Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
9dOKGgFNL2.exe

Overview

General Information

Sample name:9dOKGgFNL2.exe
renamed because original name is a hash value
Original sample name:020ec1df3b8b9d28da16edaf0d50a262.exe
Analysis ID:1557008
MD5:020ec1df3b8b9d28da16edaf0d50a262
SHA1:b9b841c39445febc098f7edbda4112194615fc10
SHA256:6eaf9b6af911a7995d490906ff5d42a36a47e4b1d4510f6fc33c7cdab2c80aae
Tags:exeRedLineStealeruser-abuse_ch
Infos:

Detection

RedLine
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected AntiVM3
Yara detected RedLine Stealer
.NET source code contains potential unpacker
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Injects a PE file into a foreign processes
Machine Learning detection for sample
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Crypto Currency Wallets
Uses known network protocols on non-standard ports
AV process strings found (often used to terminate AV products)
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara detected Credential Stealer
Yara signature match

Classification

  • System is w10x64
  • 9dOKGgFNL2.exe (PID: 7536 cmdline: "C:\Users\user\Desktop\9dOKGgFNL2.exe" MD5: 020EC1DF3B8B9D28DA16EDAF0D50A262)
    • 9dOKGgFNL2.exe (PID: 7712 cmdline: "C:\Users\user\Desktop\9dOKGgFNL2.exe" MD5: 020EC1DF3B8B9D28DA16EDAF0D50A262)
      • conhost.exe (PID: 7728 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
RedLine StealerRedLine Stealer is a malware available on underground forums for sale apparently as a standalone ($100/$150 depending on the version) or also on a subscription basis ($100/month). This malware harvests information from browsers such as saved credentials, autocomplete data, and credit card information. A system inventory is also taken when running on a target machine, to include details such as the username, location data, hardware configuration, and information regarding installed security software. More recent versions of RedLine added the ability to steal cryptocurrency. FTP and IM clients are also apparently targeted by this family, and this malware has the ability to upload and download files, execute commands, and periodically send back information about the infected computer.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.redline_stealer
{"C2 url": ["45.137.22.126:55615"], "Bot Id": "cheat"}
SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_RedLine_1Yara detected RedLine StealerJoe Security
    dump.pcapJoeSecurity_RedLineYara detected RedLine StealerJoe Security
      SourceRuleDescriptionAuthorStrings
      00000002.00000002.1857246057.0000000000402000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
        00000002.00000002.1857246057.0000000000402000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_RedLineYara detected RedLine StealerJoe Security
          00000002.00000002.1857246057.0000000000402000.00000040.00000400.00020000.00000000.sdmpWindows_Trojan_RedLineStealer_f54632ebunknownunknown
          • 0x133ca:$a4: get_ScannedWallets
          • 0x12228:$a5: get_ScanTelegram
          • 0x1304e:$a6: get_ScanGeckoBrowsersPaths
          • 0x10e6a:$a7: <Processes>k__BackingField
          • 0xed7c:$a8: <GetWindowsVersion>g__HKLM_GetString|11_0
          • 0x1079e:$a9: <ScanFTP>k__BackingField
          00000000.00000002.1741382956.0000000004491000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
            00000000.00000002.1741382956.0000000004491000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_RedLineYara detected RedLine StealerJoe Security
              Click to see the 11 entries
              SourceRuleDescriptionAuthorStrings
              2.2.9dOKGgFNL2.exe.400000.0.unpackJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
                2.2.9dOKGgFNL2.exe.400000.0.unpackJoeSecurity_RedLineYara detected RedLine StealerJoe Security
                  2.2.9dOKGgFNL2.exe.400000.0.unpackWindows_Trojan_RedLineStealer_f54632ebunknownunknown
                  • 0x135ca:$a4: get_ScannedWallets
                  • 0x12428:$a5: get_ScanTelegram
                  • 0x1324e:$a6: get_ScanGeckoBrowsersPaths
                  • 0x1106a:$a7: <Processes>k__BackingField
                  • 0xef7c:$a8: <GetWindowsVersion>g__HKLM_GetString|11_0
                  • 0x1099e:$a9: <ScanFTP>k__BackingField
                  2.2.9dOKGgFNL2.exe.400000.0.unpackMALWARE_Win_RedLineDetects RedLine infostealerditekSHen
                  • 0x1048a:$u7: RunPE
                  • 0x13b41:$u8: DownloadAndEx
                  • 0x9130:$pat14: , CommandLine:
                  • 0x13079:$v2_1: ListOfProcesses
                  • 0x1068b:$v2_2: get_ScanVPN
                  • 0x1072e:$v2_2: get_ScanFTP
                  • 0x1141e:$v2_2: get_ScanDiscord
                  • 0x1240c:$v2_2: get_ScanSteam
                  • 0x12428:$v2_2: get_ScanTelegram
                  • 0x124ce:$v2_2: get_ScanScreen
                  • 0x13216:$v2_2: get_ScanChromeBrowsersPaths
                  • 0x1324e:$v2_2: get_ScanGeckoBrowsersPaths
                  • 0x13509:$v2_2: get_ScanBrowsers
                  • 0x135ca:$v2_2: get_ScannedWallets
                  • 0x135f0:$v2_2: get_ScanWallets
                  • 0x13610:$v2_3: GetArguments
                  • 0x11cd9:$v2_4: VerifyUpdate
                  • 0x165ea:$v2_4: VerifyUpdate
                  • 0x139ca:$v2_5: VerifyScanRequest
                  • 0x130c6:$v2_6: GetUpdates
                  • 0x165cb:$v2_6: GetUpdates
                  0.2.9dOKGgFNL2.exe.458a6f0.2.unpackJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
                    Click to see the 15 entries
                    No Sigma rule has matched
                    TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                    2024-11-17T03:07:08.476379+010020450001Malware Command and Control Activity Detected45.137.22.12655615192.168.2.449733TCP
                    TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                    2024-11-17T03:07:11.420400+010020460561A Network Trojan was detected45.137.22.12655615192.168.2.449733TCP
                    TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                    2024-11-17T03:07:11.420400+010020450011Malware Command and Control Activity Detected45.137.22.12655615192.168.2.449733TCP
                    TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                    2024-11-17T03:07:03.465942+010028496621Malware Command and Control Activity Detected192.168.2.44973345.137.22.12655615TCP
                    TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                    2024-11-17T03:07:08.786615+010028493511Malware Command and Control Activity Detected192.168.2.44973345.137.22.12655615TCP
                    TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                    2024-11-17T03:07:13.993295+010028482001Malware Command and Control Activity Detected192.168.2.44973845.137.22.12655615TCP
                    TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                    2024-11-17T03:07:11.473182+010028493521Malware Command and Control Activity Detected192.168.2.44973745.137.22.12655615TCP

                    Click to jump to signature section

                    Show All Signature Results

                    AV Detection

                    barindex
                    Source: 2.2.9dOKGgFNL2.exe.400000.0.unpackMalware Configuration Extractor: RedLine {"C2 url": ["45.137.22.126:55615"], "Bot Id": "cheat"}
                    Source: 9dOKGgFNL2.exeReversingLabs: Detection: 66%
                    Source: 9dOKGgFNL2.exeVirustotal: Detection: 62%Perma Link
                    Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
                    Source: 9dOKGgFNL2.exeJoe Sandbox ML: detected
                    Source: 9dOKGgFNL2.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                    Source: 9dOKGgFNL2.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                    Source: Binary string: nmYV.pdb source: 9dOKGgFNL2.exe
                    Source: Binary string: nmYV.pdbSHA256 source: 9dOKGgFNL2.exe

                    Networking

                    barindex
                    Source: Network trafficSuricata IDS: 2849662 - Severity 1 - ETPRO MALWARE RedLine - CheckConnect Request : 192.168.2.4:49733 -> 45.137.22.126:55615
                    Source: Network trafficSuricata IDS: 2045000 - Severity 1 - ET MALWARE RedLine Stealer - CheckConnect Response : 45.137.22.126:55615 -> 192.168.2.4:49733
                    Source: Network trafficSuricata IDS: 2849351 - Severity 1 - ETPRO MALWARE RedLine - EnvironmentSettings Request : 192.168.2.4:49733 -> 45.137.22.126:55615
                    Source: Network trafficSuricata IDS: 2849352 - Severity 1 - ETPRO MALWARE RedLine - SetEnvironment Request : 192.168.2.4:49737 -> 45.137.22.126:55615
                    Source: Network trafficSuricata IDS: 2045001 - Severity 1 - ET MALWARE Win32/LeftHook Stealer Browser Extension Config Inbound : 45.137.22.126:55615 -> 192.168.2.4:49733
                    Source: Network trafficSuricata IDS: 2046056 - Severity 1 - ET MALWARE Redline Stealer/MetaStealer Family Activity (Response) : 45.137.22.126:55615 -> 192.168.2.4:49733
                    Source: Network trafficSuricata IDS: 2848200 - Severity 1 - ETPRO MALWARE RedLine - GetUpdates Request : 192.168.2.4:49738 -> 45.137.22.126:55615
                    Source: Malware configuration extractorURLs: 45.137.22.126:55615
                    Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 55615
                    Source: unknownNetwork traffic detected: HTTP traffic on port 55615 -> 49733
                    Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 55615
                    Source: unknownNetwork traffic detected: HTTP traffic on port 55615 -> 49733
                    Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 55615
                    Source: unknownNetwork traffic detected: HTTP traffic on port 55615 -> 49737
                    Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 55615
                    Source: unknownNetwork traffic detected: HTTP traffic on port 55615 -> 49738
                    Source: global trafficTCP traffic: 192.168.2.4:49733 -> 45.137.22.126:55615
                    Source: global trafficHTTP traffic detected: POST / HTTP/1.1Content-Type: text/xml; charset=utf-8SOAPAction: "http://tempuri.org/Endpoint/CheckConnect"Host: 45.137.22.126:55615Content-Length: 137Expect: 100-continueAccept-Encoding: gzip, deflateConnection: Keep-Alive
                    Source: global trafficHTTP traffic detected: POST / HTTP/1.1Content-Type: text/xml; charset=utf-8SOAPAction: "http://tempuri.org/Endpoint/EnvironmentSettings"Host: 45.137.22.126:55615Content-Length: 144Expect: 100-continueAccept-Encoding: gzip, deflate
                    Source: global trafficHTTP traffic detected: POST / HTTP/1.1Content-Type: text/xml; charset=utf-8SOAPAction: "http://tempuri.org/Endpoint/SetEnvironment"Host: 45.137.22.126:55615Content-Length: 928651Expect: 100-continueAccept-Encoding: gzip, deflate
                    Source: global trafficHTTP traffic detected: POST / HTTP/1.1Content-Type: text/xml; charset=utf-8SOAPAction: "http://tempuri.org/Endpoint/GetUpdates"Host: 45.137.22.126:55615Content-Length: 928643Expect: 100-continueAccept-Encoding: gzip, deflateConnection: Keep-Alive
                    Source: Joe Sandbox ViewASN Name: ROOTLAYERNETNL ROOTLAYERNETNL
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: unknownTCP traffic detected without corresponding DNS query: 45.137.22.126
                    Source: global trafficDNS traffic detected: DNS query: api.ip.sb
                    Source: unknownHTTP traffic detected: POST / HTTP/1.1Content-Type: text/xml; charset=utf-8SOAPAction: "http://tempuri.org/Endpoint/CheckConnect"Host: 45.137.22.126:55615Content-Length: 137Expect: 100-continueAccept-Encoding: gzip, deflateConnection: Keep-Alive
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000003103000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://45.137.22.126:5
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FF1000.00000004.00000800.00020000.00000000.sdmp, 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://45.137.22.126:55615
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://45.137.22.126:55615/
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FF1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://45.137.22.126:55615t-fq
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FF1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.datacontract.org/2004/07/
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/soap/actor/next
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FB0000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/faultX
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FB0000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/0
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/CheckConnect
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/CheckConnectResponse
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/EnvironmentSettings
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/EnvironmentSettingsResponse
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FF1000.00000004.00000800.00020000.00000000.sdmp, 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmp, 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FD7000.00000004.00000800.00020000.00000000.sdmp, 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FB0000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/GetUpdates
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/GetUpdatesResponse
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000003103000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/SetEnviron
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000003103000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/SetEnvironment
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/SetEnvironmentResponse
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/VerifyUpdate
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/VerifyUpdateResponse
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.carterandcone.coml
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/?
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/cabarga.htmlN
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers/frere-user.html
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers8
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designers?
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fontbureau.com/designersG
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.fonts.com
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn/bThe
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.founder.com.cn/cn/cThe
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.galapagosdesign.com/DPlease
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.galapagosdesign.com/staff/dennis.htm
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.goodfont.co.kr
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.jiyu-kobo.co.jp/
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sajatypeworks.com
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742706998.0000000006474000.00000004.00000020.00020000.00000000.sdmp, 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sakkal.com
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.sandoll.co.kr
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.tiro.com
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.typography.netD
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.urwpp.deDPlease
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.zhongyicts.com.cn
                    Source: tmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.drString found in binary or memory: https://ac.ecosia.org/autocomplete?q=
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FB0000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.ip.sb
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FB0000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.ip.sb/geoip
                    Source: 9dOKGgFNL2.exe, 9dOKGgFNL2.exe, 00000002.00000002.1857246057.0000000000402000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: https://api.ip.sb/geoip%USERPEnvironmentROFILE%
                    Source: 9dOKGgFNL2.exe, 9dOKGgFNL2.exe, 00000002.00000002.1857246057.0000000000402000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: https://api.ipify.orgcookies//settinString.Removeg
                    Source: tmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.drString found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
                    Source: tmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.drString found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
                    Source: tmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.drString found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
                    Source: tmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.drString found in binary or memory: https://duckduckgo.com/ac/?q=
                    Source: tmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.drString found in binary or memory: https://duckduckgo.com/chrome_newtab
                    Source: tmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.drString found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
                    Source: 9dOKGgFNL2.exe, 9dOKGgFNL2.exe, 00000002.00000002.1857246057.0000000000402000.00000040.00000400.00020000.00000000.sdmpString found in binary or memory: https://ipinfo.io/ip%appdata%
                    Source: tmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.drString found in binary or memory: https://www.ecosia.org/newtab/
                    Source: tmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.drString found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico

                    System Summary

                    barindex
                    Source: 2.2.9dOKGgFNL2.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_RedLineStealer_f54632eb Author: unknown
                    Source: 2.2.9dOKGgFNL2.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
                    Source: 0.2.9dOKGgFNL2.exe.458a6f0.2.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_RedLineStealer_f54632eb Author: unknown
                    Source: 0.2.9dOKGgFNL2.exe.458a6f0.2.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
                    Source: 0.2.9dOKGgFNL2.exe.45a2510.1.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_RedLineStealer_f54632eb Author: unknown
                    Source: 0.2.9dOKGgFNL2.exe.45a2510.1.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
                    Source: 0.2.9dOKGgFNL2.exe.45a2510.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_RedLineStealer_f54632eb Author: unknown
                    Source: 0.2.9dOKGgFNL2.exe.45a2510.1.raw.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
                    Source: 0.2.9dOKGgFNL2.exe.458a6f0.2.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_RedLineStealer_f54632eb Author: unknown
                    Source: 0.2.9dOKGgFNL2.exe.458a6f0.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
                    Source: 00000002.00000002.1857246057.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_f54632eb Author: unknown
                    Source: 00000000.00000002.1741382956.0000000004491000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_f54632eb Author: unknown
                    Source: 00000000.00000002.1741382956.000000000458A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_f54632eb Author: unknown
                    Source: Process Memory Space: 9dOKGgFNL2.exe PID: 7536, type: MEMORYSTRMatched rule: Windows_Trojan_RedLineStealer_f54632eb Author: unknown
                    Source: Process Memory Space: 9dOKGgFNL2.exe PID: 7712, type: MEMORYSTRMatched rule: Windows_Trojan_RedLineStealer_f54632eb Author: unknown
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 0_2_031F3E280_2_031F3E28
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 0_2_031F6F900_2_031F6F90
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 0_2_031FF0440_2_031FF044
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 0_2_065994F00_2_065994F0
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 0_2_065911FC0_2_065911FC
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 0_2_065935BA0_2_065935BA
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 0_2_07D797080_2_07D79708
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 0_2_07D73E380_2_07D73E38
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 0_2_07D73E290_2_07D73E29
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 0_2_07D735A80_2_07D735A8
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 0_2_07D73A000_2_07D73A00
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 0_2_07D759B00_2_07D759B0
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 0_2_07D750D80_2_07D750D8
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 2_2_013EE7B02_2_013EE7B0
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 2_2_013EDC902_2_013EDC90
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 2_2_067D96302_2_067D9630
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 2_2_067D44682_2_067D4468
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 2_2_067D12102_2_067D1210
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 2_2_067D329F2_2_067D329F
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 2_2_067DDD182_2_067DDD18
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 2_2_067DDA242_2_067DDA24
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 2_2_067DD5282_2_067DD528
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 2_2_071FC1982_2_071FC198
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 2_2_071FEAC02_2_071FEAC0
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 2_2_071F075A2_2_071F075A
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 2_2_071F07682_2_071F0768
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 2_2_071FF2582_2_071FF258
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 2_2_071FF2482_2_071FF248
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 2_2_071F0CF42_2_071F0CF4
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1742563541.0000000005E60000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameArthur.dll" vs 9dOKGgFNL2.exe
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1741382956.000000000458A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameImplosions.exe4 vs 9dOKGgFNL2.exe
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1741382956.000000000458A000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMontero.dll8 vs 9dOKGgFNL2.exe
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1740909601.00000000033E1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameImplosions.exe4 vs 9dOKGgFNL2.exe
                    Source: 9dOKGgFNL2.exe, 00000000.00000000.1684748049.0000000001074000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenamenmYV.exe* vs 9dOKGgFNL2.exe
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1743705514.0000000007D00000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameMontero.dll8 vs 9dOKGgFNL2.exe
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1740116770.00000000016BE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameclr.dllT vs 9dOKGgFNL2.exe
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1858196730.0000000001108000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameclr.dllT vs 9dOKGgFNL2.exe
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FF1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilename vs 9dOKGgFNL2.exe
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1857246057.0000000000402000.00000040.00000400.00020000.00000000.sdmpBinary or memory string: OriginalFilenameImplosions.exe4 vs 9dOKGgFNL2.exe
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000003103000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamefirefox.exe0 vs 9dOKGgFNL2.exe
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000003103000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilename vs 9dOKGgFNL2.exe
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000003103000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: $fq,\\StringFileInfo\\000004B0\\OriginalFilename vs 9dOKGgFNL2.exe
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000003103000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamechrome.exe< vs 9dOKGgFNL2.exe
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000003103000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: $fq,\\StringFileInfo\\040904B0\\OriginalFilename vs 9dOKGgFNL2.exe
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000003103000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameIEXPLORE.EXE.MUID vs 9dOKGgFNL2.exe
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000003103000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameIEXPLORE.EXED vs 9dOKGgFNL2.exe
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000003103000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: $fq,\\StringFileInfo\\080904B0\\OriginalFilename vs 9dOKGgFNL2.exe
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000003103000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemsedge.exe> vs 9dOKGgFNL2.exe
                    Source: 9dOKGgFNL2.exeBinary or memory string: OriginalFilenamenmYV.exe* vs 9dOKGgFNL2.exe
                    Source: 9dOKGgFNL2.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                    Source: 2.2.9dOKGgFNL2.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23
                    Source: 2.2.9dOKGgFNL2.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
                    Source: 0.2.9dOKGgFNL2.exe.458a6f0.2.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23
                    Source: 0.2.9dOKGgFNL2.exe.458a6f0.2.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
                    Source: 0.2.9dOKGgFNL2.exe.45a2510.1.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23
                    Source: 0.2.9dOKGgFNL2.exe.45a2510.1.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
                    Source: 0.2.9dOKGgFNL2.exe.45a2510.1.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23
                    Source: 0.2.9dOKGgFNL2.exe.45a2510.1.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
                    Source: 0.2.9dOKGgFNL2.exe.458a6f0.2.raw.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23
                    Source: 0.2.9dOKGgFNL2.exe.458a6f0.2.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
                    Source: 00000002.00000002.1857246057.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23
                    Source: 00000000.00000002.1741382956.0000000004491000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23
                    Source: 00000000.00000002.1741382956.000000000458A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23
                    Source: Process Memory Space: 9dOKGgFNL2.exe PID: 7536, type: MEMORYSTRMatched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23
                    Source: Process Memory Space: 9dOKGgFNL2.exe PID: 7712, type: MEMORYSTRMatched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23
                    Source: 9dOKGgFNL2.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                    Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, demNsXKQQ5dOWKyKaT.csSecurity API names: _0020.SetAccessControl
                    Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, demNsXKQQ5dOWKyKaT.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
                    Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, demNsXKQQ5dOWKyKaT.csSecurity API names: _0020.AddAccessRule
                    Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, iZq82EZ6VPakI888Ti.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
                    Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, iZq82EZ6VPakI888Ti.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
                    Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, demNsXKQQ5dOWKyKaT.csSecurity API names: _0020.SetAccessControl
                    Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, demNsXKQQ5dOWKyKaT.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
                    Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, demNsXKQQ5dOWKyKaT.csSecurity API names: _0020.AddAccessRule
                    Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@4/43@1/1
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeFile created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\9dOKGgFNL2.exe.logJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeMutant created: NULL
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeMutant created: \Sessions\1\BaseNamedObjects\YUNDhpkGx
                    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7728:120:WilError_03
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeFile created: C:\Users\user\AppData\Local\Temp\tmpD144.tmpJump to behavior
                    Source: 9dOKGgFNL2.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                    Source: 9dOKGgFNL2.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.83%
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Process Where SessionId=&apos;1&apos;
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Process Where SessionId=&apos;1&apos;
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                    Source: tmpD177.tmp.2.dr, tmpD19B.tmp.2.dr, tmpD18A.tmp.2.dr, tmpD19A.tmp.2.dr, tmpD189.tmp.2.dr, tmpD178.tmp.2.drBinary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
                    Source: 9dOKGgFNL2.exeReversingLabs: Detection: 66%
                    Source: 9dOKGgFNL2.exeVirustotal: Detection: 62%
                    Source: unknownProcess created: C:\Users\user\Desktop\9dOKGgFNL2.exe "C:\Users\user\Desktop\9dOKGgFNL2.exe"
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess created: C:\Users\user\Desktop\9dOKGgFNL2.exe "C:\Users\user\Desktop\9dOKGgFNL2.exe"
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess created: C:\Users\user\Desktop\9dOKGgFNL2.exe "C:\Users\user\Desktop\9dOKGgFNL2.exe"Jump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: mscoree.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: apphelp.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: kernel.appcore.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: version.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: uxtheme.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: windows.storage.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: wldp.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: profapi.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: cryptsp.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: rsaenh.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: cryptbase.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: dwrite.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: windowscodecs.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: amsi.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: userenv.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: msasn1.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: gpapi.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: textshaping.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: iconcodecservice.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: mscoree.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: kernel.appcore.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: version.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: cryptsp.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: rsaenh.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: cryptbase.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: windows.storage.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: wldp.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: profapi.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: rasapi32.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: rasman.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: rtutils.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: mswsock.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: winhttp.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: iphlpapi.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: dhcpcsvc6.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: dhcpcsvc.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: dnsapi.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: winnsi.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: rasadhlp.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: fwpuclnt.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: secur32.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: sspicli.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: schannel.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: mskeyprotect.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: ntasn1.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: ncrypt.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: ncryptsslp.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: msasn1.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: gpapi.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: userenv.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: wbemcomn.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: amsi.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: ntmarta.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: uxtheme.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeSection loaded: windowscodecs.dllJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32Jump to behavior
                    Source: Window RecorderWindow detected: More than 3 window changes detected
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
                    Source: 9dOKGgFNL2.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
                    Source: 9dOKGgFNL2.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                    Source: 9dOKGgFNL2.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
                    Source: Binary string: nmYV.pdb source: 9dOKGgFNL2.exe
                    Source: Binary string: nmYV.pdbSHA256 source: 9dOKGgFNL2.exe

                    Data Obfuscation

                    barindex
                    Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, demNsXKQQ5dOWKyKaT.cs.Net Code: CuR0MWy3sX System.Reflection.Assembly.Load(byte[])
                    Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, demNsXKQQ5dOWKyKaT.cs.Net Code: CuR0MWy3sX System.Reflection.Assembly.Load(byte[])
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 2_2_067DE5DF push es; ret 2_2_067DE5E0
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 2_2_071FBD9F push dword ptr [esp+ecx*2-75h]; ret 2_2_071FBDA3
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeCode function: 2_2_071F4DE4 pushfd ; retf 2_2_071F4DF1
                    Source: 9dOKGgFNL2.exeStatic PE information: section name: .text entropy: 7.770995746521688
                    Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, RI5CbnHZJMOX38NIWe.csHigh entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'Jja8bB6lEU', 'NpG8WY4SLZ', 'i5g8z9xtJM', 'llbGpIplh1', 's9gGkAL39b', 'zgOG8XliWj', 'gRYGG5q8Fv', 'OWoDag98XMVVT6ETqbp'
                    Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, TVYCZS8CsAAf6xRfPr.csHigh entropy of concatenated method names: 'abTMGse3k', 'FfQD8fGjE', 'ocWX9F3Qj', 'o7EEysSd2', 'I7yu3gEtP', 'Ye1BG8lwQ', 'I34Ti0u4RcG9Qa7hdb', 'c0F1wry08HThRQ3JtF', 'woQY4oQUq', 'YwOoaVpYZ'
                    Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, mT0lgMk0UGmjhglQpy2.csHigh entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'oNRRJJjkvv', 'CjuRoHlLyi', 'lHLR5jNOxN', 'aT3RRnSxHv', 'e7xRdkc7fx', 'xhKRsaPn3I', 'gVNR2Pxsy6'
                    Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, KXppZwBPgJ7E76VbXs.csHigh entropy of concatenated method names: 'cuulhrjjTF', 'A6alEaKRRv', 'XDDHgVl8Pd', 'PkjHFw6B1X', 'nSdHcJfTXo', 'OoJHL1JuHO', 'SeDHvKtLK0', 'fapHx59X52', 'r99HTYZJSi', 'fJcHCe16Rq'
                    Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, nlmoTBWi5RrBNjduPP.csHigh entropy of concatenated method names: 'v3UoH7e74r', 'r5ColW5onc', 'QEcotKLZDq', 'E6noIJVudW', 'cjyoJEWJf6', 'yCWoKUh9fA', 'Next', 'Next', 'Next', 'NextBytes'
                    Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, T5CUBJkkW6oTYTPm6hD.csHigh entropy of concatenated method names: 'utQoWGyfoQ', 'EBXozPAXTS', 'vCk5pjR2wW', 'qsf5ktLSs9', 'f2k58Y4chO', 'HvI5G57mZ0', 'I9X50wT2Z7', 'rjT53EdlhF', 'OjE5yVTrP7', 'YmP5q5xPxi'
                    Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, qDbtOObWgkLUDUcOmK.csHigh entropy of concatenated method names: 'cunJ6k4HuC', 'RtjJUh4WPV', 'OldJgCnBv1', 'F1YJFAfh04', 'ArwJcubO61', 'ye1JLGOyeY', 's69JvqD3yP', 'OstJxSfJAf', 'L6VJTTx7vZ', 'FJMJC6wGqb'
                    Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, Tgldtnuspxe3w9nTJA.csHigh entropy of concatenated method names: 'M9wHDRHrdU', 'lPpHXPKqoQ', 'VDPHZGtRXK', 'Xb6HuwNOpL', 'kuGHPAmcBH', 'vpIHSc0G6B', 'p4sHVwZLO6', 'rxtHY6Tmrv', 'CbBHJaf2CW', 'KHRHo7QA90'
                    Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, pa30ECvIFvyAltBGSh.csHigh entropy of concatenated method names: 'tBDIyO21fN', 'iE8IHYIm0a', 'hw3ItxSF45', 'B1rtWHGog3', 'KIItzWhFfb', 'j2sIpCAW4U', 'HVsIkyN3DW', 'UqbI80l6MO', 'FU1IGsgEUS', 'IO9I0U0D91'
                    Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, to6tbw1Sv4LCFDGbFJ.csHigh entropy of concatenated method names: 'KJZ7ZJJeLY', 'l8D7u7wv5m', 'TuI76cIJeD', 'y317UNlsQn', 'LNU7FTlA4i', 'x187ceYm7b', 'del7v1ZEX9', 'pyn7xTJ7u1', 'r0k7CLxjj7', 'OUQ7ja5j8L'
                    Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, neicNOfGWVJmDBuMMa.csHigh entropy of concatenated method names: 'DikVmP2p2L', 'PeIVW2r6qk', 'JYYYpHBxAr', 'qKmYkZRh9D', 'MY3VjXuh8G', 'R89VNoYK3i', 'eXtV1fpGv4', 'KrpV4JsD35', 'lHKVA3upPb', 'AJxViniaRr'
                    Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, Rc2muXTKqVZvJsmYO7.csHigh entropy of concatenated method names: 'cfIIeo0CNR', 'JmhIOHRY7q', 'eh0IMm9UBh', 'nDkIDJR07p', 'qoxIhLi5oB', 'i2oIXM3EfE', 'XQHIEVrjOW', 'ySLIZSAb7Y', 'QxjIu9oM3E', 'lEvIB0OCXs'
                    Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, TLjf954KTOhdvwbmoK.csHigh entropy of concatenated method names: 'TN6PCUfeNQ', 'UIjPNB2QMf', 'IubP4pjyUb', 'xFBPADHqnK', 'twkPUQLnkX', 'wQVPgP0Iet', 'Hr2PFDLgXT', 'yQ6PcVARZE', 'TLRPLLHUji', 'hMMPvfiAEj'
                    Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, demNsXKQQ5dOWKyKaT.csHigh entropy of concatenated method names: 'K0EG3hIdYk', 'nZqGy7xs3s', 'lyyGqyJu0d', 'zCcGHbB18s', 'mOMGlFWd1D', 'c7aGtdJoPg', 'hE8GIADHYc', 'jIHGKFEn6e', 'aUsGnvT6Y0', 'oWxGQvwnQy'
                    Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, O23pNJ6EhjttsNQhGK.csHigh entropy of concatenated method names: 'VqYt3uxTLn', 'FRQtqg3KDy', 'H6rtl4LRLm', 'GRgtIocc4x', 'eXYtKXqBnb', 'LjtlwUL1qE', 'vA7lf8XP7U', 'AN8l9viaIk', 'Ee9lmjH2qK', 'vXMlb9qiZb'
                    Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, d5oNk0qNHVBJ02cV5H.csHigh entropy of concatenated method names: 'Dispose', 'dKNkbKj2BC', 'N6F8U9nZPW', 'xt8nNCcuZx', 'WaPkWj1CsY', 'lAGkzIRUAJ', 'ProcessDialogKey', 'duV8pDbtOO', 'Ygk8kLUDUc', 'ymK887lmoT'
                    Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, GnKswFzT5fBSNjTCYX.csHigh entropy of concatenated method names: 'guZoXFdbJD', 'zaGoZj1VEJ', 'TkxouXkZK9', 'UqKo660TxR', 'dj6oUNCV5S', 'lUdoFCiJwd', 'aEUockj3NL', 'BbSo2DlJTs', 'jjuoeHRPNO', 'JHFoOqssRx'
                    Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, anJOVC9Gs0KNKj2BCm.csHigh entropy of concatenated method names: 'nLBJPSNxIK', 'MX0JV8rTGU', 'zXgJJSJDia', 'hZdJ5VUsh9', 'cQnJdRxPDQ', 'AaZJ2akfLy', 'Dispose', 'qpOYy6aJAf', 'CPxYqCafiQ', 'C9lYHy4aBY'
                    Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, iZq82EZ6VPakI888Ti.csHigh entropy of concatenated method names: 'ETaq4qXUTJ', 'XKJqAsVrDR', 'T8CqiVQ8GZ', 'WFkqr0rMWw', 'kdyqwQf4v5', 'i8tqfUDUg5', 'rgWq93sdG4', 'N7MqmNm0Gq', 'itEqbXKUMv', 'FIWqW9FIZ6'
                    Source: 0.2.9dOKGgFNL2.exe.45c6af0.0.raw.unpack, QjRGfp0mhEGSXg3p4e.csHigh entropy of concatenated method names: 'GmtkIZq82E', 'GVPkKakI88', 'lspkQxe3w9', 'lTJkaALXpp', 'GVbkPXsj23', 'aNJkSEhjtt', 'iOcjHrm9R8xWXHVrkP', 'fuhlW7qAUmE8DYZHrv', 'Tvbkk4Xbfl', 'tDjkGf3dpI'
                    Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, RI5CbnHZJMOX38NIWe.csHigh entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'Jja8bB6lEU', 'NpG8WY4SLZ', 'i5g8z9xtJM', 'llbGpIplh1', 's9gGkAL39b', 'zgOG8XliWj', 'gRYGG5q8Fv', 'OWoDag98XMVVT6ETqbp'
                    Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, TVYCZS8CsAAf6xRfPr.csHigh entropy of concatenated method names: 'abTMGse3k', 'FfQD8fGjE', 'ocWX9F3Qj', 'o7EEysSd2', 'I7yu3gEtP', 'Ye1BG8lwQ', 'I34Ti0u4RcG9Qa7hdb', 'c0F1wry08HThRQ3JtF', 'woQY4oQUq', 'YwOoaVpYZ'
                    Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, mT0lgMk0UGmjhglQpy2.csHigh entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'oNRRJJjkvv', 'CjuRoHlLyi', 'lHLR5jNOxN', 'aT3RRnSxHv', 'e7xRdkc7fx', 'xhKRsaPn3I', 'gVNR2Pxsy6'
                    Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, KXppZwBPgJ7E76VbXs.csHigh entropy of concatenated method names: 'cuulhrjjTF', 'A6alEaKRRv', 'XDDHgVl8Pd', 'PkjHFw6B1X', 'nSdHcJfTXo', 'OoJHL1JuHO', 'SeDHvKtLK0', 'fapHx59X52', 'r99HTYZJSi', 'fJcHCe16Rq'
                    Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, nlmoTBWi5RrBNjduPP.csHigh entropy of concatenated method names: 'v3UoH7e74r', 'r5ColW5onc', 'QEcotKLZDq', 'E6noIJVudW', 'cjyoJEWJf6', 'yCWoKUh9fA', 'Next', 'Next', 'Next', 'NextBytes'
                    Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, T5CUBJkkW6oTYTPm6hD.csHigh entropy of concatenated method names: 'utQoWGyfoQ', 'EBXozPAXTS', 'vCk5pjR2wW', 'qsf5ktLSs9', 'f2k58Y4chO', 'HvI5G57mZ0', 'I9X50wT2Z7', 'rjT53EdlhF', 'OjE5yVTrP7', 'YmP5q5xPxi'
                    Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, qDbtOObWgkLUDUcOmK.csHigh entropy of concatenated method names: 'cunJ6k4HuC', 'RtjJUh4WPV', 'OldJgCnBv1', 'F1YJFAfh04', 'ArwJcubO61', 'ye1JLGOyeY', 's69JvqD3yP', 'OstJxSfJAf', 'L6VJTTx7vZ', 'FJMJC6wGqb'
                    Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, Tgldtnuspxe3w9nTJA.csHigh entropy of concatenated method names: 'M9wHDRHrdU', 'lPpHXPKqoQ', 'VDPHZGtRXK', 'Xb6HuwNOpL', 'kuGHPAmcBH', 'vpIHSc0G6B', 'p4sHVwZLO6', 'rxtHY6Tmrv', 'CbBHJaf2CW', 'KHRHo7QA90'
                    Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, pa30ECvIFvyAltBGSh.csHigh entropy of concatenated method names: 'tBDIyO21fN', 'iE8IHYIm0a', 'hw3ItxSF45', 'B1rtWHGog3', 'KIItzWhFfb', 'j2sIpCAW4U', 'HVsIkyN3DW', 'UqbI80l6MO', 'FU1IGsgEUS', 'IO9I0U0D91'
                    Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, to6tbw1Sv4LCFDGbFJ.csHigh entropy of concatenated method names: 'KJZ7ZJJeLY', 'l8D7u7wv5m', 'TuI76cIJeD', 'y317UNlsQn', 'LNU7FTlA4i', 'x187ceYm7b', 'del7v1ZEX9', 'pyn7xTJ7u1', 'r0k7CLxjj7', 'OUQ7ja5j8L'
                    Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, neicNOfGWVJmDBuMMa.csHigh entropy of concatenated method names: 'DikVmP2p2L', 'PeIVW2r6qk', 'JYYYpHBxAr', 'qKmYkZRh9D', 'MY3VjXuh8G', 'R89VNoYK3i', 'eXtV1fpGv4', 'KrpV4JsD35', 'lHKVA3upPb', 'AJxViniaRr'
                    Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, Rc2muXTKqVZvJsmYO7.csHigh entropy of concatenated method names: 'cfIIeo0CNR', 'JmhIOHRY7q', 'eh0IMm9UBh', 'nDkIDJR07p', 'qoxIhLi5oB', 'i2oIXM3EfE', 'XQHIEVrjOW', 'ySLIZSAb7Y', 'QxjIu9oM3E', 'lEvIB0OCXs'
                    Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, TLjf954KTOhdvwbmoK.csHigh entropy of concatenated method names: 'TN6PCUfeNQ', 'UIjPNB2QMf', 'IubP4pjyUb', 'xFBPADHqnK', 'twkPUQLnkX', 'wQVPgP0Iet', 'Hr2PFDLgXT', 'yQ6PcVARZE', 'TLRPLLHUji', 'hMMPvfiAEj'
                    Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, demNsXKQQ5dOWKyKaT.csHigh entropy of concatenated method names: 'K0EG3hIdYk', 'nZqGy7xs3s', 'lyyGqyJu0d', 'zCcGHbB18s', 'mOMGlFWd1D', 'c7aGtdJoPg', 'hE8GIADHYc', 'jIHGKFEn6e', 'aUsGnvT6Y0', 'oWxGQvwnQy'
                    Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, O23pNJ6EhjttsNQhGK.csHigh entropy of concatenated method names: 'VqYt3uxTLn', 'FRQtqg3KDy', 'H6rtl4LRLm', 'GRgtIocc4x', 'eXYtKXqBnb', 'LjtlwUL1qE', 'vA7lf8XP7U', 'AN8l9viaIk', 'Ee9lmjH2qK', 'vXMlb9qiZb'
                    Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, d5oNk0qNHVBJ02cV5H.csHigh entropy of concatenated method names: 'Dispose', 'dKNkbKj2BC', 'N6F8U9nZPW', 'xt8nNCcuZx', 'WaPkWj1CsY', 'lAGkzIRUAJ', 'ProcessDialogKey', 'duV8pDbtOO', 'Ygk8kLUDUc', 'ymK887lmoT'
                    Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, GnKswFzT5fBSNjTCYX.csHigh entropy of concatenated method names: 'guZoXFdbJD', 'zaGoZj1VEJ', 'TkxouXkZK9', 'UqKo660TxR', 'dj6oUNCV5S', 'lUdoFCiJwd', 'aEUockj3NL', 'BbSo2DlJTs', 'jjuoeHRPNO', 'JHFoOqssRx'
                    Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, anJOVC9Gs0KNKj2BCm.csHigh entropy of concatenated method names: 'nLBJPSNxIK', 'MX0JV8rTGU', 'zXgJJSJDia', 'hZdJ5VUsh9', 'cQnJdRxPDQ', 'AaZJ2akfLy', 'Dispose', 'qpOYy6aJAf', 'CPxYqCafiQ', 'C9lYHy4aBY'
                    Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, iZq82EZ6VPakI888Ti.csHigh entropy of concatenated method names: 'ETaq4qXUTJ', 'XKJqAsVrDR', 'T8CqiVQ8GZ', 'WFkqr0rMWw', 'kdyqwQf4v5', 'i8tqfUDUg5', 'rgWq93sdG4', 'N7MqmNm0Gq', 'itEqbXKUMv', 'FIWqW9FIZ6'
                    Source: 0.2.9dOKGgFNL2.exe.7d00000.4.raw.unpack, QjRGfp0mhEGSXg3p4e.csHigh entropy of concatenated method names: 'GmtkIZq82E', 'GVPkKakI88', 'lspkQxe3w9', 'lTJkaALXpp', 'GVbkPXsj23', 'aNJkSEhjtt', 'iOcjHrm9R8xWXHVrkP', 'fuhlW7qAUmE8DYZHrv', 'Tvbkk4Xbfl', 'tDjkGf3dpI'

                    Hooking and other Techniques for Hiding and Protection

                    barindex
                    Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 55615
                    Source: unknownNetwork traffic detected: HTTP traffic on port 55615 -> 49733
                    Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 55615
                    Source: unknownNetwork traffic detected: HTTP traffic on port 55615 -> 49733
                    Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 55615
                    Source: unknownNetwork traffic detected: HTTP traffic on port 55615 -> 49737
                    Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 55615
                    Source: unknownNetwork traffic detected: HTTP traffic on port 55615 -> 49738
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

                    Malware Analysis System Evasion

                    barindex
                    Source: Yara matchFile source: Process Memory Space: 9dOKGgFNL2.exe PID: 7536, type: MEMORYSTR
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_DiskDrive
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_VideoController
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeMemory allocated: 31B0000 memory reserve | memory write watchJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeMemory allocated: 33E0000 memory reserve | memory write watchJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeMemory allocated: 53E0000 memory reserve | memory write watchJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeMemory allocated: 95B0000 memory reserve | memory write watchJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeMemory allocated: A5B0000 memory reserve | memory write watchJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeMemory allocated: A7C0000 memory reserve | memory write watchJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeMemory allocated: B7C0000 memory reserve | memory write watchJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeMemory allocated: 13E0000 memory reserve | memory write watchJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeMemory allocated: 2F60000 memory reserve | memory write watchJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeMemory allocated: 2CE0000 memory reserve | memory write watchJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeWindow / User API: threadDelayed 7733Jump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeWindow / User API: threadDelayed 1854Jump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exe TID: 7556Thread sleep time: -922337203685477s >= -30000sJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exe TID: 7920Thread sleep time: -31359464925306218s >= -30000sJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exe TID: 7804Thread sleep time: -30000s >= -30000sJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exe TID: 7772Thread sleep time: -922337203685477s >= -30000sJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeThread delayed: delay time: 922337203685477Jump to behavior
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1858196730.0000000001193000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess information queried: ProcessInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess token adjusted: DebugJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess token adjusted: DebugJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeMemory allocated: page read and write | page guardJump to behavior

                    HIPS / PFW / Operating System Protection Evasion

                    barindex
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeMemory written: C:\Users\user\Desktop\9dOKGgFNL2.exe base: 400000 value starts with: 4D5AJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeProcess created: C:\Users\user\Desktop\9dOKGgFNL2.exe "C:\Users\user\Desktop\9dOKGgFNL2.exe"Jump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Users\user\Desktop\9dOKGgFNL2.exe VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\bahnschrift.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\calibrili.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\cambriai.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\cambriaz.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\cambria.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\Candara.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\Candaral.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\Candarai.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\Candarali.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\Candarab.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\Candaraz.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\comic.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\comici.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\comicbd.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\comicz.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\constan.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\constani.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\constanb.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\constanz.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\corbel.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\corbell.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\corbeli.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\corbelli.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\corbelb.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\corbelz.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\cour.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\couri.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\courbd.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\courbi.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\ebrima.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\ebrimabd.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\framd.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\FRADM.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\framdit.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\FRADMIT.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\FRAMDCN.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\FRAHVIT.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\gadugi.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\gadugib.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\georgia.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\georgiai.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\georgiab.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\georgiaz.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\impact.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\Inkfree.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\javatext.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\LeelawUI.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\LeelUIsl.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\LeelaUIb.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\lucon.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\l_10646.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\malgun.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\malgunsl.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\malgunbd.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\himalaya.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\msjhbd.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\msjh.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\msjhl.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\ntailu.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\ntailub.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\phagspa.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\phagspab.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\taileb.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\msyhbd.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\msyh.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\msyhl.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\mingliub.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\monbaiti.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\msgothic.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\mvboli.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\mmrtext.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\mmrtextb.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\Nirmala.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\NirmalaS.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\NirmalaB.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\pala.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\palai.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\palab.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\palabi.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\segoepr.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\segoeprb.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\seguihis.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\simsun.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\simsunb.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\SitkaB.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\Sitka.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\SitkaI.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\SitkaZ.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\sylfaen.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\symbol.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\trebuc.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\trebucit.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\trebucbd.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\trebucbi.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\verdana.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\verdanai.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\verdanab.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\verdanaz.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\webdings.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\wingding.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\YuGothL.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\YuGothB.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\YuGothM.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\YuGothR.ttc VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\holomdl2.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\AGENCYR.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\ALGER.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\BKANT.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\ANTQUAI.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\ANTQUAB.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\ANTQUABI.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\ARLRDBD.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\BASKVILL.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\BAUHS93.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\BELL.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\BELLI.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\BOD_R.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\BOD_BI.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\BOD_CR.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\BOD_BLAR.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\BOD_CB.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\BOD_PSTC.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\BOOKOS.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\BRADHITC.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\BRLNSDB.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\BROADW.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\CALIFI.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\CALIFB.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\CALIST.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\CASTELAR.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\SCHLBKI.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\SCHLBKB.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\SCHLBKBI.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\CENTURY.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\CHILLER.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\COLONNA.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\DUBAI-MEDIUM.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\DUBAI-LIGHT.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\DUBAI-BOLD.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\ELEPHNT.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\ERASDEMI.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\ERASBD.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\FRABKIT.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\FTLTLT.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\GIL_____.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\GILI____.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\GILB____.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\GOTHICI.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\GOTHICB.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\GOUDOS.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\GOUDOSB.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\IMPRISHA.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\LFAX.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\LSANS.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\LSANSD.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\LSANSI.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\MTEXTRA.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\OLDENGL.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\PERTILI.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\POORICH.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\ROCK.TTF VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Fonts\micross.ttf VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Users\user\Desktop\9dOKGgFNL2.exe VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Internals\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Internals.dll VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll VolumeInformationJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1869047589.000000000678A000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: %ProgramFiles%\Windows Defender\MsMpeng.exe
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT * FROM AntivirusProduct
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter : SELECT * FROM AntivirusProduct
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT * FROM AntiSpyWareProduct
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter : SELECT * FROM AntiSpyWareProduct
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT * FROM FirewallProduct
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter : SELECT * FROM FirewallProduct

                    Stealing of Sensitive Information

                    barindex
                    Source: Yara matchFile source: dump.pcap, type: PCAP
                    Source: Yara matchFile source: 2.2.9dOKGgFNL2.exe.400000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 0.2.9dOKGgFNL2.exe.458a6f0.2.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 0.2.9dOKGgFNL2.exe.45a2510.1.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 0.2.9dOKGgFNL2.exe.45a2510.1.raw.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 0.2.9dOKGgFNL2.exe.458a6f0.2.raw.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 00000002.00000002.1857246057.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000000.00000002.1741382956.0000000004491000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000000.00000002.1741382956.000000000458A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: Process Memory Space: 9dOKGgFNL2.exe PID: 7536, type: MEMORYSTR
                    Source: Yara matchFile source: Process Memory Space: 9dOKGgFNL2.exe PID: 7712, type: MEMORYSTR
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1741382956.000000000458A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: [^\u0020-\u007F]ProcessIdname_on_cardencrypted_valuehttps://ipinfo.io/ip%appdata%\logins{0}\FileZilla\recentservers.xml%appdata%\discord\Local Storage\leveldb\tdataAtomicWalletv10/C \EtFile.IOhereuFile.IOm\walFile.IOletsESystem.UItherSystem.UIeumElectrum[AString-ZaString-z\d]{2String4}\.[String\w-]{String6}\.[\wString-]{2String7}profiles\Windows\valueexpiras21ation_moas21nth
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000003103000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: $fq1C:\Users\user\AppData\Roaming\Electrum\wallets\*
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1741382956.000000000458A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: user.config{0}\FileZilla\sitemanager.xmlcookies.sqlite\Program Files (x86)\configRoninWalletdisplayNamehost_key\Electrum\walletsName\Exodus\exodus.walletnanjmdknhkinifnkgdcggcfnhdaammmjtdataexpires_utc\Program Data\coMANGOokies.sqMANGOlite*ssfn*ExodusDisplayVersion%localappdata%\GuildWalletOpHandlerenVPHandlerN ConHandlernect%DSK_23%YoroiWalletcmdOpera GXhttps://api.ipify.orgcookies//settinString.Removeg[@name=\PasswString.Removeord\]/valuString.RemoveeSaturnWalletWeb DataSteamPathwaasflleasft.datasfCommandLineSOFTWARE\Microsoft\Windows\CurrentVersion\UninstallCookiesis_secureSoftware\Valve\SteamLogin DataID: isSecureNoDefrdDefVPNDefwaasflletasfMewCxv11\Program Files\Opera GX StableSELECT * FROM Win32_Process Where SessionId='nlbmnnijcnlegkjjpcfjclmcfggfefdmnkddgncdjgjfcddamfgcmfnlhccnimig\coFile.IOm.libeFile.IOrty.jFile.IOaxFile.IOxnamefnjhmkhhmkbjkkabndcnnogagogbneecfhilaheimglignddkjgofkcbgekhenbhProfile_Unknowncard_number_encrypted, Name: AppData\Roaming\TReplaceokReplaceenReplaces.tReplacext //settString.Replaceing[@name=\UString.Replacesername\]/vaString.ReplacelueNWinordVWinpn.eWinxe*Winhostmoz_cookiesUser Datawindows-1251, CommandLine: \ExodusDisplayNameexpiry*.vstring.ReplacedfJaxxpathBSJB
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1741382956.000000000458A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: user.config{0}\FileZilla\sitemanager.xmlcookies.sqlite\Program Files (x86)\configRoninWalletdisplayNamehost_key\Electrum\walletsName\Exodus\exodus.walletnanjmdknhkinifnkgdcggcfnhdaammmjtdataexpires_utc\Program Data\coMANGOokies.sqMANGOlite*ssfn*ExodusDisplayVersion%localappdata%\GuildWalletOpHandlerenVPHandlerN ConHandlernect%DSK_23%YoroiWalletcmdOpera GXhttps://api.ipify.orgcookies//settinString.Removeg[@name=\PasswString.Removeord\]/valuString.RemoveeSaturnWalletWeb DataSteamPathwaasflleasft.datasfCommandLineSOFTWARE\Microsoft\Windows\CurrentVersion\UninstallCookiesis_secureSoftware\Valve\SteamLogin DataID: isSecureNoDefrdDefVPNDefwaasflletasfMewCxv11\Program Files\Opera GX StableSELECT * FROM Win32_Process Where SessionId='nlbmnnijcnlegkjjpcfjclmcfggfefdmnkddgncdjgjfcddamfgcmfnlhccnimig\coFile.IOm.libeFile.IOrty.jFile.IOaxFile.IOxnamefnjhmkhhmkbjkkabndcnnogagogbneecfhilaheimglignddkjgofkcbgekhenbhProfile_Unknowncard_number_encrypted, Name: AppData\Roaming\TReplaceokReplaceenReplaces.tReplacext //settString.Replaceing[@name=\UString.Replacesername\]/vaString.ReplacelueNWinordVWinpn.eWinxe*Winhostmoz_cookiesUser Datawindows-1251, CommandLine: \ExodusDisplayNameexpiry*.vstring.ReplacedfJaxxpathBSJB
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000003103000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: \Ethereum\wallets
                    Source: 9dOKGgFNL2.exe, 00000000.00000002.1741382956.000000000458A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: user.config{0}\FileZilla\sitemanager.xmlcookies.sqlite\Program Files (x86)\configRoninWalletdisplayNamehost_key\Electrum\walletsName\Exodus\exodus.walletnanjmdknhkinifnkgdcggcfnhdaammmjtdataexpires_utc\Program Data\coMANGOokies.sqMANGOlite*ssfn*ExodusDisplayVersion%localappdata%\GuildWalletOpHandlerenVPHandlerN ConHandlernect%DSK_23%YoroiWalletcmdOpera GXhttps://api.ipify.orgcookies//settinString.Removeg[@name=\PasswString.Removeord\]/valuString.RemoveeSaturnWalletWeb DataSteamPathwaasflleasft.datasfCommandLineSOFTWARE\Microsoft\Windows\CurrentVersion\UninstallCookiesis_secureSoftware\Valve\SteamLogin DataID: isSecureNoDefrdDefVPNDefwaasflletasfMewCxv11\Program Files\Opera GX StableSELECT * FROM Win32_Process Where SessionId='nlbmnnijcnlegkjjpcfjclmcfggfefdmnkddgncdjgjfcddamfgcmfnlhccnimig\coFile.IOm.libeFile.IOrty.jFile.IOaxFile.IOxnamefnjhmkhhmkbjkkabndcnnogagogbneecfhilaheimglignddkjgofkcbgekhenbhProfile_Unknowncard_number_encrypted, Name: AppData\Roaming\TReplaceokReplaceenReplaces.tReplacext //settString.Replaceing[@name=\UString.Replacesername\]/vaString.ReplacelueNWinordVWinpn.eWinxe*Winhostmoz_cookiesUser Datawindows-1251, CommandLine: \ExodusDisplayNameexpiry*.vstring.ReplacedfJaxxpathBSJB
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000003103000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: Ethereum
                    Source: 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000003103000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: $fq5C:\Users\user\AppData\Roaming\Exodus\exodus.wallet\*
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login DataJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\cookies.sqliteJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web DataJump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeFile opened: C:\Users\user\AppData\Roaming\atomic\Jump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeFile opened: C:\Users\user\AppData\Roaming\Electrum\wallets\Jump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeFile opened: C:\Users\user\AppData\Roaming\Electrum\wallets\Jump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeFile opened: C:\Users\user\AppData\Roaming\Ethereum\wallets\Jump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeFile opened: C:\Users\user\AppData\Roaming\Exodus\Jump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeFile opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet\Jump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeFile opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet\Jump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeFile opened: C:\Users\user\AppData\Roaming\Guarda\Jump to behavior
                    Source: C:\Users\user\Desktop\9dOKGgFNL2.exeFile opened: C:\Users\user\AppData\Roaming\com.liberty.jaxx\Jump to behavior
                    Source: Yara matchFile source: 2.2.9dOKGgFNL2.exe.400000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 0.2.9dOKGgFNL2.exe.458a6f0.2.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 0.2.9dOKGgFNL2.exe.45a2510.1.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 0.2.9dOKGgFNL2.exe.45a2510.1.raw.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 0.2.9dOKGgFNL2.exe.458a6f0.2.raw.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 00000002.00000002.1857246057.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000000.00000002.1741382956.0000000004491000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000000.00000002.1741382956.000000000458A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: Process Memory Space: 9dOKGgFNL2.exe PID: 7536, type: MEMORYSTR
                    Source: Yara matchFile source: Process Memory Space: 9dOKGgFNL2.exe PID: 7712, type: MEMORYSTR

                    Remote Access Functionality

                    barindex
                    Source: Yara matchFile source: dump.pcap, type: PCAP
                    Source: Yara matchFile source: 2.2.9dOKGgFNL2.exe.400000.0.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 0.2.9dOKGgFNL2.exe.458a6f0.2.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 0.2.9dOKGgFNL2.exe.45a2510.1.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 0.2.9dOKGgFNL2.exe.45a2510.1.raw.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 0.2.9dOKGgFNL2.exe.458a6f0.2.raw.unpack, type: UNPACKEDPE
                    Source: Yara matchFile source: 00000002.00000002.1857246057.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000000.00000002.1741382956.0000000004491000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: 00000000.00000002.1741382956.000000000458A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                    Source: Yara matchFile source: Process Memory Space: 9dOKGgFNL2.exe PID: 7536, type: MEMORYSTR
                    Source: Yara matchFile source: Process Memory Space: 9dOKGgFNL2.exe PID: 7712, type: MEMORYSTR
                    ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                    Gather Victim Identity InformationAcquire InfrastructureValid Accounts221
                    Windows Management Instrumentation
                    1
                    DLL Side-Loading
                    111
                    Process Injection
                    1
                    Masquerading
                    1
                    OS Credential Dumping
                    231
                    Security Software Discovery
                    Remote Services1
                    Archive Collected Data
                    1
                    Encrypted Channel
                    Exfiltration Over Other Network MediumAbuse Accessibility Features
                    CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
                    DLL Side-Loading
                    1
                    Disable or Modify Tools
                    LSASS Memory1
                    Process Discovery
                    Remote Desktop Protocol3
                    Data from Local System
                    11
                    Non-Standard Port
                    Exfiltration Over BluetoothNetwork Denial of Service
                    Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)241
                    Virtualization/Sandbox Evasion
                    Security Account Manager241
                    Virtualization/Sandbox Evasion
                    SMB/Windows Admin SharesData from Network Shared Drive2
                    Non-Application Layer Protocol
                    Automated ExfiltrationData Encrypted for Impact
                    Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook111
                    Process Injection
                    NTDS1
                    Application Window Discovery
                    Distributed Component Object ModelInput Capture12
                    Application Layer Protocol
                    Traffic DuplicationData Destruction
                    Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script2
                    Obfuscated Files or Information
                    LSA Secrets113
                    System Information Discovery
                    SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
                    Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts12
                    Software Packing
                    Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                    DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
                    DLL Side-Loading
                    DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
                    Hide Legend

                    Legend:

                    • Process
                    • Signature
                    • Created File
                    • DNS/IP Info
                    • Is Dropped
                    • Is Windows Process
                    • Number of created Registry Values
                    • Number of created Files
                    • Visual Basic
                    • Delphi
                    • Java
                    • .Net C# or VB.NET
                    • C, C++ or other language
                    • Is malicious
                    • Internet

                    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                    windows-stand
                    SourceDetectionScannerLabelLink
                    9dOKGgFNL2.exe67%ReversingLabsByteCode-MSIL.Trojan.AgentTesla
                    9dOKGgFNL2.exe62%VirustotalBrowse
                    9dOKGgFNL2.exe100%Joe Sandbox ML
                    No Antivirus matches
                    No Antivirus matches
                    No Antivirus matches
                    SourceDetectionScannerLabelLink
                    http://45.137.22.126:55615/0%Avira URL Cloudsafe
                    http://45.137.22.126:55615t-fq0%Avira URL Cloudsafe
                    http://45.137.22.126:50%Avira URL Cloudsafe
                    45.137.22.126:556150%Avira URL Cloudsafe
                    http://45.137.22.126:556150%Avira URL Cloudsafe
                    45.137.22.126:556153%VirustotalBrowse
                    http://45.137.22.126:55615/3%VirustotalBrowse
                    http://45.137.22.126:52%VirustotalBrowse
                    NameIPActiveMaliciousAntivirus DetectionReputation
                    api.ip.sb
                    unknown
                    unknownfalse
                      high
                      NameMaliciousAntivirus DetectionReputation
                      45.137.22.126:55615true
                      • 3%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      http://45.137.22.126:55615/true
                      • 3%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      NameSourceMaliciousAntivirus DetectionReputation
                      https://duckduckgo.com/chrome_newtabtmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.drfalse
                        high
                        http://www.fontbureau.com/designersG9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpfalse
                          high
                          https://duckduckgo.com/ac/?q=tmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.drfalse
                            high
                            http://www.fontbureau.com/designers/?9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpfalse
                              high
                              http://www.founder.com.cn/cn/bThe9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpfalse
                                high
                                http://schemas.xmlsoap.org/ws/2004/08/addressing/faultX9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpfalse
                                  high
                                  http://www.fontbureau.com/designers?9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpfalse
                                    high
                                    http://tempuri.org/Endpoint/EnvironmentSettings9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpfalse
                                      high
                                      https://api.ip.sb/geoip9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FB0000.00000004.00000800.00020000.00000000.sdmpfalse
                                        high
                                        http://schemas.xmlsoap.org/soap/envelope/9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FB0000.00000004.00000800.00020000.00000000.sdmpfalse
                                          high
                                          http://www.tiro.com9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpfalse
                                            high
                                            http://tempuri.org/9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FB0000.00000004.00000800.00020000.00000000.sdmpfalse
                                              high
                                              https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=tmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.drfalse
                                                high
                                                http://www.fontbureau.com/designers9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpfalse
                                                  high
                                                  http://www.goodfont.co.kr9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpfalse
                                                    high
                                                    http://45.137.22.126:59dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000003103000.00000004.00000800.00020000.00000000.sdmpfalse
                                                    • 2%, Virustotal, Browse
                                                    • Avira URL Cloud: safe
                                                    unknown
                                                    http://tempuri.org/Endpoint/VerifyUpdateResponse9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpfalse
                                                      high
                                                      http://tempuri.org/Endpoint/SetEnvironment9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000003103000.00000004.00000800.00020000.00000000.sdmpfalse
                                                        high
                                                        http://tempuri.org/Endpoint/SetEnvironmentResponse9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpfalse
                                                          high
                                                          http://www.sajatypeworks.com9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpfalse
                                                            high
                                                            http://tempuri.org/Endpoint/GetUpdates9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FF1000.00000004.00000800.00020000.00000000.sdmp, 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmp, 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FD7000.00000004.00000800.00020000.00000000.sdmp, 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FB0000.00000004.00000800.00020000.00000000.sdmpfalse
                                                              high
                                                              http://www.typography.netD9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                high
                                                                http://www.founder.com.cn/cn/cThe9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                  high
                                                                  http://www.galapagosdesign.com/staff/dennis.htm9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                    high
                                                                    https://api.ipify.orgcookies//settinString.Removeg9dOKGgFNL2.exe, 9dOKGgFNL2.exe, 00000002.00000002.1857246057.0000000000402000.00000040.00000400.00020000.00000000.sdmpfalse
                                                                      high
                                                                      https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/searchtmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.drfalse
                                                                        high
                                                                        http://www.galapagosdesign.com/DPlease9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                          high
                                                                          http://tempuri.org/Endpoint/VerifyUpdate9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                            high
                                                                            http://tempuri.org/09dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                              high
                                                                              http://www.fonts.com9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                high
                                                                                http://www.sandoll.co.kr9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                  high
                                                                                  http://www.urwpp.deDPlease9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                    high
                                                                                    http://www.zhongyicts.com.cn9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                      high
                                                                                      http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                        high
                                                                                        http://www.sakkal.com9dOKGgFNL2.exe, 00000000.00000002.1742706998.0000000006474000.00000004.00000020.00020000.00000000.sdmp, 9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                          high
                                                                                          https://ipinfo.io/ip%appdata%9dOKGgFNL2.exe, 9dOKGgFNL2.exe, 00000002.00000002.1857246057.0000000000402000.00000040.00000400.00020000.00000000.sdmpfalse
                                                                                            high
                                                                                            http://www.apache.org/licenses/LICENSE-2.09dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                              high
                                                                                              http://www.fontbureau.com9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                high
                                                                                                https://www.google.com/images/branding/product/ico/googleg_lodp.icotmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.drfalse
                                                                                                  high
                                                                                                  http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                    high
                                                                                                    http://tempuri.org/Endpoint/CheckConnectResponse9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                      high
                                                                                                      http://schemas.datacontract.org/2004/07/9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FF1000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                        high
                                                                                                        https://api.ip.sb/geoip%USERPEnvironmentROFILE%9dOKGgFNL2.exe, 9dOKGgFNL2.exe, 00000002.00000002.1857246057.0000000000402000.00000040.00000400.00020000.00000000.sdmpfalse
                                                                                                          high
                                                                                                          https://api.ip.sb9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FB0000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                            high
                                                                                                            https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=tmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.drfalse
                                                                                                              high
                                                                                                              http://tempuri.org/Endpoint/CheckConnect9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                high
                                                                                                                https://www.ecosia.org/newtab/tmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.drfalse
                                                                                                                  high
                                                                                                                  http://45.137.22.126:55615t-fq9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FF1000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                  • Avira URL Cloud: safe
                                                                                                                  unknown
                                                                                                                  http://tempuri.org/Endpoint/SetEnviron9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000003103000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                    high
                                                                                                                    http://www.carterandcone.coml9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                      high
                                                                                                                      https://ac.ecosia.org/autocomplete?q=tmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.drfalse
                                                                                                                        high
                                                                                                                        http://www.fontbureau.com/designers/cabarga.htmlN9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                          high
                                                                                                                          http://www.founder.com.cn/cn9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                            high
                                                                                                                            http://www.fontbureau.com/designers/frere-user.html9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                              high
                                                                                                                              http://schemas.xmlsoap.org/ws/2004/08/addressing9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                high
                                                                                                                                http://tempuri.org/Endpoint/GetUpdatesResponse9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                  high
                                                                                                                                  http://www.jiyu-kobo.co.jp/9dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                    high
                                                                                                                                    http://tempuri.org/Endpoint/EnvironmentSettingsResponse9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                      high
                                                                                                                                      http://www.fontbureau.com/designers89dOKGgFNL2.exe, 00000000.00000002.1742968092.0000000007612000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                        high
                                                                                                                                        https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=tmpB5A.tmp.2.dr, tmpB9E.tmp.2.dr, tmpBC1.tmp.2.dr, tmpBD2.tmp.2.dr, tmpBB1.tmp.2.dr, tmpBB0.tmp.2.dr, tmpB8D.tmp.2.dr, tmpB9F.tmp.2.dr, tmpB7D.tmp.2.dr, tmpB7C.tmp.2.dr, tmpB59.tmp.2.dr, tmpB6B.tmp.2.drfalse
                                                                                                                                          high
                                                                                                                                          http://schemas.xmlsoap.org/soap/actor/next9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                            high
                                                                                                                                            http://45.137.22.126:556159dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002FF1000.00000004.00000800.00020000.00000000.sdmp, 9dOKGgFNL2.exe, 00000002.00000002.1859206314.0000000002F61000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                            • Avira URL Cloud: safe
                                                                                                                                            unknown
                                                                                                                                            • No. of IPs < 25%
                                                                                                                                            • 25% < No. of IPs < 50%
                                                                                                                                            • 50% < No. of IPs < 75%
                                                                                                                                            • 75% < No. of IPs
                                                                                                                                            IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                            45.137.22.126
                                                                                                                                            unknownNetherlands
                                                                                                                                            51447ROOTLAYERNETNLtrue
                                                                                                                                            Joe Sandbox version:41.0.0 Charoite
                                                                                                                                            Analysis ID:1557008
                                                                                                                                            Start date and time:2024-11-17 03:06:05 +01:00
                                                                                                                                            Joe Sandbox product:CloudBasic
                                                                                                                                            Overall analysis duration:0h 6m 25s
                                                                                                                                            Hypervisor based Inspection enabled:false
                                                                                                                                            Report type:full
                                                                                                                                            Cookbook file name:default.jbs
                                                                                                                                            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                                                                            Number of analysed new started processes analysed:8
                                                                                                                                            Number of new started drivers analysed:0
                                                                                                                                            Number of existing processes analysed:0
                                                                                                                                            Number of existing drivers analysed:0
                                                                                                                                            Number of injected processes analysed:0
                                                                                                                                            Technologies:
                                                                                                                                            • HCA enabled
                                                                                                                                            • EGA enabled
                                                                                                                                            • AMSI enabled
                                                                                                                                            Analysis Mode:default
                                                                                                                                            Analysis stop reason:Timeout
                                                                                                                                            Sample name:9dOKGgFNL2.exe
                                                                                                                                            renamed because original name is a hash value
                                                                                                                                            Original Sample Name:020ec1df3b8b9d28da16edaf0d50a262.exe
                                                                                                                                            Detection:MAL
                                                                                                                                            Classification:mal100.troj.spyw.evad.winEXE@4/43@1/1
                                                                                                                                            EGA Information:
                                                                                                                                            • Successful, ratio: 100%
                                                                                                                                            HCA Information:
                                                                                                                                            • Successful, ratio: 100%
                                                                                                                                            • Number of executed functions: 80
                                                                                                                                            • Number of non-executed functions: 9
                                                                                                                                            Cookbook Comments:
                                                                                                                                            • Found application associated with file extension: .exe
                                                                                                                                            • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
                                                                                                                                            • Excluded IPs from analysis (whitelisted): 104.26.13.31, 172.67.75.172, 104.26.12.31
                                                                                                                                            • Excluded domains from analysis (whitelisted): api.ip.sb.cdn.cloudflare.net, fs.microsoft.com, ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                                                                                                                            • Not all processes where analyzed, report is missing behavior information
                                                                                                                                            • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                                                                                                                                            • Report size getting too big, too many NtOpenKeyEx calls found.
                                                                                                                                            • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                                                                                                                            • Report size getting too big, too many NtQueryValueKey calls found.
                                                                                                                                            TimeTypeDescription
                                                                                                                                            21:06:58API Interceptor51x Sleep call for process: 9dOKGgFNL2.exe modified
                                                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                            45.137.22.126DEVIS + FACTURE.exeGet hashmaliciousRemcos, GuLoaderBrowse
                                                                                                                                            • pharmaciedelaplage.bounceme.net/KLnDNWENP155.bin
                                                                                                                                            No context
                                                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                            ROOTLAYERNETNLRFQ List and airflight 2024.pif.exeGet hashmaliciousPureLog StealerBrowse
                                                                                                                                            • 45.137.22.174
                                                                                                                                            Calyciform.exeGet hashmaliciousGuLoaderBrowse
                                                                                                                                            • 45.137.22.248
                                                                                                                                            I5pvP0CU6M.exeGet hashmaliciousRedLineBrowse
                                                                                                                                            • 45.137.22.248
                                                                                                                                            gLsenXDHxP.exeGet hashmaliciousRedLineBrowse
                                                                                                                                            • 185.222.58.240
                                                                                                                                            DEVIS + FACTURE.exeGet hashmaliciousRemcos, GuLoaderBrowse
                                                                                                                                            • 45.137.22.126
                                                                                                                                            PZNfhfaj9O.exeGet hashmaliciousRedLineBrowse
                                                                                                                                            • 185.222.58.80
                                                                                                                                            ZxS8mP8uE6.exeGet hashmaliciousRedLineBrowse
                                                                                                                                            • 45.137.22.123
                                                                                                                                            nu28HwzQwC.exeGet hashmaliciousRedLineBrowse
                                                                                                                                            • 185.222.58.52
                                                                                                                                            DKO6uy1Tia.exeGet hashmaliciousRedLineBrowse
                                                                                                                                            • 45.137.22.70
                                                                                                                                            3BOCQ22aUs.ps1Get hashmaliciousUnknownBrowse
                                                                                                                                            • 45.137.20.45
                                                                                                                                            No context
                                                                                                                                            No context
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):1216
                                                                                                                                            Entropy (8bit):5.34331486778365
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:24:MLUE4K5E4KH1qE4qXKDE4KhKiKhPKIE4oKNzKoZAE4Kze0E4x84j:MIHK5HKH1qHiYHKh3oPtHo6hAHKze0HJ
                                                                                                                                            MD5:1330C80CAAC9A0FB172F202485E9B1E8
                                                                                                                                            SHA1:86BAFDA4E4AE68C7C3012714A33D85D2B6E1A492
                                                                                                                                            SHA-256:B6C63ECE799A8F7E497C2A158B1FFC2F5CB4F745A2F8E585F794572B7CF03560
                                                                                                                                            SHA-512:75A17AB129FE97BBAB36AA2BD66D59F41DB5AFF44A705EF3E4D094EC5FCD056A3ED59992A0AC96C9D0D40E490F8596B07DCA9B60E606B67223867B061D9D0EB2
                                                                                                                                            Malicious:true
                                                                                                                                            Reputation:high, very likely benign file
                                                                                                                                            Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..2,"System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089",0..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\920e3d1d70447c3c10e69e6df0766568\System.ni.dll",0..2,"System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8b2c1203fd20aea8260bfbc518004720\System.Core.ni.dll",0..3,"System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\2192b0d5aa4aa14486ae08118d3b9fcc\System.Configuration.ni.dll",0..3,"System.Xml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\2062ed810929ec0e33254c02
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):49152
                                                                                                                                            Entropy (8bit):0.8180424350137764
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:96:uRMKLyeymwxCn8MZyFlSynlbiXyKwt8hG:uRkxGOXnlbibhG
                                                                                                                                            MD5:349E6EB110E34A08924D92F6B334801D
                                                                                                                                            SHA1:BDFB289DAFF51890CC71697B6322AA4B35EC9169
                                                                                                                                            SHA-256:C9FD7BE4579E4AA942E8C2B44AB10115FA6C2FE6AFD0C584865413D9D53F3B2A
                                                                                                                                            SHA-512:2A635B815A5E117EA181EE79305EE1BAF591459427ACC5210D8C6C7E447BE3513EAD871C605EB3D32E4AB4111B2A335F26520D0EF8C1245A4AF44E1FAEC44574
                                                                                                                                            Malicious:false
                                                                                                                                            Reputation:high, very likely benign file
                                                                                                                                            Preview:SQLite format 3......@ ..........................................................................O}....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):49152
                                                                                                                                            Entropy (8bit):0.8180424350137764
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:96:uRMKLyeymwxCn8MZyFlSynlbiXyKwt8hG:uRkxGOXnlbibhG
                                                                                                                                            MD5:349E6EB110E34A08924D92F6B334801D
                                                                                                                                            SHA1:BDFB289DAFF51890CC71697B6322AA4B35EC9169
                                                                                                                                            SHA-256:C9FD7BE4579E4AA942E8C2B44AB10115FA6C2FE6AFD0C584865413D9D53F3B2A
                                                                                                                                            SHA-512:2A635B815A5E117EA181EE79305EE1BAF591459427ACC5210D8C6C7E447BE3513EAD871C605EB3D32E4AB4111B2A335F26520D0EF8C1245A4AF44E1FAEC44574
                                                                                                                                            Malicious:false
                                                                                                                                            Reputation:high, very likely benign file
                                                                                                                                            Preview:SQLite format 3......@ ..........................................................................O}....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):49152
                                                                                                                                            Entropy (8bit):0.8180424350137764
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:96:uRMKLyeymwxCn8MZyFlSynlbiXyKwt8hG:uRkxGOXnlbibhG
                                                                                                                                            MD5:349E6EB110E34A08924D92F6B334801D
                                                                                                                                            SHA1:BDFB289DAFF51890CC71697B6322AA4B35EC9169
                                                                                                                                            SHA-256:C9FD7BE4579E4AA942E8C2B44AB10115FA6C2FE6AFD0C584865413D9D53F3B2A
                                                                                                                                            SHA-512:2A635B815A5E117EA181EE79305EE1BAF591459427ACC5210D8C6C7E447BE3513EAD871C605EB3D32E4AB4111B2A335F26520D0EF8C1245A4AF44E1FAEC44574
                                                                                                                                            Malicious:false
                                                                                                                                            Reputation:high, very likely benign file
                                                                                                                                            Preview:SQLite format 3......@ ..........................................................................O}....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):49152
                                                                                                                                            Entropy (8bit):0.8180424350137764
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:96:uRMKLyeymwxCn8MZyFlSynlbiXyKwt8hG:uRkxGOXnlbibhG
                                                                                                                                            MD5:349E6EB110E34A08924D92F6B334801D
                                                                                                                                            SHA1:BDFB289DAFF51890CC71697B6322AA4B35EC9169
                                                                                                                                            SHA-256:C9FD7BE4579E4AA942E8C2B44AB10115FA6C2FE6AFD0C584865413D9D53F3B2A
                                                                                                                                            SHA-512:2A635B815A5E117EA181EE79305EE1BAF591459427ACC5210D8C6C7E447BE3513EAD871C605EB3D32E4AB4111B2A335F26520D0EF8C1245A4AF44E1FAEC44574
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ ..........................................................................O}....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):49152
                                                                                                                                            Entropy (8bit):0.8180424350137764
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:96:uRMKLyeymwxCn8MZyFlSynlbiXyKwt8hG:uRkxGOXnlbibhG
                                                                                                                                            MD5:349E6EB110E34A08924D92F6B334801D
                                                                                                                                            SHA1:BDFB289DAFF51890CC71697B6322AA4B35EC9169
                                                                                                                                            SHA-256:C9FD7BE4579E4AA942E8C2B44AB10115FA6C2FE6AFD0C584865413D9D53F3B2A
                                                                                                                                            SHA-512:2A635B815A5E117EA181EE79305EE1BAF591459427ACC5210D8C6C7E447BE3513EAD871C605EB3D32E4AB4111B2A335F26520D0EF8C1245A4AF44E1FAEC44574
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ ..........................................................................O}....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):49152
                                                                                                                                            Entropy (8bit):0.8180424350137764
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:96:uRMKLyeymwxCn8MZyFlSynlbiXyKwt8hG:uRkxGOXnlbibhG
                                                                                                                                            MD5:349E6EB110E34A08924D92F6B334801D
                                                                                                                                            SHA1:BDFB289DAFF51890CC71697B6322AA4B35EC9169
                                                                                                                                            SHA-256:C9FD7BE4579E4AA942E8C2B44AB10115FA6C2FE6AFD0C584865413D9D53F3B2A
                                                                                                                                            SHA-512:2A635B815A5E117EA181EE79305EE1BAF591459427ACC5210D8C6C7E447BE3513EAD871C605EB3D32E4AB4111B2A335F26520D0EF8C1245A4AF44E1FAEC44574
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ ..........................................................................O}....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):114688
                                                                                                                                            Entropy (8bit):0.9746603542602881
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn
                                                                                                                                            MD5:780853CDDEAEE8DE70F28A4B255A600B
                                                                                                                                            SHA1:AD7A5DA33F7AD12946153C497E990720B09005ED
                                                                                                                                            SHA-256:1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3
                                                                                                                                            SHA-512:E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ .......8...........$......................................................O}...........4........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):114688
                                                                                                                                            Entropy (8bit):0.9746603542602881
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn
                                                                                                                                            MD5:780853CDDEAEE8DE70F28A4B255A600B
                                                                                                                                            SHA1:AD7A5DA33F7AD12946153C497E990720B09005ED
                                                                                                                                            SHA-256:1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3
                                                                                                                                            SHA-512:E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ .......8...........$......................................................O}...........4........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):114688
                                                                                                                                            Entropy (8bit):0.9746603542602881
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn
                                                                                                                                            MD5:780853CDDEAEE8DE70F28A4B255A600B
                                                                                                                                            SHA1:AD7A5DA33F7AD12946153C497E990720B09005ED
                                                                                                                                            SHA-256:1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3
                                                                                                                                            SHA-512:E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ .......8...........$......................................................O}...........4........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):114688
                                                                                                                                            Entropy (8bit):0.9746603542602881
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn
                                                                                                                                            MD5:780853CDDEAEE8DE70F28A4B255A600B
                                                                                                                                            SHA1:AD7A5DA33F7AD12946153C497E990720B09005ED
                                                                                                                                            SHA-256:1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3
                                                                                                                                            SHA-512:E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ .......8...........$......................................................O}...........4........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):114688
                                                                                                                                            Entropy (8bit):0.9746603542602881
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn
                                                                                                                                            MD5:780853CDDEAEE8DE70F28A4B255A600B
                                                                                                                                            SHA1:AD7A5DA33F7AD12946153C497E990720B09005ED
                                                                                                                                            SHA-256:1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3
                                                                                                                                            SHA-512:E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ .......8...........$......................................................O}...........4........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):114688
                                                                                                                                            Entropy (8bit):0.9746603542602881
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn
                                                                                                                                            MD5:780853CDDEAEE8DE70F28A4B255A600B
                                                                                                                                            SHA1:AD7A5DA33F7AD12946153C497E990720B09005ED
                                                                                                                                            SHA-256:1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3
                                                                                                                                            SHA-512:E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ .......8...........$......................................................O}...........4........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):114688
                                                                                                                                            Entropy (8bit):0.9746603542602881
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn
                                                                                                                                            MD5:780853CDDEAEE8DE70F28A4B255A600B
                                                                                                                                            SHA1:AD7A5DA33F7AD12946153C497E990720B09005ED
                                                                                                                                            SHA-256:1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3
                                                                                                                                            SHA-512:E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ .......8...........$......................................................O}...........4........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):114688
                                                                                                                                            Entropy (8bit):0.9746603542602881
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn
                                                                                                                                            MD5:780853CDDEAEE8DE70F28A4B255A600B
                                                                                                                                            SHA1:AD7A5DA33F7AD12946153C497E990720B09005ED
                                                                                                                                            SHA-256:1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3
                                                                                                                                            SHA-512:E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ .......8...........$......................................................O}...........4........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):114688
                                                                                                                                            Entropy (8bit):0.9746603542602881
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn
                                                                                                                                            MD5:780853CDDEAEE8DE70F28A4B255A600B
                                                                                                                                            SHA1:AD7A5DA33F7AD12946153C497E990720B09005ED
                                                                                                                                            SHA-256:1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3
                                                                                                                                            SHA-512:E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ .......8...........$......................................................O}...........4........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):114688
                                                                                                                                            Entropy (8bit):0.9746603542602881
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn
                                                                                                                                            MD5:780853CDDEAEE8DE70F28A4B255A600B
                                                                                                                                            SHA1:AD7A5DA33F7AD12946153C497E990720B09005ED
                                                                                                                                            SHA-256:1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3
                                                                                                                                            SHA-512:E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ .......8...........$......................................................O}...........4........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):114688
                                                                                                                                            Entropy (8bit):0.9746603542602881
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn
                                                                                                                                            MD5:780853CDDEAEE8DE70F28A4B255A600B
                                                                                                                                            SHA1:AD7A5DA33F7AD12946153C497E990720B09005ED
                                                                                                                                            SHA-256:1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3
                                                                                                                                            SHA-512:E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ .......8...........$......................................................O}...........4........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):114688
                                                                                                                                            Entropy (8bit):0.9746603542602881
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn
                                                                                                                                            MD5:780853CDDEAEE8DE70F28A4B255A600B
                                                                                                                                            SHA1:AD7A5DA33F7AD12946153C497E990720B09005ED
                                                                                                                                            SHA-256:1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3
                                                                                                                                            SHA-512:E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ .......8...........$......................................................O}...........4........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, user version 12, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 3, database pages 3, cookie 0x1, schema 4, UTF-8, version-valid-for 3
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):98304
                                                                                                                                            Entropy (8bit):0.08235737944063153
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:12:DQAsfWk73Fmdmc/OPVJXfPNn43etRRfYR5O8atLqxeYaNcDakMG/lO:DQAsff32mNVpP965Ra8KN0MG/lO
                                                                                                                                            MD5:369B6DD66F1CAD49D0952C40FEB9AD41
                                                                                                                                            SHA1:D05B2DE29433FB113EC4C558FF33087ED7481DD4
                                                                                                                                            SHA-256:14150D582B5321D91BDE0841066312AB3E6673CA51C982922BC293B82527220D
                                                                                                                                            SHA-512:771054845B27274054B6C73776204C235C46E0C742ECF3E2D9B650772BA5D259C8867B2FA92C3A9413D3E1AD35589D8431AC683DF84A53E13CDE361789045928
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ ..........................................................................j......}..}...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):106496
                                                                                                                                            Entropy (8bit):1.1358696453229276
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                                                            MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                                                            SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                                                            SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                                                            SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):106496
                                                                                                                                            Entropy (8bit):1.1358696453229276
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                                                            MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                                                            SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                                                            SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                                                            SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):106496
                                                                                                                                            Entropy (8bit):1.1358696453229276
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                                                            MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                                                            SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                                                            SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                                                            SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, user version 12, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 3, database pages 3, cookie 0x1, schema 4, UTF-8, version-valid-for 3
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):98304
                                                                                                                                            Entropy (8bit):0.08235737944063153
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:12:DQAsfWk73Fmdmc/OPVJXfPNn43etRRfYR5O8atLqxeYaNcDakMG/lO:DQAsff32mNVpP965Ra8KN0MG/lO
                                                                                                                                            MD5:369B6DD66F1CAD49D0952C40FEB9AD41
                                                                                                                                            SHA1:D05B2DE29433FB113EC4C558FF33087ED7481DD4
                                                                                                                                            SHA-256:14150D582B5321D91BDE0841066312AB3E6673CA51C982922BC293B82527220D
                                                                                                                                            SHA-512:771054845B27274054B6C73776204C235C46E0C742ECF3E2D9B650772BA5D259C8867B2FA92C3A9413D3E1AD35589D8431AC683DF84A53E13CDE361789045928
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ ..........................................................................j......}..}...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):106496
                                                                                                                                            Entropy (8bit):1.1358696453229276
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                                                            MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                                                            SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                                                            SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                                                            SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):106496
                                                                                                                                            Entropy (8bit):1.1358696453229276
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                                                            MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                                                            SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                                                            SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                                                            SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):106496
                                                                                                                                            Entropy (8bit):1.1358696453229276
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                                                            MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                                                            SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                                                            SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                                                            SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):106496
                                                                                                                                            Entropy (8bit):1.1358696453229276
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                                                            MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                                                            SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                                                            SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                                                            SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):106496
                                                                                                                                            Entropy (8bit):1.1358696453229276
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                                                            MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                                                            SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                                                            SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                                                            SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):106496
                                                                                                                                            Entropy (8bit):1.1358696453229276
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                                                            MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                                                            SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                                                            SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                                                            SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):106496
                                                                                                                                            Entropy (8bit):1.1358696453229276
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                                                            MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                                                            SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                                                            SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                                                            SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):106496
                                                                                                                                            Entropy (8bit):1.1358696453229276
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                                                            MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                                                            SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                                                            SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                                                            SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):106496
                                                                                                                                            Entropy (8bit):1.1358696453229276
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                                                            MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                                                            SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                                                            SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                                                            SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):1026
                                                                                                                                            Entropy (8bit):4.695685570184741
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:24:SYuCgqv/1uycbC6SHsJPWXpOxTeVtblICcFX4xlyzK7y45wR39IRh:S1CPvsC6YE+XgleVtbQuKGf5M39IRh
                                                                                                                                            MD5:A28F7445BB3D064C83EB9DBC98091F76
                                                                                                                                            SHA1:D4E174D2D26333FCB66D3FD84E3D0F67AF41D182
                                                                                                                                            SHA-256:10A802E683A2C669BB581DE0A192C8291DD2D53D89A2883A59CC29EB14453B93
                                                                                                                                            SHA-512:42526FEC4220E50DB60BD7D83A07DEB9D5BE4F63AD093B518E9ECC86B779210B0170F6F64C9F16064D50CB12F03643BAC9995D4F3C0AFD5F8D38428D57ADE487
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:UMMBDNEQBNVIMBNGHYZCBKXWMQJKYISTANSRNFXXBKALIIEMEWAFQEPTEMZCIXXNMQBGOXWSDYSAWKIYPJITNREMVRXPPJZFUTMGRRRGTCHVLEWVUJGZEUQVONQVACEFWZUCIAFXPFGXIUOOBZEEMGMWJQIEKKICYJJWAFUKYZAJEGUQKGDPRPXCOWIPBRUGHWDFZLGSKZVCHVVPGLEFNGIVLBVNAOVXAPGATADJBIQTBNJGWXRSEYKCSVZOSTCBHYFHUDEWNGEIFCVREPZDZDZRITFEVFCQQWJYZXPUKJWHTWGWASTKDCAVEWZOIGFZHRWCJBVRLDWGVKPABCQUOHQIMLUFUGYGMPGPEMSRPPSGWIGRVPBGZIWLNEVYFFJBCMBSXVABNRNXULCTUAANAXDHKZOGVCNQZHMRBENWTTLQVVMDLNBEWHLPZHMPDGRLJWAQJDJRCWTFWIOLAURRCSMFJOCFDKUGPLTPABARXKPCRXOIHHVRWXAKGHOTYLCEQQYYDKVZQSYLCAEGGBQMMJGSNJWBTJXSVALINNRLURMPNGFXHJRVJIKQJSDLNIOXGIGDFDCOTGGXMDLTDYSIKCMPVINDDXXQCEQCRUBLFEWMYMSEGUHIKIGUYOMOXSKOTVNUNGWUFYKYRNZXOOTSRYXLZHRZXNEDJUNPYGNIIZSPVQBOLBRRRWGDMQWUTRSZWBYMXNMLKLFNZWJVDDPMJOXTVBMYRXNQFGBLURKFIUAHJBFFXNWQDYRLZADYGMETNXEOXLOJKYQPEYHUVTFGXQTGPQBWZQTVFXZFUVQERQZJCYYPFBYONAVFDOLTNRGWQYGSYWCWUWRETJZGVJMEFQTYPOLONVZFREVORMBQJOCLOALCJHHCHQSHKLUNBIRHRBSQSMERLKKFTGHUQKRPFIIELZZVXZVNHCIQYYXNMJNSOZOIRGGJKUWXNCWSNCFMGQIQVNKVIGRCLSDWQPEDLSLTGBRXRTMGFWYQSCLN
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):1026
                                                                                                                                            Entropy (8bit):4.701757898321461
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                                                            MD5:520219000D5681B63804A2D138617B27
                                                                                                                                            SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                                                            SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                                                            SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):1026
                                                                                                                                            Entropy (8bit):4.695685570184741
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:24:SYuCgqv/1uycbC6SHsJPWXpOxTeVtblICcFX4xlyzK7y45wR39IRh:S1CPvsC6YE+XgleVtbQuKGf5M39IRh
                                                                                                                                            MD5:A28F7445BB3D064C83EB9DBC98091F76
                                                                                                                                            SHA1:D4E174D2D26333FCB66D3FD84E3D0F67AF41D182
                                                                                                                                            SHA-256:10A802E683A2C669BB581DE0A192C8291DD2D53D89A2883A59CC29EB14453B93
                                                                                                                                            SHA-512:42526FEC4220E50DB60BD7D83A07DEB9D5BE4F63AD093B518E9ECC86B779210B0170F6F64C9F16064D50CB12F03643BAC9995D4F3C0AFD5F8D38428D57ADE487
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:UMMBDNEQBNVIMBNGHYZCBKXWMQJKYISTANSRNFXXBKALIIEMEWAFQEPTEMZCIXXNMQBGOXWSDYSAWKIYPJITNREMVRXPPJZFUTMGRRRGTCHVLEWVUJGZEUQVONQVACEFWZUCIAFXPFGXIUOOBZEEMGMWJQIEKKICYJJWAFUKYZAJEGUQKGDPRPXCOWIPBRUGHWDFZLGSKZVCHVVPGLEFNGIVLBVNAOVXAPGATADJBIQTBNJGWXRSEYKCSVZOSTCBHYFHUDEWNGEIFCVREPZDZDZRITFEVFCQQWJYZXPUKJWHTWGWASTKDCAVEWZOIGFZHRWCJBVRLDWGVKPABCQUOHQIMLUFUGYGMPGPEMSRPPSGWIGRVPBGZIWLNEVYFFJBCMBSXVABNRNXULCTUAANAXDHKZOGVCNQZHMRBENWTTLQVVMDLNBEWHLPZHMPDGRLJWAQJDJRCWTFWIOLAURRCSMFJOCFDKUGPLTPABARXKPCRXOIHHVRWXAKGHOTYLCEQQYYDKVZQSYLCAEGGBQMMJGSNJWBTJXSVALINNRLURMPNGFXHJRVJIKQJSDLNIOXGIGDFDCOTGGXMDLTDYSIKCMPVINDDXXQCEQCRUBLFEWMYMSEGUHIKIGUYOMOXSKOTVNUNGWUFYKYRNZXOOTSRYXLZHRZXNEDJUNPYGNIIZSPVQBOLBRRRWGDMQWUTRSZWBYMXNMLKLFNZWJVDDPMJOXTVBMYRXNQFGBLURKFIUAHJBFFXNWQDYRLZADYGMETNXEOXLOJKYQPEYHUVTFGXQTGPQBWZQTVFXZFUVQERQZJCYYPFBYONAVFDOLTNRGWQYGSYWCWUWRETJZGVJMEFQTYPOLONVZFREVORMBQJOCLOALCJHHCHQSHKLUNBIRHRBSQSMERLKKFTGHUQKRPFIIELZZVXZVNHCIQYYXNMJNSOZOIRGGJKUWXNCWSNCFMGQIQVNKVIGRCLSDWQPEDLSLTGBRXRTMGFWYQSCLN
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):1026
                                                                                                                                            Entropy (8bit):4.701757898321461
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                                                            MD5:520219000D5681B63804A2D138617B27
                                                                                                                                            SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                                                            SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                                                            SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):40960
                                                                                                                                            Entropy (8bit):0.8553638852307782
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:48:2x7BA+IIF7CVEq8Ma0D0HOlf/6ykwp1EUwMHZq10bvJKLkw8s8LKvUf9KVyJ7h/f:QNDCn8MouB6wz8iZqmvJKLPeymwil
                                                                                                                                            MD5:28222628A3465C5F0D4B28F70F97F482
                                                                                                                                            SHA1:1BAA3DEB7DFD7C9B4CA9FDB540F236C24917DD14
                                                                                                                                            SHA-256:93A6AF6939B17143531FA4474DFC564FA55359308B910E6F0DCA774D322C9BE4
                                                                                                                                            SHA-512:C8FB93F658C1A654186FA6AA2039E40791E6B0A1260B223272BB01279A7B574E238B28217DADF3E1850C7083ADFA2FE5DA0CCE6F9BCABD59E1FFD1061B3A88F7
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):40960
                                                                                                                                            Entropy (8bit):0.8553638852307782
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:48:2x7BA+IIF7CVEq8Ma0D0HOlf/6ykwp1EUwMHZq10bvJKLkw8s8LKvUf9KVyJ7h/f:QNDCn8MouB6wz8iZqmvJKLPeymwil
                                                                                                                                            MD5:28222628A3465C5F0D4B28F70F97F482
                                                                                                                                            SHA1:1BAA3DEB7DFD7C9B4CA9FDB540F236C24917DD14
                                                                                                                                            SHA-256:93A6AF6939B17143531FA4474DFC564FA55359308B910E6F0DCA774D322C9BE4
                                                                                                                                            SHA-512:C8FB93F658C1A654186FA6AA2039E40791E6B0A1260B223272BB01279A7B574E238B28217DADF3E1850C7083ADFA2FE5DA0CCE6F9BCABD59E1FFD1061B3A88F7
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):40960
                                                                                                                                            Entropy (8bit):0.8553638852307782
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:48:2x7BA+IIF7CVEq8Ma0D0HOlf/6ykwp1EUwMHZq10bvJKLkw8s8LKvUf9KVyJ7h/f:QNDCn8MouB6wz8iZqmvJKLPeymwil
                                                                                                                                            MD5:28222628A3465C5F0D4B28F70F97F482
                                                                                                                                            SHA1:1BAA3DEB7DFD7C9B4CA9FDB540F236C24917DD14
                                                                                                                                            SHA-256:93A6AF6939B17143531FA4474DFC564FA55359308B910E6F0DCA774D322C9BE4
                                                                                                                                            SHA-512:C8FB93F658C1A654186FA6AA2039E40791E6B0A1260B223272BB01279A7B574E238B28217DADF3E1850C7083ADFA2FE5DA0CCE6F9BCABD59E1FFD1061B3A88F7
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):40960
                                                                                                                                            Entropy (8bit):0.8553638852307782
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:48:2x7BA+IIF7CVEq8Ma0D0HOlf/6ykwp1EUwMHZq10bvJKLkw8s8LKvUf9KVyJ7h/f:QNDCn8MouB6wz8iZqmvJKLPeymwil
                                                                                                                                            MD5:28222628A3465C5F0D4B28F70F97F482
                                                                                                                                            SHA1:1BAA3DEB7DFD7C9B4CA9FDB540F236C24917DD14
                                                                                                                                            SHA-256:93A6AF6939B17143531FA4474DFC564FA55359308B910E6F0DCA774D322C9BE4
                                                                                                                                            SHA-512:C8FB93F658C1A654186FA6AA2039E40791E6B0A1260B223272BB01279A7B574E238B28217DADF3E1850C7083ADFA2FE5DA0CCE6F9BCABD59E1FFD1061B3A88F7
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):40960
                                                                                                                                            Entropy (8bit):0.8553638852307782
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:48:2x7BA+IIF7CVEq8Ma0D0HOlf/6ykwp1EUwMHZq10bvJKLkw8s8LKvUf9KVyJ7h/f:QNDCn8MouB6wz8iZqmvJKLPeymwil
                                                                                                                                            MD5:28222628A3465C5F0D4B28F70F97F482
                                                                                                                                            SHA1:1BAA3DEB7DFD7C9B4CA9FDB540F236C24917DD14
                                                                                                                                            SHA-256:93A6AF6939B17143531FA4474DFC564FA55359308B910E6F0DCA774D322C9BE4
                                                                                                                                            SHA-512:C8FB93F658C1A654186FA6AA2039E40791E6B0A1260B223272BB01279A7B574E238B28217DADF3E1850C7083ADFA2FE5DA0CCE6F9BCABD59E1FFD1061B3A88F7
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            Process:C:\Users\user\Desktop\9dOKGgFNL2.exe
                                                                                                                                            File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
                                                                                                                                            Category:dropped
                                                                                                                                            Size (bytes):40960
                                                                                                                                            Entropy (8bit):0.8553638852307782
                                                                                                                                            Encrypted:false
                                                                                                                                            SSDEEP:48:2x7BA+IIF7CVEq8Ma0D0HOlf/6ykwp1EUwMHZq10bvJKLkw8s8LKvUf9KVyJ7h/f:QNDCn8MouB6wz8iZqmvJKLPeymwil
                                                                                                                                            MD5:28222628A3465C5F0D4B28F70F97F482
                                                                                                                                            SHA1:1BAA3DEB7DFD7C9B4CA9FDB540F236C24917DD14
                                                                                                                                            SHA-256:93A6AF6939B17143531FA4474DFC564FA55359308B910E6F0DCA774D322C9BE4
                                                                                                                                            SHA-512:C8FB93F658C1A654186FA6AA2039E40791E6B0A1260B223272BB01279A7B574E238B28217DADF3E1850C7083ADFA2FE5DA0CCE6F9BCABD59E1FFD1061B3A88F7
                                                                                                                                            Malicious:false
                                                                                                                                            Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                            File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                                                            Entropy (8bit):7.761554280381937
                                                                                                                                            TrID:
                                                                                                                                            • Win32 Executable (generic) Net Framework (10011505/4) 49.83%
                                                                                                                                            • Win32 Executable (generic) a (10002005/4) 49.78%
                                                                                                                                            • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
                                                                                                                                            • Generic Win/DOS Executable (2004/3) 0.01%
                                                                                                                                            • DOS Executable Generic (2002/1) 0.01%
                                                                                                                                            File name:9dOKGgFNL2.exe
                                                                                                                                            File size:534'528 bytes
                                                                                                                                            MD5:020ec1df3b8b9d28da16edaf0d50a262
                                                                                                                                            SHA1:b9b841c39445febc098f7edbda4112194615fc10
                                                                                                                                            SHA256:6eaf9b6af911a7995d490906ff5d42a36a47e4b1d4510f6fc33c7cdab2c80aae
                                                                                                                                            SHA512:214c186d842409891d905d612223b944ec8e0d86cb344aada20e35b211ec908c84469d266d961162e7d70d4300471c7d9ce1401e7552b10d8d7d9412b96d5261
                                                                                                                                            SSDEEP:12288:IMyCpQuRWIPxTIeVJbZnjlz3W/9Fex4XmwRzbgTzzha+:IMyCQuHzHx6/XeKXJy1
                                                                                                                                            TLSH:6EB40164FA25E957CAE547F81431D3BA07B68D4DE812D3039FEAACD73C06B1D6A04293
                                                                                                                                            File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....3g..............0..............&... ...@....@.. ....................................`................................
                                                                                                                                            Icon Hash:1bb3b3b3b3d389b3
                                                                                                                                            Entrypoint:0x48269e
                                                                                                                                            Entrypoint Section:.text
                                                                                                                                            Digitally signed:false
                                                                                                                                            Imagebase:0x400000
                                                                                                                                            Subsystem:windows gui
                                                                                                                                            Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                                                                                                                            DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                                                                                                                                            Time Stamp:0x6733F893 [Wed Nov 13 00:53:39 2024 UTC]
                                                                                                                                            TLS Callbacks:
                                                                                                                                            CLR (.Net) Version:
                                                                                                                                            OS Version Major:4
                                                                                                                                            OS Version Minor:0
                                                                                                                                            File Version Major:4
                                                                                                                                            File Version Minor:0
                                                                                                                                            Subsystem Version Major:4
                                                                                                                                            Subsystem Version Minor:0
                                                                                                                                            Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
                                                                                                                                            Instruction
                                                                                                                                            jmp dword ptr [00402000h]
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            add byte ptr [eax], al
                                                                                                                                            NameVirtual AddressVirtual Size Is in Section
                                                                                                                                            IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                                                                                            IMAGE_DIRECTORY_ENTRY_IMPORT0x8264b0x4f.text
                                                                                                                                            IMAGE_DIRECTORY_ENTRY_RESOURCE0x840000x1b48.rsrc
                                                                                                                                            IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                                                                                            IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                                                                                            IMAGE_DIRECTORY_ENTRY_BASERELOC0x860000xc.reloc
                                                                                                                                            IMAGE_DIRECTORY_ENTRY_DEBUG0x806d80x54.text
                                                                                                                                            IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                                                                                            IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                                                                                            IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                                                                                                            IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                                                                                                                            IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                                                                                            IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
                                                                                                                                            IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                                                                                            IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
                                                                                                                                            IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                                                                                            NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                                                                                            .text0x20000x806a40x80800df1912e430955b2a4cbcfee03a136d9cFalse0.8940809672908561data7.770995746521688IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                                                                                                            .rsrc0x840000x1b480x1c0057997b2441a336a16ef2b08040b4c0b4False0.7726004464285714data7.226831072922865IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                            .reloc0x860000xc0x200d8d6d45757f1a173512e291562cbb0d5False0.044921875data0.10191042566270775IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                                                                                            NameRVASizeTypeLanguageCountryZLIB Complexity
                                                                                                                                            RT_ICON0x841300x151aPNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced0.8863383931877082
                                                                                                                                            RT_GROUP_ICON0x8564c0x14data0.9
                                                                                                                                            RT_VERSION0x856600x2fcdata0.4410994764397906
                                                                                                                                            RT_MANIFEST0x8595c0x1eaXML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators0.5489795918367347
                                                                                                                                            DLLImport
                                                                                                                                            mscoree.dll_CorExeMain
                                                                                                                                            TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                                                                                            2024-11-17T03:07:03.465942+01002849662ETPRO MALWARE RedLine - CheckConnect Request1192.168.2.44973345.137.22.12655615TCP
                                                                                                                                            2024-11-17T03:07:08.476379+01002045000ET MALWARE RedLine Stealer - CheckConnect Response145.137.22.12655615192.168.2.449733TCP
                                                                                                                                            2024-11-17T03:07:08.786615+01002849351ETPRO MALWARE RedLine - EnvironmentSettings Request1192.168.2.44973345.137.22.12655615TCP
                                                                                                                                            2024-11-17T03:07:11.420400+01002045001ET MALWARE Win32/LeftHook Stealer Browser Extension Config Inbound145.137.22.12655615192.168.2.449733TCP
                                                                                                                                            2024-11-17T03:07:11.420400+01002046056ET MALWARE Redline Stealer/MetaStealer Family Activity (Response)145.137.22.12655615192.168.2.449733TCP
                                                                                                                                            2024-11-17T03:07:11.473182+01002849352ETPRO MALWARE RedLine - SetEnvironment Request1192.168.2.44973745.137.22.12655615TCP
                                                                                                                                            2024-11-17T03:07:13.993295+01002848200ETPRO MALWARE RedLine - GetUpdates Request1192.168.2.44973845.137.22.12655615TCP
                                                                                                                                            TimestampSource PortDest PortSource IPDest IP
                                                                                                                                            Nov 17, 2024 03:07:02.567902088 CET4973355615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:02.573175907 CET556154973345.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:02.573249102 CET4973355615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:02.587853909 CET4973355615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:02.592741013 CET556154973345.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:02.935049057 CET4973355615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:02.940236092 CET556154973345.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:03.422421932 CET556154973345.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:03.465941906 CET4973355615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:08.471224070 CET4973355615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:08.471296072 CET4973355615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:08.476378918 CET556154973345.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:08.476547956 CET556154973345.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:08.786478996 CET556154973345.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:08.786526918 CET556154973345.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:08.786561966 CET556154973345.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:08.786598921 CET556154973345.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:08.786614895 CET4973355615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:08.786633968 CET556154973345.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:08.786705971 CET4973355615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:08.840959072 CET4973355615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:11.414999962 CET4973355615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:11.415204048 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:11.420197010 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.420280933 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:11.420399904 CET556154973345.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.420510054 CET4973355615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:11.420854092 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:11.421082973 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:11.425668001 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.425987959 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.425997019 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.426048994 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.426057100 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.426069021 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.426084995 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:11.426166058 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:11.426182032 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.426223993 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.426610947 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:11.430351019 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.430360079 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.430418968 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:11.431015968 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.431056023 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.431077003 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:11.431128025 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.431129932 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:11.431138039 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.431154966 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.431162119 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.431197882 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:11.431236982 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:11.472970963 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.473181963 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:11.521291018 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.521361113 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:11.569304943 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.569370985 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:11.616894960 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.616957903 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:11.668976068 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.669069052 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:11.720884085 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.720969915 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:11.769052029 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.769119024 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:11.816984892 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.817045927 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:11.864947081 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.865010023 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:11.913229942 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.913307905 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:11.965133905 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:11.965203047 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.013509035 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.013581038 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.019471884 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.019737959 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.019865990 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.025293112 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.025321960 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.025366068 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.025439978 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.025468111 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.025501966 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.025517941 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.025541067 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.025544882 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.025566101 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.025595903 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.025602102 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.025629997 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.025656939 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.025679111 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.025681973 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.025707006 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.025732994 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.025755882 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.025832891 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.025861025 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.025887012 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.025890112 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.025914907 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.025921106 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.025955915 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.025978088 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.025983095 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.026005030 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.026031971 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.026032925 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.026057959 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.026077032 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.026103973 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.026103973 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.026130915 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.026154995 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.026200056 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.026212931 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.026262999 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.026268005 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.026325941 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.026326895 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.026357889 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.026391983 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.026421070 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.026428938 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.026483059 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.026484013 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.026544094 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.026576996 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.026603937 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.026633978 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.026638031 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.026679993 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.026693106 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.026705980 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.026740074 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.026746988 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.026783943 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.026798964 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.026845932 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.026851892 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.026873112 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.026915073 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.030553102 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.030607939 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.030849934 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.030908108 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.032552004 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.032608986 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.032659054 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.032712936 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.032733917 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.032783985 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.032783985 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.032814026 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.032867908 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.032877922 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.032906055 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.032928944 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.032954931 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.032955885 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.032984018 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.033005953 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.033030987 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.033042908 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.033057928 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.033085108 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.033088923 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.033111095 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.033114910 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.033138037 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.033157110 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.033168077 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.033184052 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.033210993 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.033216953 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.033237934 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.033245087 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.033265114 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.033268929 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.033291101 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.033292055 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.033313036 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.033334017 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.033340931 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.033369064 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.033395052 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.033399105 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.033421040 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.033447027 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.033448935 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.033474922 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.033487082 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.033509970 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.033521891 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.033529997 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.033548117 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.033575058 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.033576965 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.033601999 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.033628941 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.033652067 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.034918070 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.034981012 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.035021067 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.035080910 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.035087109 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.035119057 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.035136938 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.035182953 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.035231113 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.035233974 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.035285950 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.035296917 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.035342932 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.035355091 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.035392046 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.035392046 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.035424948 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.035459042 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.035487890 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.035490990 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.035517931 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.035537958 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.035561085 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.035640001 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.035667896 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.035691977 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.035715103 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.035729885 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.035757065 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.035780907 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.035793066 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.035804033 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.035839081 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.035847902 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.035887957 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.035906076 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.035932064 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.035955906 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.035980940 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.035993099 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.036019087 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.036041975 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.036068916 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.036098957 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.036125898 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.036151886 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.036175013 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.036179066 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.036201954 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.036226034 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.036257982 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.036308050 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.036334038 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.036362886 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.036381006 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.036387920 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.036412001 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.036427975 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.036457062 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.036513090 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.036540031 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.036562920 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.036588907 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.036603928 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.036631107 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.036652088 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.036674023 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.036680937 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.036720037 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.036732912 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.036772013 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.036775112 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.036820889 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.036827087 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.036878109 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.036885977 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.036912918 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.036938906 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.036977053 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.037008047 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.037034035 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.037065029 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.037071943 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.037091970 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.037122011 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.037127972 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.037148952 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.037172079 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.037180901 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.037198067 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.037228107 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.037229061 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.037259102 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.037278891 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.037302971 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.037306070 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.037338018 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.037354946 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.037383080 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.037405968 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.037435055 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.037460089 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.037484884 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.037491083 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.037514925 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.037537098 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.037560940 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.037561893 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.037592888 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.037609100 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.037641048 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.037676096 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.037702084 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.037739992 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.037766933 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.037794113 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.037818909 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.037842035 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.037847996 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.037868977 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.037892103 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.037914038 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.037919044 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.037945032 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.037966013 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.037991047 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.038741112 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.038769007 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.038795948 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.038813114 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.038821936 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.038868904 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.038880110 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.038930893 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.038950920 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.038978100 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.039006948 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.039033890 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.039119005 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.039145947 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.039175034 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.039212942 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.039237022 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.039263010 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.039289951 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.039309978 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.039335966 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.039351940 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.039362907 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.039406061 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.039429903 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.039457083 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.039495945 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.039505005 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.039536953 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.039554119 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.039582968 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.039625883 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.039653063 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.039675951 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.039684057 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.039700031 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.039732933 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.039747953 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.039794922 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.039817095 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.039861917 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.039870024 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.039922953 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.039926052 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.039968967 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.039997101 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.040039062 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.040049076 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.040066957 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.040091991 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.040112972 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.040115118 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.040139914 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.040160894 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.040186882 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.040204048 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.040230036 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.040273905 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.040276051 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.040302992 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.040319920 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.040333986 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.040344954 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.040383101 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.040390968 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.040416956 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.040436983 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.040460110 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.040465117 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.040498018 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.040544033 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.040546894 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.040576935 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.040594101 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.040625095 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.040633917 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.040656090 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.040677071 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.040702105 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.040704012 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.040760040 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.040787935 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.040819883 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.040842056 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.040863037 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.040868998 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.040919065 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.040942907 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.040997982 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.041019917 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.041047096 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.041074038 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.041100025 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.041121960 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.041148901 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.041177034 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.041194916 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.041202068 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.041220903 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.041244984 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.041268110 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.041349888 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.041403055 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.041405916 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.041456938 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.041467905 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.041495085 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.041522026 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.041527033 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.041555882 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.041558981 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.041582108 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.041606903 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.041624069 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.041651011 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.041676044 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.041698933 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.041699886 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.041731119 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.041745901 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.041779041 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.041779995 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.041810036 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.041831017 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.041857958 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.041862011 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.041908026 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.041924000 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.041950941 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.041970968 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.041999102 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.041999102 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.042031050 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.042047977 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.042078018 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.042088032 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.042131901 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.042140961 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.042167902 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.042190075 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.042198896 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.042212963 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.042247057 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.042262077 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.042296886 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.042309046 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.042335987 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.042361021 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.042382002 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.042387009 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.042407990 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.042434931 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.042439938 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.042460918 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.042485952 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.042486906 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.042538881 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.042548895 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.042581081 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.042606115 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.042639017 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.042643070 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.042692900 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.042694092 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.042746067 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.042923927 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.042952061 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.042973042 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.042996883 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.043029070 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.043077946 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.043080091 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.043128014 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.043145895 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.043173075 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.043193102 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.043221951 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.043236971 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.043263912 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.043287992 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.043312073 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.043364048 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.043390989 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.043418884 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.043426991 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.043442011 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.043473959 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.043476105 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.043524027 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.043540955 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.043569088 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.043592930 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.043625116 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.043636084 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.043663979 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.043708086 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.043711901 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.043742895 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.043767929 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.043792963 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.043797016 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.043823957 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.043838978 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.043867111 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.043905020 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.043931007 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.043955088 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.043962002 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.043977976 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.044008970 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.044030905 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.044071913 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.044073105 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.044099092 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.044126034 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.044145107 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.044157028 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.044172049 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.044200897 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.044203043 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.044226885 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.044249058 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.044250965 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.044280052 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.044295073 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.044326067 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.044332027 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.044373035 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.044409037 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.044435978 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.044457912 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.044492960 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.044501066 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.044528008 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.044548988 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.044574976 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.044578075 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.044609070 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.044626951 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.044658899 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.044703007 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.044729948 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.044751883 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.044781923 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.044867039 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.044894934 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.044924021 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.044943094 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.044950008 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.044969082 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.044992924 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.045005083 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.045021057 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.045053005 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.045084000 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.045097113 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.045131922 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.045152903 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.045191050 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.045195103 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.045221090 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.045245886 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.045268059 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.045270920 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.045299053 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.045329094 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.045353889 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.045375109 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.045424938 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.045425892 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.045473099 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.045496941 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.045523882 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.045545101 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.045567036 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.045569897 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.045599937 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.045628071 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.045660019 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.045664072 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.045713902 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.045727968 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.045772076 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.045778036 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.045818090 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.045820951 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.045870066 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.045893908 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.045943975 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.045954943 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.045999050 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.046004057 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.046046019 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.046053886 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.046097994 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.046108961 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.046134949 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.046164036 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.046190023 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.046216965 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.046243906 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.046266079 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.046289921 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.046309948 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.046336889 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.046356916 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.046384096 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.046384096 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.046415091 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.046442032 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.046473026 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.046494961 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.046520948 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.046542883 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.046552896 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.046566010 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.046593904 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.046602011 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.046633005 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.046659946 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.046694994 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.046695948 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.046741009 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.046747923 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.046792030 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.046802998 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.046857119 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.046865940 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.046892881 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.046920061 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:12.046936035 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.047002077 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.047032118 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.047065020 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.047369003 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.047454119 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.047580004 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.047624111 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.047668934 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.047736883 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.047821045 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.047847033 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.047895908 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.047923088 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.047970057 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.047996998 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.048027039 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.048053026 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.048110008 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.048140049 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.048217058 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.048254967 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.048300028 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.048413038 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.048679113 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.048851967 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.049138069 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.049212933 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.049455881 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.049587011 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.049596071 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.049690962 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.049700022 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.049798012 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.049968958 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.050142050 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.050206900 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.050322056 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.050420046 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.050435066 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.050494909 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.050753117 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.050762892 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.050868034 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.050877094 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.050915956 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.051021099 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.051035881 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.051100016 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.051245928 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.051534891 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.051635027 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.051651001 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.051702023 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.051800966 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.051956892 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.051990032 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.052081108 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.052134991 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.052227020 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.052253008 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.052313089 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.052320004 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.052460909 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.052469969 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.052478075 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.052510977 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.052613974 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.052622080 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.052700996 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.052707911 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.052789927 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.052825928 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.052894115 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.052901983 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.053028107 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.053035975 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.053090096 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.053129911 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.053222895 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.053253889 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.053381920 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.053396940 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.053489923 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.053504944 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.053611994 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.053643942 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.053729057 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.053742886 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.053822041 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.053878069 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.053987026 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.053994894 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.054045916 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.054078102 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.054168940 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.054200888 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.054302931 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.054311037 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.054367065 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.054398060 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.054558992 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.054565907 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.054626942 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.054677010 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.054747105 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.054754972 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.054893017 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.054900885 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.054935932 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.054999113 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.055056095 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.055071115 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.055169106 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.055176020 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.055255890 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.055269957 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.055370092 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.055383921 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.055450916 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.055490971 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.055536032 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.055567026 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.055624008 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.055674076 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.055721998 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.055753946 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.055809975 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.055888891 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.055938959 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.055953979 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.056018114 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.056049109 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.056102037 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.056133986 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.056243896 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.056251049 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.056341887 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.056349039 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.056402922 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.056418896 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.056477070 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.056529999 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.056596041 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.056652069 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.056766033 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.056773901 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.056787968 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.056832075 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.056905031 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.056915045 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.057028055 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.057037115 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.057090998 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.057140112 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.057233095 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.057240963 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.057305098 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.057312012 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.057401896 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.057420015 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.057538986 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.057619095 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.057626009 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.057632923 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.057681084 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.057712078 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.057764053 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.057780027 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.057853937 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.057861090 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.057919979 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.057960987 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.058027983 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.058034897 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.058099031 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.058105946 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.058176994 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.058185101 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.058239937 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.058290958 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.058351040 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.058358908 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.058407068 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.058415890 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.058515072 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.058522940 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.058590889 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.058598042 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.058657885 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.058695078 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.058743954 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.058775902 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.058860064 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.058867931 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.058916092 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.058929920 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059034109 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059041977 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059078932 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059097052 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059171915 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059181929 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059240103 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059256077 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059356928 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059365034 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059417963 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059426069 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059520960 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059529066 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059576988 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059608936 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059681892 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059689999 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059813976 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059822083 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059829950 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059844017 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059971094 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059978962 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059984922 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.059992075 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060113907 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060122013 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060128927 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060136080 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060240984 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060249090 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060255051 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060261965 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060270071 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060372114 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060379982 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060386896 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060394049 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060400963 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060488939 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060497046 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060503006 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060509920 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060610056 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060617924 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060625076 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060631990 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060729980 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060738087 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060744047 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060750961 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060873985 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060880899 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060888052 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.060889959 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061003923 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061012030 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061017990 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061024904 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061100960 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061108112 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061115026 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061117887 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061220884 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061228991 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061235905 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061242104 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061332941 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061341047 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061347008 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061353922 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061362028 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061469078 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061476946 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061482906 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061490059 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061496973 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061606884 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061614037 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061620951 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061628103 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061636925 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061644077 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061676025 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061686039 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061753988 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061781883 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061861038 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061870098 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061928988 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.061938047 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.062009096 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.062017918 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.062144995 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.062153101 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.062196970 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.062227964 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.062272072 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.062304974 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.062366962 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.062374115 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.062423944 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.062431097 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.062520027 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.062527895 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.062575102 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.062606096 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.062654972 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.062669992 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.062724113 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.062772036 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.062818050 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.062833071 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.062906981 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.062913895 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.062958956 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.063014030 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.063083887 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.063091040 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.063123941 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.063138008 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.063194036 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.063235044 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.063293934 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.063308954 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.063369036 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.063401937 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.063458920 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.063472986 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.063524961 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.063539028 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.063631058 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.063644886 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.063703060 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.063749075 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.063823938 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.063832045 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.063879967 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.063895941 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.063958883 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.063972950 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.064080954 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.064088106 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.064127922 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.064142942 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.064246893 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.064254045 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.064287901 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.064302921 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.064418077 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.064424992 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.064466000 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:12.105180025 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:13.577146053 CET556154973745.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:13.578758955 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:13.583937883 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:13.584105015 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:13.584538937 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:13.589499950 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:13.622355938 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:13.935134888 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:13.940514088 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:13.940552950 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:13.940582037 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:13.940596104 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:13.940609932 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:13.940640926 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:13.940663099 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:13.940677881 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:13.940690041 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:13.940716982 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:13.940742970 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:13.940752029 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:13.940768957 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:13.940789938 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:13.940795898 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:13.940838099 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:13.945776939 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:13.945950031 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:13.945950985 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:13.946008921 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:13.946104050 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:13.946152925 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:13.946180105 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:13.946197987 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:13.946206093 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:13.946223021 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:13.946249008 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:13.992815018 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:13.993294954 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.040852070 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.040936947 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.088942051 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.089004040 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.140853882 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.140950918 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.172996044 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.173157930 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.178281069 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.178308964 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.178345919 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.178364992 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.178421974 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.178448915 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.178498983 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.178543091 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.178570032 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.178594112 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.178621054 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.178647995 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.178694963 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.178697109 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.178792000 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.178956985 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.179004908 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.179007053 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.179065943 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.179164886 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.179193020 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.179239988 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.179292917 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.179341078 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.179387093 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.179439068 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.179462910 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.179514885 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.179517984 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.179575920 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.179646969 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.179692030 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.179707050 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.179752111 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.179775000 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.179826021 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.179883003 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.179938078 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.179979086 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.180011034 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.180068016 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.180104971 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.180166960 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.180303097 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.180331945 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.180362940 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.180381060 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.180404902 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.183491945 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.183543921 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.183631897 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.183682919 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.183736086 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.183805943 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.183844090 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.183887959 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.183895111 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.183954000 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.184004068 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.184071064 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.184119940 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.184217930 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.184271097 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.184314013 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.184357882 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.184401035 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.184453011 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.184478045 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.184525967 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.184534073 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.184577942 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.184637070 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.184670925 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.184715033 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.184747934 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.184823036 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.184879065 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.184962988 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.185010910 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.185064077 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.185091972 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.185116053 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.185122967 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.185144901 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.185179949 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.185236931 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.185264111 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.185285091 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.185290098 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.185313940 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.185337067 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.185338974 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.185364008 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.185384035 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.185412884 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.185417891 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.185440063 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.185463905 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.185486078 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.185487986 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.185513020 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.185545921 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.185560942 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.185564041 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.185589075 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.185615063 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.185633898 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.185645103 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.185664892 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.185692072 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.185694933 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.185739994 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.185767889 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.185775995 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.185797930 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.185801029 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.185818911 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.185859919 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.185862064 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.185889006 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.185920000 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.185939074 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.185966969 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.185970068 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.185993910 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.186012983 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.186041117 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.186045885 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.186068058 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.186088085 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.186115980 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.186125040 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.186142921 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.186165094 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.186189890 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.186193943 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.186216116 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.186242104 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.186256886 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.186263084 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.186289072 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.186311960 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.186315060 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.186336994 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.186346054 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.186362982 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.186395884 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.186409950 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.186435938 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.186466932 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.186491966 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.186492920 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.186517954 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.186542034 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.186547041 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.186570883 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.186589956 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.186619043 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.186625004 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.186645985 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.186661005 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.186693907 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.186702967 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.186721087 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.186763048 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.186765909 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.186793089 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.186815023 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.186842918 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.188494921 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.188519001 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.188559055 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.188595057 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.188770056 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.188781977 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.188822031 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.188852072 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.188863993 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.188909054 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.188970089 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.188982010 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.189028025 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.189042091 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.189047098 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.189090967 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.189138889 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.189156055 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.189188957 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.189230919 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.189232111 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.189279079 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.189282894 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.189356089 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.189373016 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.189382076 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.189412117 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.189444065 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.189452887 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.189466000 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.189495087 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.189502001 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.189536095 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.189546108 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.189593077 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.189614058 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.189625025 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.189683914 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.189712048 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.189724922 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.189739943 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.189762115 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.189781904 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.189805984 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.189831018 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.189846039 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.189867973 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.189898968 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.189909935 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.189924955 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.189964056 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.190038919 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.190051079 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.190073967 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.190085888 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.190124989 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.190129995 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.190176964 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.190685987 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.190737009 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.191170931 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.191358089 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.191663027 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.191685915 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.191719055 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.191730976 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.191742897 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.191767931 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.191788912 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.191807032 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.191817999 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.191896915 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.191900015 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.191943884 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.191947937 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.191960096 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.191987991 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.191992044 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.192053080 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.192059040 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.192074060 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.192127943 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.192179918 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.192194939 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.192240000 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.192251921 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.192291021 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.192292929 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.192343950 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.192382097 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.192403078 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.192435980 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.192470074 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.192517996 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.192569971 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.192580938 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.192617893 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.192661047 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.192675114 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.192712069 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.192750931 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.192785978 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.192810059 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.192842960 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.192878008 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.192897081 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.192997932 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193010092 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193057060 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.193068981 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193090916 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193104029 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193114996 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193120003 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.193171978 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.193201065 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193212986 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193253040 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.193257093 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193276882 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193289995 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193324089 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193340063 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.193368912 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193383932 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.193398952 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193423033 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.193449974 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.193471909 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193483114 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193535089 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193537951 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.193584919 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.193614006 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193625927 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193641901 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193662882 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.193702936 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.193746090 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193757057 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193789959 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193800926 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193802118 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.193837881 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.193860054 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.193865061 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193876982 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193945885 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.193949938 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193962097 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193975925 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.193999052 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.194005013 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.194031000 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.194053888 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.194060087 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.194083929 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.194118023 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.194139957 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.194140911 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.194152117 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.194205999 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.194233894 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.194247007 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.194299936 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.194330931 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.194344044 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.194376945 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.194391012 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.194400072 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.194422007 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.194452047 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.194485903 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.194499969 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.194510937 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.194540024 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.194566965 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.194585085 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.194591045 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.194643021 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.194653034 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.194700956 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.194708109 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.194744110 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.194755077 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.194756985 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.194827080 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.194835901 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.194859028 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.194916010 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.194960117 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.194972038 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.195024967 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.195075989 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.195154905 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.195157051 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.195167065 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.195190907 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.195202112 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.195228100 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.195269108 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.195272923 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.195283890 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.195332050 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.195343018 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.195354939 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.195379972 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.195419073 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.195427895 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.195440054 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.195461035 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.195472956 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.195475101 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.195496082 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.195518017 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.195554018 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.195580959 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.195595026 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.195641994 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.195658922 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.195671082 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.195724964 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.195749044 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.195804119 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.195827007 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.195836067 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.195847988 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.195847034 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.195900917 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.195909977 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.195935011 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196001053 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.196012020 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196023941 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196050882 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196062088 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196074963 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.196115971 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.196125984 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196141005 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196187019 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.196194887 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196207047 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196248055 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196268082 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.196274996 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196307898 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.196338892 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.196365118 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196377039 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196432114 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.196454048 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196468115 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196494102 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.196522951 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196536064 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.196563959 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196609974 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.196654081 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196666002 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196687937 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196698904 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196707964 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.196728945 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.196757078 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.196816921 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196830034 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196882963 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.196887970 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196899891 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196907043 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.196928024 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.196964979 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.196976900 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.196990013 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.197025061 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.197041988 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.197046995 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.197056055 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.197110891 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.197113037 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.197153091 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.197177887 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.197207928 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.197247982 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.197278976 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.197299004 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.197336912 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.197341919 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.197354078 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.197390079 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.197424889 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.197484016 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.197495937 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.197551966 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.197561026 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.197573900 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.197612047 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.197623968 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.197637081 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.197679043 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.197698116 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.197704077 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.197726965 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.197767019 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.197829962 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.197841883 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.197885036 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.197887897 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.197896957 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.197941065 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.197962046 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.197990894 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.198043108 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.198054075 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.198065042 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.198122025 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.198122978 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.198164940 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.198175907 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.198216915 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.198230028 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.198240995 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.198261023 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.198287010 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.198303938 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.198314905 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.198347092 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.198348045 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.198393106 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.198406935 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.198445082 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.198489904 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.198502064 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.198554993 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.198568106 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.198602915 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.198610067 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.198649883 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.198668957 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.198699951 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.198710918 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.198771000 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.198771000 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.198782921 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.198838949 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.198914051 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.198951006 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.198960066 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.198964119 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.198976994 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.199016094 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.199024916 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.199038982 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.199095964 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.199120998 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.199132919 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.199171066 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.199182034 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.199182034 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.199233055 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:14.199274063 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.199287891 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.199357986 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.199415922 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.199486017 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.199496984 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.199608088 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.199619055 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.199631929 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.199671984 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.199740887 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.199752092 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.199851036 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.199863911 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.199877024 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.199912071 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.200016975 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.200028896 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.200042963 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.200102091 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.200176001 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.200186968 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.200244904 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.200256109 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.200347900 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.200391054 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.200433016 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.200474977 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.200515032 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.200584888 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.200634003 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.200645924 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.200728893 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.200742960 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.200855017 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.200865984 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.200911045 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.200953960 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.201025009 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.201037884 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.201102972 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.201114893 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.201162100 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.201194048 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.201262951 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.201283932 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.201400995 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.201411963 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.201426029 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.201447964 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.201559067 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.201570988 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.201637030 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.201709986 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.201720953 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.201735973 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.201829910 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.201842070 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.201884031 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.201951981 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.202003002 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.202025890 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.202126026 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.202152967 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.202167034 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.202214956 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.202315092 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.202327013 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.202363968 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.202385902 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.202466011 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.202487946 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.202558041 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.202600002 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.202663898 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.202675104 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.202738047 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.202759027 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.202812910 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.202924967 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.202935934 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.203097105 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.203109026 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.203219891 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.203232050 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.203263044 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.203284979 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.203344107 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.203355074 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.203461885 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.203474045 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.203507900 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.203563929 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.203665018 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.203788042 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.203807116 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.203819036 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.203869104 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.203880072 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.203958988 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.203970909 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204039097 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204050064 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204114914 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204125881 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204169035 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204180956 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204229116 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204240084 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204308987 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204319954 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204360962 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204411983 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204476118 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204488039 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204555035 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204566956 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204600096 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204612017 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204668045 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204679012 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204772949 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204785109 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204830885 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204842091 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204886913 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204907894 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.204998970 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205010891 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205117941 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205128908 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205169916 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205180883 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205230951 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205241919 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205308914 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205321074 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205369949 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205380917 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205425024 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205436945 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205504894 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205516100 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205566883 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205578089 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205631018 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205642939 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205714941 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205725908 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205739021 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205791950 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205847025 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205890894 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205940962 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.205951929 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206003904 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206015110 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206054926 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206075907 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206156015 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206167936 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206212044 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206223011 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206310034 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206321001 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206370115 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206382036 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206428051 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206501961 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206512928 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206526041 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206567049 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206610918 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206686974 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206697941 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206743956 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206756115 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206789970 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206865072 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206876993 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.206888914 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.207231998 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.207243919 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.207659960 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.207672119 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.207922935 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.207933903 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.208002090 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.208044052 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.208106995 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.208118916 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.208164930 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.208177090 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.208252907 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.208264112 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.208314896 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.208374023 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.208444118 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.208456039 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.208513975 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.208524942 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.208583117 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.208595037 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.208628893 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.208650112 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.208730936 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.208775043 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.208856106 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.208867073 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.208918095 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.208929062 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209000111 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209011078 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209067106 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209079027 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209183931 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209194899 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209248066 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209259033 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209312916 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209323883 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209364891 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209377050 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209414959 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209435940 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209547997 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209559917 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209573030 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209634066 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209646940 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209686995 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209739923 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209772110 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209785938 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209796906 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209876060 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209887981 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209960938 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.209973097 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210031033 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210042953 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210104942 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210117102 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210160017 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210181952 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210264921 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210285902 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210331917 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210371971 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210432053 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210443974 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210486889 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210498095 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210553885 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210566044 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210616112 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210627079 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210660934 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210695982 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210767031 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210778952 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210855961 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210867882 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210920095 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210978985 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.210994005 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211042881 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211116076 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211127043 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211167097 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211213112 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211270094 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211282015 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211337090 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211420059 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211431980 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211442947 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211482048 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211493969 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211566925 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211577892 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211658001 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211707115 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211719036 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211775064 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211786032 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211854935 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211867094 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211914062 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211925030 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211937904 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.211976051 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212034941 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212045908 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212084055 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212129116 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212178946 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212189913 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212256908 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212268114 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212287903 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212299109 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212349892 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212362051 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212382078 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212393045 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212445974 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212457895 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212469101 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212490082 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212501049 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212512970 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212532997 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212543964 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212554932 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212567091 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212587118 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212598085 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212619066 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212629080 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212649107 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212661028 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212681055 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212692022 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212704897 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212744951 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212779999 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212806940 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212829113 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212842941 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212862015 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212872982 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212883949 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212894917 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212914944 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212925911 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212946892 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212959051 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.212970972 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:14.256872892 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:15.467576981 CET556154973845.137.22.126192.168.2.4
                                                                                                                                            Nov 17, 2024 03:07:15.528460026 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:15.595179081 CET4973755615192.168.2.445.137.22.126
                                                                                                                                            Nov 17, 2024 03:07:15.595650911 CET4973855615192.168.2.445.137.22.126
                                                                                                                                            TimestampSource PortDest PortSource IPDest IP
                                                                                                                                            Nov 17, 2024 03:07:08.826909065 CET5284453192.168.2.41.1.1.1
                                                                                                                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                                                                            Nov 17, 2024 03:07:08.826909065 CET192.168.2.41.1.1.10x5ba4Standard query (0)api.ip.sbA (IP address)IN (0x0001)false