.00000000034CE000.00000004.00000800.00020000.00000000.sdmp, xkzdRi6nGpg3.exe, 00000001.00000002.2851642273.00000000034D1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Program Manager
          Source: xkzdRi6nGpg3.exe, 00000001.00000002.2851642273.00000000034BA000.00000004.00000800.00020000.00000000.sdmp, xkzdRi6nGpg3.exe, 00000001.00000002.2851642273.00000000034CE000.00000004.00000800.00020000.00000000.sdmp, xkzdRi6nGpg3.exe, 00000001.00000002.2851642273.00000000034D1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Program Manager@9cl
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeQueries volume information: C:\ VolumeInformationJump to behavior
          Source: C:\Users\user\Desktop\xkzdRi6nGpg3.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

          Stealing of Sensitive Information

          barindex
          Source: Yara matchFile source: xkzdRi6nGpg3.exe, type: SAMPLE
          Source: Yara matchFile source: 1.0.xkzdRi6nGpg3.exe.ca0000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000001.00000000.1272554302.0000000000CA2000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: xkzdRi6nGpg3.exe PID: 5980, type: MEMORYSTR

          Remote Access Functionality

          barindex
          Source: Yara matchFile source: xkzdRi6nGpg3.exe, type: SAMPLE
          Source: Yara matchFile source: 1.0.xkzdRi6nGpg3.exe.ca0000.0.unpack, type: UNPACKEDPE
          Source: Yara matchFile source: 00000001.00000000.1272554302.0000000000CA2000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
          Source: Yara matchFile source: Process Memory Space: xkzdRi6nGpg3.exe PID: 5980, type: MEMORYSTR
          ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
          Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
          Native API
          1
          DLL Side-Loading
          1
          Access Token Manipulation
          1
          Masquerading
          1
          Input Capture
          1
          Security Software Discovery
          Remote Services1
          Input Capture
          1
          Encrypted Channel
          Exfiltration Over Other Network MediumAbuse Accessibility Features
          CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts2
          Process Injection
          2
          Virtualization/Sandbox Evasion
          LSASS Memory2
          Virtualization/Sandbox Evasion
          Remote Desktop Protocol1
          Archive Collected Data
          1
          Non-Standard Port
          Exfiltration Over BluetoothNetwork Denial of Service
          Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
          DLL Side-Loading
          1
          Disable or Modify Tools
          Security Account Manager1
          Process Discovery
          SMB/Windows Admin SharesData from Network Shared Drive1
          Ingress Tool Transfer
          Automated ExfiltrationData Encrypted for Impact
          Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
          Access Token Manipulation
          NTDS1
          Application Window Discovery
          Distributed Component Object ModelInput Capture1
          Non-Application Layer Protocol
          Traffic DuplicationData Destruction
          Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script2
          Process Injection
          LSA Secrets12
          System Information Discovery
          SSHKeylogging21
          Application Layer Protocol
          Scheduled TransferData Encrypted for Impact
          Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
          Software Packing
          Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
          DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
          DLL Side-Loading
          DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
          Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
          File Deletion
          Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
          Hide Legend

          Legend:

          • Process
          • Signature
          • Created File
          • DNS/IP Info
          • Is Dropped
          • Is Windows Process
          • Number of created Registry Values
          • Number of created Files
          • Visual Basic
          • Delphi
          • Java
          • .Net C# or VB.NET
          • C, C++ or other language
          • Is malicious
          • Internet

          This section contains all screenshots as thumbnails, including those not shown in the slideshow.


          windows-stand
          SourceDetectionScannerLabelLink
          xkzdRi6nGpg3.exe100%AviraTR/Dropper.Gen7
          xkzdRi6nGpg3.exe100%Joe Sandbox ML
          No Antivirus matches
          No Antivirus matches
          No Antivirus matches
          SourceDetectionScannerLabelLink
          rusia.duckdns.org100%Avira URL Cloudmalware
          NameIPActiveMaliciousAntivirus DetectionReputation
          rusia.duckdns.org
          46.246.84.12
          truetrue
            unknown
            NameMaliciousAntivirus DetectionReputation
            rusia.duckdns.orgtrue
            • Avira URL Cloud: malware
            unknown
            • No. of IPs < 25%
            • 25% < No. of IPs < 50%
            • 50% < No. of IPs < 75%
            • 75% < No. of IPs
            IPDomainCountryFlagASNASN NameMalicious
            46.246.84.12
            rusia.duckdns.orgSweden
            42708PORTLANEwwwportlanecomSEtrue
            Joe Sandbox version:40.0.0 Tourmaline
            Analysis ID:1431189
            Start date and time:2024-04-24 17:05:06 +02:00
            Joe Sandbox product:CloudBasic
            Overall analysis duration:0h 6m 34s
            Hypervisor based Inspection enabled:false
            Report type:full
            Cookbook file name:default.jbs
            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
            Number of analysed new started processes analysed:16
            Number of new started drivers analysed:0
            Number of existing processes analysed:0
            Number of existing drivers analysed:0
            Number of injected processes analysed:0
            Technologies:
            • HCA enabled
            • EGA enabled
            • AMSI enabled
            Analysis Mode:default
            Analysis stop reason:Timeout
            Sample name:xkzdRi6nGpg3.exe
            Detection:MAL
            Classification:mal100.troj.spyw.evad.winEXE@4/1@2/1
            EGA Information:
            • Successful, ratio: 100%
            HCA Information:
            • Successful, ratio: 100%
            • Number of executed functions: 92
            • Number of non-executed functions: 0
            Cookbook Comments:
            • Found application associated with file extension: .exe
            • Override analysis time to 240000 for current running targets taking high CPU consumption
            • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, MoUsoCoreWorker.exe, conhost.exe, svchost.exe
            • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
            • Not all processes where analyzed, report is missing behavior information
            • Report size getting too big, too many NtQueryValueKey calls found.
            • VT rate limit hit for: xkzdRi6nGpg3.exe
            TimeTypeDescription
            17:06:28API Interceptor607483x Sleep call for process: xkzdRi6nGpg3.exe modified
            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
            46.246.84.121L79IBlk3o.exeGet hashmaliciousXWormBrowse
              xueSatPQMUFH.exeGet hashmaliciousArrowRATBrowse
                x2xFapxhdTcU.exeGet hashmaliciousArrowRATBrowse
                  Claro Securty.apkGet hashmaliciousUnknownBrowse
                    Win defender.exeGet hashmaliciousNjratBrowse
                      cgdifn.msiGet hashmaliciousUnknownBrowse
                        Corona App.apkGet hashmaliciousUnknownBrowse
                          cgdifn.msiGet hashmaliciousUnknownBrowse
                            CGDIFN.exeGet hashmaliciousLodaRATBrowse
                              Winver.exeGet hashmaliciousUnknownBrowse
                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                rusia.duckdns.orgxjXIE2ZFFSw4.exeGet hashmaliciousAsyncRAT, DcRatBrowse
                                • 46.246.14.10
                                xjXIE2ZFFSw4.exeGet hashmaliciousAsyncRAT, DcRatBrowse
                                • 46.246.14.10
                                xyyDAUDPeYEH.exeGet hashmaliciousNjratBrowse
                                • 46.246.6.20
                                x7RZVIWaDKb5.exeGet hashmaliciousNjratBrowse
                                • 46.246.14.17
                                x7RZVIWaDKb5.exeGet hashmaliciousNjratBrowse
                                • 46.246.14.17
                                bUBL.exeGet hashmaliciousNjratBrowse
                                • 46.246.14.17
                                x6Xw7vcuD9zM.exeGet hashmaliciousNjratBrowse
                                • 46.246.14.23
                                bTAB.exeGet hashmaliciousNjratBrowse
                                • 46.246.80.3
                                xbd0vU3xnyOS.exeGet hashmaliciousNjratBrowse
                                • 46.246.6.7
                                x38kbgLd6bPu.exeGet hashmaliciousNjratBrowse
                                • 46.246.12.24
                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                PORTLANEwwwportlanecomSEPrice request N#U00b0DEM23000199.jsGet hashmaliciousAsyncRAT, PureLog Stealer, RedLineBrowse
                                • 178.73.192.3
                                xjXIE2ZFFSw4.exeGet hashmaliciousAsyncRAT, DcRatBrowse
                                • 46.246.14.10
                                xjXIE2ZFFSw4.exeGet hashmaliciousAsyncRAT, DcRatBrowse
                                • 46.246.14.10
                                BitTorrent-7.6.exeGet hashmaliciousUnknownBrowse
                                • 188.126.94.80
                                xVcsGL5R1Nbh.exeGet hashmaliciousNjratBrowse
                                • 46.246.6.20
                                xyyDAUDPeYEH.exeGet hashmaliciousNjratBrowse
                                • 46.246.6.20
                                xzcQo6GenFVf.exeGet hashmaliciousAsyncRAT, DcRatBrowse
                                • 46.246.14.5
                                tajma.x86-20240422-0535.elfGet hashmaliciousMirai, OkiruBrowse
                                • 188.126.69.245
                                x7RZVIWaDKb5.exeGet hashmaliciousNjratBrowse
                                • 46.246.14.17
                                x7RZVIWaDKb5.exeGet hashmaliciousNjratBrowse
                                • 46.246.14.17
                                No context
                                No context
                                Process:C:\Users\user\Desktop\xkzdRi6nGpg3.exe
                                File Type:ASCII text, with CRLF line terminators
                                Category:dropped
                                Size (bytes):907
                                Entropy (8bit):5.243019596074263
                                Encrypted:false
                                SSDEEP:24:MLF2CpI329Iz52VMzffup26KTnKoO2+b2hHAa/:MwQd9IzoaXuY6Ux+SF/
                                MD5:48A0572426885EBDE53CA62C7F2E194E
                                SHA1:035628CDF6276367F6C83E9F4AA2172933850AA8
                                SHA-256:4C68E10691304CAC8DA65A05CF2580728EC0E294104F267840712AF1C46A6538
                                SHA-512:DEFE728C2312918D94BD43C98908C08CCCA5EBFB77F873779DCA784F14C607B33A4E29AC5ECB798F2F741668B7692F72BCB60DEFD536EA86B296B64FA359C42D
                                Malicious:false
                                Reputation:moderate, very likely benign file
                                Preview:1,"fusion","GAC",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\System\bec14584c93014efbc76285c35d1e891\System.ni.dll",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\2cdaeaf53e3d49038cf7cb0ce9d805d3\System.Drawing.ni.dll",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d0e5535854cce87ea7f2d69d0594b7a8\System.Windows.Forms.ni.dll",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\7d443c6c007fe8696f9aa6ff1da53ef7\Microsoft.VisualBasic.ni.dll",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\53992d421e2c7ecf6609c62b3510a6f0\System.Configuration.ni.dll",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\74774597e319a738b792e6a6c06d3559\System.Xml.ni.dll",0..3,"C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\1bd56c432cb9ff27e335d97f404caf8f\System.Management.ni.dll",0..
                                File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                Entropy (8bit):3.799206784996852
                                TrID:
                                • Win32 Executable (generic) Net Framework (10011505/4) 49.79%
                                • Win32 Executable (generic) a (10002005/4) 49.75%
                                • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
                                • Windows Screen Saver (13104/52) 0.07%
                                • Win16/32 Executable Delphi generic (2074/23) 0.01%
                                File name:xkzdRi6nGpg3.exe
                                File size:32'768 bytes
                                MD5:12d3e11ae0227e8182db020a1f875b67
                                SHA1:ec4525cf7bd7b85e9fbd3101faf7dafaeb83424e
                                SHA256:ba1c1884ec9bc5326e183aa6a6f31a7f0f3a78f0ae04a5d13aba1eba1ac3448e
                                SHA512:6b4b5d773e43e0dc6668d361b16c2f414649320ee96e5ea22de132f17870fe002212f7a7324bd7ad8347917392319d934b164cae01941234818c90ef2399e379
                                SSDEEP:384:70bUe5XB4e0XLO3fw0Q0mS03AWTxtTUFQqzFbObbJ:4T9Buyo55d5bJ
                                TLSH:9CE218067BE94215C6BC5AFC8CB313214772E3838532EB6F5CDC88CA4B676D04655EE9
                                File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....'f.................P... ......^g... ........@.. ....................................@................................
                                Icon Hash:00928e8e8686b000
                                Entrypoint:0x40675e
                                Entrypoint Section:.text
                                Digitally signed:false
                                Imagebase:0x400000
                                Subsystem:windows gui
                                Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                                Time Stamp:0x6627EC9B [Tue Apr 23 17:15:07 2024 UTC]
                                TLS Callbacks:
                                CLR (.Net) Version:
                                OS Version Major:4
                                OS Version Minor:0
                                File Version Major:4
                                File Version Minor:0
                                Subsystem Version Major:4
                                Subsystem Version Minor:0
                                Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
                                Instruction
                                jmp dword ptr [00402000h]
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                add byte ptr [eax], al
                                NameVirtual AddressVirtual Size Is in Section
                                IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                IMAGE_DIRECTORY_ENTRY_IMPORT0x67100x4b.text
                                IMAGE_DIRECTORY_ENTRY_RESOURCE0x80000x2a0.rsrc
                                IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                IMAGE_DIRECTORY_ENTRY_BASERELOC0xa0000xc.reloc
                                IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
                                IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
                                IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                .text0x20000x47640x5000c2ffa275f338b879319868cae547162fFalse0.474853515625data5.289358800701343IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                .rsrc0x80000x2a00x100072e29550a9764ae2ca0bc9263e829114False0.07666015625data0.6655850551657312IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                .reloc0xa0000xc0x1000e8ad62578d6ea2b62af23f514f67d89bFalse0.008544921875data0.012638662471219527IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                NameRVASizeTypeLanguageCountryZLIB Complexity
                                RT_VERSION0x80580x244data0.46379310344827585
                                DLLImport
                                mscoree.dll_CorExeMain
                                TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                                04/24/24-17:06:01.844441TCP2825563ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (inf)497061994192.168.2.946.246.84.12
                                04/24/24-17:08:27.238731TCP2825564ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act)497061994192.168.2.946.246.84.12
                                04/24/24-17:06:01.270296TCP2033132ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll)497061994192.168.2.946.246.84.12
                                TimestampSource PortDest PortSource IPDest IP
                                Apr 24, 2024 17:06:00.746093035 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:06:01.182585001 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:06:01.182677031 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:06:01.270296097 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:06:01.844364882 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:06:01.844440937 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:06:02.427820921 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:06:05.138428926 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:06:05.744266033 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:06:07.819595098 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:06:07.872313976 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:06:08.085750103 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:06:08.629610062 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:06:26.340260983 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:06:26.340668917 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:06:26.839423895 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:06:44.952464104 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:06:44.953372955 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:06:45.538222075 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:06:51.747775078 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:06:52.264784098 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:06:53.591557026 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:06:54.139394045 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:06:58.904611111 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:06:59.536788940 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:06:59.536957026 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:00.127911091 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:00.326009989 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:00.444757938 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:00.497189999 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:00.837302923 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:00.837497950 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:01.205102921 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:01.441679955 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:01.441819906 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:01.601663113 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:01.601861000 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:01.839376926 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:01.993784904 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:01.993969917 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:02.183692932 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:02.237637997 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:02.237867117 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:02.441766977 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:02.587404013 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:02.587816954 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:02.638187885 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:02.638397932 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:02.838143110 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:02.838265896 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:02.857207060 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:02.857403040 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:03.042215109 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:03.042336941 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:03.241549969 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:03.250114918 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:03.470350981 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:03.639056921 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:03.639183044 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:03.658076048 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:03.658216953 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:03.881113052 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:03.881423950 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:04.084922075 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:04.085113049 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:04.292733908 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:04.335120916 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:04.335311890 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:04.539048910 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:04.539227009 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:04.749056101 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:04.749218941 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:04.931279898 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:04.931447029 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:05.183856010 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:05.327444077 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:05.327629089 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:05.593053102 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:05.593262911 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:05.851212978 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:05.942291021 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:05.942374945 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:06.129530907 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:06.129960060 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:06.287316084 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:06.287570000 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:06.521930933 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:06.525398970 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:06.721234083 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:06.839282990 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:06.839505911 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:06.919415951 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:06.919586897 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:07.140302896 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:07.140398026 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:07.325186968 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:07.325377941 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:07.542752981 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:07.641318083 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:07.641473055 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:07.842371941 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:07.842480898 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:07.943387985 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:07.943635941 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:08.179194927 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:08.242280006 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:08.242413044 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:08.375493050 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:08.375648022 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:08.588282108 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:08.592431068 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:08.592765093 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:08.767760038 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:08.767963886 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:08.998471975 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:08.998651981 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:09.176254988 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:09.176747084 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:09.414163113 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:09.582703114 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:09.582839966 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:09.812788010 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:09.816631079 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:09.817158937 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:10.023793936 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:10.130654097 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:10.130938053 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:10.234781981 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:10.234963894 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:10.425533056 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:10.425668955 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:10.564682961 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:10.564820051 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:10.779958963 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:10.828917980 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:10.829153061 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:11.040254116 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:11.142653942 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:11.142752886 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:11.191680908 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:11.191971064 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:11.339535952 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:11.339848042 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:11.479655027 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:11.480370998 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:11.613830090 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:11.613951921 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:11.840074062 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:11.916270971 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:11.916580915 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:12.145844936 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:12.145968914 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:12.255877018 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:12.256064892 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:12.438927889 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:12.439030886 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:12.635081053 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:12.640161037 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:12.642086983 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:12.842111111 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:12.842220068 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:13.040365934 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:13.040471077 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:13.054188013 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:13.054477930 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:13.138067961 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:13.142059088 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:13.342124939 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:13.346101046 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:13.451307058 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:13.452347994 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:13.743263960 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:13.743355989 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:13.942044973 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:13.942209959 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:14.346406937 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:14.568257093 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:14.743594885 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:15.087789059 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:15.243475914 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:15.243654966 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:15.455166101 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:15.496359110 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:15.496455908 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:15.701056957 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:15.737256050 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:15.737363100 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:15.879281044 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:15.879831076 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:15.941335917 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:15.941473007 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:16.098452091 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:16.098566055 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:16.275439978 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:16.275590897 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:16.438575983 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:16.438672066 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:16.640388966 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:16.640697002 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:16.840425968 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:16.840509892 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:17.030674934 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:17.041253090 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:17.041416883 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:17.233419895 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:17.233805895 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:17.425342083 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:17.425565958 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:17.542694092 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:17.542875051 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:17.744803905 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:17.744872093 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:17.933660984 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:17.933917999 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:18.156230927 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:18.240736961 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:18.240950108 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:18.442773104 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:18.443084955 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:18.575834036 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:18.576011896 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:18.778820992 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:18.829746008 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:18.829833031 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:18.939698935 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:18.939789057 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:19.145627022 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:19.145744085 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:19.179665089 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:19.179929018 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:19.332087994 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:19.332279921 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:19.400402069 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:19.400537968 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:19.588691950 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:19.588871956 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:19.612199068 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:19.612329006 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:19.810695887 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:19.811012030 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:20.030577898 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:20.030777931 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:20.240268946 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:20.337646008 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:20.337769985 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:20.552264929 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:20.634325027 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:20.634460926 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:20.663830042 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:20.663923979 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:20.869283915 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:20.942919016 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:20.943051100 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:20.948872089 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:20.948965073 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:21.097162008 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:21.097373962 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:21.269263029 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:21.272089005 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:21.354990005 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:21.355190992 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:21.597445011 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:21.665002108 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:21.665169001 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:21.860297918 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:21.944972992 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:21.945097923 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:22.001863956 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:22.001977921 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:22.164092064 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:22.164206982 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:22.292905092 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:22.292964935 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:22.413499117 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:22.413614035 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:22.592699051 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:22.710305929 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:22.710418940 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:22.889703989 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:22.929153919 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:22.929259062 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:23.019646883 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:23.019757032 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:23.189121008 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:23.297674894 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:23.297909021 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:23.358414888 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:23.358546972 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:23.540932894 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:23.540994883 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:23.591074944 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:23.591356993 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:23.776160955 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:23.776401043 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:23.982369900 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:23.982485056 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:24.165519953 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:24.165652037 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:24.330501080 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:24.330594063 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:24.494266033 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:24.607580900 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:24.607745886 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:24.789463043 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:24.846411943 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:24.846611977 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:24.889482975 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:24.889662027 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:25.122853041 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:25.139425039 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:25.139529943 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:25.186408043 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:25.186600924 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:25.282321930 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:25.282454967 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:25.522960901 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:25.526601076 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:25.591372967 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:25.591497898 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:25.758337021 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:25.758449078 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:25.929317951 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:25.929496050 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:25.932334900 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:25.932423115 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:26.152756929 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:26.178505898 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:26.178728104 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:26.351613045 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:26.351742983 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:26.549407005 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:26.549581051 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:26.642426968 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:26.642549038 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:26.829363108 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:26.829600096 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:27.051706076 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:27.051903009 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:27.310062885 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:27.337528944 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:27.337660074 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:27.542834997 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:27.543023109 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:27.708947897 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:27.709137917 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:27.943891048 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:27.944128036 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:28.108542919 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:28.108638048 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:28.391408920 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:28.436666965 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:28.436763048 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:28.680108070 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:28.746710062 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:28.746834993 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:28.809706926 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:28.809807062 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:28.812577963 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:28.812757015 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:28.941623926 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:28.941836119 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:29.075675011 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:29.075695992 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:29.075822115 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:29.204679012 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:29.204830885 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:29.477749109 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:29.477953911 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:29.740691900 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:29.740820885 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:29.941617012 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:29.941764116 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:30.147000074 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:30.236999989 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:30.237143993 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:30.476972103 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:30.532140970 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:30.532361031 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:30.566898108 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:30.567028999 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:30.839819908 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:30.840217113 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:30.900167942 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:30.900435925 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:30.962984085 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:30.963073015 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:31.235234022 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:31.303770065 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:31.304001093 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:31.430797100 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:31.431088924 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:31.663938046 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:31.664119005 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:31.831950903 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:31.832118988 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:31.884260893 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:31.884459972 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:32.056018114 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:32.056221962 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:32.221987009 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:32.222225904 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:32.436317921 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:32.441973925 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:32.646178007 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:32.646387100 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:32.849145889 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:32.849276066 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:33.100805044 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:33.143477917 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:33.143706083 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:33.343365908 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:33.343486071 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:33.510370970 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:33.510653973 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:33.742459059 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:33.742618084 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:33.921504021 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:33.921701908 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:34.283464909 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:34.321250916 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:34.321540117 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:34.619374990 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:34.706440926 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:34.706661940 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:34.931579113 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:34.943242073 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:34.943420887 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:35.044341087 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:35.044434071 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:35.108321905 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:35.108587980 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:35.329456091 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:35.336452007 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:35.336498976 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:35.510410070 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:35.510612011 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:35.723524094 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:35.744505882 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:35.744659901 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:35.909832001 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:36.092704058 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:36.114347935 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:36.114473104 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:36.141609907 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:36.141685009 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:36.338548899 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:36.338773966 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:36.506004095 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:36.506320000 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:36.582602024 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:36.582750082 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:36.840544939 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:36.912589073 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:36.912882090 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:37.142627001 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:37.142751932 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:37.236557007 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:37.236646891 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:37.444864035 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:37.445208073 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:37.666687965 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:37.667062044 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:37.841723919 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:37.841901064 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:38.030811071 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:38.031023026 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:38.133651018 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:38.133922100 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:38.245687962 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:38.245933056 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:38.457989931 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:38.536650896 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:38.536911011 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:38.643667936 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:38.643974066 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:38.829778910 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:38.830195904 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:38.890809059 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:38.891035080 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:39.045999050 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:39.046211958 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:39.280467987 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:39.305962086 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:39.306479931 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:39.538209915 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:39.538316965 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:39.670845985 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:39.671134949 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:39.867942095 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:39.931502104 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:39.931713104 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:40.042238951 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:40.042479992 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:40.241972923 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:40.242259979 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:40.330761909 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:40.331015110 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:40.438973904 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:40.439253092 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:40.640744925 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:40.640863895 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:40.734925032 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:40.735184908 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:40.987828970 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:41.042968988 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:41.043171883 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:41.141026020 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:41.141283989 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:41.387259960 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:41.392198086 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:41.392781019 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:41.392900944 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:41.547890902 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:41.548038006 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:41.725620031 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:41.809829950 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:41.809922934 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:41.810209990 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:42.021336079 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:42.037940025 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:42.038141966 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:42.147643089 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:42.147890091 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:42.378963947 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:42.431039095 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:42.431360960 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:42.465462923 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:42.465728045 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:42.731358051 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:42.731570005 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:42.801282883 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:42.801491022 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:42.866976023 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:42.867086887 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:43.124082088 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:43.191539049 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:43.192679882 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:43.344068050 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:43.344320059 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:43.545258999 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:43.545363903 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:43.746654034 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:43.746750116 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:43.986892939 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:44.041373968 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:44.041558027 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:44.245349884 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:44.245512009 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:44.399410009 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:44.399533033 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:44.631432056 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:44.631516933 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:44.636413097 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:44.684542894 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:44.836716890 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:44.936322927 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:44.936551094 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:45.022314072 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:45.022393942 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:45.259227037 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:45.259730101 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:45.426604033 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:45.427077055 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:45.736738920 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:45.737957954 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:46.033512115 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:46.033982992 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:46.328841925 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:46.330020905 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:46.640600920 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:46.640718937 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:46.841784954 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:46.841934919 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:47.263516903 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:47.263643026 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:47.638874054 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:47.639017105 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:47.742643118 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:47.742974043 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:47.950339079 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:48.129754066 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:48.129888058 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:48.236656904 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:48.236731052 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:48.404856920 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:48.404990911 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:48.639887094 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:48.640270948 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:48.945193052 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:48.945408106 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:49.129978895 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:49.130060911 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:49.380732059 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:49.442821980 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:49.442996025 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:49.643526077 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:49.646085978 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:49.783006907 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:49.784085035 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:49.996947050 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:50.041054010 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:50.046070099 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:50.193974972 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:50.196017027 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:50.390197039 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:50.412811041 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:50.413036108 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:50.591905117 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:50.592047930 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:50.725925922 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:50.726047993 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:50.788702011 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:50.788724899 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:50.788965940 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:50.939856052 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:50.939922094 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:51.126943111 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:51.127024889 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:51.329910040 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:51.330058098 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:51.511128902 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:51.641391039 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:51.641608000 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:51.845679045 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:51.845966101 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:51.937211990 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:51.937526941 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:52.133071899 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:52.140338898 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:52.140492916 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:52.342133045 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:52.342231035 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:52.530219078 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:52.530308962 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:52.555252075 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:52.555325985 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:52.638830900 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:52.638897896 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:52.842571020 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:52.842659950 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:52.950423956 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:52.950522900 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:53.136353016 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:53.140254021 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:53.336473942 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:53.336668015 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:53.444411039 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:53.444519043 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:53.630382061 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:53.633997917 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:53.779433966 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:53.782016993 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:53.848332882 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:53.849992990 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:54.065974951 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:54.141293049 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:54.142043114 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:54.285278082 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:54.285372019 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:54.457297087 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:54.460448980 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:54.639389992 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:54.639467955 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:54.842031002 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:54.842242956 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:55.040467978 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:55.040673018 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:55.242615938 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:55.242693901 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:55.444091082 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:55.444363117 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:55.630546093 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:55.634062052 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:55.738643885 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:55.738719940 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:55.936422110 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:55.937980890 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:56.130683899 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:56.136018038 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:56.336823940 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:56.539657116 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:56.542000055 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:56.735387087 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:56.735471010 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:56.863493919 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:56.863688946 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:57.082771063 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:57.132575035 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:57.132828951 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:57.345047951 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:57.345282078 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:57.488487959 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:57.488620996 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:57.730715036 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:57.746854067 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:57.748357058 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:57.884850979 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:57.886117935 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:58.143033028 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:58.145951986 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:58.238893986 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:58.242175102 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:58.344945908 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:58.346163988 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:58.611629009 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:58.637834072 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:58.637923002 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:58.739658117 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:58.739778042 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:58.988003016 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:59.015814066 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:59.015949965 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:59.133255005 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:59.133466005 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:59.343707085 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:59.388010025 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:59.388202906 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:59.534915924 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:59.535079002 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:59.741588116 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:59.762959957 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:59.763721943 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:07:59.892203093 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:07:59.892607927 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:00.036849976 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:00.037359953 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:00.140706062 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:00.140723944 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:00.140930891 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:00.238799095 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:00.239109993 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:00.437714100 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:00.437892914 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:00.540829897 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:00.541013002 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:00.766916990 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:00.840156078 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:00.840387106 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:00.937009096 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:00.937109947 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:01.149642944 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:01.204180002 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:01.204750061 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:01.346854925 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:01.347064972 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:01.547107935 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:01.547311068 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:01.662902117 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:01.663366079 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:01.841089010 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:01.841267109 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:02.042896032 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:02.043683052 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:02.239986897 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:02.240176916 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:02.439198017 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:02.630228996 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:02.630300999 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:02.767713070 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:02.767862082 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:02.831232071 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:02.831490040 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:02.998507023 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:02.998591900 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:03.144408941 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:03.144593954 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:03.265290022 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:03.265435934 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:03.432310104 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:03.432404041 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:03.688060999 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:03.694408894 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:03.694617987 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:03.902959108 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:03.942331076 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:03.945852995 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:04.087490082 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:04.088006020 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:04.145351887 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:04.146819115 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:04.327678919 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:04.327775002 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:04.443892956 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:04.444113016 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:04.577621937 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:04.577712059 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:04.795428038 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:04.843693018 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:04.844109058 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:05.065963030 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:05.139389992 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:05.139617920 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:05.217586994 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:05.217694044 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:05.341579914 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:05.341804028 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:05.489880085 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:05.489994049 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:05.620487928 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:05.620837927 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:05.853588104 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:05.886531115 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:05.886674881 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:06.088006020 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:06.126651049 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:06.126782894 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:06.256762028 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:06.257042885 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:06.271750927 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:06.271873951 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:06.443006039 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:06.443073988 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:06.500921965 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:06.500945091 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:06.501044035 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:06.629769087 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:06.629870892 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:06.704456091 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:06.704633951 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:06.902489901 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:06.902710915 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:07.131469011 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:07.141535997 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:07.141606092 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:07.298588037 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:07.298710108 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:07.498260975 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:07.533554077 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:07.533761978 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:07.639735937 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:07.639961958 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:07.841460943 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:07.841630936 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:07.916925907 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:07.917067051 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:08.040731907 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:08.041081905 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:08.240535975 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:08.240668058 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:08.308590889 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:08.308671951 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:08.530371904 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:08.638856888 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:08.638983011 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:08.733217001 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:08.733333111 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:08.954703093 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:08.954921007 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:09.139744997 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:09.139885902 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:09.279819012 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:09.279917955 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:09.429750919 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:09.430059910 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:09.570766926 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:09.571091890 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:09.822118998 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:09.828887939 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:09.829005957 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:10.043134928 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:10.045933962 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:10.241890907 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:10.241982937 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:10.438761950 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:10.450814009 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:10.450928926 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:10.640250921 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:10.640387058 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:10.836952925 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:10.837168932 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:10.846178055 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:10.846295118 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:10.941965103 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:10.942214012 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:11.143779039 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:11.143923998 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:11.242018938 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:11.242351055 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:11.442032099 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:11.543899059 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:11.544023991 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:11.641760111 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:11.642127991 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:11.834114075 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:11.835706949 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:12.050970078 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:12.051208973 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:12.281974077 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:12.282068968 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:12.507093906 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:12.544997931 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:12.545109987 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:12.740135908 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:12.742482901 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:12.912273884 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:12.912431002 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:13.111833096 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:13.131392956 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:13.133811951 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:13.244262934 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:13.244829893 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:13.435365915 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:13.435539007 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:13.540764093 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:13.544055939 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:13.649302959 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:13.650002956 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:13.907589912 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:13.942269087 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:13.942600965 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:14.067002058 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:14.067157030 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:14.313388109 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:14.313563108 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:14.469239950 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:14.469382048 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:14.694391966 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:14.879519939 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:14.879780054 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:15.083436966 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:15.083602905 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:15.317801952 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:15.439532995 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:15.439677954 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:15.513613939 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:15.513798952 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:15.518342972 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:15.518538952 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:15.718585968 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:15.725802898 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:15.733473063 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:15.737812996 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:15.955661058 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:15.955950975 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:16.043948889 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:16.044079065 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:16.165664911 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:16.165863037 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:16.404774904 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:16.433826923 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:16.433944941 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:16.643588066 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:16.643739939 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:16.804779053 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:16.804934978 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:17.042954922 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:17.043032885 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:17.214384079 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:17.214534044 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:17.418188095 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:17.546006918 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:17.546108961 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:17.750267982 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:17.750499010 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:17.863810062 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:17.864842892 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:18.141732931 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:18.141952991 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:18.268781900 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:18.268938065 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:18.620908022 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:18.621139050 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:18.744158030 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:18.744308949 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:19.145519018 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:19.145656109 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:19.346050024 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:19.717402935 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:19.730139017 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:19.730237007 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:19.901639938 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:20.106043100 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:20.115607023 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:20.115830898 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:20.269715071 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:20.269927979 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:20.295725107 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:20.297914028 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:20.498795033 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:20.498940945 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:20.630812883 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:20.630896091 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:20.706777096 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:20.706906080 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:20.888251066 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:21.019085884 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:21.019401073 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:21.280910015 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:21.281023026 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:21.343102932 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:21.343271971 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:21.531069040 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:21.531470060 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:21.715625048 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:21.750972986 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:21.753609896 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:21.763000965 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:21.763134956 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:22.032998085 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:22.043078899 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:22.043493986 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:22.113188982 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:22.113202095 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:22.113377094 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:22.159755945 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:22.160113096 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:22.396318913 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:22.473913908 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:22.474016905 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:22.507700920 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:22.507767916 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:22.647665024 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:22.647955894 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:22.811115980 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:22.811388016 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:22.918951035 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:22.919032097 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:23.155666113 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:23.226808071 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:23.227060080 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:23.427117109 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:23.440493107 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:23.440603971 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:23.563358068 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:23.563492060 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:23.789136887 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:23.841783047 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:23.842303991 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:23.867824078 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:23.868936062 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:23.986927986 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:23.987091064 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:24.211683989 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:24.212466955 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:24.285893917 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:24.286061049 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:24.520855904 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:24.635312080 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:24.635576963 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:24.685475111 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:24.685564041 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:24.848639011 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:24.848901987 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:24.938939095 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:24.939131021 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:24.953304052 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:24.953478098 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:25.108920097 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:25.109265089 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:25.332613945 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:25.332731962 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:25.527422905 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:25.527735949 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:25.757193089 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:25.928494930 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:25.928714037 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:26.009572983 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:26.010018110 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:26.114696026 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:26.158993959 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:26.160924911 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:26.162303925 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:26.417442083 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:26.417538881 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:26.533337116 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:26.533457994 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:26.643392086 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:26.643528938 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:26.862508059 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:26.929337025 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:26.929528952 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:27.219918966 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:27.238554955 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:27.238730907 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:27.282877922 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:27.282970905 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:27.501292944 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:27.530699968 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:27.530864954 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:27.620192051 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:27.624037027 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:27.693002939 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:27.694680929 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:27.837708950 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:27.838083029 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:27.920588970 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:27.921478987 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:27.926126957 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:28.024669886 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:28.025998116 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:28.145760059 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:28.145867109 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:28.332878113 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:28.336123943 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:28.436820984 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:28.436892033 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:28.544714928 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:28.544827938 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:28.741092920 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:28.741216898 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:28.944227934 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:28.944508076 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:29.143075943 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:29.143182993 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:29.337744951 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:29.337856054 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:29.443451881 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:29.443784952 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:29.648789883 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:29.648976088 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:29.674206018 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:29.867700100 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:29.867805958 CEST497061994192.168.2.946.246.84.12
                                Apr 24, 2024 17:08:29.868205070 CEST19944970646.246.84.12192.168.2.9
                                Apr 24, 2024 17:08:29.868294001 CEST497061994192.168.2.946.246.84.12
                                TimestampSource PortDest PortSource IPDest IP
                                Apr 24, 2024 17:05:59.093383074 CEST5496353192.168.2.91.1.1.1
                                Apr 24, 2024 17:06:00.106811047 CEST5496353192.168.2.91.1.1.1
                                Apr 24, 2024 17:06:00.743782043 CEST53549631.1.1.1192.168.2.9
                                Apr 24, 2024 17:06:00.743823051 CEST53549631.1.1.1192.168.2.9
                                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                Apr 24, 2024 17:05:59.093383074 CEST192.168.2.91.1.1.10x3d04Standard query (0)rusia.duckdns.orgA (IP address)IN (0x0001)false
                                Apr 24, 2024 17:06:00.106811047 CEST192.168.2.91.1.1.10x3d04Standard query (0)rusia.duckdns.orgA (IP address)IN (0x0001)false
                                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                Apr 24, 2024 17:06:00.743782043 CEST1.1.1.1192.168.2.90x3d04No error (0)rusia.duckdns.org46.246.84.12A (IP address)IN (0x0001)false
                                Apr 24, 2024 17:06:00.743823051 CEST1.1.1.1192.168.2.90x3d04No error (0)rusia.duckdns.org46.246.84.12A (IP address)IN (0x0001)false

                                Click to jump to process

                                Click to jump to process

                                Click to dive into process behavior distribution

                                Click to jump to process

                                Target ID:1
                                Start time:17:05:50
                                Start date:24/04/2024
                                Path:C:\Users\user\Desktop\xkzdRi6nGpg3.exe
                                Wow64 process (32bit):true
                                Commandline:"C:\Users\user\Desktop\xkzdRi6nGpg3.exe"
                                Imagebase:0xca0000
                                File size:32'768 bytes
                                MD5 hash:12D3E11AE0227E8182DB020A1F875B67
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Yara matches:
                                • Rule: JoeSecurity_Njrat, Description: Yara detected Njrat, Source: 00000001.00000000.1272554302.0000000000CA2000.00000002.00000001.01000000.00000003.sdmp, Author: Joe Security
                                Reputation:low
                                Has exited:true

                                Target ID:14
                                Start time:17:08:28
                                Start date:24/04/2024
                                Path:C:\Windows\SysWOW64\cmd.exe
                                Wow64 process (32bit):true
                                Commandline:cmd.exe /C Y /N /D Y /T 1 & Del "C:\Users\user\Desktop\xkzdRi6nGpg3.exe"
                                Imagebase:0xc50000
                                File size:236'544 bytes
                                MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Reputation:high
                                Has exited:true

                                Target ID:15
                                Start time:17:08:28
                                Start date:24/04/2024
                                Path:C:\Windows\System32\conhost.exe
                                Wow64 process (32bit):false
                                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                Imagebase:0x7ff70f010000
                                File size:862'208 bytes
                                MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                Has elevated privileges:true
                                Has administrator privileges:true
                                Programmed in:C, C++ or other language
                                Reputation:high
                                Has exited:true

                                Reset < >

                                  Execution Graph

                                  Execution Coverage:15.3%
                                  Dynamic/Decrypted Code Coverage:100%
                                  Signature Coverage:2.1%
                                  Total number of Nodes:145
                                  Total number of Limit Nodes:8
                                  execution_graph 6615 136b736 6618 136b76b GetFileType 6615->6618 6617 136b798 6618->6617 6667 55e0b9e 6668 55e0bd3 WSAConnect 6667->6668 6670 55e0bf2 6668->6670 6671 136b9f6 6673 136ba2b ReadFile 6671->6673 6674 136ba5d 6673->6674 6619 55e2056 6622 55e207f select 6619->6622 6621 55e20b4 6622->6621 6675 55e3b16 6676 55e3b4b PostMessageW 6675->6676 6677 55e3b76 6675->6677 6678 55e3b60 6676->6678 6677->6676 6623 55e08d2 6625 55e0907 GetProcessTimes 6623->6625 6626 55e0939 6625->6626 6679 136a7fa 6680 136a832 RegOpenKeyExW 6679->6680 6682 136a888 6680->6682 6683 136bd62 6684 136bdd2 6683->6684 6685 136bd9a setsockopt 6683->6685 6684->6685 6686 136bda8 6685->6686 6631 136ac2a 6632 136aca0 6631->6632 6633 136ac68 DuplicateHandle 6631->6633 6632->6633 6634 136ac76 6633->6634 6687 55e2502 6689 55e2537 GetProcessWorkingSetSize 6687->6689 6690 55e2563 6689->6690 6695 55e09be 6696 55e09f9 getaddrinfo 6695->6696 6698 55e0a6b 6696->6698 6699 55e37be 6700 55e37f3 RegDeleteKeyW 6699->6700 6702 55e382b 6700->6702 6635 55e1f7a 6636 55e1faf ioctlsocket 6635->6636 6638 55e1fdb 6636->6638 6639 136a392 6641 136a3c7 RegQueryValueExW 6639->6641 6642 136a41b 6641->6642 6703 55e2e3a 6704 55e2e66 LoadLibraryShim 6703->6704 6706 55e2e94 6704->6706 6643 136b61e 6644 136b656 CreateFileW 6643->6644 6646 136b6a5 6644->6646 6707 136bc5e 6709 136bc96 WSASocketW 6707->6709 6710 136bcd2 6709->6710 6711 55e01b6 6712 55e01ee ConvertStringSecurityDescriptorToSecurityDescriptorW 6711->6712 6714 55e022f 6712->6714 6647 55e0ff2 6648 55e102d LoadLibraryA 6647->6648 6650 55e106a 6648->6650 6715 55e0032 6716 55e0082 GetComputerNameW 6715->6716 6717 55e0090 6716->6717 6718 136a2da 6719 136a306 SetErrorMode 6718->6719 6720 136a32f 6718->6720 6721 136a31b 6719->6721 6720->6719 6722 55e3db2 6723 55e3dde DispatchMessageW 6722->6723 6724 55e3e07 6722->6724 6725 55e3df3 6723->6725 6724->6723 6651 136a186 6652 136a1f3 6651->6652 6653 136a1bb recv 6651->6653 6652->6653 6654 136a1c9 6653->6654 6655 136a486 6658 136a4bb RegSetValueExW 6655->6658 6657 136a507 6658->6657 6726 136a646 6728 136a67e CreateMutexW 6726->6728 6729 136a6c1 6728->6729 6730 55e212a 6731 55e2153 LookupPrivilegeValueW 6730->6731 6733 55e217a 6731->6733 6734 1860972 6735 1860622 6734->6735 6740 1860a13 6735->6740 6745 1860998 6735->6745 6750 1860a1a 6735->6750 6755 1860a01 6735->6755 6741 1860a18 6740->6741 6742 1860ad7 6741->6742 6760 1860ce6 6741->6760 6764 1860cf8 6741->6764 6746 18609d3 6745->6746 6747 1860ad7 6746->6747 6748 1860ce6 2 API calls 6746->6748 6749 1860cf8 2 API calls 6746->6749 6748->6747 6749->6747 6751 1860a1f 6750->6751 6752 1860ad7 6751->6752 6753 1860ce6 2 API calls 6751->6753 6754 1860cf8 2 API calls 6751->6754 6753->6752 6754->6752 6756 1860a06 6755->6756 6757 1860ad7 6756->6757 6758 1860ce6 2 API calls 6756->6758 6759 1860cf8 2 API calls 6756->6759 6758->6757 6759->6757 6761 1860d23 6760->6761 6762 1860d6a 6761->6762 6768 18611c2 6761->6768 6762->6742 6765 1860d23 6764->6765 6766 1860d6a 6765->6766 6767 18611c2 2 API calls 6765->6767 6766->6742 6767->6766 6769 18611f5 6768->6769 6770 1861233 6769->6770 6773 55e0d66 6769->6773 6776 55e0d10 6769->6776 6770->6762 6774 55e0db6 GetVolumeInformationA 6773->6774 6775 55e0dbe 6774->6775 6775->6770 6777 55e0d66 GetVolumeInformationA 6776->6777 6779 55e0dbe 6777->6779 6779->6770 6780 55e1daa 6781 55e1de2 RegCreateKeyExW 6780->6781 6783 55e1e54 6781->6783 6787 55e22aa 6788 55e22d9 AdjustTokenPrivileges 6787->6788 6790 55e22fb 6788->6790 6659 55e0366 6660 55e039e MapViewOfFile 6659->6660 6662 55e03ed 6660->6662 6663 55e25e6 6665 55e261b SetProcessWorkingSetSize 6663->6665 6666 55e2647 6665->6666 6791 136a74e 6792 136a77a FindCloseChangeNotification 6791->6792 6793 136a7b9 6791->6793 6794 136a788 6792->6794 6793->6792 6795 55e2426 6796 55e245b GetExitCodeProcess 6795->6796 6798 55e2484 6796->6798 6799 136adce 6800 136ae30 6799->6800 6801 136adfa OleInitialize 6799->6801 6800->6801 6802 136ae08 6801->6802 6803 18603f8 KiUserExceptionDispatcher 6804 186042c 6803->6804

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 0 18619f0-1861a4c 4 1861a52-1861a66 0->4 5 1862f39-1862f5a 0->5 8 1861a74-1861a85 4->8 9 1861a68-1861a6f 4->9 10 1862fc6-1863002 5->10 11 1862f5c-1862f66 5->11 18 1861a87-1861ac7 call 18613b0 8->18 19 1861acc-1861add 8->19 12 186306e-1863075 9->12 30 1863004-186304b call 18613b0 10->30 31 186304d-1863052 10->31 13 1862f6c-1862fbc 11->13 14 1863069 11->14 13->10 26 1862fbe-1862fc0 13->26 14->12 18->12 24 1861c12-1861c23 19->24 25 1861ae3-1861aed 19->25 35 1861e61-1861e72 24->35 36 1861c29-1861c33 24->36 25->5 28 1861af3-1861b07 25->28 26->10 39 1861b3b-1861b4c 28->39 40 1861b09-1861b13 28->40 42 186305d-1863067 30->42 31->42 50 1862288-1862299 35->50 51 1861e78-1861e82 35->51 36->5 41 1861c39-1861c40 36->41 55 1861b52-1861b5c 39->55 56 1861bdd-1861bee 39->56 40->5 45 1861b19-1861b26 40->45 41->5 46 1861c46-1861c4b 41->46 42->12 45->5 52 1861b2c-1861b36 call 1861908 45->52 53 1861c51-1861c7a 46->53 54 1861d0d-1861d36 46->54 72 1862583-1862594 50->72 73 186229f-18622a9 50->73 51->5 60 1861e88-1861eb8 call 1860550 51->60 52->12 81 1861ccf-1861d08 call 18613b0 * 2 53->81 82 1861c7c-1861ca0 53->82 94 1861d71-1861d8d call 18613b0 54->94 55->5 62 1861b62-1861b6f 55->62 56->12 76 1861bf4-1861bfe 56->76 60->5 100 1861ebe-1861edf 60->100 62->5 68 1861b75-1861bd8 call 1861908 call 1860550 call 18613b0 62->68 68->12 87 1862932-1862943 72->87 88 186259a-1862761 72->88 73->5 74 18622af-18622df call 1860550 73->74 74->5 126 18622e5-1862306 74->126 76->5 83 1861c04-1861c0d 76->83 81->12 104 1861ca2-1861cc5 82->104 105 1861cca 82->105 83->12 112 18629fe-1862a0f 87->112 113 1862949-1862953 87->113 88->5 314 1862767-186277f 88->314 94->5 129 1861d93-1861dfd call 18613b0 94->129 109 1861ee5-1861f63 call 18613b0 100->109 110 1861f68-1861f6f 100->110 104->94 105->81 109->12 117 1861f75-1861ff1 110->117 118 1862069-186217e call 18613b0 110->118 130 1862a15-1862a1f 112->130 131 1862c51-1862c62 112->131 113->5 121 1862959-186296d 113->121 117->5 246 1861ff7-186202f 117->246 118->5 347 1862184-18621c8 118->347 141 186296f 121->141 142 186297a-186298b 121->142 135 186238f-1862396 126->135 136 186230c-186238a call 18613b0 126->136 129->12 130->5 140 1862a25-1862a2c 130->140 156 1862de1-1862df2 131->156 157 1862c68-1862c6f 131->157 145 186241f-186257e call 18613b0 * 2 135->145 146 186239c-18623e5 135->146 136->12 140->5 149 1862a32-1862a37 140->149 413 186296f call 18631b2 141->413 414 186296f call 18631a0 141->414 415 186296f call 1863081 141->415 416 186296f call 186316c 141->416 172 18629b1-18629c2 142->172 173 186298d-18629ac 142->173 145->12 203 1862f34 146->203 204 18623eb-186241a call 1861908 146->204 159 1862a3d-1862a80 149->159 160 1862aeb-1862b1a 149->160 156->12 183 1862df8-1862e3b 156->183 167 1862c75-1862c9e call 18613b0 157->167 168 1862cfe-1862d65 157->168 225 1862a82-1862aa8 159->225 226 1862aad-1862ae6 call 18613b0 * 2 159->226 221 1862b55-1862c4c call 18613b0 * 2 160->221 162 1862975 162->12 195 1862ca0-1862ca3 167->195 196 1862cdc-1862cf8 167->196 168->5 233 1862d6b-1862d94 168->233 172->12 201 18629c8-18629f9 172->201 173->12 183->203 247 1862e41-1862f2f 183->247 195->203 206 1862ca9-1862cda 195->206 196->12 196->168 201->12 203->5 204->145 206->195 206->196 221->12 225->221 226->12 233->12 260 1862d9a-1862d9e 233->260 246->203 298 1862035-1862064 call 1861908 246->298 247->12 260->5 269 1862da4-1862ddc 260->269 269->12 298->118 314->5 322 1862785-186289d call 1863081 314->322 393 18628f3-18628f7 322->393 394 186289f-18628cb 322->394 364 18621d4-186223c 347->364 385 186223e-1862283 364->385 386 18621ca 364->386 385->12 386->364 397 18628ff-1862928 call 18613e8 393->397 403 18628d7-18628da 394->403 404 18628cd-18628cf 394->404 411 186292d 397->411 403->203 406 18628e0-18628f1 403->406 404->203 405 18628d5 404->405 405->406 406->397 411->12 413->162 414->162 415->162 416->162
                                  Strings
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851570318.0000000001860000.00000040.00000800.00020000.00000000.sdmp, Offset: 01860000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_1860000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID: $ $:@<l$:@<l$:@<l$:@<l$:@<l$:@<l$:@<l
                                  • API String ID: 0-564494652
                                  • Opcode ID: e8a186cb6e8b93d06696836388f6fd1a0f8e326c9a1d9f9b7d2ea886b88e7a57
                                  • Instruction ID: e68e73eeb50429005723097380c8990375194dab43deda2d0ab71e945ada89cd
                                  • Opcode Fuzzy Hash: e8a186cb6e8b93d06696836388f6fd1a0f8e326c9a1d9f9b7d2ea886b88e7a57
                                  • Instruction Fuzzy Hash: 9AC27D34B002148FDB14DB69C954BAEB7A7BF88308F0180A9D50ADB7A1DF759E45CF91
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • AdjustTokenPrivileges.KERNELBASE(?,?,?,?,?,?), ref: 055E22F3
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: AdjustPrivilegesToken
                                  • String ID:
                                  • API String ID: 2874748243-0
                                  • Opcode ID: 58af15e8a535d8694f1cb787e13dda8b12e83b1147f84a03c40ddd91eaf81b33
                                  • Instruction ID: 5a90fb70add8951293a5c51459554e535678544341017239e15b27ea76ba5ad7
                                  • Opcode Fuzzy Hash: 58af15e8a535d8694f1cb787e13dda8b12e83b1147f84a03c40ddd91eaf81b33
                                  • Instruction Fuzzy Hash: BA21DE765093809FDB228F25DC40B52BFF8FF0A310F0985DAE9858B563D271A908CB62
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • AdjustTokenPrivileges.KERNELBASE(?,?,?,?,?,?), ref: 055E22F3
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: AdjustPrivilegesToken
                                  • String ID:
                                  • API String ID: 2874748243-0
                                  • Opcode ID: f39f861d93740bae1276c164a8c474fbed294b78e8b4ad980e74782fd1813d83
                                  • Instruction ID: ba94d0aa416a5f48248b85328f190633a147b2f18b3220a9ae7b2ac2a69d4f94
                                  • Opcode Fuzzy Hash: f39f861d93740bae1276c164a8c474fbed294b78e8b4ad980e74782fd1813d83
                                  • Instruction Fuzzy Hash: BC115E7A5002009FDB25CF56D844B66FBE8FF08220F08C9AAED458BA55D375E418DF61
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: recv
                                  • String ID:
                                  • API String ID: 1507349165-0
                                  • Opcode ID: e97cebd945257dc9e325944c0e62e752b1fa0236d085dcb73cb9d58466cbabf5
                                  • Instruction ID: 739151ae4476e24119916fd760360e0091b4aaee05e857a6352aac6c70e8f347
                                  • Opcode Fuzzy Hash: e97cebd945257dc9e325944c0e62e752b1fa0236d085dcb73cb9d58466cbabf5
                                  • Instruction Fuzzy Hash: 9D01B131804240DFDB20CF55D884B52FBE8FF04364F08C49ADD494BA56D375A408CFA2
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 552 18603f8-1860436 KiUserExceptionDispatcher 555 1860439-186043f 552->555 556 1860445-1860448 555->556 557 186052d-186053e 555->557 558 186044a 556->558 586 186044c call 18005e0 558->586 587 186044c call 1800606 558->587 560 1860451-1860472 563 1860474-1860476 560->563 564 18604b9-18604bc 560->564 583 1860478 call 18005e0 563->583 584 1860478 call 1861587 563->584 585 1860478 call 1800606 563->585 564->557 565 18604be-18604c4 564->565 565->558 566 18604c6-18604cd 565->566 568 186051e-1860528 566->568 569 18604cf-18604e5 566->569 567 186047e-1860485 570 18604b6 567->570 571 1860487-18604ae 567->571 568->555 569->557 575 18604e7-18604ef 569->575 570->564 571->570 576 1860510-1860516 575->576 577 18604f1-18604fc 575->577 576->568 577->557 579 18604fe-1860508 577->579 579->576 583->567 584->567 585->567 586->560 587->560
                                  APIs
                                  • KiUserExceptionDispatcher.NTDLL ref: 0186041F
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851570318.0000000001860000.00000040.00000800.00020000.00000000.sdmp, Offset: 01860000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_1860000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: DispatcherExceptionUser
                                  • String ID:
                                  • API String ID: 6842923-0
                                  • Opcode ID: 9a020e253ed608ad31cdc35af75add357b0aa588c6ab206760499d407db332cd
                                  • Instruction ID: 4a9e5ec3a130277575a7fbc2544d942d685ee48fb6532989ae22af1967f8ec91
                                  • Opcode Fuzzy Hash: 9a020e253ed608ad31cdc35af75add357b0aa588c6ab206760499d407db332cd
                                  • Instruction Fuzzy Hash: 24316D31A002048FCB14DF79D88459DB7BAEF88308F148079E908EB759DB75DE85CBA5
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 588 136b5de-136b676 592 136b67b-136b687 588->592 593 136b678 588->593 594 136b68c-136b695 592->594 595 136b689 592->595 593->592 596 136b6e6-136b6eb 594->596 597 136b697-136b6bb CreateFileW 594->597 595->594 596->597 600 136b6ed-136b6f2 597->600 601 136b6bd-136b6e3 597->601 600->601
                                  APIs
                                  • CreateFileW.KERNELBASE(?,?,?,?,?,?), ref: 0136B69D
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: CreateFile
                                  • String ID:
                                  • API String ID: 823142352-0
                                  • Opcode ID: 6e3760c1bac180ce1313d3c69dd0e4af1e5d5f2b42019c118e2ea0cb9a4fd41b
                                  • Instruction ID: 92b126ca8ba48ed2f01c00dce2146346fe2ff33cdae872c6343ce93a20892ff1
                                  • Opcode Fuzzy Hash: 6e3760c1bac180ce1313d3c69dd0e4af1e5d5f2b42019c118e2ea0cb9a4fd41b
                                  • Instruction Fuzzy Hash: 4631C5B1504380AFE712CF25DC44BA2BFE8EF06314F08849AE984CB653D335A809DB71
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 604 18603e8-1860425 KiUserExceptionDispatcher 605 186042c-1860436 604->605 607 1860439-186043f 605->607 608 1860445-1860448 607->608 609 186052d-186053e 607->609 610 186044a 608->610 638 186044c call 18005e0 610->638 639 186044c call 1800606 610->639 612 1860451-1860472 615 1860474-1860476 612->615 616 18604b9-18604bc 612->616 635 1860478 call 18005e0 615->635 636 1860478 call 1861587 615->636 637 1860478 call 1800606 615->637 616->609 617 18604be-18604c4 616->617 617->610 618 18604c6-18604cd 617->618 620 186051e-1860528 618->620 621 18604cf-18604e5 618->621 619 186047e-1860485 622 18604b6 619->622 623 1860487-18604ae 619->623 620->607 621->609 627 18604e7-18604ef 621->627 622->616 623->622 628 1860510-1860516 627->628 629 18604f1-18604fc 627->629 628->620 629->609 631 18604fe-1860508 629->631 631->628 635->619 636->619 637->619 638->612 639->612
                                  APIs
                                  • KiUserExceptionDispatcher.NTDLL ref: 0186041F
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851570318.0000000001860000.00000040.00000800.00020000.00000000.sdmp, Offset: 01860000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_1860000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: DispatcherExceptionUser
                                  • String ID:
                                  • API String ID: 6842923-0
                                  • Opcode ID: 21610bdf7d81d1f4e2ff217401b094479c24136b1c0748c8f0cf504a9eee56a5
                                  • Instruction ID: a183c07a1ba27f2d983a4243fdb498053c69d51e103168871e391def00b12450
                                  • Opcode Fuzzy Hash: 21610bdf7d81d1f4e2ff217401b094479c24136b1c0748c8f0cf504a9eee56a5
                                  • Instruction Fuzzy Hash: 1A415F71A002058FCB14DF78C89459DBBFAEF88304F548169E809DB35ADB75DE41CBA5
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 640 55e1d7e-55e1e02 644 55e1e07-55e1e13 640->644 645 55e1e04 640->645 646 55e1e18-55e1e21 644->646 647 55e1e15 644->647 645->644 648 55e1e26-55e1e3d 646->648 649 55e1e23 646->649 647->646 651 55e1e7f-55e1e84 648->651 652 55e1e3f-55e1e52 RegCreateKeyExW 648->652 649->648 651->652 653 55e1e86-55e1e8b 652->653 654 55e1e54-55e1e7c 652->654 653->654
                                  APIs
                                  • RegCreateKeyExW.KERNELBASE(?,00000E24), ref: 055E1E45
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: Create
                                  • String ID:
                                  • API String ID: 2289755597-0
                                  • Opcode ID: cc924d03e392759355047e0f19db0cf6987ca65c760af75383f65719edd682fd
                                  • Instruction ID: 1c125db0827591fe596bd6428ffc2aa757e1b02c261ad331fdb5ef54c95a762d
                                  • Opcode Fuzzy Hash: cc924d03e392759355047e0f19db0cf6987ca65c760af75383f65719edd682fd
                                  • Instruction Fuzzy Hash: 39315072504744AFE7218B65CC44F67BFFCEF09214F08459AF9858B552D324E508CBA1
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 659 136bb4b-136bb6b 660 136bb8d-136bbbf 659->660 661 136bb6d-136bb8c 659->661 665 136bbc2-136bc1a RegQueryValueExW 660->665 661->660 667 136bc20-136bc36 665->667
                                  APIs
                                  • RegQueryValueExW.KERNELBASE(?,00000E24,?,?), ref: 0136BC12
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: QueryValue
                                  • String ID:
                                  • API String ID: 3660427363-0
                                  • Opcode ID: c4e245ed2f1e341b32ddb818e53077128400e6ff5d45d1378d74f33654d47911
                                  • Instruction ID: d003184f299080a8eb9a6e9db3b2fb7d311f33e592664f648e803bc045268115
                                  • Opcode Fuzzy Hash: c4e245ed2f1e341b32ddb818e53077128400e6ff5d45d1378d74f33654d47911
                                  • Instruction Fuzzy Hash: 10319E6510E3C0AFD3139B258C65A61BFB4EF47614B0E85CBE8C48F6A3D2196909D7B2
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 668 136a7c7-136a855 672 136a857 668->672 673 136a85a-136a871 668->673 672->673 675 136a8b3-136a8b8 673->675 676 136a873-136a886 RegOpenKeyExW 673->676 675->676 677 136a8ba-136a8bf 676->677 678 136a888-136a8b0 676->678 677->678
                                  APIs
                                  • RegOpenKeyExW.KERNELBASE(?,00000E24), ref: 0136A879
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: Open
                                  • String ID:
                                  • API String ID: 71445658-0
                                  • Opcode ID: ee7c9b51e5ef6724bc876afba9035489fbd653ebc1991c2e38c9359ca5227cd7
                                  • Instruction ID: d319a9230e135ab1baa4f2a0f05472a0a0bf06463a0550a3abbc8181a0555323
                                  • Opcode Fuzzy Hash: ee7c9b51e5ef6724bc876afba9035489fbd653ebc1991c2e38c9359ca5227cd7
                                  • Instruction Fuzzy Hash: D231A7B24083846FE7228B55DC44FA7BFFCEF06214F09859AE9849B653D264A909C771
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 683 55e099c-55e0a5b 689 55e0aad-55e0ab2 683->689 690 55e0a5d-55e0a65 getaddrinfo 683->690 689->690 691 55e0a6b-55e0a7d 690->691 693 55e0a7f-55e0aaa 691->693 694 55e0ab4-55e0ab9 691->694 694->693
                                  APIs
                                  • getaddrinfo.WS2_32(?,00000E24), ref: 055E0A63
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: getaddrinfo
                                  • String ID:
                                  • API String ID: 300660673-0
                                  • Opcode ID: 95f257c32a577f744e745ff3bd23e225a3d50931a7550ff3cb3ca62f2bf4de4d
                                  • Instruction ID: daa7a1b5270ea06891c9d90788f019df3e6426330a062009b0dbd58f77487ff3
                                  • Opcode Fuzzy Hash: 95f257c32a577f744e745ff3bd23e225a3d50931a7550ff3cb3ca62f2bf4de4d
                                  • Instruction Fuzzy Hash: 5B31C2B2404344AFEB21CB51CC85FA6FBACEF44314F04499AFA489B192D3B5A908CB71
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 729 55e0894-55e0929 734 55e092b-55e0933 GetProcessTimes 729->734 735 55e0976-55e097b 729->735 737 55e0939-55e094b 734->737 735->734 738 55e097d-55e0982 737->738 739 55e094d-55e0973 737->739 738->739
                                  APIs
                                  • GetProcessTimes.KERNELBASE(?,00000E24,4ED910D6,00000000,00000000,00000000,00000000), ref: 055E0931
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: ProcessTimes
                                  • String ID:
                                  • API String ID: 1995159646-0
                                  • Opcode ID: 50c151f43bedf0a0aeff49ca15e63319de919657a5be57d6674a15b69668bde9
                                  • Instruction ID: a4381cb71507cfcecaa7a1173cc4074ad34239792cfa3be778a4fac9e5e1b4f4
                                  • Opcode Fuzzy Hash: 50c151f43bedf0a0aeff49ca15e63319de919657a5be57d6674a15b69668bde9
                                  • Instruction Fuzzy Hash: 1031DC724053806FDB128F61DC45FA6BFB8EF06314F0984DAE984CB5A3D3259909C771
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 714 55e0190-55e0211 718 55e0216-55e021f 714->718 719 55e0213 714->719 720 55e0277-55e027c 718->720 721 55e0221-55e0229 ConvertStringSecurityDescriptorToSecurityDescriptorW 718->721 719->718 720->721 723 55e022f-55e0241 721->723 724 55e027e-55e0283 723->724 725 55e0243-55e0274 723->725 724->725
                                  APIs
                                  • ConvertStringSecurityDescriptorToSecurityDescriptorW.ADVAPI32(?,00000E24), ref: 055E0227
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: DescriptorSecurity$ConvertString
                                  • String ID:
                                  • API String ID: 3907675253-0
                                  • Opcode ID: b04a8ee3da8011ad05c7a443ac36052ad15eb6f9d9e7f17d8d882dce3df9dd9f
                                  • Instruction ID: 2d65eacbe39d509c011621da7a8387005e0953562489d8f5df96448217526104
                                  • Opcode Fuzzy Hash: b04a8ee3da8011ad05c7a443ac36052ad15eb6f9d9e7f17d8d882dce3df9dd9f
                                  • Instruction Fuzzy Hash: 05319372504385AFEB21CB65DC45FA7BBF8FF05210F0984AAE944CB692D364A908CB71
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 698 136a612-136a695 702 136a697 698->702 703 136a69a-136a6a3 698->703 702->703 704 136a6a5 703->704 705 136a6a8-136a6b1 703->705 704->705 706 136a702-136a707 705->706 707 136a6b3-136a6d7 CreateMutexW 705->707 706->707 710 136a709-136a70e 707->710 711 136a6d9-136a6ff 707->711 710->711
                                  APIs
                                  • CreateMutexW.KERNELBASE(?,?), ref: 0136A6B9
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: CreateMutex
                                  • String ID:
                                  • API String ID: 1964310414-0
                                  • Opcode ID: 3e3375b34f9f7073a6b47aa1d224be6f81912f7d4d4495e6bebdf5f9c8b2937c
                                  • Instruction ID: fba326595f8d1b3eebf0d68c41852beb9a9c6fff0702f71a16604f428ef317fd
                                  • Opcode Fuzzy Hash: 3e3375b34f9f7073a6b47aa1d224be6f81912f7d4d4495e6bebdf5f9c8b2937c
                                  • Instruction Fuzzy Hash: 1931B3B15093805FE712CB65CC45B96BFF8EF06214F09849AE984CB693D375E909CB62
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Control-flow Graph

                                  • Executed
                                  • Not Executed
                                  control_flow_graph 742 55e1daa-55e1e02 745 55e1e07-55e1e13 742->745 746 55e1e04 742->746 747 55e1e18-55e1e21 745->747 748 55e1e15 745->748 746->745 749 55e1e26-55e1e3d 747->749 750 55e1e23 747->750 748->747 752 55e1e7f-55e1e84 749->752 753 55e1e3f-55e1e52 RegCreateKeyExW 749->753 750->749 752->753 754 55e1e86-55e1e8b 753->754 755 55e1e54-55e1e7c 753->755 754->755
                                  APIs
                                  • RegCreateKeyExW.KERNELBASE(?,00000E24), ref: 055E1E45
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: Create
                                  • String ID:
                                  • API String ID: 2289755597-0
                                  • Opcode ID: e757fbb5cab8deed9ba6e5151669e514ceed8239de7647c7464970fee74764da
                                  • Instruction ID: 9690b20e76706a490dcdd6e85b18bd82b2efe83b7ed210c6e9e295a990119f6f
                                  • Opcode Fuzzy Hash: e757fbb5cab8deed9ba6e5151669e514ceed8239de7647c7464970fee74764da
                                  • Instruction Fuzzy Hash: B4215AB2500704AFEB21DE25DC44FA7BBECFF08614F08895AF945DAA51E774E508CAA1
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • getaddrinfo.WS2_32(?,00000E24), ref: 055E0A63
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: getaddrinfo
                                  • String ID:
                                  • API String ID: 300660673-0
                                  • Opcode ID: 42c6f5847ebb7ea9473d7fc34b79b984954317044d11debeb2c811126315782f
                                  • Instruction ID: cb7f7b43cc5e17f57b33f74087b5c2d2b7008a8d90abb4214544573f33eea7d4
                                  • Opcode Fuzzy Hash: 42c6f5847ebb7ea9473d7fc34b79b984954317044d11debeb2c811126315782f
                                  • Instruction Fuzzy Hash: DD21A1B2500204AEFB21DB51CC85FA6F7ACEF04714F04899AFA499B691D7B5A5088BB1
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • GetVolumeInformationA.KERNELBASE(?,00000E24,?,?), ref: 055E0DB6
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: InformationVolume
                                  • String ID:
                                  • API String ID: 2039140958-0
                                  • Opcode ID: 69e4f7a1eaff28db7c0a2e47b39e9fc7c3f7fa25496b9110d163d96f3d239d4e
                                  • Instruction ID: 53804670ce6c94dc1c69a0e867f586783c9876f249c568e7845ea5f21b2c3b20
                                  • Opcode Fuzzy Hash: 69e4f7a1eaff28db7c0a2e47b39e9fc7c3f7fa25496b9110d163d96f3d239d4e
                                  • Instruction Fuzzy Hash: C631917150D3C16FD3128B258C55B62BFB8EF47610F0A85DBE884CF693D225A948C7A2
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: select
                                  • String ID:
                                  • API String ID: 1274211008-0
                                  • Opcode ID: 93eec27c8bf8247611f9636cbb63685eb1628e9e4a2a4454b22b07d0a4a02110
                                  • Instruction ID: 9e07219d12f26e1107bde05bbc2415810b376df2fe3895213a927acbc93f9fcd
                                  • Opcode Fuzzy Hash: 93eec27c8bf8247611f9636cbb63685eb1628e9e4a2a4454b22b07d0a4a02110
                                  • Instruction Fuzzy Hash: 122191755093849FDB22CF25CC44B52BFF8FF06310F0984DAE885CB162D225E909CB62
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • GetFileType.KERNELBASE(?,00000E24,4ED910D6,00000000,00000000,00000000,00000000), ref: 0136B789
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: FileType
                                  • String ID:
                                  • API String ID: 3081899298-0
                                  • Opcode ID: 7d9601b537d5ff396d37f6abe235e19a22dc1dddf477ebd158869bc089765a58
                                  • Instruction ID: 0ce623766bdac74b33a8a4add1cef0e16354348d60e4f651993ac21710d9ca6d
                                  • Opcode Fuzzy Hash: 7d9601b537d5ff396d37f6abe235e19a22dc1dddf477ebd158869bc089765a58
                                  • Instruction Fuzzy Hash: D121F8B54093806FD7138B259C85BA2BFBCEF47724F0981D6ED848B693D264A909CB71
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • RegQueryValueExW.KERNELBASE(?,00000E24,4ED910D6,00000000,00000000,00000000,00000000), ref: 0136A40C
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: QueryValue
                                  • String ID:
                                  • API String ID: 3660427363-0
                                  • Opcode ID: cae159ce6e54d8bddb8bb239d334c54e894859fe82aa7fce88f9d1bd190a6f8e
                                  • Instruction ID: 07a6e0c3bcb908afe0b6a9e4e150b2a5a0a4c03d024e4741eb0f229711ef9984
                                  • Opcode Fuzzy Hash: cae159ce6e54d8bddb8bb239d334c54e894859fe82aa7fce88f9d1bd190a6f8e
                                  • Instruction Fuzzy Hash: 1D219FB6504740AFE722CF15CC84FA2BBFCEF45614F08849AE985DB692D364E908CB71
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • GetExitCodeProcess.KERNELBASE(?,00000E24,4ED910D6,00000000,00000000,00000000,00000000), ref: 055E247C
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: CodeExitProcess
                                  • String ID:
                                  • API String ID: 3861947596-0
                                  • Opcode ID: 3176099b309af6742dec227aec50dee88fecd8a7f98e345f0e6b25c891f6cf8e
                                  • Instruction ID: d7ef68aa118bd4bd6394785e5ef6f59a04b8c6d8fbd356ec8e2bad5271f793f4
                                  • Opcode Fuzzy Hash: 3176099b309af6742dec227aec50dee88fecd8a7f98e345f0e6b25c891f6cf8e
                                  • Instruction Fuzzy Hash: EE21C4B25093806FE712CB25DC45F96BFB8EF42314F0984DAF944CF292D264A908C771
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: FileView
                                  • String ID:
                                  • API String ID: 3314676101-0
                                  • Opcode ID: 55e86896048fe86ab0324e2dfb4c5dd21f2fb1b27a995bb2211bc716de5e3517
                                  • Instruction ID: 92e2286460eecb34f250d6d163f0bed92f59db91104205b96b87394f819dabaf
                                  • Opcode Fuzzy Hash: 55e86896048fe86ab0324e2dfb4c5dd21f2fb1b27a995bb2211bc716de5e3517
                                  • Instruction Fuzzy Hash: 6D2191B1405384AFE722CB55DD44F96FFF8EF09224F08849EE9858B692D375A508CB62
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • WSASocketW.WS2_32(?,?,?,?,?), ref: 0136BCCA
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: Socket
                                  • String ID:
                                  • API String ID: 38366605-0
                                  • Opcode ID: e4baae91ba5e93626be2235c521eade957118eb88943e559cdbbce14de675ae9
                                  • Instruction ID: ac71946f1023f5aeecfbd9baec406b1d7885692756696c409e0ad8f2f07d52d9
                                  • Opcode Fuzzy Hash: e4baae91ba5e93626be2235c521eade957118eb88943e559cdbbce14de675ae9
                                  • Instruction Fuzzy Hash: 422160B1505380AFD722CF55DC45F96FFB8EF05224F08889EE9858B692D375A508CB62
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • RegSetValueExW.KERNELBASE(?,00000E24,4ED910D6,00000000,00000000,00000000,00000000), ref: 0136A4F8
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: Value
                                  • String ID:
                                  • API String ID: 3702945584-0
                                  • Opcode ID: bb48c1d7c4b58efca6df5c25e0de502bbd38f67597b9e9a4dbf0d17165de6fa8
                                  • Instruction ID: eaf4c68070f9b7b049a71311790f461ef06bbcd6fb90b9c0593e57a936f21dd7
                                  • Opcode Fuzzy Hash: bb48c1d7c4b58efca6df5c25e0de502bbd38f67597b9e9a4dbf0d17165de6fa8
                                  • Instruction Fuzzy Hash: F02181B65043806FD7228F15DC44FA7BFBCEF46214F08849AE9859B652D365E908C771
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • LookupPrivilegeValueW.ADVAPI32(?,?,?), ref: 055E2172
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: LookupPrivilegeValue
                                  • String ID:
                                  • API String ID: 3899507212-0
                                  • Opcode ID: ba098c453bc3d143cb1c44ee37174208edf2b80b284edefa865d770bb090769e
                                  • Instruction ID: adc7f7519d34afb4db3f11ec5a6fd641b9663a508b5dc85ac8af1f3ae1ecba7c
                                  • Opcode Fuzzy Hash: ba098c453bc3d143cb1c44ee37174208edf2b80b284edefa865d770bb090769e
                                  • Instruction Fuzzy Hash: 0921A4B65093C09FD716CF25DC50B56BFA8BF46224F0D84DAE989CB253E225D908C771
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • ConvertStringSecurityDescriptorToSecurityDescriptorW.ADVAPI32(?,00000E24), ref: 055E0227
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: DescriptorSecurity$ConvertString
                                  • String ID:
                                  • API String ID: 3907675253-0
                                  • Opcode ID: 3fccb5919d88450ce4562912ccde545a2d535021dd498f6d80387ea6d6d60c9f
                                  • Instruction ID: 350f6fd17369a6770ff551d2c180362337c0364a990064a2b2b1c727d881210c
                                  • Opcode Fuzzy Hash: 3fccb5919d88450ce4562912ccde545a2d535021dd498f6d80387ea6d6d60c9f
                                  • Instruction Fuzzy Hash: 17216272500205AFEB20DF65DC45F6ABBE8FF04614F08886AE945DB691D774E5088AB1
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • CreateFileW.KERNELBASE(?,?,?,?,?,?), ref: 0136B69D
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: CreateFile
                                  • String ID:
                                  • API String ID: 823142352-0
                                  • Opcode ID: 9d758872d64a97778cc348b10cb3f59d7c1de9f996aabd9c53eae6625e92af95
                                  • Instruction ID: d350658d3fe627eccc482fdabb81651369383c5e477ef97439658a68c23b1fcd
                                  • Opcode Fuzzy Hash: 9d758872d64a97778cc348b10cb3f59d7c1de9f996aabd9c53eae6625e92af95
                                  • Instruction Fuzzy Hash: FD21A171600204AFE721CF66CD45B66FBE8EF08224F088459E945CBA55D371E808CF71
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • RegQueryValueExW.KERNELBASE(?,00000E24,4ED910D6,00000000,00000000,00000000,00000000), ref: 055E013C
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: QueryValue
                                  • String ID:
                                  • API String ID: 3660427363-0
                                  • Opcode ID: cee8f9dc8b6b7398f8f368cb5d6e53955a62c9a3468e5cf64bce1ebd7fcaa2e7
                                  • Instruction ID: 9d6063af4aba84f0ddb4f23c046e2d1ade2fc082e47a94b933b80b12074cba12
                                  • Opcode Fuzzy Hash: cee8f9dc8b6b7398f8f368cb5d6e53955a62c9a3468e5cf64bce1ebd7fcaa2e7
                                  • Instruction Fuzzy Hash: D321AFB2504744AFD722CF11DC44FA7BBF8EF05610F08849AE9858B6A2D365E908CB71
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • RegOpenKeyExW.KERNELBASE(?,00000E24), ref: 0136A879
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: Open
                                  • String ID:
                                  • API String ID: 71445658-0
                                  • Opcode ID: 6356c499f23ca97fec02a517cac93c4cd23c155fd6880c05b8d946b81078a121
                                  • Instruction ID: f7fcb0cb4a6cc765061eb01e85a419c2d0ca3f3d52a96982b630dcac22d68f16
                                  • Opcode Fuzzy Hash: 6356c499f23ca97fec02a517cac93c4cd23c155fd6880c05b8d946b81078a121
                                  • Instruction Fuzzy Hash: 7D21A1B2500204AEE7219F55DC44FABFFECEF08218F04855AFA459BA52D764E5098AB1
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • GetProcessWorkingSetSize.KERNEL32(?,00000E24,4ED910D6,00000000,00000000,00000000,00000000), ref: 055E255B
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: ProcessSizeWorking
                                  • String ID:
                                  • API String ID: 3584180929-0
                                  • Opcode ID: 9bc112d2527c69b4827c38d48be6715447532909e828430c3ff0b6c02ec090eb
                                  • Instruction ID: ecb3588bebfce6f33e9855ba872c30eb445932934a2067c7385766b2f6a535ec
                                  • Opcode Fuzzy Hash: 9bc112d2527c69b4827c38d48be6715447532909e828430c3ff0b6c02ec090eb
                                  • Instruction Fuzzy Hash: E02195B55053806FD721CB15DC45FA6BFB8EF45214F08849BF9448B692D365A508CB61
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • SetProcessWorkingSetSize.KERNEL32(?,00000E24,4ED910D6,00000000,00000000,00000000,00000000), ref: 055E263F
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: ProcessSizeWorking
                                  • String ID:
                                  • API String ID: 3584180929-0
                                  • Opcode ID: 9bc112d2527c69b4827c38d48be6715447532909e828430c3ff0b6c02ec090eb
                                  • Instruction ID: 3c14fac0913858aec7547a02c7286ec2a2f02b5f8aba94a9fe0217e8b79dac13
                                  • Opcode Fuzzy Hash: 9bc112d2527c69b4827c38d48be6715447532909e828430c3ff0b6c02ec090eb
                                  • Instruction Fuzzy Hash: 2721D4B14043806FDB22CF21DC44FA6BFB8EF46224F08849AF944CB692D364A908CB71
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • CreateMutexW.KERNELBASE(?,?), ref: 0136A6B9
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: CreateMutex
                                  • String ID:
                                  • API String ID: 1964310414-0
                                  • Opcode ID: 3075eb2d4bdbb713760207867336b2efe00ee4167765cdbf293f453319a0b244
                                  • Instruction ID: 6466b7b1e71f0c1caf5ea4b77efaaae190d7952f6be6d669c5e3b20113cbc992
                                  • Opcode Fuzzy Hash: 3075eb2d4bdbb713760207867336b2efe00ee4167765cdbf293f453319a0b244
                                  • Instruction Fuzzy Hash: 5821D4B15002409FE710CF69CD45BA6FBECEF04228F08C469ED459BB41D375E809CA71
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • RegDeleteKeyW.ADVAPI32(?,00000E24,4ED910D6,00000000,00000000,00000000,00000000), ref: 055E381C
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: Delete
                                  • String ID:
                                  • API String ID: 1035893169-0
                                  • Opcode ID: cf00f1f2023436be821edf4035be74b6e0d32d815594cb55a434af6e882e9beb
                                  • Instruction ID: 1dad4f580615c5565c802f5b8934d095fa89816170ebd1ec85b77147f270732b
                                  • Opcode Fuzzy Hash: cf00f1f2023436be821edf4035be74b6e0d32d815594cb55a434af6e882e9beb
                                  • Instruction Fuzzy Hash: 9721C3B15093806FD722CB51DC45FA6FFB8EF46220F0984DBE9848B692D264B908C772
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • ReadFile.KERNELBASE(?,00000E24,4ED910D6,00000000,00000000,00000000,00000000), ref: 0136BA55
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: FileRead
                                  • String ID:
                                  • API String ID: 2738559852-0
                                  • Opcode ID: 02aaf862566d050ea0a26c46af4eb147f4226206b080ab9bc465ae1c69ff96b0
                                  • Instruction ID: 15e68e8c5d0abc3511b76a113c4cd7a6cda492e763bfd1b91a0ecf262c00710a
                                  • Opcode Fuzzy Hash: 02aaf862566d050ea0a26c46af4eb147f4226206b080ab9bc465ae1c69ff96b0
                                  • Instruction Fuzzy Hash: 40219272405380AFDB22CF55DC44F96FFB8EF45314F08849AE9448B652D225A508CB71
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: recv
                                  • String ID:
                                  • API String ID: 1507349165-0
                                  • Opcode ID: 06447bd2ab78465e00b75c40936da542aa5ae1cd5ee062b3b0c5edf4b2017714
                                  • Instruction ID: f7f1595bc866d508ff593015a3854b06c6f6071e9249bc9222a6ba3609d95859
                                  • Opcode Fuzzy Hash: 06447bd2ab78465e00b75c40936da542aa5ae1cd5ee062b3b0c5edf4b2017714
                                  • Instruction Fuzzy Hash: B9219A7140D3C09FD7238B619C54A52BFB4EF47220F0A85DBD9848B5A3D269A819CB62
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • ioctlsocket.WS2_32(?,00000E24,4ED910D6,00000000,00000000,00000000,00000000), ref: 055E1FD3
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: ioctlsocket
                                  • String ID:
                                  • API String ID: 3577187118-0
                                  • Opcode ID: ab42972ab28ee6c8802acf17958045296332fe7d2247e1c75a811cdbe23515f6
                                  • Instruction ID: b29a90bcecaf9d9f8388f33c793bb78e65ffd47a061ad7a94c6e96e853216506
                                  • Opcode Fuzzy Hash: ab42972ab28ee6c8802acf17958045296332fe7d2247e1c75a811cdbe23515f6
                                  • Instruction Fuzzy Hash: 6A21C3B14093806FDB22CF11DC44FA6BFB8EF46214F08849AF9449B692D375A508C772
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • RegQueryValueExW.KERNELBASE(?,00000E24,4ED910D6,00000000,00000000,00000000,00000000), ref: 0136A40C
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: QueryValue
                                  • String ID:
                                  • API String ID: 3660427363-0
                                  • Opcode ID: 8328002bb12292ef411be6ba4e17d6a2079ffe012c58c122b37593558b02735a
                                  • Instruction ID: d3bc97d59d5a9c3014d9ea78fe960ff036ab5067f76c5f6175e3c955f540c356
                                  • Opcode Fuzzy Hash: 8328002bb12292ef411be6ba4e17d6a2079ffe012c58c122b37593558b02735a
                                  • Instruction Fuzzy Hash: 5921C0B55002049FEB21CF16CC84FA6FBECEF04614F08C45AE945EBB52D360E909CA71
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • setsockopt.WS2_32(?,?,?,?,?), ref: 0136BDA0
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: setsockopt
                                  • String ID:
                                  • API String ID: 3981526788-0
                                  • Opcode ID: a03e04ac53ab1a0ca6a5920930f0205aae2fdf6c99f08d7efab58179201cc1ea
                                  • Instruction ID: 9436f64801aaa70915e383b92078753bed53e42fa656bebc30afd4e8a8defd3e
                                  • Opcode Fuzzy Hash: a03e04ac53ab1a0ca6a5920930f0205aae2fdf6c99f08d7efab58179201cc1ea
                                  • Instruction Fuzzy Hash: FC219A314093C09FDB228F65DC55A92BFB4EF07324F0985DAE9C48F563C2259859CB62
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • FindCloseChangeNotification.KERNELBASE(?), ref: 0136A780
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: ChangeCloseFindNotification
                                  • String ID:
                                  • API String ID: 2591292051-0
                                  • Opcode ID: 46bdd5aa3c2d36150869bf415878e53f7a5c8e5b39a8b4960cfa9feb5194f0d2
                                  • Instruction ID: cae59f75a220bb5d6b6b001f9ab858870d323b380bf0deeb053769e945d9b476
                                  • Opcode Fuzzy Hash: 46bdd5aa3c2d36150869bf415878e53f7a5c8e5b39a8b4960cfa9feb5194f0d2
                                  • Instruction Fuzzy Hash: FC21D2B54083809FDB128F65DD85752BFB8EF02324F0984EAEC858B653D2359909DBA1
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • WSAConnect.WS2_32(?,?,?,?,?,?,?), ref: 055E0BEA
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: Connect
                                  • String ID:
                                  • API String ID: 3144859779-0
                                  • Opcode ID: 63c8988cd7a2559bd81f780a1b8151a3d18b1ed71de9eb2d6c50790be318a8de
                                  • Instruction ID: 82c149a3b68664a1b7348e0c1b29f0aa27b5400c4a09add82a9a0c11daed6737
                                  • Opcode Fuzzy Hash: 63c8988cd7a2559bd81f780a1b8151a3d18b1ed71de9eb2d6c50790be318a8de
                                  • Instruction Fuzzy Hash: 6F219271408780AFDB228F51DC44B62FFF8FF06310F0885DAE9858B562D375A819DB61
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: FileView
                                  • String ID:
                                  • API String ID: 3314676101-0
                                  • Opcode ID: c951da1b2acfc11db5e147fd5d082479a88474c1445dc5a0821ad6205edb649c
                                  • Instruction ID: 0a4bd2ff524066a8c88afc0d3587e1d88de66377eb648f76d4ea7f44357ff407
                                  • Opcode Fuzzy Hash: c951da1b2acfc11db5e147fd5d082479a88474c1445dc5a0821ad6205edb649c
                                  • Instruction Fuzzy Hash: 052181B1500204AFE721CF55DD49FA6FBE8EF08324F048559E9858B691D3B5F509CBA2
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • WSASocketW.WS2_32(?,?,?,?,?), ref: 0136BCCA
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: Socket
                                  • String ID:
                                  • API String ID: 38366605-0
                                  • Opcode ID: a3f3ab1faff5a88192ef0803de68fbd5558bb475b9c5ff4c17f755fefc7414c5
                                  • Instruction ID: c1986c9418d95f6664c8cecfffa181c77bd31945a020912fff76e542ba6c3e88
                                  • Opcode Fuzzy Hash: a3f3ab1faff5a88192ef0803de68fbd5558bb475b9c5ff4c17f755fefc7414c5
                                  • Instruction Fuzzy Hash: DA21A171500204AFEB21CF55DD45B96FBE8EF08324F08885EE9458BA56D375A509CB72
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • LoadLibraryA.KERNELBASE(?,00000E24), ref: 055E105B
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: LibraryLoad
                                  • String ID:
                                  • API String ID: 1029625771-0
                                  • Opcode ID: bc451c8cdfadd3fb4d544476a25836806eead01e1895eb11ce03ffcedc3af0e4
                                  • Instruction ID: 36afe1baff676f070c6096b8e640b3d29feda4fdbedaf94b634c22446877eabf
                                  • Opcode Fuzzy Hash: bc451c8cdfadd3fb4d544476a25836806eead01e1895eb11ce03ffcedc3af0e4
                                  • Instruction Fuzzy Hash: 8111B4714083806FE721CB11DC85FA6FBB8EF45724F0880DAF9445B692D265B948CB71
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • LoadLibraryShim.MSCOREE(?,?,?,?), ref: 055E2E85
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: LibraryLoadShim
                                  • String ID:
                                  • API String ID: 1475914169-0
                                  • Opcode ID: 0a65f550afd674563da6a852f5a7410a6a01dfd2f9c623c62b8fe9e84944d476
                                  • Instruction ID: 6b6e44d9302c275a904610d170c5d8efd7b3fb4522d8a95adb13e576e3f2b71f
                                  • Opcode Fuzzy Hash: 0a65f550afd674563da6a852f5a7410a6a01dfd2f9c623c62b8fe9e84944d476
                                  • Instruction Fuzzy Hash: 892190B55083809FDB228F15DC44B62BFF8FF46214F09808AED85CB653D265A908CB72
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • RegQueryValueExW.KERNELBASE(?,00000E24,4ED910D6,00000000,00000000,00000000,00000000), ref: 055E013C
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: QueryValue
                                  • String ID:
                                  • API String ID: 3660427363-0
                                  • Opcode ID: 766a68553655eb357d1769fabc029e838e7cd8f1aa196b3a7cb77cd9d5c94db7
                                  • Instruction ID: 17cca61e6e42d287a78f49de520d957858dff9ccbf14af4e655b6a6fe4217565
                                  • Opcode Fuzzy Hash: 766a68553655eb357d1769fabc029e838e7cd8f1aa196b3a7cb77cd9d5c94db7
                                  • Instruction Fuzzy Hash: 02118176500704AFEB25CF15DC85FA7F7E8FF04724F08855AE9458B6A1D3A4E508CAB1
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • RegSetValueExW.KERNELBASE(?,00000E24,4ED910D6,00000000,00000000,00000000,00000000), ref: 0136A4F8
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: Value
                                  • String ID:
                                  • API String ID: 3702945584-0
                                  • Opcode ID: f67c03e196d1199066dd49890b363e6f3927057a60200c1fdd6c29f6f075849f
                                  • Instruction ID: 84edbc5c154647a22b6b036434ad30e19493b5364056fdb69b59fac25961118e
                                  • Opcode Fuzzy Hash: f67c03e196d1199066dd49890b363e6f3927057a60200c1fdd6c29f6f075849f
                                  • Instruction Fuzzy Hash: 7911D3B6500204AFEB21CE15DC44FA7FBECEF04614F08C55AEE45ABB41D360E508CA71
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • GetProcessTimes.KERNELBASE(?,00000E24,4ED910D6,00000000,00000000,00000000,00000000), ref: 055E0931
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: ProcessTimes
                                  • String ID:
                                  • API String ID: 1995159646-0
                                  • Opcode ID: 58e55127e535c8d0b4f95e8312c54dac3307f44c9f8c37cceb144ca903b29970
                                  • Instruction ID: a31d800fbcebcb4484767cb95e88eea04e85602cf2a0d65f2b4c270da7a6d198
                                  • Opcode Fuzzy Hash: 58e55127e535c8d0b4f95e8312c54dac3307f44c9f8c37cceb144ca903b29970
                                  • Instruction Fuzzy Hash: DF11B672500204AFEB21CF55DC45FA6FBE8EF04324F08C45AE945CB691D775A508CBB1
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • GetComputerNameW.KERNEL32(?,00000E24,?,?), ref: 055E0082
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: ComputerName
                                  • String ID:
                                  • API String ID: 3545744682-0
                                  • Opcode ID: ee7366b760e32923c9dca720153a8f1cfbd7a657fee5e1e128bb14c0d423ceab
                                  • Instruction ID: af643473e78c45ed33ee04ac64230b3741b5975eee84f44e46a7c55d109b0443
                                  • Opcode Fuzzy Hash: ee7366b760e32923c9dca720153a8f1cfbd7a657fee5e1e128bb14c0d423ceab
                                  • Instruction Fuzzy Hash: 0611E7715043406FD311DB16DC41F72BFF8EF8AA20F09819AFC4897A42D265B919CBB2
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • GetProcessWorkingSetSize.KERNEL32(?,00000E24,4ED910D6,00000000,00000000,00000000,00000000), ref: 055E255B
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: ProcessSizeWorking
                                  • String ID:
                                  • API String ID: 3584180929-0
                                  • Opcode ID: 08209f5e9ce9b54c5f5137b1bc41502e74373fa253aea391fe094f8ce43600ea
                                  • Instruction ID: f6797f9f006dad627b92cd842e12de17a0eec4683b2faf629d52a8a2b8780a8c
                                  • Opcode Fuzzy Hash: 08209f5e9ce9b54c5f5137b1bc41502e74373fa253aea391fe094f8ce43600ea
                                  • Instruction Fuzzy Hash: F711C1B6900200AFEB21CF15DD85FAABBECEF44324F08846AED458F641D774A509CAB1
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • PostMessageW.USER32(?,?,?,?), ref: 055E3B51
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: MessagePost
                                  • String ID:
                                  • API String ID: 410705778-0
                                  • Opcode ID: 0283948e548cedfe02b3a3c4caa98666fa94acb15c8888c33e37878e2b9ed357
                                  • Instruction ID: 9d91132254124795a4c4f3c7e7d1b54a5f7eeb2dee7ed020c746a67996042fb9
                                  • Opcode Fuzzy Hash: 0283948e548cedfe02b3a3c4caa98666fa94acb15c8888c33e37878e2b9ed357
                                  • Instruction Fuzzy Hash: C0216D724093C09FDB238F25DC44A52BFB4EF17220F0985DBE9858F563D265A918DB62
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • SetProcessWorkingSetSize.KERNEL32(?,00000E24,4ED910D6,00000000,00000000,00000000,00000000), ref: 055E263F
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: ProcessSizeWorking
                                  • String ID:
                                  • API String ID: 3584180929-0
                                  • Opcode ID: 08209f5e9ce9b54c5f5137b1bc41502e74373fa253aea391fe094f8ce43600ea
                                  • Instruction ID: 950240b8e9edfde93f5cd8905070f0e4e15bdfb5c9a0981c17ea15495f76b654
                                  • Opcode Fuzzy Hash: 08209f5e9ce9b54c5f5137b1bc41502e74373fa253aea391fe094f8ce43600ea
                                  • Instruction Fuzzy Hash: 3D11C4B55002009FEB25CF15DC45FA6B7ACEF45324F0889AAED45CBA45D774A508CAB1
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • GetExitCodeProcess.KERNELBASE(?,00000E24,4ED910D6,00000000,00000000,00000000,00000000), ref: 055E247C
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: CodeExitProcess
                                  • String ID:
                                  • API String ID: 3861947596-0
                                  • Opcode ID: 99993366377b4fcb9ca717c9dce9df6135e7283c9488fa9025b7b7924f1edd33
                                  • Instruction ID: 40dcff66b3c41aca7b56a71955a87ad117b57397208d70c1072f980fb6401095
                                  • Opcode Fuzzy Hash: 99993366377b4fcb9ca717c9dce9df6135e7283c9488fa9025b7b7924f1edd33
                                  • Instruction Fuzzy Hash: 3711A3B6500204AFEB21CF15DC45BAAB7ACEF44324F08C4AAED49CB685D775A508CAB1
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?), ref: 0136AC6E
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: DuplicateHandle
                                  • String ID:
                                  • API String ID: 3793708945-0
                                  • Opcode ID: 59863b584fc7ab68a2cfa5de34570f193afc6abce112f60b3705b2ae3642e338
                                  • Instruction ID: dfa76b579a9e2fd447e21d3de4c9dbdaade3c8ac19e0b4227649aec9932200b5
                                  • Opcode Fuzzy Hash: 59863b584fc7ab68a2cfa5de34570f193afc6abce112f60b3705b2ae3642e338
                                  • Instruction Fuzzy Hash: 8611B471408380AFDB228F55DC44B62FFF8EF4A320F0888DAED858B563C275A418DB61
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • ReadFile.KERNELBASE(?,00000E24,4ED910D6,00000000,00000000,00000000,00000000), ref: 0136BA55
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: FileRead
                                  • String ID:
                                  • API String ID: 2738559852-0
                                  • Opcode ID: 1161af2e772e07cf7cfce93f52fcad159c2164f1339504f4f45011c18376f606
                                  • Instruction ID: 89d4e33f800835b97a4c7beff6a56cf71a4a7aac8204cbf72e844b617edf43e7
                                  • Opcode Fuzzy Hash: 1161af2e772e07cf7cfce93f52fcad159c2164f1339504f4f45011c18376f606
                                  • Instruction Fuzzy Hash: 0411BF72500204AFEB21CF55DC44FAAFBECEF04324F08C85AE9498AA55D375A508CBB1
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • ioctlsocket.WS2_32(?,00000E24,4ED910D6,00000000,00000000,00000000,00000000), ref: 055E1FD3
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: ioctlsocket
                                  • String ID:
                                  • API String ID: 3577187118-0
                                  • Opcode ID: 70e39d64b4529982d313487bb1c6e0ffaa2e890c9cc4d5160c7bbb45d31557c2
                                  • Instruction ID: 3fe714dea9135549dd0f79ddf1ac0e428581e5769f081689e10256a1b297e72a
                                  • Opcode Fuzzy Hash: 70e39d64b4529982d313487bb1c6e0ffaa2e890c9cc4d5160c7bbb45d31557c2
                                  • Instruction Fuzzy Hash: 4A11A3B5400200AFEB21DF51DC44FA6FBE8FF44324F08885AED459B681D775A508CAB5
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • RegDeleteKeyW.ADVAPI32(?,00000E24,4ED910D6,00000000,00000000,00000000,00000000), ref: 055E381C
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: Delete
                                  • String ID:
                                  • API String ID: 1035893169-0
                                  • Opcode ID: a7f9dcc5b7b1c408852f724671fcafab1c211ff2343cb397dc5ce9a15a7a929b
                                  • Instruction ID: ed57256f1942c36d9ebf6e868b03b8fc303f58a0e6fd2c77387eb1aa5fd2e4dc
                                  • Opcode Fuzzy Hash: a7f9dcc5b7b1c408852f724671fcafab1c211ff2343cb397dc5ce9a15a7a929b
                                  • Instruction Fuzzy Hash: D611E5B2504200AEEB21CB02DC45FA6FBECFF04624F09C49AED459BB41D364F508CAB1
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • PostMessageW.USER32(?,?,?,?), ref: 055E3F3D
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: MessagePost
                                  • String ID:
                                  • API String ID: 410705778-0
                                  • Opcode ID: 112da231fda63800c3a6e161365e9ad5387fb142815f043f41636e01019400b9
                                  • Instruction ID: 26b38e439d75be59356f8d0110e0a53fbb1f9590a965f1e53fedea064f15ba34
                                  • Opcode Fuzzy Hash: 112da231fda63800c3a6e161365e9ad5387fb142815f043f41636e01019400b9
                                  • Instruction Fuzzy Hash: 3C11C475509780AFDB228F15DC44A52FFB4FF06320F08849EED858B663D365A918DB62
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • LoadLibraryA.KERNELBASE(?,00000E24), ref: 055E105B
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: LibraryLoad
                                  • String ID:
                                  • API String ID: 1029625771-0
                                  • Opcode ID: d8185906f4da8558bbace7f9896e06764065158dc72e528fe7bd6e270c7472a9
                                  • Instruction ID: 8479dfd07dd3c468576dbe6bbf2c7f3a3de132b8d9a0747856e9905469068da7
                                  • Opcode Fuzzy Hash: d8185906f4da8558bbace7f9896e06764065158dc72e528fe7bd6e270c7472a9
                                  • Instruction Fuzzy Hash: 9811E571504640AFEB21DB12DC45FB6F7A8EF44724F08819AFE445A681D3B5B548CAB1
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • SetErrorMode.KERNELBASE(?), ref: 0136A30C
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: ErrorMode
                                  • String ID:
                                  • API String ID: 2340568224-0
                                  • Opcode ID: 988f5a33ddbcc909b90b689da92052431043ae4dbaa0dc47b9af6c2348765f41
                                  • Instruction ID: 9b34655bbba88f1ebf73918bcc80e6b6841ab0e79af8cf181cb996b0147b241b
                                  • Opcode Fuzzy Hash: 988f5a33ddbcc909b90b689da92052431043ae4dbaa0dc47b9af6c2348765f41
                                  • Instruction Fuzzy Hash: AC1191714093C06FDB238B15DC54A62BFB8DF47224F0981CBED848F663D2656918C772
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: select
                                  • String ID:
                                  • API String ID: 1274211008-0
                                  • Opcode ID: b7f4f9b34cd9caef42854988342e50db889e06e46f6bf156e772fdda28e030f7
                                  • Instruction ID: 394588de03c12eb40d30f6b8af161c582e4d74f0b35e8465d32afe10b9892d8a
                                  • Opcode Fuzzy Hash: b7f4f9b34cd9caef42854988342e50db889e06e46f6bf156e772fdda28e030f7
                                  • Instruction Fuzzy Hash: A3116D795002048FDB25CF15D884F62FBE8FF04220F08C8AADD4ACB695D335E548CB62
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: Initialize
                                  • String ID:
                                  • API String ID: 2538663250-0
                                  • Opcode ID: 64cfc973b57e58ef464a3fea8f006c3887f585a8811c92cb41e17a977048efad
                                  • Instruction ID: c0601c12fcd32fb16999f3e2c23578b18e0cc27a64fd4fe5a3fbedc7c3585838
                                  • Opcode Fuzzy Hash: 64cfc973b57e58ef464a3fea8f006c3887f585a8811c92cb41e17a977048efad
                                  • Instruction Fuzzy Hash: 29116D714493C09FDB128B15DC45B52BFB4EF46224F0884DAED898B693D279A918CB62
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • LookupPrivilegeValueW.ADVAPI32(?,?,?), ref: 055E2172
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: LookupPrivilegeValue
                                  • String ID:
                                  • API String ID: 3899507212-0
                                  • Opcode ID: a6bae53c7b1cc96b03c3612b61edc89b88f31b5a9d2d2775e142c818c9dc61b7
                                  • Instruction ID: 72d5a11a807f9cd75cfcda812b0d09de25540a815e4196a808e8600677662f78
                                  • Opcode Fuzzy Hash: a6bae53c7b1cc96b03c3612b61edc89b88f31b5a9d2d2775e142c818c9dc61b7
                                  • Instruction Fuzzy Hash: 82116575A042409FDB28CF16DC85B5AFBE8FF44220F08C4AADD49CB745D775D504CA61
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • GetFileType.KERNELBASE(?,00000E24,4ED910D6,00000000,00000000,00000000,00000000), ref: 0136B789
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: FileType
                                  • String ID:
                                  • API String ID: 3081899298-0
                                  • Opcode ID: c3bbed87fd59b6eb94e55b37460d8ab8023af3804a57ed29a88f04f528ded3f4
                                  • Instruction ID: 5c638ac821ab8469e4412317b695f04ff46f09da123a0ff41420381d73c07acb
                                  • Opcode Fuzzy Hash: c3bbed87fd59b6eb94e55b37460d8ab8023af3804a57ed29a88f04f528ded3f4
                                  • Instruction Fuzzy Hash: 9501C0B5500204AEE721CF16DC84BA6FBACDF44628F08C096EE048BB45D368A5088EB6
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • WSAConnect.WS2_32(?,?,?,?,?,?,?), ref: 055E0BEA
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: Connect
                                  • String ID:
                                  • API String ID: 3144859779-0
                                  • Opcode ID: f4135282e188ec654ed995fa5de7efc6832c07280d13fb4f5ec4d596eb63c459
                                  • Instruction ID: 186a9b9bae6c8e1c0d8f83badd525b59a8556b2cac21b471b6ba1beafb86f9ba
                                  • Opcode Fuzzy Hash: f4135282e188ec654ed995fa5de7efc6832c07280d13fb4f5ec4d596eb63c459
                                  • Instruction Fuzzy Hash: 471170714006449FDB20CF55D844B66FBE5FF08310F08C99AED498BA61D375E418DF61
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • DispatchMessageW.USER32(?), ref: 055E3DE4
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: DispatchMessage
                                  • String ID:
                                  • API String ID: 2061451462-0
                                  • Opcode ID: ad304c171290089fc87e4d2b1739143e7acb4bbbb7302cf00e4440b5d436a433
                                  • Instruction ID: 100f94dd8ad22bc01a85e78652fc8a6d6a98988a6d1ee9e2ecc9ce909925fc88
                                  • Opcode Fuzzy Hash: ad304c171290089fc87e4d2b1739143e7acb4bbbb7302cf00e4440b5d436a433
                                  • Instruction Fuzzy Hash: 2E11C4714093C0AFDB228F15DC44B62FFB4EF46224F0980DAED848B653D275A908CBB2
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • GetVolumeInformationA.KERNELBASE(?,00000E24,?,?), ref: 055E0DB6
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: InformationVolume
                                  • String ID:
                                  • API String ID: 2039140958-0
                                  • Opcode ID: b0b7371f228321892d10cf21d6e380d2a16b891c42fb903591f60d6c33c04012
                                  • Instruction ID: c0b101783644540ac1e93a0a2693698102ca1c42c67c927c9d78bead77e2944d
                                  • Opcode Fuzzy Hash: b0b7371f228321892d10cf21d6e380d2a16b891c42fb903591f60d6c33c04012
                                  • Instruction Fuzzy Hash: B701B171900200ABD310DF16CC46B66FBE8FB88B20F14855AEC089BB41D735B915CBE1
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • LoadLibraryShim.MSCOREE(?,?,?,?), ref: 055E2E85
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: LibraryLoadShim
                                  • String ID:
                                  • API String ID: 1475914169-0
                                  • Opcode ID: 2644abe0bb0c84ab0dc109d943e598b9684d1a4977e3172235cc24615cc4fbae
                                  • Instruction ID: 6ed0651ca4aac6a9f22909f96b97cd4957c381fe1f1f134e96af1e88e7ab226e
                                  • Opcode Fuzzy Hash: 2644abe0bb0c84ab0dc109d943e598b9684d1a4977e3172235cc24615cc4fbae
                                  • Instruction Fuzzy Hash: 3F014C7A9043409FDB24CF16D885B62FBE8FF54620F08C59ADD498BB56D375E408CA62
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?), ref: 0136AC6E
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: DuplicateHandle
                                  • String ID:
                                  • API String ID: 3793708945-0
                                  • Opcode ID: b7c92a9dfcb4e6d96e90cd348ae68aa1770cbbaf8c9880f48d8bf3f29f22f701
                                  • Instruction ID: 7797430877ce1e0e8ea0264cd00a926d843368fe82474379523b02d83c958a00
                                  • Opcode Fuzzy Hash: b7c92a9dfcb4e6d96e90cd348ae68aa1770cbbaf8c9880f48d8bf3f29f22f701
                                  • Instruction Fuzzy Hash: 77015E318006409FDB218F55D944B52FBE4EF48324F08C99ADE498BA56D375A418DF62
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • GetComputerNameW.KERNEL32(?,00000E24,?,?), ref: 055E0082
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: ComputerName
                                  • String ID:
                                  • API String ID: 3545744682-0
                                  • Opcode ID: 98528c17c20cb06edf5f0d28b5e214ab3c2a03e3587dc59c47657160c8892cf1
                                  • Instruction ID: 90907b9e21b96fa00bcd424235048e938ea08d7eed212a669c27915f1fc5461a
                                  • Opcode Fuzzy Hash: 98528c17c20cb06edf5f0d28b5e214ab3c2a03e3587dc59c47657160c8892cf1
                                  • Instruction Fuzzy Hash: CC01D671900200ABD310DF16CC46B66FBE8FB88B20F148159EC089BB41D735F915CBE6
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • setsockopt.WS2_32(?,?,?,?,?), ref: 0136BDA0
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: setsockopt
                                  • String ID:
                                  • API String ID: 3981526788-0
                                  • Opcode ID: 75379bde698f0b0caac8dbee8457e3af9e8d43454885b7b21db243097bfc9ec9
                                  • Instruction ID: f474f025f7ee5ed3e0fc4c69557606cf0d6254185937d1f7867da5294dd63516
                                  • Opcode Fuzzy Hash: 75379bde698f0b0caac8dbee8457e3af9e8d43454885b7b21db243097bfc9ec9
                                  • Instruction Fuzzy Hash: ED01C031900200DFDB208F45D844B55FBE4EF14324F08C49ADD898EA16C335A018CF62
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • RegQueryValueExW.KERNELBASE(?,00000E24,?,?), ref: 0136BC12
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: QueryValue
                                  • String ID:
                                  • API String ID: 3660427363-0
                                  • Opcode ID: 78073f8bd3797361775ad54c52105c13b1975c5b6c241f1ffcc8d3fc74c6a675
                                  • Instruction ID: 12137c7e950a4302d9a7b7a874cbf0c558d3a69a242aa6db99c0795a5882fa0b
                                  • Opcode Fuzzy Hash: 78073f8bd3797361775ad54c52105c13b1975c5b6c241f1ffcc8d3fc74c6a675
                                  • Instruction Fuzzy Hash: D401D671900200ABD310DF16CC46B66FBE8FB88B20F14815AEC089BB41D771F915CBE6
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • FindCloseChangeNotification.KERNELBASE(?), ref: 0136A780
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: ChangeCloseFindNotification
                                  • String ID:
                                  • API String ID: 2591292051-0
                                  • Opcode ID: d06ac989f7b175280a3db6e6a828207ffff1b4f20ddff5b5abf1a29e8d2a74d4
                                  • Instruction ID: af7aef25bb235a062b439c96255bd2d94b5521bcc3cf74607596ea24b18d1a41
                                  • Opcode Fuzzy Hash: d06ac989f7b175280a3db6e6a828207ffff1b4f20ddff5b5abf1a29e8d2a74d4
                                  • Instruction Fuzzy Hash: 5701F2759002408FDB10CF5AD985766FBE8EF04224F08C4ABDC4A8FB46D379E408CEA2
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • PostMessageW.USER32(?,?,?,?), ref: 055E3F3D
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: MessagePost
                                  • String ID:
                                  • API String ID: 410705778-0
                                  • Opcode ID: 3ab06408eecb0e7baf8049a94c8407e65090287c29c371c9d43f40136af7b79c
                                  • Instruction ID: 8b4746051cf311b7d9ce8d8068633dbe9fab724c8a23410b1945e7606f1fb4ac
                                  • Opcode Fuzzy Hash: 3ab06408eecb0e7baf8049a94c8407e65090287c29c371c9d43f40136af7b79c
                                  • Instruction Fuzzy Hash: 920171369006409FDB248F16D884B65FBF4FF04720F08C59EED554BA62D375E458DBA2
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: Initialize
                                  • String ID:
                                  • API String ID: 2538663250-0
                                  • Opcode ID: 04b69e3288ddab933090cad3b656f213e869f21daceb7f1490f9be149771b186
                                  • Instruction ID: 26c5f9e87a5457efeb53fb4cd7d82ac024618f1b45bdbb0a7e69a509362f8cd9
                                  • Opcode Fuzzy Hash: 04b69e3288ddab933090cad3b656f213e869f21daceb7f1490f9be149771b186
                                  • Instruction Fuzzy Hash: 4301DC71800244CFDB20CF1ADC84762FBE8EF44324F08C4AADD499FB56D379A448CAA2
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • PostMessageW.USER32(?,?,?,?), ref: 055E3B51
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: MessagePost
                                  • String ID:
                                  • API String ID: 410705778-0
                                  • Opcode ID: 3744af391f02b95245ba680b6a211568e59e4df088fc1a2b5b5f0029b45d754c
                                  • Instruction ID: c08ba35a1a5f7b875b820b69361ce2f509cb5aa369a76c0798e0bae58e9bc287
                                  • Opcode Fuzzy Hash: 3744af391f02b95245ba680b6a211568e59e4df088fc1a2b5b5f0029b45d754c
                                  • Instruction Fuzzy Hash: C4018F36804244DFDB20CF06D884B61FBE4FF08320F09C99ADD4A4BA62D375A418CBA2
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • DispatchMessageW.USER32(?), ref: 055E3DE4
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852961360.00000000055E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 055E0000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_55e0000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: DispatchMessage
                                  • String ID:
                                  • API String ID: 2061451462-0
                                  • Opcode ID: 3a7f45e6284e86529a38d76664a56b170390048ffd8b827f624bc742a900f810
                                  • Instruction ID: c4abea701c28180212921823243ff26cafa17047139efde60e3c9d17e796b3e2
                                  • Opcode Fuzzy Hash: 3a7f45e6284e86529a38d76664a56b170390048ffd8b827f624bc742a900f810
                                  • Instruction Fuzzy Hash: BFF087759002409FDB24CF06D985B61FBA4FF44224F09C9EADD494BB52D379A508CEA2
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  APIs
                                  • SetErrorMode.KERNELBASE(?), ref: 0136A30C
                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851009910.000000000136A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0136A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_136a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID: ErrorMode
                                  • String ID:
                                  • API String ID: 2340568224-0
                                  • Opcode ID: b629689f2bc900944c6a6b9f63aa92881f6ea0a07d07afa7bc4bdeb68aa9a97c
                                  • Instruction ID: 40290f06e8cd28c641214749d74a29258926d4d7e12d1f790d80c2fdb6cdfd26
                                  • Opcode Fuzzy Hash: b629689f2bc900944c6a6b9f63aa92881f6ea0a07d07afa7bc4bdeb68aa9a97c
                                  • Instruction Fuzzy Hash: 3FF0AF358042448FDB208F06D884761FBE8EF04624F18C19ADD495FB56D3B9A548CAA2
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852984743.0000000005620000.00000040.00000800.00020000.00000000.sdmp, Offset: 05620000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_5620000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: a047b054e5582b5bbaa129ebd1cb9a863a03669c62b5b2f3e81075d6fa0a99ab
                                  • Instruction ID: bd317fe7321ff611519d3fd79ffb9cbea474daf1d1f8cfc96f65e55e8ac7050d
                                  • Opcode Fuzzy Hash: a047b054e5582b5bbaa129ebd1cb9a863a03669c62b5b2f3e81075d6fa0a99ab
                                  • Instruction Fuzzy Hash: EE11BAB5908341AFD350CF19D840A5BFBE4FB88664F04895EF998D7711D335EA088FA2
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851511713.0000000001800000.00000040.00000020.00020000.00000000.sdmp, Offset: 01800000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_1800000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: a4fb0a89c896cbba27319e9f3ef3fb624d30ec602d79204b53dd08debc5fe937
                                  • Instruction ID: 31490f0d24845d7a3fdba6dc44bab3e83a20268fa94eb4cb9a06b91d90dd19b2
                                  • Opcode Fuzzy Hash: a4fb0a89c896cbba27319e9f3ef3fb624d30ec602d79204b53dd08debc5fe937
                                  • Instruction Fuzzy Hash: 0A11D231208248DFD716CB14DD40B25BBA5AB88718F24C5ADF9499BB93C77BDA03CA91
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851511713.0000000001800000.00000040.00000020.00020000.00000000.sdmp, Offset: 01800000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_1800000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: b8344cccb5fa1215ca2523c054a26114bbf0578d603c78f46eb087e722d390bf
                                  • Instruction ID: 1fc9a3e204881b8dc39e9f4b9f4d1baffcd5b371d903ba5dd6f93ed90cb83611
                                  • Opcode Fuzzy Hash: b8344cccb5fa1215ca2523c054a26114bbf0578d603c78f46eb087e722d390bf
                                  • Instruction Fuzzy Hash: E721383110D7C48FC7138B24DD94B10BFB1AB46308F1986EEE4898A6A3C33A8906CB52
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852984743.0000000005620000.00000040.00000800.00020000.00000000.sdmp, Offset: 05620000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_5620000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 4558c23ed3a0ac6973515561c1442a865dfd5e4eeedcbd96200672e40a43f026
                                  • Instruction ID: a2c21cc8b1d6cfbb4710cf78a0f0df73d58d909d42939dda28eaa6c81e568040
                                  • Opcode Fuzzy Hash: 4558c23ed3a0ac6973515561c1442a865dfd5e4eeedcbd96200672e40a43f026
                                  • Instruction Fuzzy Hash: 2B11BEB5908301AFD750CF09DC41E57FBE8EB88660F04891EF95997711D275E9088FA2
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851058184.000000000137A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0137A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_137a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: aec7dac4e54e6069620c488214696295be5b2a684945a445007114d73b17268f
                                  • Instruction ID: cfd040dbff875f5207b5f318bc4355fe2818c5273d8c8a2ce6354ab8117fd3b0
                                  • Opcode Fuzzy Hash: aec7dac4e54e6069620c488214696295be5b2a684945a445007114d73b17268f
                                  • Instruction Fuzzy Hash: 9E11BEB5908301AFD350CF09DC41E57FBE8EB88660F04891EF95997711D275E9088FA2
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851511713.0000000001800000.00000040.00000020.00020000.00000000.sdmp, Offset: 01800000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_1800000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 08bbd260416b07ebc498b9dc657058e410367781e45036bc2377f4bf3e700329
                                  • Instruction ID: 31d3923b81a202f600520ad382ab3aca365f58f47f51516911f0018ae5ba0541
                                  • Opcode Fuzzy Hash: 08bbd260416b07ebc498b9dc657058e410367781e45036bc2377f4bf3e700329
                                  • Instruction Fuzzy Hash: 3D018BB55097805FD7118F16AC40862FFF8DE86620749849FF88987612D265A908C772
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851511713.0000000001800000.00000040.00000020.00020000.00000000.sdmp, Offset: 01800000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_1800000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 1211cc8331e0b50b07ffe12ea701b48e6298c326ccc82b5efa8e48cefb80fa31
                                  • Instruction ID: 530156b938d1bbb51ab7e7ae0eb58152422b1dfba3de09af6483cdb226459ef2
                                  • Opcode Fuzzy Hash: 1211cc8331e0b50b07ffe12ea701b48e6298c326ccc82b5efa8e48cefb80fa31
                                  • Instruction Fuzzy Hash: CDF03135108644DFC316CF04D940B15FBA2FB89718F24C6ADE94917B62C737D913DA81
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851511713.0000000001800000.00000040.00000020.00020000.00000000.sdmp, Offset: 01800000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_1800000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 5cdd77bfe8561b83ef7e50c76358b8569c3b176aa67975e72b22786af185a331
                                  • Instruction ID: 6a4d96ce899cb2384a0157fcc19d13bcbabea8c608e2c22c84aab0bed1f3bc12
                                  • Opcode Fuzzy Hash: 5cdd77bfe8561b83ef7e50c76358b8569c3b176aa67975e72b22786af185a331
                                  • Instruction Fuzzy Hash: BDF03C35108684DFC316CF10D980B25FBA2FB89718F24C6ADE94957BA2C337D912DA81
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851511713.0000000001800000.00000040.00000020.00020000.00000000.sdmp, Offset: 01800000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_1800000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 0c25bfcb9d893b47408381747e166967b91e6ba260984a7994383b6e7af3c08f
                                  • Instruction ID: 582ce607677485843946a411be48e5e5a2595cdc3b5135da2788e63fc14196b8
                                  • Opcode Fuzzy Hash: 0c25bfcb9d893b47408381747e166967b91e6ba260984a7994383b6e7af3c08f
                                  • Instruction Fuzzy Hash: BCE092B6A006404B9760CF0BFC41452F7D8EB88630B08C17FEC0D8BB01E27AB508CAA6
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852984743.0000000005620000.00000040.00000800.00020000.00000000.sdmp, Offset: 05620000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_5620000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 1da2cfc445b244f1c15052f40c0d915d17d47cb39f24a812e8f08c03b00f8342
                                  • Instruction ID: ac8685bc2df2ac3cf42ee0a2557d0052c552e844319c56c1454e264fdda9d2c7
                                  • Opcode Fuzzy Hash: 1da2cfc445b244f1c15052f40c0d915d17d47cb39f24a812e8f08c03b00f8342
                                  • Instruction Fuzzy Hash: 61E0D8B690030067D220DE079C45F53FB98DB84A30F08C557EE081BB01E176B514C9E1
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852984743.0000000005620000.00000040.00000800.00020000.00000000.sdmp, Offset: 05620000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_5620000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: f38f1f95a8ca598413906a86cf8b35771d8466bd0315300d7497382cd8b37475
                                  • Instruction ID: 78cf1289abe94511dcc5f81166a92ad079cdacb4d533d99bb3b13d765f5e545a
                                  • Opcode Fuzzy Hash: f38f1f95a8ca598413906a86cf8b35771d8466bd0315300d7497382cd8b37475
                                  • Instruction Fuzzy Hash: 78E0D8B290030467D2609E079C45F53FB98DB44A30F04C557EE0C1BB02E176B50489F1
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2852984743.0000000005620000.00000040.00000800.00020000.00000000.sdmp, Offset: 05620000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_5620000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 72035db374aefa5f97cf91890af36035affa35a7b3f53124042f259cdc3def1d
                                  • Instruction ID: fc7b0cf768d52291d73d35638303995f81a54f76eb71736521e0c10f9ba48437
                                  • Opcode Fuzzy Hash: 72035db374aefa5f97cf91890af36035affa35a7b3f53124042f259cdc3def1d
                                  • Instruction Fuzzy Hash: 97E0D8B294030067D3208E079C45F52FBDCDB84A31F04C567ED081BB41E176B51889E1
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2851058184.000000000137A000.00000040.00000800.00020000.00000000.sdmp, Offset: 0137A000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_137a000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: d12553ea8bb37df78d5a39d5e2cf7d11f5af072645cc71859f108c117a01da48
                                  • Instruction ID: 29e30c397f6c79f769f00ff5494212aba529b38719f586b08c27993fcbf30cae
                                  • Opcode Fuzzy Hash: d12553ea8bb37df78d5a39d5e2cf7d11f5af072645cc71859f108c117a01da48
                                  • Instruction Fuzzy Hash: FBE0D8B294020467D2208E079C45F52FB98DB44A31F04C557FE091B701E176B50489F1
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2850994289.0000000001362000.00000040.00000800.00020000.00000000.sdmp, Offset: 01362000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_1362000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: cf7f78bd4fcc6288fdb48920b54f481eb413a9ea14d433beffbb234a4127893e
                                  • Instruction ID: 3710ae34dbcebbbf2d7bd1e48a371aab86412a2ba369ac540809c001d5f621e1
                                  • Opcode Fuzzy Hash: cf7f78bd4fcc6288fdb48920b54f481eb413a9ea14d433beffbb234a4127893e
                                  • Instruction Fuzzy Hash: 15D05E792056C14FE7179A1CC1A8BA63FE8AF55718F4B84F9A8008BB67CB68D585D600
                                  Uniqueness

                                  Uniqueness Score: -1.00%

                                  Memory Dump Source
                                  • Source File: 00000001.00000002.2850994289.0000000001362000.00000040.00000800.00020000.00000000.sdmp, Offset: 01362000, based on PE: false
                                  Joe Sandbox IDA Plugin
                                  • Snapshot File: hcaresult_1_2_1362000_xkzdRi6nGpg3.jbxd
                                  Similarity
                                  • API ID:
                                  • String ID:
                                  • API String ID:
                                  • Opcode ID: 37ed65dc29493f34555542321c28f52a97fa63083cd99c855e1e46fb965e19aa
                                  • Instruction ID: 3b479683a3d1729830d604cb5434b67102e48c7d6f5edf2b348cda42d1513136
                                  • Opcode Fuzzy Hash: 37ed65dc29493f34555542321c28f52a97fa63083cd99c855e1e46fb965e19aa
                                  • Instruction Fuzzy Hash: 6AD05E342002814BEB19DB0CC2D4F5A3BD8AB44718F1684E9AC108B766C7A4D8C0DA00
                                  Uniqueness

                                  Uniqueness Score: -1.00%