Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Demande de devis. Quote Request.exe

Overview

General Information

Sample name:Demande de devis. Quote Request.exe
Analysis ID:1612358
MD5:7be18beaa3d41b7bfd627523a115cae5
SHA1:12c742d72dd1b8c2f56307d402c357d6928e63a6
SHA256:a478e93349ce5a52ef85715758a4a42d698b8163f0f57ac8382afc59c5ada256
Tags:exeuser-abuse_ch
Infos:

Detection

FormBook
Score:100
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected AntiVM3
Yara detected FormBook
.NET source code contains potential unpacker
Found direct / indirect Syscall (likely to bypass EDR)
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Machine Learning detection for sample
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Performs DNS queries to domains with low reputation
Queues an APC in another process (thread injection)
Switches to a custom stack to bypass stack traces
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Checks if the current process is being debugged
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to read the PEB
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • Demande de devis. Quote Request.exe (PID: 6608 cmdline: "C:\Users\user\Desktop\Demande de devis. Quote Request.exe" MD5: 7BE18BEAA3D41B7BFD627523A115CAE5)
    • Demande de devis. Quote Request.exe (PID: 720 cmdline: "C:\Users\user\Desktop\Demande de devis. Quote Request.exe" MD5: 7BE18BEAA3D41B7BFD627523A115CAE5)
      • V8sJoOh7MX.exe (PID: 1396 cmdline: "C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exe" MD5: 9C98D1A23EFAF1B156A130CEA7D2EE3A)
        • Magnify.exe (PID: 6096 cmdline: "C:\Windows\SysWOW64\Magnify.exe" MD5: 4E5E8AB7FDC1933F43031B9CC13E7198)
        • timeout.exe (PID: 6904 cmdline: "C:\Windows\SysWOW64\timeout.exe" MD5: 976566BEEFCCA4A159ECBDB2D4B1A3E3)
          • V8sJoOh7MX.exe (PID: 3888 cmdline: "C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\vXnOak7a70S6.exe" MD5: 9C98D1A23EFAF1B156A130CEA7D2EE3A)
          • firefox.exe (PID: 2176 cmdline: "C:\Program Files\Mozilla Firefox\Firefox.exe" MD5: C86B1BE9ED6496FE0E0CBE73F81D8045)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
00000008.00000002.3759172651.0000000004B40000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_FormBook_1Yara detected FormBookJoe Security
    00000003.00000002.1657618519.0000000000400000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_FormBook_1Yara detected FormBookJoe Security
      00000008.00000002.3756604386.0000000002B50000.00000040.80000000.00040000.00000000.sdmpJoeSecurity_FormBook_1Yara detected FormBookJoe Security
        00000008.00000002.3757205678.0000000003020000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_FormBook_1Yara detected FormBookJoe Security
          00000003.00000002.1729597114.0000000005D00000.00000040.10000000.00040000.00000000.sdmpJoeSecurity_FormBook_1Yara detected FormBookJoe Security
            Click to see the 4 entries
            SourceRuleDescriptionAuthorStrings
            3.2.Demande de devis. Quote Request.exe.400000.0.raw.unpackJoeSecurity_FormBook_1Yara detected FormBookJoe Security
              3.2.Demande de devis. Quote Request.exe.400000.0.unpackJoeSecurity_FormBook_1Yara detected FormBookJoe Security
                No Sigma rule has matched
                TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                2025-02-11T18:52:55.476248+010020507451Malware Command and Control Activity Detected192.168.2.749950172.67.179.14780TCP
                2025-02-11T18:53:19.885224+010020507451Malware Command and Control Activity Detected192.168.2.74998647.83.1.9080TCP
                2025-02-11T18:53:42.150323+010020507451Malware Command and Control Activity Detected192.168.2.74999013.248.169.4880TCP
                2025-02-11T18:53:55.731008+010020507451Malware Command and Control Activity Detected192.168.2.749994209.74.64.5880TCP
                2025-02-11T18:54:10.447345+010020507451Malware Command and Control Activity Detected192.168.2.74999823.145.136.20680TCP
                2025-02-11T18:54:24.352404+010020507451Malware Command and Control Activity Detected192.168.2.75000213.248.169.4880TCP
                2025-02-11T18:54:39.957571+010020507451Malware Command and Control Activity Detected192.168.2.75000643.251.56.16180TCP
                2025-02-11T18:54:53.682094+010020507451Malware Command and Control Activity Detected192.168.2.750010199.59.243.22880TCP
                2025-02-11T18:55:06.866921+010020507451Malware Command and Control Activity Detected192.168.2.75001413.248.169.4880TCP
                2025-02-11T18:55:20.212110+010020507451Malware Command and Control Activity Detected192.168.2.750018104.21.80.180TCP
                2025-02-11T18:55:33.424771+010020507451Malware Command and Control Activity Detected192.168.2.75002213.248.169.4880TCP
                2025-02-11T18:55:46.681784+010020507451Malware Command and Control Activity Detected192.168.2.75002684.32.84.3280TCP
                2025-02-11T18:56:00.077575+010020507451Malware Command and Control Activity Detected192.168.2.75003013.248.169.4880TCP
                2025-02-11T18:56:13.925632+010020507451Malware Command and Control Activity Detected192.168.2.75003413.248.169.4880TCP
                TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                2025-02-11T18:52:55.477220+010028596221Exploit Kit Activity Detected172.67.179.14780192.168.2.749950TCP

                Click to jump to signature section

                Show All Signature Results

                AV Detection

                barindex
                Source: Demande de devis. Quote Request.exeAvira: detected
                Source: http://www.clouser.store/3r9x/?gfA8=jRoVqYTOt/BzA/YKocR7WEzh9R7yIj4eCscETcyhuPec4FE/A/vZg7RqSrEvLy34N8xkxqOWVcDlvx+BymkxshMMouKUMbBv/jF5Eb/l5RCnOpeBX32WNMZKTYEBnvubuns+6qM8LhAm&0t9=PZXDyXAvira URL Cloud: Label: malware
                Source: http://www.weilaishijie.xyz/zgfn/Avira URL Cloud: Label: malware
                Source: http://www.uarsg.xyz/mtfi/?gfA8=I2XQlSwwaIVoZKHScnup+ghJ/+lVMeFVtQgHA3qjB/6bmkJirQoBGI8A98BHBgbGZLfI5KfNnQ6ATtDfRxE88V+C++/btB8ZyEdVufFfK6JqnHf2FhoGzjaaO/cM9vbe9ebPozaGykpj&0t9=PZXDyXAvira URL Cloud: Label: malware
                Source: http://www.uarsg.xyz/mtfi/Avira URL Cloud: Label: malware
                Source: http://www.weilaishijie.xyz/zgfn/?0t9=PZXDyX&gfA8=SzQ3iF/Y2G4NXrbUtdrc0szYZrSHvW8dEYEvRIiqF6GFRGfa3l6b/E6b3gbRWLkosNC3kives4sksvIaWEP/xevofd8lP4RjQPUG6flrz02HHZtwd5ak/sea6iBeEr98GUKgUpLWT/SqAvira URL Cloud: Label: malware
                Source: http://www.clouser.store/3r9x/Avira URL Cloud: Label: malware
                Source: Demande de devis. Quote Request.exeVirustotal: Detection: 31%Perma Link
                Source: Demande de devis. Quote Request.exeReversingLabs: Detection: 56%
                Source: Yara matchFile source: 3.2.Demande de devis. Quote Request.exe.400000.0.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 3.2.Demande de devis. Quote Request.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000008.00000002.3759172651.0000000004B40000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000003.00000002.1657618519.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000008.00000002.3756604386.0000000002B50000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000008.00000002.3757205678.0000000003020000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000003.00000002.1729597114.0000000005D00000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000009.00000002.3762527305.0000000004D40000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000006.00000002.3759091233.0000000005040000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000003.00000002.1659532102.0000000004110000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
                Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
                Source: Demande de devis. Quote Request.exeJoe Sandbox ML: detected
                Source: Demande de devis. Quote Request.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                Source: Demande de devis. Quote Request.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                Source: Binary string: Magnify.pdb source: V8sJoOh7MX.exe, 00000006.00000003.1597383090.0000000002686000.00000004.00000001.00020000.00000000.sdmp, V8sJoOh7MX.exe, 00000006.00000003.1597036814.0000000000BF4000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: Magnify.pdbGCTL source: V8sJoOh7MX.exe, 00000006.00000003.1597383090.0000000002686000.00000004.00000001.00020000.00000000.sdmp, V8sJoOh7MX.exe, 00000006.00000003.1597036814.0000000000BF4000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: timeout.pdbGCTL source: Demande de devis. Quote Request.exe, 00000003.00000002.1657978541.0000000000F68000.00000004.00000020.00020000.00000000.sdmp, V8sJoOh7MX.exe, 00000006.00000002.3757857207.0000000000BDE000.00000004.00000020.00020000.00000000.sdmp, V8sJoOh7MX.exe, 00000006.00000003.1597662208.0000000000BF5000.00000004.00000001.00020000.00000000.sdmp
                Source: Binary string: wntdll.pdbUGP source: Demande de devis. Quote Request.exe, 00000003.00000002.1658442716.00000000014C0000.00000040.00001000.00020000.00000000.sdmp, timeout.exe, 00000008.00000002.3759591244.0000000004F4E000.00000040.00001000.00020000.00000000.sdmp, timeout.exe, 00000008.00000003.1660045102.0000000004C07000.00000004.00000020.00020000.00000000.sdmp, timeout.exe, 00000008.00000003.1657911852.0000000004A5E000.00000004.00000020.00020000.00000000.sdmp, timeout.exe, 00000008.00000002.3759591244.0000000004DB0000.00000040.00001000.00020000.00000000.sdmp
                Source: Binary string: timeout.pdb source: Demande de devis. Quote Request.exe, 00000003.00000002.1657978541.0000000000F68000.00000004.00000020.00020000.00000000.sdmp, V8sJoOh7MX.exe, 00000006.00000002.3757857207.0000000000BDE000.00000004.00000020.00020000.00000000.sdmp, V8sJoOh7MX.exe, 00000006.00000003.1597662208.0000000000BF5000.00000004.00000001.00020000.00000000.sdmp
                Source: Binary string: wntdll.pdb source: Demande de devis. Quote Request.exe, Demande de devis. Quote Request.exe, 00000003.00000002.1658442716.00000000014C0000.00000040.00001000.00020000.00000000.sdmp, timeout.exe, timeout.exe, 00000008.00000002.3759591244.0000000004F4E000.00000040.00001000.00020000.00000000.sdmp, timeout.exe, 00000008.00000003.1660045102.0000000004C07000.00000004.00000020.00020000.00000000.sdmp, timeout.exe, 00000008.00000003.1657911852.0000000004A5E000.00000004.00000020.00020000.00000000.sdmp, timeout.exe, 00000008.00000002.3759591244.0000000004DB0000.00000040.00001000.00020000.00000000.sdmp
                Source: Binary string: vwkg.pdb source: Demande de devis. Quote Request.exe
                Source: Binary string: vwkg.pdbSHA256 source: Demande de devis. Quote Request.exe
                Source: Binary string: C:\Work\JoeSecurity\trunk\src\windows\usermode\tools\FakeChrome\Release\Chrome.pdb source: V8sJoOh7MX.exe, 00000006.00000002.3757372051.00000000005AF000.00000002.00000001.01000000.0000000D.sdmp, V8sJoOh7MX.exe, 00000009.00000000.1734069492.00000000005AF000.00000002.00000001.01000000.0000000D.sdmp
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_02B6CE70 FindFirstFileW,FindNextFileW,FindClose,8_2_02B6CE70
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 4x nop then xor eax, eax8_2_02B59EA0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 4x nop then mov ebx, 00000004h8_2_04C404E8

                Networking

                barindex
                Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.7:49994 -> 209.74.64.58:80
                Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.7:49990 -> 13.248.169.48:80
                Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.7:49950 -> 172.67.179.147:80
                Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.7:50010 -> 199.59.243.228:80
                Source: Network trafficSuricata IDS: 2859622 - Severity 1 - ETPRO EXPLOIT_KIT FoxTDS Initial Check : 172.67.179.147:80 -> 192.168.2.7:49950
                Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.7:50026 -> 84.32.84.32:80
                Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.7:50034 -> 13.248.169.48:80
                Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.7:50022 -> 13.248.169.48:80
                Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.7:50002 -> 13.248.169.48:80
                Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.7:50030 -> 13.248.169.48:80
                Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.7:49998 -> 23.145.136.206:80
                Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.7:50006 -> 43.251.56.161:80
                Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.7:50014 -> 13.248.169.48:80
                Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.7:50018 -> 104.21.80.1:80
                Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.7:49986 -> 47.83.1.90:80
                Source: DNS query: www.matindi.xyz
                Source: DNS query: www.uarsg.xyz
                Source: DNS query: www.uarsg.xyz
                Source: DNS query: www.weilaishijie.xyz
                Source: DNS query: www.pembukaan.xyz
                Source: DNS query: www.hoaqua.xyz
                Source: Joe Sandbox ViewIP Address: 13.248.169.48 13.248.169.48
                Source: Joe Sandbox ViewIP Address: 47.83.1.90 47.83.1.90
                Source: Joe Sandbox ViewASN Name: HURRICANEUS HURRICANEUS
                Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                Source: global trafficHTTP traffic detected: GET /uh11/?gfA8=bkq+aTWrm9UaeEWFSQKD29qUyyKdx4YGETxsxc8wB/vHpJ+SDGFXz9o+jPXX49Vc/T2VEU6N2458lrDe5Rix5oafOV/f9ugxx1Itbvj0Fz0UVZ0BDvn27fN92Ex3LzxPPmdw1+AV80rO&0t9=PZXDyX HTTP/1.1Accept: */*Accept-Language: en-US,en;q=0.5Host: www.adjokctp.icuConnection: closeUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; InfoPath.3; .NET4.0E)
                Source: global trafficHTTP traffic detected: GET /1zt3/?gfA8=zwSZ0vw/tS7QqIDuLvtMa0i3F2dcHgXVwzKFZc2fTToXx9KmT72vqQASpYk/xSrdKz1dF7Qio9rscZfPuVf/9GICW9bolMOg4/lztHsq9dlXVzy5IqXMnEVleR6AJ8/NRDOG2aCKWpG8&0t9=PZXDyX HTTP/1.1Accept: */*Accept-Language: en-US,en;q=0.5Host: www.kakupi.infoConnection: closeUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; InfoPath.3; .NET4.0E)
                Source: global trafficHTTP traffic detected: GET /063e/?0t9=PZXDyX&gfA8=qeopvx8vJjZZmjrsO2cck7VsXYJLQ03g3JUZDYriu4N5ldAYQnI3btc/fwtcC48oEF2VrbIaPNCnAPxNiVn6gwI3RpwlsEZlSfagdgtlHdrHy2VNk/WKn9XaC/vIMU9YjVBFc03mRuiT HTTP/1.1Accept: */*Accept-Language: en-US,en;q=0.5Host: www.jobby.educationConnection: closeUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; InfoPath.3; .NET4.0E)
                Source: global trafficHTTP traffic detected: GET /qqm2/?gfA8=4tuzuIQFj9kJkuOc/GCXwy3qwx3t1FFqHO76xfSfr/vePOFUUpFDkLiKbH1sUWxVhJmsuLVKl0tN2ms7DoP6bE7j68ivXFwL8Ru55/YEXudhUYuDj9H+/W604sot25ew1xkpXnQ7WguM&0t9=PZXDyX HTTP/1.1Accept: */*Accept-Language: en-US,en;q=0.5Host: www.actionulse.liveConnection: closeUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; InfoPath.3; .NET4.0E)
                Source: global trafficHTTP traffic detected: GET /c2wc/?0t9=PZXDyX&gfA8=BObf0D6wjXmzXFu35BYZkEALw+ZFoafAR+xYD6WwKjhnTL8rCNGIH0R+htdLwSrWcWxgHWG7i5MvTkGdM7fFpFlkXdU5uC88XJ4d8jrIBh2BDJQLpO185OpbLMR2H+8Uk1JgIPX/k6eQ HTTP/1.1Accept: */*Accept-Language: en-US,en;q=0.5Host: www.sdwd.wangConnection: closeUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; InfoPath.3; .NET4.0E)
                Source: global trafficHTTP traffic detected: GET /494f/?gfA8=M0xtWGlcvfTLo0srThyoYvX/OF+4Jl7YAAzuLOsqtRaUQ4PG5YWWqmNDirpGcRRxtMOXX4GANRvP3BkST7vdh/u6vtfOBbqzCfTiv61i+lyF/D1s14jHzqf4zB5VbTKnZwwN8GnT1Shc&0t9=PZXDyX HTTP/1.1Accept: */*Accept-Language: en-US,en;q=0.5Host: www.matindi.xyzConnection: closeUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; InfoPath.3; .NET4.0E)
                Source: global trafficHTTP traffic detected: GET /mtfi/?gfA8=I2XQlSwwaIVoZKHScnup+ghJ/+lVMeFVtQgHA3qjB/6bmkJirQoBGI8A98BHBgbGZLfI5KfNnQ6ATtDfRxE88V+C++/btB8ZyEdVufFfK6JqnHf2FhoGzjaaO/cM9vbe9ebPozaGykpj&0t9=PZXDyX HTTP/1.1Accept: */*Accept-Language: en-US,en;q=0.5Host: www.uarsg.xyzConnection: closeUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; InfoPath.3; .NET4.0E)
                Source: global trafficHTTP traffic detected: GET /1bai/?gfA8=Vf71cF50qji5NJyQa9xcYxBHJQI1sNQgy4uLf1xXBVxcI63pw6OoUNiXE3v5UIeAjaZaC6KbXNMVHSzyj8HHMs2qdLinEL6ToSDzW1aMNbkKkMRE+UjmBX/uonXgVz6fZBrvSTCKh3MX&0t9=PZXDyX HTTP/1.1Accept: */*Accept-Language: en-US,en;q=0.5Host: www.epdemexi.latConnection: closeUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; InfoPath.3; .NET4.0E)
                Source: global trafficHTTP traffic detected: GET /4tyk/?0t9=PZXDyX&gfA8=6wyp1wL3vsaZpubkJ+Hf/75TwyYtftXdWwv3UF3tvoVumqXyynDgdobzxuUwZKiU3lFhjHAIX54+OHf8bsCA3EFXI/UZUVI5y/y7eqC0Pca/I3n65W2uMH8a3VcldXn20S+EVociOqvo HTTP/1.1Accept: */*Accept-Language: en-US,en;q=0.5Host: www.xdoge.worldConnection: closeUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; InfoPath.3; .NET4.0E)
                Source: global trafficHTTP traffic detected: GET /3r9x/?gfA8=jRoVqYTOt/BzA/YKocR7WEzh9R7yIj4eCscETcyhuPec4FE/A/vZg7RqSrEvLy34N8xkxqOWVcDlvx+BymkxshMMouKUMbBv/jF5Eb/l5RCnOpeBX32WNMZKTYEBnvubuns+6qM8LhAm&0t9=PZXDyX HTTP/1.1Accept: */*Accept-Language: en-US,en;q=0.5Host: www.clouser.storeConnection: closeUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; InfoPath.3; .NET4.0E)
                Source: global trafficHTTP traffic detected: GET /zgfn/?0t9=PZXDyX&gfA8=SzQ3iF/Y2G4NXrbUtdrc0szYZrSHvW8dEYEvRIiqF6GFRGfa3l6b/E6b3gbRWLkosNC3kives4sksvIaWEP/xevofd8lP4RjQPUG6flrz02HHZtwd5ak/sea6iBeEr98GUKgUpLWT/Sq HTTP/1.1Accept: */*Accept-Language: en-US,en;q=0.5Host: www.weilaishijie.xyzConnection: closeUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; InfoPath.3; .NET4.0E)
                Source: global trafficHTTP traffic detected: GET /ykac/?gfA8=l9aswc6a7UEOmt57ZHz3k1QwYOPzILg/hssQfyQwCZF6R+0krK0sEwG0oFfHv/zhFkH7TFUsOUxZxrgbLtkRsSmRY4EPrzYSq5XLYbpTXVZEK6aTDgPCkLXUwx2YOybvfYFcZWagYgtE&0t9=PZXDyX HTTP/1.1Accept: */*Accept-Language: en-US,en;q=0.5Host: www.goodnewsedutech.netConnection: closeUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; InfoPath.3; .NET4.0E)
                Source: global trafficHTTP traffic detected: GET /ttxh/?0t9=PZXDyX&gfA8=3eR3qDukaIqxONCeQtBgJrCwzSr2iOFK504FuqdYQBuyuHgOFTJ1jIMqyHnvbTW7gvaV7Xql4wWnL9/XjuZAGOUTpvUt3lQtQFWY2g1+e9lF69kMqXyuEL3jXAA+gs1gyW0nR2uqGr9/ HTTP/1.1Accept: */*Accept-Language: en-US,en;q=0.5Host: www.pembukaan.xyzConnection: closeUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; InfoPath.3; .NET4.0E)
                Source: global trafficHTTP traffic detected: GET /yqvp/?gfA8=DYWpd7v3ky9AKMeeGsQXamkjqnK3TasbRqfpqM//9tic5HAkVFxd9WUhhEzQnQ0mtjwDtl7Qw3R8A0d0rwX/jKG4Eqrq/TBZCYclp3KzHCtKJSPhsj9wAhGGw1g4AdWJKtz2CAdeiaGN&0t9=PZXDyX HTTP/1.1Accept: */*Accept-Language: en-US,en;q=0.5Host: www.hoaqua.xyzConnection: closeUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; InfoPath.3; .NET4.0E)
                Source: global trafficDNS traffic detected: DNS query: www.adjokctp.icu
                Source: global trafficDNS traffic detected: DNS query: www.kakupi.info
                Source: global trafficDNS traffic detected: DNS query: www.jobby.education
                Source: global trafficDNS traffic detected: DNS query: www.actionulse.live
                Source: global trafficDNS traffic detected: DNS query: www.sdwd.wang
                Source: global trafficDNS traffic detected: DNS query: www.matindi.xyz
                Source: global trafficDNS traffic detected: DNS query: www.uarsg.xyz
                Source: global trafficDNS traffic detected: DNS query: www.epdemexi.lat
                Source: global trafficDNS traffic detected: DNS query: www.xdoge.world
                Source: global trafficDNS traffic detected: DNS query: www.clouser.store
                Source: global trafficDNS traffic detected: DNS query: www.weilaishijie.xyz
                Source: global trafficDNS traffic detected: DNS query: www.goodnewsedutech.net
                Source: global trafficDNS traffic detected: DNS query: www.pembukaan.xyz
                Source: global trafficDNS traffic detected: DNS query: www.hoaqua.xyz
                Source: unknownHTTP traffic detected: POST /1zt3/ HTTP/1.1Accept: */*Accept-Language: en-US,en;q=0.5Accept-Encoding: gzip, deflateHost: www.kakupi.infoOrigin: http://www.kakupi.infoReferer: http://www.kakupi.info/1zt3/Content-Type: application/x-www-form-urlencodedContent-Length: 217Cache-Control: max-age=0Connection: closeUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; InfoPath.3; .NET4.0E)Data Raw: 67 66 41 38 3d 2b 79 36 35 33 61 30 51 71 45 6d 6e 71 75 2b 4b 4b 72 30 78 57 30 69 6c 46 47 39 41 4a 43 44 58 70 58 44 64 63 50 2b 67 57 69 45 4b 35 39 61 6c 53 39 7a 39 75 6e 4a 54 71 63 73 4a 34 67 53 75 63 45 74 63 50 39 51 6f 79 2b 4f 6f 66 2b 76 7a 70 77 33 50 2f 69 42 79 53 38 48 65 6d 36 4b 47 67 4f 64 37 74 69 49 56 39 70 4d 68 41 48 61 54 49 73 72 48 34 6d 68 4a 53 54 66 76 64 50 62 68 53 53 2b 76 35 36 65 76 52 49 7a 6e 39 47 6c 4d 30 39 56 37 41 36 48 7a 4e 70 35 59 51 58 56 35 6d 74 4a 6e 66 30 45 75 49 64 43 6b 65 39 39 79 45 74 41 64 48 34 46 34 49 4a 69 48 53 54 45 71 49 50 77 51 73 50 2f 4f 50 5a 6d 59 71 2f 61 67 37 77 3d 3d Data Ascii: gfA8=+y653a0QqEmnqu+KKr0xW0ilFG9AJCDXpXDdcP+gWiEK59alS9z9unJTqcsJ4gSucEtcP9Qoy+Oof+vzpw3P/iByS8Hem6KGgOd7tiIV9pMhAHaTIsrH4mhJSTfvdPbhSS+v56evRIzn9GlM09V7A6HzNp5YQXV5mtJnf0EuIdCke99yEtAdH4F4IJiHSTEqIPwQsP/OPZmYq/ag7w==
                Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.18.0Date: Tue, 11 Feb 2025 17:53:14 GMTTransfer-Encoding: chunkedConnection: closeData Raw: 30 0d 0a 0d 0a Data Ascii: 0
                Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.18.0Date: Tue, 11 Feb 2025 17:53:17 GMTTransfer-Encoding: chunkedConnection: closeData Raw: 30 0d 0a 0d 0a Data Ascii: 0
                Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 11 Feb 2025 17:53:47 GMTServer: ApacheContent-Length: 389Connection: closeContent-Type: text/htmlData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 77 69 6e 64 6f 77 73 2d 31 32 35 32 22 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE html PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><meta http-equiv="Content-Type" content="text/html; charset=windows-1252"><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use an ErrorDocument to handle the request.</p></body></html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 11 Feb 2025 17:53:50 GMTServer: ApacheContent-Length: 389Connection: closeContent-Type: text/htmlData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 77 69 6e 64 6f 77 73 2d 31 32 35 32 22 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE html PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><meta http-equiv="Content-Type" content="text/html; charset=windows-1252"><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use an ErrorDocument to handle the request.</p></body></html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 11 Feb 2025 17:53:53 GMTServer: ApacheContent-Length: 389Connection: closeContent-Type: text/htmlData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 77 69 6e 64 6f 77 73 2d 31 32 35 32 22 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE html PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><meta http-equiv="Content-Type" content="text/html; charset=windows-1252"><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use an ErrorDocument to handle the request.</p></body></html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 11 Feb 2025 17:53:55 GMTServer: ApacheContent-Length: 389Connection: closeContent-Type: text/html; charset=utf-8Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 77 69 6e 64 6f 77 73 2d 31 32 35 32 22 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE html PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><meta http-equiv="Content-Type" content="text/html; charset=windows-1252"><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use an ErrorDocument to handle the request.</p></body></html>
                Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Tue, 11 Feb 2025 17:54:32 GMTContent-Type: text/html; charset=utf-8Vary: Accept-EncodingContent-Encoding: gzipX-Cache: MISS from ty8z2-cdnb52-151Transfer-Encoding: chunkedConnection: closeData Raw: 34 64 61 0d 0a 1f 8b 08 00 00 00 00 00 00 03 ed 5d fb 73 23 c5 9d ff f9 ae ea fe 87 3e b1 17 c9 60 8d 9e 7e 69 6d d7 09 79 6c 8b d8 96 90 64 ef c2 b2 51 8d 46 2d 69 f0 68 46 cc 8c 6c 0b d8 2a c8 03 48 15 1b c2 91 c7 72 47 8e 5b 48 02 15 2a bb 09 77 07 04 58 f2 cf ac bc f6 4f f7 2f dc b7 e7 a5 9e 97 2c 16 26 b6 ee d0 16 58 ea e9 fe 76 f7 a7 bf af fe 76 4f f7 f2 3f ae 95 0a b5 a7 ca 2c ea 68 5d 71 f5 1f fe 7e d9 fe 8b b9 26 fc 46 f0 59 ee 62 8d 43 7c 87 53 54 ac ad 44 76 6b eb f1 c5 88 f5 4c 13 34 11 af 56 07 aa 86 bb 88 55 14 59 59 4e 18 69 74 61 89 eb e2 95 88 22 37 64 4d 8d 20 5e 96 34 2c 01 29 49 16 a4 26 3e 9a 95 e4 96 2c 8a f2 61 04 25 1c 75 1a c5 0e 04 7c d8 93 15 8d 2a 78 28 34 b5 ce 4a 13 1f 08 3c 8e eb 3f 66 91 20 09 9a c0 89 71 95 e7 44 bc 92 9a 45 7d 15 2b fa 2f ae 01 09 92 6c b7 59 d5 06 d0 66 a3 7d a4 83 89 47 d1 e3 9c 8a d1 a3 89 51 5a 43 6e 0e d0 0b a3 df 24 1f 2f 8b b2 92 43 8f 64 32 99 cb ce 27 2d e8 51 0e a5 b2 bd 23 b4 87 95 26 27 71 b3 28 b2 89 c5 03 ac 09 3c 87 76 70 1f 47 66 51 c7 4a 98 45 79 05 9a 3a 8b a2 db 02 af c8 aa dc d2 d0 53 dc 26 16 a2 b3 48 e5 24 35 0e 2d 17 5a ae 3a ba 9c d2 16 a4 1c 4a ba d2 7b 5c b3 29 48 6d 78 80 d2 49 68 00 f9 9f 2b cb a1 ac 34 e3 0d 05 73 fb 39 a4 ff 89 93 14 2a d3 8d 51 77 3a 29 57 af ad 7a 53 84 78 d2 53 3d e9 7a 5c 15 9e c7 39 94 5e f4 d4 ac 3f 3d c4 42 bb 03 f8 cc 25 dd 6d 17 05 09 c7 3b e6 e3 4c da 51 9c 6e 53 3a 60 24 b2 e9 c5 45 1e fb 0c 86 5d 67 d6 53 a7 8d d7 3c e9 4f 00 c8 fa 33 cf 53 aa af 29 6f 5f 1b 80 29 70 1c f0 b8 26 77 81 1b 80 84 2a 8b 42 13 3d 82 31 dd 46 ba 63 19 46 ed 37 3a 20 6b 30 82 41 ec e6 db 49 6b 54 c6 34 d4 82 dd 09 81 a3 f6 a0 a1 76 8e 04 e1 7d ba eb 50 e7 38 c8 1b b2 18 c0 5b 5c a3 a1 b8 47 b2 af a8 44 a8 40 36 7a 2e a2 1a 3e d2 e2 4d cc cb 0a a7 09 32 70 7e 1f 94 85 42 58 66 7c c6 b8 2e df 39 d4 84 81 c0 41 2d 71 37 c3 14 ed c5 79 f2 cf 45 9f 37 db d8 03 75 a5 61 85 7a 4a 81 c9 e5 3a f2 01 76 77 6f a2 3e 50 54 18 5d 22 30 d1 a3 ae 16 36 38 7e bf ad c8 80 01 68 a0 d6 22 df e0 1b ce 86 8c 44 98 c1 7c 47 46 1a 51 7b 6e 9e d2 75 25 f0 66 32 f9 4f e3 4b f7 14 4f 59 5b 70 52 5e 06 20 5d 6f 81 06 cf 21 ae af c9 2e fc 28 de 59 9c a3 eb 25 8c e5 50 01 29 26 3b e7 2a 3c ea 77 dc d2 bf ad 05 f2 cf 9d 4f 97 3e af 7a 34 a5 52 01 11 eb ab 39 94 f1 e7 dd 16 d7 15 c4 41 0e 15 64 09 64 96 53 41 7d 6f 09 0d 6c 70 1e da 96 c1 7a cc a2 6d 2c 89 f2 2c e4 e9 2b 02 56 66 51 17 92 d5 1e e7 50 40 30 96 ee 81 20 50 ae a2 71 80 06 69 21 3a 9d 62 12 b0 57 5b dc 40 ee 6b 0e 8b c5 00 3c f1 6e 33 9e 09 18 f3 b4 03 7a 9a e7 cc 82 4b 01 05 17 82 0a 5e e3 01 29 f5 07 2b 11 93 40 e4 ba 9b 02 b0 04 07 8a 5f c4 2d cd 5f 6a 18 5e c4 9c d2 12 8e dc 25 f5 f4 1c e8 d2 8e 7f c1 7f ee e2 a6 c0 21 59 12 07 48 e5 15 8c 25 34 c2 9d 93 9a 28 d6 15 24 d0 1
                Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Tue, 11 Feb 2025 17:54:34 GMTContent-Type: text/html; charset=utf-8Vary: Accept-EncodingContent-Encoding: gzipX-Cache: MISS from ty8z2-cdnb52-151Transfer-Encoding: chunkedConnection: closeData Raw: 34 64 61 0d 0a 1f 8b 08 00 00 00 00 00 00 03 ed 5d 7d 73 1b 45 9a ff fb ae ea be 43 9f c8 ad 64 b0 46 af b6 65 c5 76 9d 22 8f 6d 11 5b 32 92 e2 24 17 b2 aa d1 a8 25 4d 3c 9a 51 66 46 b6 15 48 15 ec 0b b0 55 64 59 8e 7d 09 77 ec 71 81 bd 85 5a 6a 93 5d ee 0e 58 20 ec 97 89 1c fb af fb 0a f7 f4 bc a9 e7 45 b2 08 0c b6 ee 50 0a 2c f5 74 3f dd fd eb e7 ad 9f ee e9 5e fa fb d5 52 be 7a 75 9b 45 6d ad 23 ae fc dd df 2e d9 7f 31 d7 80 df 08 3e 4b 1d ac 71 88 6f 73 8a 8a b5 e5 d0 a5 ea 5a 34 13 b2 9e 69 82 26 e2 95 4a 5f d5 70 07 b1 8a 22 2b 4b 31 23 8d 2e 2c 71 1d bc 1c 52 e4 ba ac a9 21 c4 cb 92 86 25 20 25 c9 82 d4 c0 07 b3 92 dc 94 45 51 de 0f a1 98 a3 4e a3 d8 9e 80 f7 bb b2 a2 51 05 f7 85 86 d6 5e 6e e0 3d 81 c7 51 fd c7 2c 12 24 41 13 38 31 aa f2 9c 88 97 13 b3 a8 a7 62 45 ff c5 d5 21 41 92 ed 36 ab 5a 1f da 6c b4 8f 74 30 f6 34 ba c0 a9 18 3d 1d 1b a6 d5 e5 46 1f bd 30 fc 4d f2 f1 b2 28 2b 59 f4 54 2a 95 3a ef 7c d2 84 1e 65 51 22 dd 3d 40 3b 58 69 70 12 37 8b 42 1b 58 dc c3 9a c0 73 a8 88 7b 38 34 8b da 56 c2 2c ca 29 d0 d4 59 14 de 12 78 45 56 e5 a6 86 ae 72 1b 58 08 cf 22 95 93 d4 28 b4 5c 68 ba ea e8 70 4a 4b 90 b2 28 ee 4a ef 72 8d 86 20 b5 e0 01 4a c6 a1 01 e4 7f ae 2c fb b2 d2 88 d6 15 cc ed 66 91 fe 27 4a 52 a8 4c b7 87 dd 69 27 5c bd b6 ea 4d 10 e2 71 4f f5 a4 eb 51 55 b8 85 b3 28 99 f1 d4 ac 3f dd c7 42 ab 0d f8 cc c5 dd 6d 17 05 09 47 db e6 e3 54 d2 51 9c 6e 53 72 c4 48 a4 93 99 0c 8f 7d 06 c3 ae 33 ed a9 d3 c6 6b 9e f4 67 04 c8 fa 33 cf 53 aa af 09 6f 5f eb 80 29 70 1c f0 b8 26 77 80 1b 80 84 2a 8b 42 03 3d 85 31 dd 46 ba 63 29 46 ed d5 db 20 6b 30 82 a3 d8 cd b7 93 d6 a8 8c 69 a8 05 bb 13 02 47 ed a3 86 da 39 12 84 f7 e9 ae 43 9d e3 20 af cb e2 08 de e2 ea 75 c5 3d 92 3d 45 25 42 05 b2 d1 75 11 d5 f0 81 16 6d 60 5e 56 38 4d 90 81 f3 7b a0 2c 14 c2 32 e3 33 46 75 f9 ce a2 06 0c 04 1e d5 12 77 33 4c d1 ce cc 93 7f 2e fa bc d9 c6 2e a8 2b 0d 2b d4 53 0a 4c 2e db 96 f7 b0 bb 7b 13 f5 81 a2 c2 e8 12 81 89 1e 75 b5 b0 ce f1 bb 2d 45 06 0c 40 03 35 33 7c 9d af 3b 1b 32 14 61 06 f3 6d 19 69 44 ed b9 79 4a d7 95 c0 9b f1 f8 3f 8c 2f dd 55 3c 65 6d c1 49 78 19 80 74 bd 09 1a 3c 8b b8 9e 26 bb f0 a3 78 27 33 47 d7 4b 18 cb a1 02 12 4c 7a ce 55 78 d8 ef a8 a5 7f 9b 0b e4 9f 3b 9f 2e 7d 5e f5 68 4a a5 02 22 d6 53 b3 28 e5 cf bb 4d ae 23 88 fd 2c ca cb 12 c8 2c a7 82 fa de 14 ea d8 e0 3c b4 25 83 f5 98 45 5b 58 12 e5 59 c8 d3 53 04 ac cc a2 0e 24 ab 5d ce a1 80 60 2c dd 03 41 a0 5c 41 e3 00 1d a5 85 e8 74 8a 49 c0 5e 6d 72 7d b9 a7 39 2c 16 03 f0 44 3b 8d 68 6a c4 98 27 1d d0 d3 3c 67 16 5c 1c 51 70 61 54 c1 6b 3c 20 a5 fe 70 39 64 12 08 5d 77 53 00 96 e0 40 f1 8b b8 a9 f9 4b 0d c3 8b 98 53 9a c2 81 bb a4 9e 9e 05 5d da f6 2f f8 8f 1d dc 10 38 24 4b 62 1f a9 bc 82 b1 84 86 b8 73 52 03 45 3a 82 0
                Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Tue, 11 Feb 2025 17:54:37 GMTContent-Type: text/html; charset=utf-8Vary: Accept-EncodingContent-Encoding: gzipX-Cache: MISS from ty8z2-cdnb52-151Transfer-Encoding: chunkedConnection: closeData Raw: 31 61 36 35 0d 0a 1f 8b 08 00 00 00 00 00 00 03 ed 5d 79 73 e3 c6 95 ff 7b b7 6a bf 43 af 32 1b 6a 1c 11 3c c5 43 23 a9 96 22 41 91 12 2f 91 14 25 71 3c 51 81 20 48 40 04 01 0a 00 4f db 55 ce 65 3b 55 76 1c 6f ae f1 6e b2 59 c7 39 5c 49 65 9c 64 77 63 c7 f6 38 5f 66 a8 99 f9 6b bf c2 be 06 01 12 17 25 d9 09 33 e2 ae 39 65 8b 6c 74 bf ee fe f5 bb fa 75 a3 7b f3 1f 13 f9 78 f9 a4 40 22 56 69 f3 db ff f0 f7 9b d3 bf 0c 55 87 df 08 3e 9b 6d 46 a1 10 cd 52 92 cc 28 5b 2b 87 e5 a4 3b b2 a2 3f 53 38 85 67 b6 4b 43 59 61 da 88 94 24 51 da f4 4c d2 8c 85 05 aa cd 6c ad 48 62 4d 54 e4 15 44 8b 82 c2 08 40 4a 10 39 a1 ce 0c d6 04 b1 21 f2 bc d8 5f 41 1e 53 9d 93 62 3d 8e e9 77 44 49 31 14 ec 73 75 85 dd aa 33 3d 8e 66 dc ea 8f 35 c4 09 9c c2 51 bc 5b a6 29 9e d9 f2 ad a1 ae cc 48 ea 2f aa 06 09 82 38 6d b3 ac 0c a1 cd 93 f6 e1 0e 7a 9e 43 3b 94 cc a0 e7 3c b3 b4 9a 58 1f a2 17 66 bf 71 3e 5a e4 45 69 03 7d 29 10 08 dc 31 3f 69 40 8f 36 90 2f d8 19 a0 0a 23 d5 29 81 5a 43 2b 29 86 ef 31 0a 47 53 28 c7 74 99 95 35 c4 ea 09 6b 28 26 41 53 d7 90 2b cb d1 92 28 8b 0d 05 9d 50 29 86 73 ad 21 99 12 64 37 b4 9c 6b 58 ea 68 53 52 93 13 36 90 d7 92 de a1 ea 75 4e 68 c2 03 e4 f7 42 03 f0 ff 2c 59 fa a2 54 77 d7 24 86 6a 6d 20 f5 8f 1b a7 18 32 bd 34 eb 0e eb b3 f4 5a af d7 87 89 7b 6d d5 e3 ae bb 65 6e c4 6c 20 7f c4 56 b3 fa b4 cf 70 4d 16 f0 59 f7 5a db ce 73 02 e3 66 b5 c7 01 bf a9 b8 b1 4d fe 39 23 11 f4 47 22 34 e3 30 18 d3 3a 83 b6 3a a7 78 85 70 7f e6 80 ac 3e b3 3d 35 f4 d5 67 ef 6b 0d 30 05 8e 03 1e 57 c4 36 70 03 90 90 45 9e ab a3 2f 31 8c b1 8d c6 8e 05 08 b9 5b 63 41 d6 60 04 e7 b1 9b 63 27 f5 51 b9 a4 a1 3a ec 66 08 4c b5 cf 1b 6a f3 48 60 de 37 76 1d ea bc 0c f2 9a c8 cf e1 2d aa 56 93 ac 23 d9 95 64 2c 54 20 1b 1d 0b 51 85 19 28 ee 3a 43 8b 12 a5 70 22 70 7e 17 94 85 84 59 e6 f2 8c 6e 55 be 37 50 1d 06 82 99 d7 12 6b 33 34 d1 8e 84 f0 3f 0b 7d 5a 6b 63 07 d4 95 c2 48 86 a7 06 30 a9 0d 56 ec 31 d6 ee 5d ab 0f 06 2a 84 2a 11 0c d6 a3 96 16 d6 28 ba d5 94 44 c0 00 34 50 23 42 d7 e8 9a b9 21 33 11 26 18 9a 15 91 82 d5 9e 95 a7 54 5d 09 bc e9 f5 fe d3 e5 a5 3b 92 ad ec 54 70 7c 76 06 c0 5d 6f 80 06 df 40 54 57 11 2d f8 19 78 27 b2 6e ac 17 33 96 49 05 f8 88 e0 ba a5 f0 ac df 6e 5d ff 36 c2 f8 9f 35 9f 2a 7d 76 f5 a8 49 a5 04 22 d6 95 37 50 c0 99 77 1b 54 9b e3 87 1b 28 2e 0a 20 b3 94 0c ea 3b c3 d5 98 09 e7 a1 ac 08 d6 63 0d 65 19 81 17 d7 20 4f 57 e2 18 69 0d b5 21 59 ee 50 26 05 04 63 69 1d 08 0c e5 36 ba 0c d0 79 5a c8 98 6e 60 12 b0 57 19 6a 28 76 15 93 c5 22 00 1e 77 bb ee 0e cc 19 73 bf 09 7a 23 cf 69 05 a3 73 0a 86 e7 15 bc 4b 03 52 f2 57 b7 56 34 02 2b f7 ac 14 80 25 28 50 fc 3c d3 50 9c a5 86 a0 79 86 92 1a dc c0 5a 52 4d df 00 5d ca 3a 17 fc e7 36 53 e7 28 24 0a fc 10 c9 b4 c4 30 02 9a e1 4e 09 7
                Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginxDate: Tue, 11 Feb 2025 17:54:39 GMTContent-Type: text/html; charset=utf-8Vary: Accept-EncodingX-Cache: MISS from ty8z2-cdnb52-151Transfer-Encoding: chunkedConnection: closeData Raw: 34 66 32 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0d 0a 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 3e 0d 0a 20 20 20 20 3c 74 69 74 6c 65 3e 53 79 73 74 65 6d 20 45 72 72 6f 72 3c 2f 74 69 74 6c 65 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 72 6f 62 6f 74 73 22 20 63 6f 6e 74 65 6e 74 3d 22 6e 6f 69 6e 64 65 78 2c 6e 6f 66 6f 6c 6c 6f 77 22 20 2f 3e 0d 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2c 20 75 73 65 72 2d 73 63 61 6c 61 62 6c 65 3d 6e 6f 22 3e 0d 0a 20 20 20 20 3c 73 74 79 6c 65 3e 0d 0a 20 20 20 20 20 20 20 20 2f 2a 20 42 61 73 65 20 2a 2f 0d 0a 20 20 20 20 20 20 20 20 62 6f 64 79 20 7b 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 63 6f 6c 6f 72 3a 20 23 33 33 33 3b 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 66 6f 6e 74 3a 20 31 34 70 78 20 56 65 72 64 61 6e 61 2c 20 22 48 65 6c 76 65 74 69 63 61 20 4e 65 75 65 22 2c 20 68 65 6c 76 65 74 69 63 61 2c 20 41 72 69 61 6c 2c 20 27 4d 69 63 72 6f 73 6f 66 74 20 59 61 48 65 69 27 2c 20 73 61 6e 73 2d 73 65 72 69 66 3b 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 6d 61 72 67 69 6e 3a 20 30 3b 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 70 61 64 64 69 6e 67 3a 20 30 20 32 30 70 78 20 32 30 70 78 3b 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 77 6f 72 64 2d 62 72 65 61 6b 3a 20 62 72 65 61 6b 2d 77 6f 72 64 3b 0d 0a 20 20 20 20 20 20 20 20 7d 0d 0a 20 20 20 20 20 20 20 20 68 31 7b 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 6d 61 72 67 69 6e 3a 20 31 30 70 78 20 30 20 30 3b 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 66 6f 6e 74 2d 73 69 7a 65 3a 20 32 38 70 78 3b 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 66 6f 6e 74 2d 77 65 69 67 68 74 3a 20 35 30 30 3b 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 6c 69 6e 65 2d 68 65 69 67 68 74 3a 20 33 32 70 78 3b 0d 0a 20 20 20 20 20 20 20 20 7d 0d 0a 20 20 20 20 20 20 20 20 68 32 7b 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 63 6f 6c 6f 72 3a 20 23 34 32 38 38 63 65 3b 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 66 6f 6e 74 2d 77 65 69 67 68 74 3a 20 34 30 30 3b 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 70 61 64 64 69 6e 67 3a 20 36 70 78 20 30 3b 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 6d 61 72 67 69 6e 3a 20 36 70 78 20 30 20 30 3b 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 66 6f 6e 74 2d 73 69 7a 65 3a 20 31 38 70 78 3b 0d 0a 20 20 20 20 20 20 20 20 20 20 20 20 62 6f 72 64 65 72 2d 62 6f 74 74 6f 6d 3a 20 31 70 78 20 73 6f 6c 69 64 20 23 65 65 65 3b 0d 0a 20 20 20 20 20 20 20 20 7d 0d 0a 20 20 20 20 20 20 20 20 68 33 2e 73 75 62 68 65 61 64 69 6e 67 20 7b 0d 0a 20 20 20 20 2
                Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 11 Feb 2025 17:55:12 GMTContent-Type: text/html; charset=iso-8859-1Transfer-Encoding: chunkedConnection: closecf-cache-status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=GesYfu69et4Ap5TNXGWpTDL7OWNwcwc4%2FPHxMHxs9SaAh%2Bqe9CBGVLje8uWGPcWqsU01jsR%2Fcx9MJYuMaKN%2BOHATAu7moxwaQMROqsKqKUx%2BftyuDfdLebiOFBXj5Pj3h4Gddg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 910635622f76c443-EWRContent-Encoding: gzipalt-svc: h3=":443"; ma=86400server-timing: cfL4;desc="?proto=TCP&rtt=1623&min_rtt=1623&rtt_var=811&sent=1&recv=3&lost=0&retrans=0&sent_bytes=0&recv_bytes=738&delivery_rate=0&cwnd=242&unsent_bytes=0&cid=0000000000000000&ts=0&x=0"Data Raw: 65 30 0d 0a 1f 8b 08 00 00 00 00 00 00 03 4c 8f c1 4e c3 30 10 44 ef fe 8a a5 77 b2 29 ea 81 c3 6a 25 68 52 51 29 94 08 dc 43 8f a6 5e e4 4a 21 0e f6 86 88 bf 47 49 85 c4 75 e6 cd 68 86 6e aa 97 ad 3d b5 35 3c d9 e7 06 da e3 63 b3 df c2 ea 16 71 5f db 1d 62 65 ab ab 73 57 94 88 f5 61 c5 86 82 7e 76 4c 41 9c 67 43 7a d1 4e 78 53 6e e0 10 15 76 71 ec 3d e1 55 34 84 0b 44 ef d1 ff cc b9 35 ff 63 c2 9a 0d 0d 6c 83 40 92 af 51 b2 8a 87 e3 6b 03 93 cb d0 47 85 8f 99 83 d8 83 86 4b 86 2c e9 5b 52 41 38 cc 4d 89 0d 39 ef 93 e4 cc 0f 83 3b 07 81 b7 05 00 a7 30 4d 53 71 ee e2 98 25 15 59 63 12 68 63 52 b8 2f 09 ff 32 86 70 19 45 b8 9c f9 05 00 00 ff ff e3 02 00 86 55 96 7d 07 01 00 00 0d 0a 30 0d 0a 0d 0a Data Ascii: e0LN0Dw)j%hRQ)C^J!GIuhn=5<cq_besWa~vLAgCzNxSnvq=U4D5cl@QkGK,[RA8M9;0MSq%YchcR/2pEU}0
                Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 11 Feb 2025 17:55:15 GMTContent-Type: text/html; charset=iso-8859-1Transfer-Encoding: chunkedConnection: closecf-cache-status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=tnPwbDE4y%2BzuTRL4njcrmc5oIxBlXQ%2BgR%2F0PtNltp4PYxFYYvqEOaKKQCqVHMbngfQUh%2BCGBctMH0eDtkA2g0oA%2Bx4OkG%2Bk3IJW1yicA2viqqERxLFXM9A%2BTQFu6%2FphoImKorQ%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 91063571eaf443ee-EWRContent-Encoding: gzipalt-svc: h3=":443"; ma=86400server-timing: cfL4;desc="?proto=TCP&rtt=1779&min_rtt=1779&rtt_var=889&sent=1&recv=3&lost=0&retrans=0&sent_bytes=0&recv_bytes=758&delivery_rate=0&cwnd=240&unsent_bytes=0&cid=0000000000000000&ts=0&x=0"Data Raw: 64 35 0d 0a 1f 8b 08 00 00 00 00 00 00 03 4c 8f c1 4e c3 30 10 44 ef fe 8a a5 77 b2 29 ea 81 c3 6a 25 68 52 51 29 94 08 dc 43 8f a6 5e e4 4a 21 0e f6 86 88 bf 47 49 85 c4 75 e6 cd 68 86 6e aa 97 ad 3d b5 35 3c d9 e7 06 da e3 63 b3 df c2 ea 16 71 5f db 1d 62 65 ab ab 73 57 94 88 f5 61 c5 86 82 7e 76 4c 41 9c 67 43 7a d1 4e 78 53 6e e0 10 15 76 71 ec 3d e1 55 34 84 0b 44 ef d1 ff cc b9 35 ff 63 c2 9a 0d 0d 6c 83 40 92 af 51 b2 8a 87 e3 6b 03 93 cb d0 47 85 8f 99 83 d8 83 86 4b 86 2c e9 5b 52 41 38 cc 4d 89 0d 39 ef 93 e4 cc 0f 83 3b 07 81 b7 05 00 a7 30 4d 53 71 ee e2 98 25 15 59 63 12 68 63 52 b8 2f 09 ff 32 86 70 19 45 b8 9c f9 05 00 00 ff ff 0d 0a 62 0d 0a e3 02 00 86 55 96 7d 07 01 00 00 0d 0a 30 0d 0a 0d 0a Data Ascii: d5LN0Dw)j%hRQ)C^J!GIuhn=5<cq_besWa~vLAgCzNxSnvq=U4D5cl@QkGK,[RA8M9;0MSq%YchcR/2pEbU}0
                Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 11 Feb 2025 17:55:17 GMTContent-Type: text/html; charset=iso-8859-1Transfer-Encoding: chunkedConnection: closecf-cache-status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=y9CKzKWV6ycgCmqcAzf6bBkxcvdWV9PbPUI6er6caKtbd5r2L7r7O3Aoo6S4rJbZOzCXMeFoGtkVczq3g4oc7itZQ5PHxuM8VVzlca5KWh6K20Z%2BDA3Y8QR7bTGA4PCHt%2F0aew%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 91063581fcdf8c0f-EWRContent-Encoding: gzipalt-svc: h3=":443"; ma=86400server-timing: cfL4;desc="?proto=TCP&rtt=1973&min_rtt=1973&rtt_var=986&sent=1&recv=4&lost=0&retrans=0&sent_bytes=0&recv_bytes=1771&delivery_rate=0&cwnd=231&unsent_bytes=0&cid=0000000000000000&ts=0&x=0"Data Raw: 65 30 0d 0a 1f 8b 08 00 00 00 00 00 00 03 4c 8f c1 4e c3 30 10 44 ef fe 8a a5 77 b2 29 ea 81 c3 6a 25 68 52 51 29 94 08 dc 43 8f a6 5e e4 4a 21 0e f6 86 88 bf 47 49 85 c4 75 e6 cd 68 86 6e aa 97 ad 3d b5 35 3c d9 e7 06 da e3 63 b3 df c2 ea 16 71 5f db 1d 62 65 ab ab 73 57 94 88 f5 61 c5 86 82 7e 76 4c 41 9c 67 43 7a d1 4e 78 53 6e e0 10 15 76 71 ec 3d e1 55 34 84 0b 44 ef d1 ff cc b9 35 ff 63 c2 9a 0d 0d 6c 83 40 92 af 51 b2 8a 87 e3 6b 03 93 cb d0 47 85 8f 99 83 d8 83 86 4b 86 2c e9 5b 52 41 38 cc 4d 89 0d 39 ef 93 e4 cc 0f 83 3b 07 81 b7 05 00 a7 30 4d 53 71 ee e2 98 25 15 59 63 12 68 63 52 b8 2f 09 ff 32 86 70 19 45 b8 9c f9 05 00 00 ff ff e3 02 00 86 55 96 7d 07 01 00 00 0d 0a 30 0d 0a 0d 0a Data Ascii: e0LN0Dw)j%hRQ)C^J!GIuhn=5<cq_besWa~vLAgCzNxSnvq=U4D5cl@QkGK,[RA8M9;0MSq%YchcR/2pEU}0
                Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Tue, 11 Feb 2025 17:55:20 GMTContent-Type: text/html; charset=iso-8859-1Transfer-Encoding: chunkedConnection: closecf-cache-status: DYNAMICReport-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=cGK1XVuR0JUQgL0kdupHNVkQUMQRcrf4Z%2FYA%2FhSsG00fmpgQUTHASK%2F79P9NTQoKP%2FA7UKS4NAqqfXob%2BZ1f3ZXKFxcWDAa0HZRgyXnXr0vSgWFqEwgKmBN9jnealDnRUAdmYg%3D%3D"}],"group":"cf-nel","max_age":604800}NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}Server: cloudflareCF-RAY: 91063591cc3442d2-EWRalt-svc: h3=":443"; ma=86400server-timing: cfL4;desc="?proto=TCP&rtt=1538&min_rtt=1538&rtt_var=769&sent=1&recv=3&lost=0&retrans=0&sent_bytes=0&recv_bytes=474&delivery_rate=0&cwnd=227&unsent_bytes=0&cid=0000000000000000&ts=0&x=0"Data Raw: 31 30 37 0d 0a 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 68 72 3e 0a 3c 61 64 64 72 65 73 73 3e 41 70 61 63 68 65 20 53 65 72 76 65 72 20 61 74 20 77 77 77 2e 63 6c 6f 75 73 65 72 2e 73 74 6f 72 65 20 50 6f 72 74 20 38 30 3c 2f 61 64 64 72 65 73 73 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a 0d 0a 30 0d 0a 0d 0a Data Ascii: 107<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><hr><address>Apache Server at www.clouser.store Port 80</address></body></html>0
                Source: Demande de devis. Quote Request.exeString found in binary or memory: http://tempuri.org/DataSet1.xsd
                Source: Demande de devis. Quote Request.exeString found in binary or memory: http://tempuri.org/airlineDataSet.xsd
                Source: Demande de devis. Quote Request.exeString found in binary or memory: http://tempuri.org/airlineDataSet1.xsd
                Source: V8sJoOh7MX.exe, 00000009.00000002.3762527305.0000000004DA2000.00000040.80000000.00040000.00000000.sdmpString found in binary or memory: http://www.hoaqua.xyz
                Source: V8sJoOh7MX.exe, 00000009.00000002.3762527305.0000000004DA2000.00000040.80000000.00040000.00000000.sdmpString found in binary or memory: http://www.hoaqua.xyz/yqvp/
                Source: timeout.exe, 00000008.00000002.3761172904.0000000006130000.00000004.10000000.00040000.00000000.sdmp, V8sJoOh7MX.exe, 00000009.00000002.3760071135.0000000003660000.00000004.00000001.00040000.00000000.sdmpString found in binary or memory: http://www.thinkphp.cn
                Source: timeout.exe, 00000008.00000003.1854365337.0000000007E88000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ac.ecosia.org/autocomplete?q=
                Source: timeout.exe, 00000008.00000003.1854365337.0000000007E88000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
                Source: timeout.exe, 00000008.00000003.1854365337.0000000007E88000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
                Source: timeout.exe, 00000008.00000003.1854365337.0000000007E88000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
                Source: timeout.exe, 00000008.00000003.1854365337.0000000007E88000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/ac/?q=
                Source: timeout.exe, 00000008.00000003.1854365337.0000000007E88000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/chrome_newtab
                Source: timeout.exe, 00000008.00000003.1854365337.0000000007E88000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
                Source: timeout.exe, 00000008.00000002.3757307349.00000000030B5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/oauth20_authorize.srf?client_id=00000000480728C5&scope=service::ssl.live.com:
                Source: timeout.exe, 00000008.00000002.3757307349.00000000030B5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/oauth20_authorize.srfclient_id=00000000480728C5&scope=service::ssl.live.com::
                Source: timeout.exe, 00000008.00000002.3757307349.00000000030B5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/oauth20_desktop.srf?lc=1033
                Source: timeout.exe, 00000008.00000002.3757307349.00000000030B5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/oauth20_desktop.srflc=1033
                Source: timeout.exe, 00000008.00000002.3757307349.00000000030B5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/oauth20_logout.srf?client_id=00000000480728C5&redirect_uri=https://login.live
                Source: timeout.exe, 00000008.00000002.3757307349.00000000030B5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/oauth20_logout.srfclient_id=00000000480728C5&redirect_uri=https://login.live.
                Source: timeout.exe, 00000008.00000003.1848968341.0000000007E65000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/oauth20_logout.srfhttps://login.live.com/oauth20_authorize.srfhttps://login.l
                Source: timeout.exe, 00000008.00000003.1854365337.0000000007E88000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.ecosia.org/newtab/
                Source: timeout.exe, 00000008.00000002.3761172904.00000000062C2000.00000004.10000000.00040000.00000000.sdmp, V8sJoOh7MX.exe, 00000009.00000002.3760071135.00000000037F2000.00000004.00000001.00040000.00000000.sdmpString found in binary or memory: https://www.google.com
                Source: timeout.exe, 00000008.00000003.1854365337.0000000007E88000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico

                E-Banking Fraud

                barindex
                Source: Yara matchFile source: 3.2.Demande de devis. Quote Request.exe.400000.0.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 3.2.Demande de devis. Quote Request.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000008.00000002.3759172651.0000000004B40000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000003.00000002.1657618519.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000008.00000002.3756604386.0000000002B50000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000008.00000002.3757205678.0000000003020000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000003.00000002.1729597114.0000000005D00000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000009.00000002.3762527305.0000000004D40000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000006.00000002.3759091233.0000000005040000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000003.00000002.1659532102.0000000004110000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0042CFE3 NtClose,3_2_0042CFE3
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532B60 NtClose,LdrInitializeThunk,3_2_01532B60
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532DF0 NtQuerySystemInformation,LdrInitializeThunk,3_2_01532DF0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532C70 NtFreeVirtualMemory,LdrInitializeThunk,3_2_01532C70
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015335C0 NtCreateMutant,LdrInitializeThunk,3_2_015335C0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01534340 NtSetContextThread,3_2_01534340
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01534650 NtSuspendThread,3_2_01534650
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532BF0 NtAllocateVirtualMemory,3_2_01532BF0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532BE0 NtQueryValueKey,3_2_01532BE0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532B80 NtQueryInformationFile,3_2_01532B80
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532BA0 NtEnumerateValueKey,3_2_01532BA0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532AD0 NtReadFile,3_2_01532AD0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532AF0 NtWriteFile,3_2_01532AF0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532AB0 NtWaitForSingleObject,3_2_01532AB0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532D10 NtMapViewOfSection,3_2_01532D10
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532D00 NtSetInformationFile,3_2_01532D00
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532D30 NtUnmapViewOfSection,3_2_01532D30
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532DD0 NtDelayExecution,3_2_01532DD0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532DB0 NtEnumerateKey,3_2_01532DB0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532C60 NtCreateKey,3_2_01532C60
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532C00 NtQueryInformationProcess,3_2_01532C00
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532CC0 NtQueryVirtualMemory,3_2_01532CC0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532CF0 NtOpenProcess,3_2_01532CF0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532CA0 NtQueryInformationToken,3_2_01532CA0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532F60 NtCreateProcessEx,3_2_01532F60
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532F30 NtCreateSection,3_2_01532F30
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532FE0 NtCreateFile,3_2_01532FE0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532F90 NtProtectVirtualMemory,3_2_01532F90
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532FB0 NtResumeThread,3_2_01532FB0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532FA0 NtQuerySection,3_2_01532FA0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532E30 NtWriteVirtualMemory,3_2_01532E30
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532EE0 NtQueueApcThread,3_2_01532EE0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532E80 NtReadVirtualMemory,3_2_01532E80
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532EA0 NtAdjustPrivilegesToken,3_2_01532EA0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01533010 NtOpenDirectoryObject,3_2_01533010
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01533090 NtSetValueKey,3_2_01533090
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015339B0 NtGetContextThread,3_2_015339B0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01533D70 NtOpenThread,3_2_01533D70
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01533D10 NtOpenProcessToken,3_2_01533D10
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E24650 NtSuspendThread,LdrInitializeThunk,8_2_04E24650
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E24340 NtSetContextThread,LdrInitializeThunk,8_2_04E24340
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22CA0 NtQueryInformationToken,LdrInitializeThunk,8_2_04E22CA0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22C60 NtCreateKey,LdrInitializeThunk,8_2_04E22C60
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22C70 NtFreeVirtualMemory,LdrInitializeThunk,8_2_04E22C70
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22DF0 NtQuerySystemInformation,LdrInitializeThunk,8_2_04E22DF0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22DD0 NtDelayExecution,LdrInitializeThunk,8_2_04E22DD0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22D30 NtUnmapViewOfSection,LdrInitializeThunk,8_2_04E22D30
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22D10 NtMapViewOfSection,LdrInitializeThunk,8_2_04E22D10
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22EE0 NtQueueApcThread,LdrInitializeThunk,8_2_04E22EE0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22E80 NtReadVirtualMemory,LdrInitializeThunk,8_2_04E22E80
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22FE0 NtCreateFile,LdrInitializeThunk,8_2_04E22FE0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22FB0 NtResumeThread,LdrInitializeThunk,8_2_04E22FB0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22F30 NtCreateSection,LdrInitializeThunk,8_2_04E22F30
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22AF0 NtWriteFile,LdrInitializeThunk,8_2_04E22AF0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22AD0 NtReadFile,LdrInitializeThunk,8_2_04E22AD0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22BE0 NtQueryValueKey,LdrInitializeThunk,8_2_04E22BE0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22BF0 NtAllocateVirtualMemory,LdrInitializeThunk,8_2_04E22BF0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22BA0 NtEnumerateValueKey,LdrInitializeThunk,8_2_04E22BA0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22B60 NtClose,LdrInitializeThunk,8_2_04E22B60
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E235C0 NtCreateMutant,LdrInitializeThunk,8_2_04E235C0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E239B0 NtGetContextThread,LdrInitializeThunk,8_2_04E239B0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22CF0 NtOpenProcess,8_2_04E22CF0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22CC0 NtQueryVirtualMemory,8_2_04E22CC0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22C00 NtQueryInformationProcess,8_2_04E22C00
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22DB0 NtEnumerateKey,8_2_04E22DB0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22D00 NtSetInformationFile,8_2_04E22D00
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22EA0 NtAdjustPrivilegesToken,8_2_04E22EA0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22E30 NtWriteVirtualMemory,8_2_04E22E30
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22FA0 NtQuerySection,8_2_04E22FA0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22F90 NtProtectVirtualMemory,8_2_04E22F90
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22F60 NtCreateProcessEx,8_2_04E22F60
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22AB0 NtWaitForSingleObject,8_2_04E22AB0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E22B80 NtQueryInformationFile,8_2_04E22B80
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E23090 NtSetValueKey,8_2_04E23090
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E23010 NtOpenDirectoryObject,8_2_04E23010
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E23D70 NtOpenThread,8_2_04E23D70
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E23D10 NtOpenProcessToken,8_2_04E23D10
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_02B79A80 NtCreateFile,8_2_02B79A80
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_02B79BF0 NtReadFile,8_2_02B79BF0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_02B79EF0 NtAllocateVirtualMemory,8_2_02B79EF0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_02B79CE0 NtDeleteFile,8_2_02B79CE0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_02B79D80 NtClose,8_2_02B79D80
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04C4FB45 NtResumeThread,8_2_04C4FB45
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_011BD4840_2_011BD484
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_079300400_2_07930040
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_079300060_2_07930006
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_07932FD00_2_07932FD0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_07934C080_2_07934C08
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_07932B980_2_07932B98
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_079354E00_2_079354E0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_079334080_2_07933408
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_079333F70_2_079333F7
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_0797B7B80_2_0797B7B8
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_07973EA80_2_07973EA8
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_07979E400_2_07979E40
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_07974DC80_2_07974DC8
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_079728980_2_07972898
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_0797B7A80_2_0797B7A8
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_0797760A0_2_0797760A
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_0797A5800_2_0797A580
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_0797A5700_2_0797A570
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_079734A80_2_079734A8
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_079773100_2_07977310
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_0797A3180_2_0797A318
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_079773000_2_07977300
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_0797A3280_2_0797A328
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_079770800_2_07977080
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_0797A0D80_2_0797A0D8
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_0797B0D80_2_0797B0D8
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_0797A0C80_2_0797A0C8
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_0797B0C80_2_0797B0C8
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_079770700_2_07977070
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_07976F100_2_07976F10
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_07976F010_2_07976F01
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_07979E2F0_2_07979E2F
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_07974DA10_2_07974DA1
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_07971DA80_2_07971DA8
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_07974D030_2_07974D03
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_07975C910_2_07975C91
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_0797BC900_2_0797BC90
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_0797BC800_2_0797BC80
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_07975CA00_2_07975CA0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_07976AE00_2_07976AE0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_0797286D0_2_0797286D
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_00418E933_2_00418E93
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_004108233_2_00410823
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0040E8233_2_0040E823
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_004010C03_2_004010C0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0041708E3_2_0041708E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_004170933_2_00417093
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_004010B23_2_004010B2
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0040E9683_2_0040E968
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0040E9733_2_0040E973
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_004011F03_2_004011F0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_004022B03_2_004022B0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_00402BF03_2_00402BF0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_004024693_2_00402469
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_004024703_2_00402470
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0042F6733_2_0042F673
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_004106003_2_00410600
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_004106033_2_00410603
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_004027503_2_00402750
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_00402FE03_2_00402FE0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015881583_2_01588158
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159A1183_2_0159A118
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F01003_2_014F0100
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015B81CC3_2_015B81CC
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015C01AA3_2_015C01AA
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015B41A23_2_015B41A2
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015920003_2_01592000
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015BA3523_2_015BA352
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0150E3F03_2_0150E3F0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015C03E63_2_015C03E6
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015A02743_2_015A0274
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015802C03_2_015802C0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015005353_2_01500535
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015C05913_2_015C0591
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015B24463_2_015B2446
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015A44203_2_015A4420
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015AE4F63_2_015AE4F6
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015247503_2_01524750
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015007703_2_01500770
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FC7C03_2_014FC7C0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151C6E03_2_0151C6E0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015169623_2_01516962
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015029A03_2_015029A0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015CA9A63_2_015CA9A6
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0150A8403_2_0150A840
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015028403_2_01502840
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152E8F03_2_0152E8F0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014E68B83_2_014E68B8
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015BAB403_2_015BAB40
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015B6BD73_2_015B6BD7
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FEA803_2_014FEA80
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159CD1F3_2_0159CD1F
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0150AD003_2_0150AD00
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FADE03_2_014FADE0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01518DBF3_2_01518DBF
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01500C003_2_01500C00
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F0CF23_2_014F0CF2
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015A0CB53_2_015A0CB5
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01574F403_2_01574F40
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01520F303_2_01520F30
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015A2F303_2_015A2F30
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01542F283_2_01542F28
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F2FC83_2_014F2FC8
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0150CFE03_2_0150CFE0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0157EFA03_2_0157EFA0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01500E593_2_01500E59
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015BEE263_2_015BEE26
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015BEEDB3_2_015BEEDB
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01512E903_2_01512E90
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015BCE933_2_015BCE93
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015CB16B3_2_015CB16B
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014EF1723_2_014EF172
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0153516C3_2_0153516C
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0150B1B03_2_0150B1B0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015070C03_2_015070C0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015AF0CC3_2_015AF0CC
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015B70E93_2_015B70E9
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015BF0E03_2_015BF0E0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014ED34C3_2_014ED34C
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015B132D3_2_015B132D
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0154739A3_2_0154739A
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151B2C03_2_0151B2C0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015A12ED3_2_015A12ED
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015052A03_2_015052A0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015B75713_2_015B7571
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159D5B03_2_0159D5B0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F14603_2_014F1460
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015BF43F3_2_015BF43F
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015BF7B03_2_015BF7B0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015456303_2_01545630
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015B16CC3_2_015B16CC
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015099503_2_01509950
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151B9503_2_0151B950
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015959103_2_01595910
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0156D8003_2_0156D800
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015038E03_2_015038E0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015BFB763_2_015BFB76
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01575BF03_2_01575BF0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0153DBF93_2_0153DBF9
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151FB803_2_0151FB80
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015BFA493_2_015BFA49
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015B7A463_2_015B7A46
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01573A6C3_2_01573A6C
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015ADAC63_2_015ADAC6
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01545AA03_2_01545AA0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159DAAC3_2_0159DAAC
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015A1AA33_2_015A1AA3
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015B1D5A3_2_015B1D5A
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01503D403_2_01503D40
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015B7D733_2_015B7D73
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151FDC03_2_0151FDC0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01579C323_2_01579C32
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015BFCF23_2_015BFCF2
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015BFF093_2_015BFF09
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01501F923_2_01501F92
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015BFFB13_2_015BFFB1
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01509EB03_2_01509EB0
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeCode function: 6_2_052D0DA16_2_052D0DA1
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeCode function: 6_2_052D2DA16_2_052D2DA1
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeCode function: 6_2_052D2B7E6_2_052D2B7E
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeCode function: 6_2_052D2B816_2_052D2B81
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeCode function: 6_2_052F1BF16_2_052F1BF1
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeCode function: 6_2_052D960C6_2_052D960C
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeCode function: 6_2_052D96116_2_052D9611
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeCode function: 6_2_052D0EE66_2_052D0EE6
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeCode function: 6_2_052D0EF16_2_052D0EF1
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E9E4F68_2_04E9E4F6
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EA24468_2_04EA2446
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E944208_2_04E94420
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EB05918_2_04EB0591
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DF05358_2_04DF0535
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E0C6E08_2_04E0C6E0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DEC7C08_2_04DEC7C0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DF07708_2_04DF0770
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E147508_2_04E14750
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E820008_2_04E82000
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EA81CC8_2_04EA81CC
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EB01AA8_2_04EB01AA
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EA41A28_2_04EA41A2
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E781588_2_04E78158
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DE01008_2_04DE0100
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E8A1188_2_04E8A118
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E702C08_2_04E702C0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E902748_2_04E90274
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EB03E68_2_04EB03E6
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DFE3F08_2_04DFE3F0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EAA3528_2_04EAA352
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DE0CF28_2_04DE0CF2
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E90CB58_2_04E90CB5
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DF0C008_2_04DF0C00
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DEADE08_2_04DEADE0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E08DBF8_2_04E08DBF
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DFAD008_2_04DFAD00
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E8CD1F8_2_04E8CD1F
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EAEEDB8_2_04EAEEDB
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E02E908_2_04E02E90
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EACE938_2_04EACE93
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DF0E598_2_04DF0E59
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EAEE268_2_04EAEE26
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DE2FC88_2_04DE2FC8
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DFCFE08_2_04DFCFE0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E6EFA08_2_04E6EFA0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E64F408_2_04E64F40
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E32F288_2_04E32F28
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E10F308_2_04E10F30
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E92F308_2_04E92F30
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E1E8F08_2_04E1E8F0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DD68B88_2_04DD68B8
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DF28408_2_04DF2840
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DFA8408_2_04DFA840
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EBA9A68_2_04EBA9A6
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DF29A08_2_04DF29A0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E069628_2_04E06962
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DEEA808_2_04DEEA80
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EA6BD78_2_04EA6BD7
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EAAB408_2_04EAAB40
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DE14608_2_04DE1460
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EAF43F8_2_04EAF43F
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EB95C38_2_04EB95C3
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E8D5B08_2_04E8D5B0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EA75718_2_04EA7571
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EA16CC8_2_04EA16CC
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E356308_2_04E35630
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EAF7B08_2_04EAF7B0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EA70E98_2_04EA70E9
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EAF0E08_2_04EAF0E0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DF70C08_2_04DF70C0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E9F0CC8_2_04E9F0CC
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DFB1B08_2_04DFB1B0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EBB16B8_2_04EBB16B
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E2516C8_2_04E2516C
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DDF1728_2_04DDF172
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E912ED8_2_04E912ED
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E0B2C08_2_04E0B2C0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DF52A08_2_04DF52A0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E3739A8_2_04E3739A
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DDD34C8_2_04DDD34C
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EA132D8_2_04EA132D
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EAFCF28_2_04EAFCF2
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E69C328_2_04E69C32
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E0FDC08_2_04E0FDC0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EA7D738_2_04EA7D73
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DF3D408_2_04DF3D40
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EA1D5A8_2_04EA1D5A
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DF9EB08_2_04DF9EB0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DB3FD28_2_04DB3FD2
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DB3FD58_2_04DB3FD5
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DF1F928_2_04DF1F92
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EAFFB18_2_04EAFFB1
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EAFF098_2_04EAFF09
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DF38E08_2_04DF38E0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E5D8008_2_04E5D800
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DF99508_2_04DF9950
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E0B9508_2_04E0B950
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E859108_2_04E85910
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E9DAC68_2_04E9DAC6
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E35AA08_2_04E35AA0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E8DAAC8_2_04E8DAAC
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E91AA38_2_04E91AA3
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E63A6C8_2_04E63A6C
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EAFA498_2_04EAFA49
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EA7A468_2_04EA7A46
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E65BF08_2_04E65BF0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E2DBF98_2_04E2DBF9
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04E0FB808_2_04E0FB80
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04EAFB768_2_04EAFB76
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_02B625708_2_02B62570
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_02B7C4108_2_02B7C410
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_02B5D3A08_2_02B5D3A0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_02B5D39D8_2_02B5D39D
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_02B5B7108_2_02B5B710
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_02B5B7058_2_02B5B705
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_02B5B5C08_2_02B5B5C0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_02B5D5C08_2_02B5D5C0
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_02B63E308_2_02B63E30
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_02B63E2B8_2_02B63E2B
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_02B65C308_2_02B65C30
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04C4E54B8_2_04C4E54B
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04C4E7828_2_04C4E782
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04C4E2C68_2_04C4E2C6
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04C4E3E38_2_04C4E3E3
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04C4D8488_2_04C4D848
                Source: C:\Windows\SysWOW64\timeout.exeCode function: String function: 04E6F290 appears 105 times
                Source: C:\Windows\SysWOW64\timeout.exeCode function: String function: 04DDB970 appears 277 times
                Source: C:\Windows\SysWOW64\timeout.exeCode function: String function: 04E37E54 appears 111 times
                Source: C:\Windows\SysWOW64\timeout.exeCode function: String function: 04E5EA12 appears 86 times
                Source: C:\Windows\SysWOW64\timeout.exeCode function: String function: 04E25130 appears 58 times
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: String function: 0157F290 appears 105 times
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: String function: 014EB970 appears 277 times
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: String function: 01535130 appears 58 times
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: String function: 0156EA12 appears 86 times
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: String function: 01547E54 appears 103 times
                Source: Demande de devis. Quote Request.exe, 00000000.00000002.1301996876.0000000001110000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameMontero.dll8 vs Demande de devis. Quote Request.exe
                Source: Demande de devis. Quote Request.exe, 00000000.00000002.1299872918.0000000000CDE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameclr.dllT vs Demande de devis. Quote Request.exe
                Source: Demande de devis. Quote Request.exe, 00000000.00000000.1288804075.00000000006A2000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenamevwkg.exeB vs Demande de devis. Quote Request.exe
                Source: Demande de devis. Quote Request.exe, 00000003.00000002.1658442716.00000000015ED000.00000040.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenamentdll.dllj% vs Demande de devis. Quote Request.exe
                Source: Demande de devis. Quote Request.exe, 00000003.00000002.1657978541.0000000000F68000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenametimeout.exej% vs Demande de devis. Quote Request.exe
                Source: Demande de devis. Quote Request.exe, 00000003.00000002.1657978541.0000000000F7E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenametimeout.exej% vs Demande de devis. Quote Request.exe
                Source: Demande de devis. Quote Request.exeBinary or memory string: OriginalFilenamevwkg.exeB vs Demande de devis. Quote Request.exe
                Source: Demande de devis. Quote Request.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                Source: Demande de devis. Quote Request.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, sy1GpvP5sykjQD99Qk.csSecurity API names: System.Security.Principal.WindowsPrincipal.IsInRole(System.Security.Principal.WindowsBuiltInRole)
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, sy1GpvP5sykjQD99Qk.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, sy1GpvP5sykjQD99Qk.csSecurity API names: System.Security.Principal.WindowsPrincipal.IsInRole(System.Security.Principal.WindowsBuiltInRole)
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, sy1GpvP5sykjQD99Qk.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, vcQuV5ROCbimuK7ZC6.csSecurity API names: System.IO.DirectoryInfo.SetAccessControl(System.Security.AccessControl.DirectorySecurity)
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, vcQuV5ROCbimuK7ZC6.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, vcQuV5ROCbimuK7ZC6.csSecurity API names: System.Security.AccessControl.FileSystemSecurity.AddAccessRule(System.Security.AccessControl.FileSystemAccessRule)
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, vcQuV5ROCbimuK7ZC6.csSecurity API names: System.IO.DirectoryInfo.SetAccessControl(System.Security.AccessControl.DirectorySecurity)
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, vcQuV5ROCbimuK7ZC6.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, vcQuV5ROCbimuK7ZC6.csSecurity API names: System.Security.AccessControl.FileSystemSecurity.AddAccessRule(System.Security.AccessControl.FileSystemAccessRule)
                Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@9/2@16/9
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeFile created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Demande de devis. Quote Request.exe.logJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeMutant created: NULL
                Source: C:\Windows\SysWOW64\timeout.exeFile created: C:\Users\user~1\AppData\Local\Temp\s47R9_107Jump to behavior
                Source: Demande de devis. Quote Request.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                Source: Demande de devis. Quote Request.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.80%
                Source: C:\Program Files\Mozilla Firefox\firefox.exeFile read: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.iniJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                Source: timeout.exe, 00000008.00000003.1853082418.000000000314A000.00000004.00000020.00020000.00000000.sdmp, timeout.exe, 00000008.00000003.1852038979.000000000312A000.00000004.00000020.00020000.00000000.sdmp, timeout.exe, 00000008.00000003.1853082418.0000000003114000.00000004.00000020.00020000.00000000.sdmp, timeout.exe, 00000008.00000003.1852188061.0000000003114000.00000004.00000020.00020000.00000000.sdmp, timeout.exe, 00000008.00000002.3757307349.0000000003114000.00000004.00000020.00020000.00000000.sdmp, timeout.exe, 00000008.00000002.3757307349.000000000314A000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
                Source: Demande de devis. Quote Request.exeVirustotal: Detection: 31%
                Source: Demande de devis. Quote Request.exeReversingLabs: Detection: 56%
                Source: unknownProcess created: C:\Users\user\Desktop\Demande de devis. Quote Request.exe "C:\Users\user\Desktop\Demande de devis. Quote Request.exe"
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess created: C:\Users\user\Desktop\Demande de devis. Quote Request.exe "C:\Users\user\Desktop\Demande de devis. Quote Request.exe"
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeProcess created: C:\Windows\SysWOW64\Magnify.exe "C:\Windows\SysWOW64\Magnify.exe"
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeProcess created: C:\Windows\SysWOW64\timeout.exe "C:\Windows\SysWOW64\timeout.exe"
                Source: C:\Windows\SysWOW64\timeout.exeProcess created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\Firefox.exe"
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess created: C:\Users\user\Desktop\Demande de devis. Quote Request.exe "C:\Users\user\Desktop\Demande de devis. Quote Request.exe"Jump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeProcess created: C:\Windows\SysWOW64\Magnify.exe "C:\Windows\SysWOW64\Magnify.exe"Jump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeProcess created: C:\Windows\SysWOW64\timeout.exe "C:\Windows\SysWOW64\timeout.exe"Jump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeProcess created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\Firefox.exe"Jump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeSection loaded: mscoree.dllJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeSection loaded: version.dllJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeSection loaded: uxtheme.dllJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeSection loaded: cryptsp.dllJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeSection loaded: rsaenh.dllJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeSection loaded: cryptbase.dllJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeSection loaded: windowscodecs.dllJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeSection loaded: amsi.dllJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeSection loaded: userenv.dllJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeSection loaded: msasn1.dllJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeSection loaded: gpapi.dllJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeSection loaded: dwrite.dllJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: version.dllJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: wininet.dllJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: uxtheme.dllJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: ieframe.dllJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: iertutil.dllJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: netapi32.dllJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: userenv.dllJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: wkscli.dllJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: netutils.dllJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: secur32.dllJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: mlang.dllJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: propsys.dllJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: winsqlite3.dllJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: vaultcli.dllJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: wintypes.dllJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: dpapi.dllJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: cryptbase.dllJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeSection loaded: wininet.dllJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeSection loaded: dnsapi.dllJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeSection loaded: fwpuclnt.dllJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeSection loaded: rasadhlp.dllJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32Jump to behavior
                Source: Window RecorderWindow detected: More than 3 window changes detected
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\15.0\Outlook\Profiles\Outlook\Jump to behavior
                Source: Demande de devis. Quote Request.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
                Source: Demande de devis. Quote Request.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                Source: Demande de devis. Quote Request.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
                Source: Binary string: Magnify.pdb source: V8sJoOh7MX.exe, 00000006.00000003.1597383090.0000000002686000.00000004.00000001.00020000.00000000.sdmp, V8sJoOh7MX.exe, 00000006.00000003.1597036814.0000000000BF4000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: Magnify.pdbGCTL source: V8sJoOh7MX.exe, 00000006.00000003.1597383090.0000000002686000.00000004.00000001.00020000.00000000.sdmp, V8sJoOh7MX.exe, 00000006.00000003.1597036814.0000000000BF4000.00000004.00000020.00020000.00000000.sdmp
                Source: Binary string: timeout.pdbGCTL source: Demande de devis. Quote Request.exe, 00000003.00000002.1657978541.0000000000F68000.00000004.00000020.00020000.00000000.sdmp, V8sJoOh7MX.exe, 00000006.00000002.3757857207.0000000000BDE000.00000004.00000020.00020000.00000000.sdmp, V8sJoOh7MX.exe, 00000006.00000003.1597662208.0000000000BF5000.00000004.00000001.00020000.00000000.sdmp
                Source: Binary string: wntdll.pdbUGP source: Demande de devis. Quote Request.exe, 00000003.00000002.1658442716.00000000014C0000.00000040.00001000.00020000.00000000.sdmp, timeout.exe, 00000008.00000002.3759591244.0000000004F4E000.00000040.00001000.00020000.00000000.sdmp, timeout.exe, 00000008.00000003.1660045102.0000000004C07000.00000004.00000020.00020000.00000000.sdmp, timeout.exe, 00000008.00000003.1657911852.0000000004A5E000.00000004.00000020.00020000.00000000.sdmp, timeout.exe, 00000008.00000002.3759591244.0000000004DB0000.00000040.00001000.00020000.00000000.sdmp
                Source: Binary string: timeout.pdb source: Demande de devis. Quote Request.exe, 00000003.00000002.1657978541.0000000000F68000.00000004.00000020.00020000.00000000.sdmp, V8sJoOh7MX.exe, 00000006.00000002.3757857207.0000000000BDE000.00000004.00000020.00020000.00000000.sdmp, V8sJoOh7MX.exe, 00000006.00000003.1597662208.0000000000BF5000.00000004.00000001.00020000.00000000.sdmp
                Source: Binary string: wntdll.pdb source: Demande de devis. Quote Request.exe, Demande de devis. Quote Request.exe, 00000003.00000002.1658442716.00000000014C0000.00000040.00001000.00020000.00000000.sdmp, timeout.exe, timeout.exe, 00000008.00000002.3759591244.0000000004F4E000.00000040.00001000.00020000.00000000.sdmp, timeout.exe, 00000008.00000003.1660045102.0000000004C07000.00000004.00000020.00020000.00000000.sdmp, timeout.exe, 00000008.00000003.1657911852.0000000004A5E000.00000004.00000020.00020000.00000000.sdmp, timeout.exe, 00000008.00000002.3759591244.0000000004DB0000.00000040.00001000.00020000.00000000.sdmp
                Source: Binary string: vwkg.pdb source: Demande de devis. Quote Request.exe
                Source: Binary string: vwkg.pdbSHA256 source: Demande de devis. Quote Request.exe
                Source: Binary string: C:\Work\JoeSecurity\trunk\src\windows\usermode\tools\FakeChrome\Release\Chrome.pdb source: V8sJoOh7MX.exe, 00000006.00000002.3757372051.00000000005AF000.00000002.00000001.01000000.0000000D.sdmp, V8sJoOh7MX.exe, 00000009.00000000.1734069492.00000000005AF000.00000002.00000001.01000000.0000000D.sdmp

                Data Obfuscation

                barindex
                Source: Demande de devis. Quote Request.exe, Form1.cs.Net Code: InitializeComponent System.Reflection.Assembly.Load(byte[])
                Source: 0.2.Demande de devis. Quote Request.exe.3c6a808.2.raw.unpack, MainForm.cs.Net Code: _200C_202A_200E_202D_202D_206E_202D_202E_202A_206A_200E_202D_206B_206B_206E_206A_202C_206E_202E_200D_206B_206E_202C_202C_202B_200E_200C_202B_202C_206E_200D_200E_206C_202A_202E_206C_202B_202D_206B_200C_202E System.Reflection.Assembly.Load(byte[])
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, vcQuV5ROCbimuK7ZC6.cs.Net Code: UhgWaxqpbR System.Reflection.Assembly.Load(byte[])
                Source: 0.2.Demande de devis. Quote Request.exe.3c4a7e8.1.raw.unpack, MainForm.cs.Net Code: _200C_202A_200E_202D_202D_206E_202D_202E_202A_206A_200E_202D_206B_206B_206E_206A_202C_206E_202E_200D_206B_206E_202C_202C_202B_200E_200C_202B_202C_206E_200D_200E_206C_202A_202E_206C_202B_202D_206B_200C_202E System.Reflection.Assembly.Load(byte[])
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, vcQuV5ROCbimuK7ZC6.cs.Net Code: UhgWaxqpbR System.Reflection.Assembly.Load(byte[])
                Source: 8.2.timeout.exe.53dcd14.2.raw.unpack, Form1.cs.Net Code: InitializeComponent System.Reflection.Assembly.Load(byte[])
                Source: 9.2.V8sJoOh7MX.exe.290cd14.1.raw.unpack, Form1.cs.Net Code: InitializeComponent System.Reflection.Assembly.Load(byte[])
                Source: 9.0.V8sJoOh7MX.exe.290cd14.1.raw.unpack, Form1.cs.Net Code: InitializeComponent System.Reflection.Assembly.Load(byte[])
                Source: 11.2.firefox.exe.2ffacd14.0.raw.unpack, Form1.cs.Net Code: InitializeComponent System.Reflection.Assembly.Load(byte[])
                Source: Demande de devis. Quote Request.exeStatic PE information: 0x86394767 [Sat May 11 15:59:35 2041 UTC]
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_011BEFB0 push esp; iretd 0_2_011BEFB1
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_07939E6D push dword ptr [edx+ebp*2-75h]; iretd 0_2_07939E77
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 0_2_07974860 push cs; ret 0_2_07974861
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_00412062 push ebp; retf 3_2_00412063
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_004050A8 push esi; ret 3_2_00405112
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_00407160 push edx; iretd 3_2_00407161
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_00414A56 push esi; ret 3_2_00414A57
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_00403260 push eax; ret 3_2_00403262
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_004193D3 push edi; retf 3_2_004193DC
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_004083E7 push eax; ret 3_2_004083F2
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_00414B91 push ecx; retf 3_2_00414BB2
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_004163BE push esp; iretd 3_2_004163BF
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0041646E pushad ; iretd 3_2_0041646F
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_00414CFB push ecx; iretd 3_2_00414CFE
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_004275A3 push edi; ret 3_2_004275AC
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F09AD push ecx; mov dword ptr [esp], ecx3_2_014F09B6
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeCode function: 6_2_052D893C push esp; iretd 6_2_052D893D
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeCode function: 6_2_052D710F push ecx; retf 6_2_052D7130
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeCode function: 6_2_052CA965 push eax; ret 6_2_052CA970
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeCode function: 6_2_052D89EC pushad ; iretd 6_2_052D89ED
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeCode function: 6_2_052D45E0 push ebp; retf 6_2_052D45E1
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeCode function: 6_2_052D6FD4 push esi; ret 6_2_052D6FD5
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeCode function: 6_2_052C7626 push esi; ret 6_2_052C7690
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeCode function: 6_2_052D726F push ecx; iretd 6_2_052D727C
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeCode function: 6_2_052C96DE push edx; iretd 6_2_052C96DF
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DB27FA pushad ; ret 8_2_04DB27F9
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DB225F pushad ; ret 8_2_04DB27F9
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DB283D push eax; iretd 8_2_04DB2858
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_04DE09AD push ecx; mov dword ptr [esp], ecx8_2_04DE09B6
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_02B66265 push esp; retf 8_2_02B66266
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_02B681E7 push esi; ret 8_2_02B681EF
                Source: Demande de devis. Quote Request.exeStatic PE information: section name: .text entropy: 7.655745649201067
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, F6q75icRv4YG6vlUG8.csHigh entropy of concatenated method names: 'TEMMpghY1Z', 'G2wMGHJ9hc', 'Do0MjJh5wN', 'DIOjShJrki', 'F91jzJFBga', 'MBbMlXPhrw', 'hqvMorOVHv', 'oEsM4Ct64g', 'GgrMCp0l6w', 'EhjMWsCc8g'
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, VWO7wBYyTEIld6VSI0.csHigh entropy of concatenated method names: 'FgFdAEfck2', 'Ceudtt2XRD', 'ToString', 'ebddpZtx4F', 'sq8dmEyPoW', 'bbGdGvkpKP', 'gqud2YtjTT', 'WZadjjNgEG', 'WqFdMkXPPV', 'OSkdRRbwyo'
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, ELHXS4olZudFNbq48lV.csHigh entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'uBs1KaXiZg', 'j6K1i5UXUi', 'Dyk1Xo19V6', 'nao1xLJw0G', 'POq1hV1swb', 'WpX1JoSOO0', 'kDq1YiZ8LR'
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, iUrjerWNLQN0TgnlBG.csHigh entropy of concatenated method names: 'Bf1oMy1Gpv', 'WsyoRkjQD9', 'uU9oAakQk4', 'zVjotpsWJT', 'I9UoOKTpXW', 'ajioFL4Loh', 'BrwFt4iOs6LBSgWAqd', 'VrqZfBDRSbTT0wl1Xj', 'Kouoodu0kZ', 'ldfoCBMrYc'
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, OBhSiQoWmimGYqKTK5k.csHigh entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'ChL3g7kXOP', 'bSj31ueJy7', 'ifF3yUB7oc', 'Glc33ty7Sr', 'Rcl3Eh9dEZ', 'qVH3kx1x55', 'TvM3vJFQx5'
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, zwj0ayz2qvp1WgAXco.csHigh entropy of concatenated method names: 'L7N1IvfDyv', 'EQl1PMhRmQ', 'vBC1evDOZ2', 'bkn1nnKDUf', 'tFE17Dl6fY', 'r8t1fIBJ76', 'FKx1858YpE', 'zCy1vZ13Bp', 'bLM1bj6igH', 'N1Z1UlRqqg'
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, vMpmh25ViGnkhPiptQ.csHigh entropy of concatenated method names: 'CWtgOxAjmk', 'Fxmgdsv1Ek', 'xiNggDRKDE', 'i8igynOJe4', 'fFVgEtd8Aj', 'OjtgvcVOVn', 'Dispose', 'P0qupr2SrV', 'pOhumcjJuM', 'TILuGR8HNR'
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, XFw8sdooseVVIrehrv2.csHigh entropy of concatenated method names: 'Yh81SeIf4T', 'dod1zqEtrp', 'gUCylmBSgG', 'NOFyoJMkhS', 'bv2y46KTLS', 'BIkyCnNZvB', 'Jf2yWuUgnp', 'RJMy03Crrk', 'iBSypm61tb', 'uOuymuhA8v'
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, HAQKDWoCnDIpjYN7rXc.csHigh entropy of concatenated method names: 'aMvySqQmwL', 'jhlyzI1FCc', 'fKD3lgD78V', 'bZW7cWm2UvqxSqdN9kG', 'Vbs6ddmHKlZPvDZTAqQ', 'CJBIugmfpVreGyXm452'
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, CUpMJCHZ44E4RPwRjr.csHigh entropy of concatenated method names: 'JFudq3HSaX', 'LmfdSxUG18', 'NHRul5Zkl8', 'tjouod9wBu', 'z8bdKM1ewb', 'yL0ditDq29', 'jkAdXUt1Y0', 'LL0dx3IhIh', 'Nn7dhiLhgU', 'qwbdJVLDuF'
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, vcQuV5ROCbimuK7ZC6.csHigh entropy of concatenated method names: 'VfIC0ACXmA', 'uq6Cpwqt0W', 'x3sCm24ARw', 'l3OCGf0ADp', 'sLxC2jPM9I', 'RMiCjWc9cX', 'WOjCMmArbT', 'lx6CRO2Odp', 'FoDCBdL6vC', 'zQWCA9XSJ7'
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, kwMTV3eU9akQk4aVjp.csHigh entropy of concatenated method names: 'kAeG99l5R0', 'y3GGInyYjL', 'nBRGP96ha3', 'GegGefWki7', 'rkDGOSgMCl', 'IB9GFJ1sNL', 'PD1GdjY6Nt', 'zwOGu1BVn3', 'lPmGgsvPC4', 'FwAG163mxX'
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, fXWljinL4LohrLS6kV.csHigh entropy of concatenated method names: 'Cwfj013t6G', 'x7Sjm4nyNB', 'viKj2OEGun', 'DOfjMsdcTs', 'gqGjRUMBfM', 'Flj2VQ9Z8p', 'knN2HhbLWb', 'gMk25tA6cT', 'wGW2qqg3PT', 'wTw2TGZHgb'
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, sy1GpvP5sykjQD99Qk.csHigh entropy of concatenated method names: 'qgemx9ioP8', 'THdmhJT3vU', 'i2amJ7R8OQ', 'gGnmYkCIb8', 'XySmVgSGWa', 'v5PmHNLxTu', 'nkjm5xAnIG', 'ekxmqFxjuZ', 'YRRmTnx5i6', 'noImSNR175'
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, upiNbaTanoqGwuHOo4.csHigh entropy of concatenated method names: 'seZgno9jR8', 'aT0g7M4sdO', 'v5fgs5qleg', 'BBngfcflmo', 'iVVg8Cp3AX', 'kLXgwm0itL', 'JJfgcUoCVg', 'vvtgN1U7m8', 'NQ2gZK9sAO', 'n2ygQujTEa'
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, q4aftM4AtQsbapyuPk.csHigh entropy of concatenated method names: 'ddhayMi7U', 'vd89TrQJY', 'pHhIOw34f', 'oA3Du6KaZ', 'tnxeG3n01', 'mIEL3UW4h', 'xybKZOegsKbBwcEhhc', 'IWjJbmkxu47heH7VNw', 'o8WuiQXK8', 'dCq11v6wO'
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, Lcd8pDGealQ37qgqu9.csHigh entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'hoD4Tuvmou', 'Egc4SERte0', 'Uyt4zDv9NB', 'e7nClqReOi', 'M1UCocZVOV', 'XYBC4jbeDu', 'reRCCIf269', 'GQYvGX22QMbwIyqvBkI'
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, HWJTxILa2hKmAs9UKT.csHigh entropy of concatenated method names: 'dt226rfK6R', 'eYO2DMWwvM', 'swxGsfhQLs', 'pAGGfvS3I3', 'trYG80m5YZ', 'YEmGwGMhtI', 'BwSGcq0ff3', 'WspGNaeZyo', 'ztPGZ3BTCG', 'IQKGQBru49'
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, j1XJLSm9pHAVyS6O18.csHigh entropy of concatenated method names: 'Dispose', 'gnkoThPipt', 'oHA472BYa9', 'tqB73sD7PD', 'NfnoSXmI6o', 'luqozQQDYf', 'ProcessDialogKey', 'B234lpiNba', 'zno4oqGwuH', 'oo444Rng5O'
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, RXUJZCXBVQq0i3NHhK.csHigh entropy of concatenated method names: 'aOdrPeXxLM', 'x28redQWGt', 'fCxrnXmwHR', 'wsTr79jr8B', 'pnBrfxVawR', 'efxr8spes2', 'XESrcudKcp', 'GTXrNfSqkr', 'msHrQw0DhH', 'Q6SrKNU4Eq'
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, CYmlYFZC7ZGi8p4Y5u.csHigh entropy of concatenated method names: 'ltyMbYUEu5', 'LLgMU7T8Ny', 'SugMaAIBrI', 'ttFM9gNhpX', 'bRYM6MEkVC', 'KMTMIc8tJu', 'YOWMDCRJSQ', 'ALWMP10Vjv', 'hJ1MeQIhaU', 'wF4MLMo1E6'
                Source: 0.2.Demande de devis. Quote Request.exe.1110000.0.raw.unpack, MgvEpvJbNF1gG3Xv3U.csHigh entropy of concatenated method names: 'ToString', 'HomFKhnEIT', 'a2SF7cQk1U', 'y71FspoYKF', 'Ey2FfTT3b9', 'X21F8qm5oQ', 'XpWFw5lmhk', 'awPFcGkhYO', 'vuVFNfV0c5', 'C2UFZ5X5ja'
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, F6q75icRv4YG6vlUG8.csHigh entropy of concatenated method names: 'TEMMpghY1Z', 'G2wMGHJ9hc', 'Do0MjJh5wN', 'DIOjShJrki', 'F91jzJFBga', 'MBbMlXPhrw', 'hqvMorOVHv', 'oEsM4Ct64g', 'GgrMCp0l6w', 'EhjMWsCc8g'
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, VWO7wBYyTEIld6VSI0.csHigh entropy of concatenated method names: 'FgFdAEfck2', 'Ceudtt2XRD', 'ToString', 'ebddpZtx4F', 'sq8dmEyPoW', 'bbGdGvkpKP', 'gqud2YtjTT', 'WZadjjNgEG', 'WqFdMkXPPV', 'OSkdRRbwyo'
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, ELHXS4olZudFNbq48lV.csHigh entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'uBs1KaXiZg', 'j6K1i5UXUi', 'Dyk1Xo19V6', 'nao1xLJw0G', 'POq1hV1swb', 'WpX1JoSOO0', 'kDq1YiZ8LR'
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, iUrjerWNLQN0TgnlBG.csHigh entropy of concatenated method names: 'Bf1oMy1Gpv', 'WsyoRkjQD9', 'uU9oAakQk4', 'zVjotpsWJT', 'I9UoOKTpXW', 'ajioFL4Loh', 'BrwFt4iOs6LBSgWAqd', 'VrqZfBDRSbTT0wl1Xj', 'Kouoodu0kZ', 'ldfoCBMrYc'
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, OBhSiQoWmimGYqKTK5k.csHigh entropy of concatenated method names: 'CanConvertFrom', 'ConvertFrom', 'ConvertTo', 'ChL3g7kXOP', 'bSj31ueJy7', 'ifF3yUB7oc', 'Glc33ty7Sr', 'Rcl3Eh9dEZ', 'qVH3kx1x55', 'TvM3vJFQx5'
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, zwj0ayz2qvp1WgAXco.csHigh entropy of concatenated method names: 'L7N1IvfDyv', 'EQl1PMhRmQ', 'vBC1evDOZ2', 'bkn1nnKDUf', 'tFE17Dl6fY', 'r8t1fIBJ76', 'FKx1858YpE', 'zCy1vZ13Bp', 'bLM1bj6igH', 'N1Z1UlRqqg'
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, vMpmh25ViGnkhPiptQ.csHigh entropy of concatenated method names: 'CWtgOxAjmk', 'Fxmgdsv1Ek', 'xiNggDRKDE', 'i8igynOJe4', 'fFVgEtd8Aj', 'OjtgvcVOVn', 'Dispose', 'P0qupr2SrV', 'pOhumcjJuM', 'TILuGR8HNR'
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, XFw8sdooseVVIrehrv2.csHigh entropy of concatenated method names: 'Yh81SeIf4T', 'dod1zqEtrp', 'gUCylmBSgG', 'NOFyoJMkhS', 'bv2y46KTLS', 'BIkyCnNZvB', 'Jf2yWuUgnp', 'RJMy03Crrk', 'iBSypm61tb', 'uOuymuhA8v'
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, HAQKDWoCnDIpjYN7rXc.csHigh entropy of concatenated method names: 'aMvySqQmwL', 'jhlyzI1FCc', 'fKD3lgD78V', 'bZW7cWm2UvqxSqdN9kG', 'Vbs6ddmHKlZPvDZTAqQ', 'CJBIugmfpVreGyXm452'
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, CUpMJCHZ44E4RPwRjr.csHigh entropy of concatenated method names: 'JFudq3HSaX', 'LmfdSxUG18', 'NHRul5Zkl8', 'tjouod9wBu', 'z8bdKM1ewb', 'yL0ditDq29', 'jkAdXUt1Y0', 'LL0dx3IhIh', 'Nn7dhiLhgU', 'qwbdJVLDuF'
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, vcQuV5ROCbimuK7ZC6.csHigh entropy of concatenated method names: 'VfIC0ACXmA', 'uq6Cpwqt0W', 'x3sCm24ARw', 'l3OCGf0ADp', 'sLxC2jPM9I', 'RMiCjWc9cX', 'WOjCMmArbT', 'lx6CRO2Odp', 'FoDCBdL6vC', 'zQWCA9XSJ7'
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, kwMTV3eU9akQk4aVjp.csHigh entropy of concatenated method names: 'kAeG99l5R0', 'y3GGInyYjL', 'nBRGP96ha3', 'GegGefWki7', 'rkDGOSgMCl', 'IB9GFJ1sNL', 'PD1GdjY6Nt', 'zwOGu1BVn3', 'lPmGgsvPC4', 'FwAG163mxX'
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, fXWljinL4LohrLS6kV.csHigh entropy of concatenated method names: 'Cwfj013t6G', 'x7Sjm4nyNB', 'viKj2OEGun', 'DOfjMsdcTs', 'gqGjRUMBfM', 'Flj2VQ9Z8p', 'knN2HhbLWb', 'gMk25tA6cT', 'wGW2qqg3PT', 'wTw2TGZHgb'
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, sy1GpvP5sykjQD99Qk.csHigh entropy of concatenated method names: 'qgemx9ioP8', 'THdmhJT3vU', 'i2amJ7R8OQ', 'gGnmYkCIb8', 'XySmVgSGWa', 'v5PmHNLxTu', 'nkjm5xAnIG', 'ekxmqFxjuZ', 'YRRmTnx5i6', 'noImSNR175'
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, upiNbaTanoqGwuHOo4.csHigh entropy of concatenated method names: 'seZgno9jR8', 'aT0g7M4sdO', 'v5fgs5qleg', 'BBngfcflmo', 'iVVg8Cp3AX', 'kLXgwm0itL', 'JJfgcUoCVg', 'vvtgN1U7m8', 'NQ2gZK9sAO', 'n2ygQujTEa'
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, q4aftM4AtQsbapyuPk.csHigh entropy of concatenated method names: 'ddhayMi7U', 'vd89TrQJY', 'pHhIOw34f', 'oA3Du6KaZ', 'tnxeG3n01', 'mIEL3UW4h', 'xybKZOegsKbBwcEhhc', 'IWjJbmkxu47heH7VNw', 'o8WuiQXK8', 'dCq11v6wO'
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, Lcd8pDGealQ37qgqu9.csHigh entropy of concatenated method names: 'EditValue', 'GetEditStyle', 'hoD4Tuvmou', 'Egc4SERte0', 'Uyt4zDv9NB', 'e7nClqReOi', 'M1UCocZVOV', 'XYBC4jbeDu', 'reRCCIf269', 'GQYvGX22QMbwIyqvBkI'
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, HWJTxILa2hKmAs9UKT.csHigh entropy of concatenated method names: 'dt226rfK6R', 'eYO2DMWwvM', 'swxGsfhQLs', 'pAGGfvS3I3', 'trYG80m5YZ', 'YEmGwGMhtI', 'BwSGcq0ff3', 'WspGNaeZyo', 'ztPGZ3BTCG', 'IQKGQBru49'
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, j1XJLSm9pHAVyS6O18.csHigh entropy of concatenated method names: 'Dispose', 'gnkoThPipt', 'oHA472BYa9', 'tqB73sD7PD', 'NfnoSXmI6o', 'luqozQQDYf', 'ProcessDialogKey', 'B234lpiNba', 'zno4oqGwuH', 'oo444Rng5O'
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, RXUJZCXBVQq0i3NHhK.csHigh entropy of concatenated method names: 'aOdrPeXxLM', 'x28redQWGt', 'fCxrnXmwHR', 'wsTr79jr8B', 'pnBrfxVawR', 'efxr8spes2', 'XESrcudKcp', 'GTXrNfSqkr', 'msHrQw0DhH', 'Q6SrKNU4Eq'
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, CYmlYFZC7ZGi8p4Y5u.csHigh entropy of concatenated method names: 'ltyMbYUEu5', 'LLgMU7T8Ny', 'SugMaAIBrI', 'ttFM9gNhpX', 'bRYM6MEkVC', 'KMTMIc8tJu', 'YOWMDCRJSQ', 'ALWMP10Vjv', 'hJ1MeQIhaU', 'wF4MLMo1E6'
                Source: 0.2.Demande de devis. Quote Request.exe.46c4c38.3.raw.unpack, MgvEpvJbNF1gG3Xv3U.csHigh entropy of concatenated method names: 'ToString', 'HomFKhnEIT', 'a2SF7cQk1U', 'y71FspoYKF', 'Ey2FfTT3b9', 'X21F8qm5oQ', 'XpWFw5lmhk', 'awPFcGkhYO', 'vuVFNfV0c5', 'C2UFZ5X5ja'
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior

                Malware Analysis System Evasion

                barindex
                Source: Yara matchFile source: Process Memory Space: Demande de devis. Quote Request.exe PID: 6608, type: MEMORYSTR
                Source: C:\Windows\SysWOW64\timeout.exeAPI/Special instruction interceptor: Address: 7FFB2CECD324
                Source: C:\Windows\SysWOW64\timeout.exeAPI/Special instruction interceptor: Address: 7FFB2CECD7E4
                Source: C:\Windows\SysWOW64\timeout.exeAPI/Special instruction interceptor: Address: 7FFB2CECD944
                Source: C:\Windows\SysWOW64\timeout.exeAPI/Special instruction interceptor: Address: 7FFB2CECD504
                Source: C:\Windows\SysWOW64\timeout.exeAPI/Special instruction interceptor: Address: 7FFB2CECD544
                Source: C:\Windows\SysWOW64\timeout.exeAPI/Special instruction interceptor: Address: 7FFB2CECD1E4
                Source: C:\Windows\SysWOW64\timeout.exeAPI/Special instruction interceptor: Address: 7FFB2CED0154
                Source: C:\Windows\SysWOW64\timeout.exeAPI/Special instruction interceptor: Address: 7FFB2CECDA44
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeMemory allocated: 1110000 memory reserve | memory write watchJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeMemory allocated: 2C20000 memory reserve | memory write watchJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeMemory allocated: 1110000 memory reserve | memory write watchJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeMemory allocated: 7980000 memory reserve | memory write watchJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeMemory allocated: 75A0000 memory reserve | memory write watchJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeMemory allocated: 8980000 memory reserve | memory write watchJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeMemory allocated: 9980000 memory reserve | memory write watchJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeMemory allocated: A1E0000 memory reserve | memory write watchJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeMemory allocated: B1E0000 memory reserve | memory write watchJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeMemory allocated: C1E0000 memory reserve | memory write watchJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0153096E rdtsc 3_2_0153096E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeThread delayed: delay time: 922337203685477Jump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeWindow / User API: threadDelayed 2598Jump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeWindow / User API: threadDelayed 7375Jump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeAPI coverage: 0.7 %
                Source: C:\Windows\SysWOW64\timeout.exeAPI coverage: 2.6 %
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exe TID: 1448Thread sleep time: -922337203685477s >= -30000sJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exe TID: 1252Thread sleep count: 2598 > 30Jump to behavior
                Source: C:\Windows\SysWOW64\timeout.exe TID: 1252Thread sleep time: -5196000s >= -30000sJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exe TID: 1252Thread sleep count: 7375 > 30Jump to behavior
                Source: C:\Windows\SysWOW64\timeout.exe TID: 1252Thread sleep time: -14750000s >= -30000sJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exe TID: 1624Thread sleep time: -65000s >= -30000sJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exe TID: 1624Thread sleep count: 37 > 30Jump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exe TID: 1624Thread sleep time: -55500s >= -30000sJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exe TID: 1624Thread sleep count: 38 > 30Jump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exe TID: 1624Thread sleep time: -38000s >= -30000sJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeLast function: Thread delayed
                Source: C:\Windows\SysWOW64\timeout.exeLast function: Thread delayed
                Source: C:\Windows\SysWOW64\timeout.exeCode function: 8_2_02B6CE70 FindFirstFileW,FindNextFileW,FindClose,8_2_02B6CE70
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeThread delayed: delay time: 922337203685477Jump to behavior
                Source: timeout.exe, 00000008.00000002.3763645708.0000000007EF2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: formVMware20,11696492231
                Source: s47R9_107.8.drBinary or memory string: Interactive Brokers - GDCDYNVMware20,11696492231p
                Source: s47R9_107.8.drBinary or memory string: Interactive Brokers - EU WestVMware20,11696492231n
                Source: s47R9_107.8.drBinary or memory string: Canara Transaction PasswordVMware20,11696492231}
                Source: s47R9_107.8.drBinary or memory string: interactivebrokers.co.inVMware20,11696492231d
                Source: s47R9_107.8.drBinary or memory string: netportal.hdfcbank.comVMware20,11696492231
                Source: s47R9_107.8.drBinary or memory string: outlook.office.comVMware20,11696492231s
                Source: timeout.exe, 00000008.00000002.3763645708.0000000007EF2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - GDCDYNVMware20,116
                Source: s47R9_107.8.drBinary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696492231
                Source: s47R9_107.8.drBinary or memory string: AMC password management pageVMware20,11696492231
                Source: s47R9_107.8.drBinary or memory string: interactivebrokers.comVMware20,11696492231
                Source: s47R9_107.8.drBinary or memory string: microsoft.visualstudio.comVMware20,11696492231x
                Source: timeout.exe, 00000008.00000002.3763645708.0000000007EF2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: ive Brokers - NDCDYNVMware20,116
                Source: s47R9_107.8.drBinary or memory string: Interactive Brokers - COM.HKVMware20,11696492231
                Source: s47R9_107.8.drBinary or memory string: Canara Change Transaction PasswordVMware20,11696492231^
                Source: s47R9_107.8.drBinary or memory string: Test URL for global passwords blocklistVMware20,11696492231
                Source: s47R9_107.8.drBinary or memory string: outlook.office365.comVMware20,11696492231t
                Source: s47R9_107.8.drBinary or memory string: Interactive Brokers - NDCDYNVMware20,11696492231z
                Source: s47R9_107.8.drBinary or memory string: discord.comVMware20,11696492231f
                Source: timeout.exe, 00000008.00000002.3757307349.00000000030A5000.00000004.00000020.00020000.00000000.sdmp, V8sJoOh7MX.exe, 00000009.00000002.3758546834.0000000000889000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
                Source: firefox.exe, 0000000B.00000002.1964229819.00000279EFEEC000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllss
                Source: s47R9_107.8.drBinary or memory string: global block list test formVMware20,11696492231
                Source: timeout.exe, 00000008.00000002.3763645708.0000000007EF2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: outlook.office.comVMware20,^
                Source: s47R9_107.8.drBinary or memory string: dev.azure.comVMware20,11696492231j
                Source: s47R9_107.8.drBinary or memory string: www.interactivebrokers.comVMware20,11696492231}
                Source: s47R9_107.8.drBinary or memory string: www.interactivebrokers.co.inVMware20,11696492231~
                Source: s47R9_107.8.drBinary or memory string: bankofamerica.comVMware20,11696492231x
                Source: s47R9_107.8.drBinary or memory string: trackpan.utiitsl.comVMware20,11696492231h
                Source: s47R9_107.8.drBinary or memory string: tasks.office.comVMware20,11696492231o
                Source: timeout.exe, 00000008.00000002.3763645708.0000000007EF2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: microsoft.visualstudio.comVMware20,116!
                Source: timeout.exe, 00000008.00000002.3763645708.0000000007EF2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Transaction PasswordVMware20,11696492231}
                Source: s47R9_107.8.drBinary or memory string: account.microsoft.com/profileVMware20,11696492231u
                Source: s47R9_107.8.drBinary or memory string: Canara Change Transaction PasswordVMware20,11696492231
                Source: timeout.exe, 00000008.00000002.3763645708.0000000007EF2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: blocklistVMware20,11696492231
                Source: s47R9_107.8.drBinary or memory string: Interactive Brokers - EU East & CentralVMware20,11696492231
                Source: s47R9_107.8.drBinary or memory string: ms.portal.azure.comVMware20,11696492231
                Source: timeout.exe, 00000008.00000002.3763645708.0000000007EF2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: AMC password management pageVMware20,11696492231f
                Source: s47R9_107.8.drBinary or memory string: turbotax.intuit.comVMware20,11696492231t
                Source: s47R9_107.8.drBinary or memory string: secure.bankofamerica.comVMware20,11696492231|UE
                Source: s47R9_107.8.drBinary or memory string: Canara Transaction PasswordVMware20,11696492231x
                Source: s47R9_107.8.drBinary or memory string: Interactive Brokers - HKVMware20,11696492231]
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess information queried: ProcessInformationJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess queried: DebugPortJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeProcess queried: DebugPortJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0153096E rdtsc 3_2_0153096E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_00418023 LdrLoadDll,3_2_00418023
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01588158 mov eax, dword ptr fs:[00000030h]3_2_01588158
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014EC156 mov eax, dword ptr fs:[00000030h]3_2_014EC156
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F6154 mov eax, dword ptr fs:[00000030h]3_2_014F6154
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F6154 mov eax, dword ptr fs:[00000030h]3_2_014F6154
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01584144 mov eax, dword ptr fs:[00000030h]3_2_01584144
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01584144 mov eax, dword ptr fs:[00000030h]3_2_01584144
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01584144 mov ecx, dword ptr fs:[00000030h]3_2_01584144
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01584144 mov eax, dword ptr fs:[00000030h]3_2_01584144
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01584144 mov eax, dword ptr fs:[00000030h]3_2_01584144
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159A118 mov ecx, dword ptr fs:[00000030h]3_2_0159A118
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159A118 mov eax, dword ptr fs:[00000030h]3_2_0159A118
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159A118 mov eax, dword ptr fs:[00000030h]3_2_0159A118
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159A118 mov eax, dword ptr fs:[00000030h]3_2_0159A118
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015B0115 mov eax, dword ptr fs:[00000030h]3_2_015B0115
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159E10E mov eax, dword ptr fs:[00000030h]3_2_0159E10E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159E10E mov ecx, dword ptr fs:[00000030h]3_2_0159E10E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159E10E mov eax, dword ptr fs:[00000030h]3_2_0159E10E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159E10E mov eax, dword ptr fs:[00000030h]3_2_0159E10E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159E10E mov ecx, dword ptr fs:[00000030h]3_2_0159E10E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159E10E mov eax, dword ptr fs:[00000030h]3_2_0159E10E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159E10E mov eax, dword ptr fs:[00000030h]3_2_0159E10E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159E10E mov ecx, dword ptr fs:[00000030h]3_2_0159E10E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159E10E mov eax, dword ptr fs:[00000030h]3_2_0159E10E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159E10E mov ecx, dword ptr fs:[00000030h]3_2_0159E10E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01520124 mov eax, dword ptr fs:[00000030h]3_2_01520124
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0156E1D0 mov eax, dword ptr fs:[00000030h]3_2_0156E1D0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0156E1D0 mov eax, dword ptr fs:[00000030h]3_2_0156E1D0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0156E1D0 mov ecx, dword ptr fs:[00000030h]3_2_0156E1D0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0156E1D0 mov eax, dword ptr fs:[00000030h]3_2_0156E1D0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0156E1D0 mov eax, dword ptr fs:[00000030h]3_2_0156E1D0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015B61C3 mov eax, dword ptr fs:[00000030h]3_2_015B61C3
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015B61C3 mov eax, dword ptr fs:[00000030h]3_2_015B61C3
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015201F8 mov eax, dword ptr fs:[00000030h]3_2_015201F8
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015C61E5 mov eax, dword ptr fs:[00000030h]3_2_015C61E5
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0157019F mov eax, dword ptr fs:[00000030h]3_2_0157019F
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0157019F mov eax, dword ptr fs:[00000030h]3_2_0157019F
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0157019F mov eax, dword ptr fs:[00000030h]3_2_0157019F
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0157019F mov eax, dword ptr fs:[00000030h]3_2_0157019F
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015AC188 mov eax, dword ptr fs:[00000030h]3_2_015AC188
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015AC188 mov eax, dword ptr fs:[00000030h]3_2_015AC188
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01530185 mov eax, dword ptr fs:[00000030h]3_2_01530185
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014EA197 mov eax, dword ptr fs:[00000030h]3_2_014EA197
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014EA197 mov eax, dword ptr fs:[00000030h]3_2_014EA197
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014EA197 mov eax, dword ptr fs:[00000030h]3_2_014EA197
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01594180 mov eax, dword ptr fs:[00000030h]3_2_01594180
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01594180 mov eax, dword ptr fs:[00000030h]3_2_01594180
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01576050 mov eax, dword ptr fs:[00000030h]3_2_01576050
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F2050 mov eax, dword ptr fs:[00000030h]3_2_014F2050
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151C073 mov eax, dword ptr fs:[00000030h]3_2_0151C073
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0150E016 mov eax, dword ptr fs:[00000030h]3_2_0150E016
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0150E016 mov eax, dword ptr fs:[00000030h]3_2_0150E016
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0150E016 mov eax, dword ptr fs:[00000030h]3_2_0150E016
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0150E016 mov eax, dword ptr fs:[00000030h]3_2_0150E016
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01574000 mov ecx, dword ptr fs:[00000030h]3_2_01574000
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01592000 mov eax, dword ptr fs:[00000030h]3_2_01592000
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01592000 mov eax, dword ptr fs:[00000030h]3_2_01592000
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01592000 mov eax, dword ptr fs:[00000030h]3_2_01592000
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01592000 mov eax, dword ptr fs:[00000030h]3_2_01592000
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01592000 mov eax, dword ptr fs:[00000030h]3_2_01592000
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01592000 mov eax, dword ptr fs:[00000030h]3_2_01592000
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01592000 mov eax, dword ptr fs:[00000030h]3_2_01592000
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01592000 mov eax, dword ptr fs:[00000030h]3_2_01592000
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01586030 mov eax, dword ptr fs:[00000030h]3_2_01586030
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014EA020 mov eax, dword ptr fs:[00000030h]3_2_014EA020
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014EC020 mov eax, dword ptr fs:[00000030h]3_2_014EC020
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015720DE mov eax, dword ptr fs:[00000030h]3_2_015720DE
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015320F0 mov ecx, dword ptr fs:[00000030h]3_2_015320F0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F80E9 mov eax, dword ptr fs:[00000030h]3_2_014F80E9
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014EA0E3 mov ecx, dword ptr fs:[00000030h]3_2_014EA0E3
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015760E0 mov eax, dword ptr fs:[00000030h]3_2_015760E0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014EC0F0 mov eax, dword ptr fs:[00000030h]3_2_014EC0F0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F208A mov eax, dword ptr fs:[00000030h]3_2_014F208A
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015B60B8 mov eax, dword ptr fs:[00000030h]3_2_015B60B8
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015B60B8 mov ecx, dword ptr fs:[00000030h]3_2_015B60B8
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015880A8 mov eax, dword ptr fs:[00000030h]3_2_015880A8
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015BA352 mov eax, dword ptr fs:[00000030h]3_2_015BA352
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01598350 mov ecx, dword ptr fs:[00000030h]3_2_01598350
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0157035C mov eax, dword ptr fs:[00000030h]3_2_0157035C
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0157035C mov eax, dword ptr fs:[00000030h]3_2_0157035C
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0157035C mov eax, dword ptr fs:[00000030h]3_2_0157035C
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0157035C mov ecx, dword ptr fs:[00000030h]3_2_0157035C
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0157035C mov eax, dword ptr fs:[00000030h]3_2_0157035C
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0157035C mov eax, dword ptr fs:[00000030h]3_2_0157035C
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01572349 mov eax, dword ptr fs:[00000030h]3_2_01572349
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01572349 mov eax, dword ptr fs:[00000030h]3_2_01572349
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01572349 mov eax, dword ptr fs:[00000030h]3_2_01572349
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01572349 mov eax, dword ptr fs:[00000030h]3_2_01572349
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01572349 mov eax, dword ptr fs:[00000030h]3_2_01572349
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01572349 mov eax, dword ptr fs:[00000030h]3_2_01572349
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01572349 mov eax, dword ptr fs:[00000030h]3_2_01572349
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01572349 mov eax, dword ptr fs:[00000030h]3_2_01572349
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01572349 mov eax, dword ptr fs:[00000030h]3_2_01572349
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01572349 mov eax, dword ptr fs:[00000030h]3_2_01572349
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01572349 mov eax, dword ptr fs:[00000030h]3_2_01572349
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01572349 mov eax, dword ptr fs:[00000030h]3_2_01572349
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01572349 mov eax, dword ptr fs:[00000030h]3_2_01572349
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01572349 mov eax, dword ptr fs:[00000030h]3_2_01572349
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01572349 mov eax, dword ptr fs:[00000030h]3_2_01572349
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159437C mov eax, dword ptr fs:[00000030h]3_2_0159437C
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01510310 mov ecx, dword ptr fs:[00000030h]3_2_01510310
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152A30B mov eax, dword ptr fs:[00000030h]3_2_0152A30B
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152A30B mov eax, dword ptr fs:[00000030h]3_2_0152A30B
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152A30B mov eax, dword ptr fs:[00000030h]3_2_0152A30B
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014EC310 mov ecx, dword ptr fs:[00000030h]3_2_014EC310
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159E3DB mov eax, dword ptr fs:[00000030h]3_2_0159E3DB
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159E3DB mov eax, dword ptr fs:[00000030h]3_2_0159E3DB
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159E3DB mov ecx, dword ptr fs:[00000030h]3_2_0159E3DB
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159E3DB mov eax, dword ptr fs:[00000030h]3_2_0159E3DB
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015943D4 mov eax, dword ptr fs:[00000030h]3_2_015943D4
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015943D4 mov eax, dword ptr fs:[00000030h]3_2_015943D4
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FA3C0 mov eax, dword ptr fs:[00000030h]3_2_014FA3C0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FA3C0 mov eax, dword ptr fs:[00000030h]3_2_014FA3C0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FA3C0 mov eax, dword ptr fs:[00000030h]3_2_014FA3C0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FA3C0 mov eax, dword ptr fs:[00000030h]3_2_014FA3C0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FA3C0 mov eax, dword ptr fs:[00000030h]3_2_014FA3C0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FA3C0 mov eax, dword ptr fs:[00000030h]3_2_014FA3C0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F83C0 mov eax, dword ptr fs:[00000030h]3_2_014F83C0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F83C0 mov eax, dword ptr fs:[00000030h]3_2_014F83C0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F83C0 mov eax, dword ptr fs:[00000030h]3_2_014F83C0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F83C0 mov eax, dword ptr fs:[00000030h]3_2_014F83C0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015AC3CD mov eax, dword ptr fs:[00000030h]3_2_015AC3CD
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015763C0 mov eax, dword ptr fs:[00000030h]3_2_015763C0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0150E3F0 mov eax, dword ptr fs:[00000030h]3_2_0150E3F0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0150E3F0 mov eax, dword ptr fs:[00000030h]3_2_0150E3F0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0150E3F0 mov eax, dword ptr fs:[00000030h]3_2_0150E3F0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015263FF mov eax, dword ptr fs:[00000030h]3_2_015263FF
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015003E9 mov eax, dword ptr fs:[00000030h]3_2_015003E9
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015003E9 mov eax, dword ptr fs:[00000030h]3_2_015003E9
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015003E9 mov eax, dword ptr fs:[00000030h]3_2_015003E9
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015003E9 mov eax, dword ptr fs:[00000030h]3_2_015003E9
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015003E9 mov eax, dword ptr fs:[00000030h]3_2_015003E9
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015003E9 mov eax, dword ptr fs:[00000030h]3_2_015003E9
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015003E9 mov eax, dword ptr fs:[00000030h]3_2_015003E9
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015003E9 mov eax, dword ptr fs:[00000030h]3_2_015003E9
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014EE388 mov eax, dword ptr fs:[00000030h]3_2_014EE388
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014EE388 mov eax, dword ptr fs:[00000030h]3_2_014EE388
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014EE388 mov eax, dword ptr fs:[00000030h]3_2_014EE388
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014E8397 mov eax, dword ptr fs:[00000030h]3_2_014E8397
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014E8397 mov eax, dword ptr fs:[00000030h]3_2_014E8397
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014E8397 mov eax, dword ptr fs:[00000030h]3_2_014E8397
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151438F mov eax, dword ptr fs:[00000030h]3_2_0151438F
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151438F mov eax, dword ptr fs:[00000030h]3_2_0151438F
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015AA250 mov eax, dword ptr fs:[00000030h]3_2_015AA250
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015AA250 mov eax, dword ptr fs:[00000030h]3_2_015AA250
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01578243 mov eax, dword ptr fs:[00000030h]3_2_01578243
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01578243 mov ecx, dword ptr fs:[00000030h]3_2_01578243
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F6259 mov eax, dword ptr fs:[00000030h]3_2_014F6259
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014EA250 mov eax, dword ptr fs:[00000030h]3_2_014EA250
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014E826B mov eax, dword ptr fs:[00000030h]3_2_014E826B
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015A0274 mov eax, dword ptr fs:[00000030h]3_2_015A0274
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015A0274 mov eax, dword ptr fs:[00000030h]3_2_015A0274
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015A0274 mov eax, dword ptr fs:[00000030h]3_2_015A0274
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015A0274 mov eax, dword ptr fs:[00000030h]3_2_015A0274
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015A0274 mov eax, dword ptr fs:[00000030h]3_2_015A0274
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015A0274 mov eax, dword ptr fs:[00000030h]3_2_015A0274
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015A0274 mov eax, dword ptr fs:[00000030h]3_2_015A0274
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015A0274 mov eax, dword ptr fs:[00000030h]3_2_015A0274
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015A0274 mov eax, dword ptr fs:[00000030h]3_2_015A0274
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015A0274 mov eax, dword ptr fs:[00000030h]3_2_015A0274
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015A0274 mov eax, dword ptr fs:[00000030h]3_2_015A0274
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015A0274 mov eax, dword ptr fs:[00000030h]3_2_015A0274
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F4260 mov eax, dword ptr fs:[00000030h]3_2_014F4260
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F4260 mov eax, dword ptr fs:[00000030h]3_2_014F4260
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F4260 mov eax, dword ptr fs:[00000030h]3_2_014F4260
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014E823B mov eax, dword ptr fs:[00000030h]3_2_014E823B
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FA2C3 mov eax, dword ptr fs:[00000030h]3_2_014FA2C3
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FA2C3 mov eax, dword ptr fs:[00000030h]3_2_014FA2C3
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FA2C3 mov eax, dword ptr fs:[00000030h]3_2_014FA2C3
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FA2C3 mov eax, dword ptr fs:[00000030h]3_2_014FA2C3
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FA2C3 mov eax, dword ptr fs:[00000030h]3_2_014FA2C3
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015002E1 mov eax, dword ptr fs:[00000030h]3_2_015002E1
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015002E1 mov eax, dword ptr fs:[00000030h]3_2_015002E1
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015002E1 mov eax, dword ptr fs:[00000030h]3_2_015002E1
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01570283 mov eax, dword ptr fs:[00000030h]3_2_01570283
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01570283 mov eax, dword ptr fs:[00000030h]3_2_01570283
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01570283 mov eax, dword ptr fs:[00000030h]3_2_01570283
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152E284 mov eax, dword ptr fs:[00000030h]3_2_0152E284
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152E284 mov eax, dword ptr fs:[00000030h]3_2_0152E284
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015002A0 mov eax, dword ptr fs:[00000030h]3_2_015002A0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015002A0 mov eax, dword ptr fs:[00000030h]3_2_015002A0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015862A0 mov eax, dword ptr fs:[00000030h]3_2_015862A0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015862A0 mov ecx, dword ptr fs:[00000030h]3_2_015862A0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015862A0 mov eax, dword ptr fs:[00000030h]3_2_015862A0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015862A0 mov eax, dword ptr fs:[00000030h]3_2_015862A0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015862A0 mov eax, dword ptr fs:[00000030h]3_2_015862A0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015862A0 mov eax, dword ptr fs:[00000030h]3_2_015862A0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F8550 mov eax, dword ptr fs:[00000030h]3_2_014F8550
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F8550 mov eax, dword ptr fs:[00000030h]3_2_014F8550
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152656A mov eax, dword ptr fs:[00000030h]3_2_0152656A
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152656A mov eax, dword ptr fs:[00000030h]3_2_0152656A
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152656A mov eax, dword ptr fs:[00000030h]3_2_0152656A
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01586500 mov eax, dword ptr fs:[00000030h]3_2_01586500
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015C4500 mov eax, dword ptr fs:[00000030h]3_2_015C4500
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015C4500 mov eax, dword ptr fs:[00000030h]3_2_015C4500
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015C4500 mov eax, dword ptr fs:[00000030h]3_2_015C4500
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015C4500 mov eax, dword ptr fs:[00000030h]3_2_015C4500
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015C4500 mov eax, dword ptr fs:[00000030h]3_2_015C4500
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015C4500 mov eax, dword ptr fs:[00000030h]3_2_015C4500
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015C4500 mov eax, dword ptr fs:[00000030h]3_2_015C4500
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01500535 mov eax, dword ptr fs:[00000030h]3_2_01500535
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01500535 mov eax, dword ptr fs:[00000030h]3_2_01500535
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01500535 mov eax, dword ptr fs:[00000030h]3_2_01500535
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01500535 mov eax, dword ptr fs:[00000030h]3_2_01500535
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01500535 mov eax, dword ptr fs:[00000030h]3_2_01500535
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01500535 mov eax, dword ptr fs:[00000030h]3_2_01500535
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151E53E mov eax, dword ptr fs:[00000030h]3_2_0151E53E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151E53E mov eax, dword ptr fs:[00000030h]3_2_0151E53E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151E53E mov eax, dword ptr fs:[00000030h]3_2_0151E53E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151E53E mov eax, dword ptr fs:[00000030h]3_2_0151E53E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151E53E mov eax, dword ptr fs:[00000030h]3_2_0151E53E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152A5D0 mov eax, dword ptr fs:[00000030h]3_2_0152A5D0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152A5D0 mov eax, dword ptr fs:[00000030h]3_2_0152A5D0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152E5CF mov eax, dword ptr fs:[00000030h]3_2_0152E5CF
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152E5CF mov eax, dword ptr fs:[00000030h]3_2_0152E5CF
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F65D0 mov eax, dword ptr fs:[00000030h]3_2_014F65D0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F25E0 mov eax, dword ptr fs:[00000030h]3_2_014F25E0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151E5E7 mov eax, dword ptr fs:[00000030h]3_2_0151E5E7
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151E5E7 mov eax, dword ptr fs:[00000030h]3_2_0151E5E7
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151E5E7 mov eax, dword ptr fs:[00000030h]3_2_0151E5E7
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151E5E7 mov eax, dword ptr fs:[00000030h]3_2_0151E5E7
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151E5E7 mov eax, dword ptr fs:[00000030h]3_2_0151E5E7
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151E5E7 mov eax, dword ptr fs:[00000030h]3_2_0151E5E7
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151E5E7 mov eax, dword ptr fs:[00000030h]3_2_0151E5E7
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151E5E7 mov eax, dword ptr fs:[00000030h]3_2_0151E5E7
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152C5ED mov eax, dword ptr fs:[00000030h]3_2_0152C5ED
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152C5ED mov eax, dword ptr fs:[00000030h]3_2_0152C5ED
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F2582 mov eax, dword ptr fs:[00000030h]3_2_014F2582
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F2582 mov ecx, dword ptr fs:[00000030h]3_2_014F2582
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152E59C mov eax, dword ptr fs:[00000030h]3_2_0152E59C
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01524588 mov eax, dword ptr fs:[00000030h]3_2_01524588
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015145B1 mov eax, dword ptr fs:[00000030h]3_2_015145B1
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015145B1 mov eax, dword ptr fs:[00000030h]3_2_015145B1
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015705A7 mov eax, dword ptr fs:[00000030h]3_2_015705A7
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015705A7 mov eax, dword ptr fs:[00000030h]3_2_015705A7
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015705A7 mov eax, dword ptr fs:[00000030h]3_2_015705A7
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151245A mov eax, dword ptr fs:[00000030h]3_2_0151245A
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015AA456 mov eax, dword ptr fs:[00000030h]3_2_015AA456
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152E443 mov eax, dword ptr fs:[00000030h]3_2_0152E443
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152E443 mov eax, dword ptr fs:[00000030h]3_2_0152E443
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152E443 mov eax, dword ptr fs:[00000030h]3_2_0152E443
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152E443 mov eax, dword ptr fs:[00000030h]3_2_0152E443
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152E443 mov eax, dword ptr fs:[00000030h]3_2_0152E443
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152E443 mov eax, dword ptr fs:[00000030h]3_2_0152E443
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152E443 mov eax, dword ptr fs:[00000030h]3_2_0152E443
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152E443 mov eax, dword ptr fs:[00000030h]3_2_0152E443
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014E645D mov eax, dword ptr fs:[00000030h]3_2_014E645D
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151A470 mov eax, dword ptr fs:[00000030h]3_2_0151A470
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151A470 mov eax, dword ptr fs:[00000030h]3_2_0151A470
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151A470 mov eax, dword ptr fs:[00000030h]3_2_0151A470
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0157C460 mov ecx, dword ptr fs:[00000030h]3_2_0157C460
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01528402 mov eax, dword ptr fs:[00000030h]3_2_01528402
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01528402 mov eax, dword ptr fs:[00000030h]3_2_01528402
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01528402 mov eax, dword ptr fs:[00000030h]3_2_01528402
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152A430 mov eax, dword ptr fs:[00000030h]3_2_0152A430
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014EC427 mov eax, dword ptr fs:[00000030h]3_2_014EC427
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014EE420 mov eax, dword ptr fs:[00000030h]3_2_014EE420
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014EE420 mov eax, dword ptr fs:[00000030h]3_2_014EE420
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014EE420 mov eax, dword ptr fs:[00000030h]3_2_014EE420
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01576420 mov eax, dword ptr fs:[00000030h]3_2_01576420
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01576420 mov eax, dword ptr fs:[00000030h]3_2_01576420
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01576420 mov eax, dword ptr fs:[00000030h]3_2_01576420
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01576420 mov eax, dword ptr fs:[00000030h]3_2_01576420
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01576420 mov eax, dword ptr fs:[00000030h]3_2_01576420
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01576420 mov eax, dword ptr fs:[00000030h]3_2_01576420
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01576420 mov eax, dword ptr fs:[00000030h]3_2_01576420
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F04E5 mov ecx, dword ptr fs:[00000030h]3_2_014F04E5
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015AA49A mov eax, dword ptr fs:[00000030h]3_2_015AA49A
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015244B0 mov ecx, dword ptr fs:[00000030h]3_2_015244B0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F64AB mov eax, dword ptr fs:[00000030h]3_2_014F64AB
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0157A4B0 mov eax, dword ptr fs:[00000030h]3_2_0157A4B0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01574755 mov eax, dword ptr fs:[00000030h]3_2_01574755
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532750 mov eax, dword ptr fs:[00000030h]3_2_01532750
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532750 mov eax, dword ptr fs:[00000030h]3_2_01532750
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0157E75D mov eax, dword ptr fs:[00000030h]3_2_0157E75D
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152674D mov esi, dword ptr fs:[00000030h]3_2_0152674D
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152674D mov eax, dword ptr fs:[00000030h]3_2_0152674D
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152674D mov eax, dword ptr fs:[00000030h]3_2_0152674D
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F0750 mov eax, dword ptr fs:[00000030h]3_2_014F0750
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01500770 mov eax, dword ptr fs:[00000030h]3_2_01500770
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01500770 mov eax, dword ptr fs:[00000030h]3_2_01500770
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01500770 mov eax, dword ptr fs:[00000030h]3_2_01500770
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01500770 mov eax, dword ptr fs:[00000030h]3_2_01500770
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01500770 mov eax, dword ptr fs:[00000030h]3_2_01500770
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01500770 mov eax, dword ptr fs:[00000030h]3_2_01500770
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01500770 mov eax, dword ptr fs:[00000030h]3_2_01500770
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01500770 mov eax, dword ptr fs:[00000030h]3_2_01500770
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01500770 mov eax, dword ptr fs:[00000030h]3_2_01500770
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01500770 mov eax, dword ptr fs:[00000030h]3_2_01500770
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01500770 mov eax, dword ptr fs:[00000030h]3_2_01500770
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01500770 mov eax, dword ptr fs:[00000030h]3_2_01500770
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F8770 mov eax, dword ptr fs:[00000030h]3_2_014F8770
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01520710 mov eax, dword ptr fs:[00000030h]3_2_01520710
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152C700 mov eax, dword ptr fs:[00000030h]3_2_0152C700
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F0710 mov eax, dword ptr fs:[00000030h]3_2_014F0710
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0156C730 mov eax, dword ptr fs:[00000030h]3_2_0156C730
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152273C mov eax, dword ptr fs:[00000030h]3_2_0152273C
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152273C mov ecx, dword ptr fs:[00000030h]3_2_0152273C
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152273C mov eax, dword ptr fs:[00000030h]3_2_0152273C
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152C720 mov eax, dword ptr fs:[00000030h]3_2_0152C720
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152C720 mov eax, dword ptr fs:[00000030h]3_2_0152C720
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FC7C0 mov eax, dword ptr fs:[00000030h]3_2_014FC7C0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015707C3 mov eax, dword ptr fs:[00000030h]3_2_015707C3
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F47FB mov eax, dword ptr fs:[00000030h]3_2_014F47FB
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F47FB mov eax, dword ptr fs:[00000030h]3_2_014F47FB
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0157E7E1 mov eax, dword ptr fs:[00000030h]3_2_0157E7E1
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015127ED mov eax, dword ptr fs:[00000030h]3_2_015127ED
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015127ED mov eax, dword ptr fs:[00000030h]3_2_015127ED
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015127ED mov eax, dword ptr fs:[00000030h]3_2_015127ED
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159678E mov eax, dword ptr fs:[00000030h]3_2_0159678E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F07AF mov eax, dword ptr fs:[00000030h]3_2_014F07AF
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015A47A0 mov eax, dword ptr fs:[00000030h]3_2_015A47A0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0150C640 mov eax, dword ptr fs:[00000030h]3_2_0150C640
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01522674 mov eax, dword ptr fs:[00000030h]3_2_01522674
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152A660 mov eax, dword ptr fs:[00000030h]3_2_0152A660
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152A660 mov eax, dword ptr fs:[00000030h]3_2_0152A660
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015B866E mov eax, dword ptr fs:[00000030h]3_2_015B866E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015B866E mov eax, dword ptr fs:[00000030h]3_2_015B866E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01532619 mov eax, dword ptr fs:[00000030h]3_2_01532619
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0150260B mov eax, dword ptr fs:[00000030h]3_2_0150260B
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0150260B mov eax, dword ptr fs:[00000030h]3_2_0150260B
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0150260B mov eax, dword ptr fs:[00000030h]3_2_0150260B
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0150260B mov eax, dword ptr fs:[00000030h]3_2_0150260B
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0150260B mov eax, dword ptr fs:[00000030h]3_2_0150260B
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0150260B mov eax, dword ptr fs:[00000030h]3_2_0150260B
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0150260B mov eax, dword ptr fs:[00000030h]3_2_0150260B
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0156E609 mov eax, dword ptr fs:[00000030h]3_2_0156E609
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F262C mov eax, dword ptr fs:[00000030h]3_2_014F262C
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01526620 mov eax, dword ptr fs:[00000030h]3_2_01526620
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01528620 mov eax, dword ptr fs:[00000030h]3_2_01528620
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0150E627 mov eax, dword ptr fs:[00000030h]3_2_0150E627
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152A6C7 mov ebx, dword ptr fs:[00000030h]3_2_0152A6C7
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152A6C7 mov eax, dword ptr fs:[00000030h]3_2_0152A6C7
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0156E6F2 mov eax, dword ptr fs:[00000030h]3_2_0156E6F2
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0156E6F2 mov eax, dword ptr fs:[00000030h]3_2_0156E6F2
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0156E6F2 mov eax, dword ptr fs:[00000030h]3_2_0156E6F2
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0156E6F2 mov eax, dword ptr fs:[00000030h]3_2_0156E6F2
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015706F1 mov eax, dword ptr fs:[00000030h]3_2_015706F1
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015706F1 mov eax, dword ptr fs:[00000030h]3_2_015706F1
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F4690 mov eax, dword ptr fs:[00000030h]3_2_014F4690
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F4690 mov eax, dword ptr fs:[00000030h]3_2_014F4690
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015266B0 mov eax, dword ptr fs:[00000030h]3_2_015266B0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152C6A6 mov eax, dword ptr fs:[00000030h]3_2_0152C6A6
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01570946 mov eax, dword ptr fs:[00000030h]3_2_01570946
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01594978 mov eax, dword ptr fs:[00000030h]3_2_01594978
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01594978 mov eax, dword ptr fs:[00000030h]3_2_01594978
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0157C97C mov eax, dword ptr fs:[00000030h]3_2_0157C97C
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01516962 mov eax, dword ptr fs:[00000030h]3_2_01516962
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01516962 mov eax, dword ptr fs:[00000030h]3_2_01516962
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01516962 mov eax, dword ptr fs:[00000030h]3_2_01516962
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0153096E mov eax, dword ptr fs:[00000030h]3_2_0153096E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0153096E mov edx, dword ptr fs:[00000030h]3_2_0153096E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0153096E mov eax, dword ptr fs:[00000030h]3_2_0153096E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0157C912 mov eax, dword ptr fs:[00000030h]3_2_0157C912
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014E8918 mov eax, dword ptr fs:[00000030h]3_2_014E8918
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014E8918 mov eax, dword ptr fs:[00000030h]3_2_014E8918
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0156E908 mov eax, dword ptr fs:[00000030h]3_2_0156E908
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0156E908 mov eax, dword ptr fs:[00000030h]3_2_0156E908
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0158892B mov eax, dword ptr fs:[00000030h]3_2_0158892B
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0157892A mov eax, dword ptr fs:[00000030h]3_2_0157892A
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015249D0 mov eax, dword ptr fs:[00000030h]3_2_015249D0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015BA9D3 mov eax, dword ptr fs:[00000030h]3_2_015BA9D3
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015869C0 mov eax, dword ptr fs:[00000030h]3_2_015869C0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FA9D0 mov eax, dword ptr fs:[00000030h]3_2_014FA9D0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FA9D0 mov eax, dword ptr fs:[00000030h]3_2_014FA9D0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FA9D0 mov eax, dword ptr fs:[00000030h]3_2_014FA9D0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FA9D0 mov eax, dword ptr fs:[00000030h]3_2_014FA9D0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FA9D0 mov eax, dword ptr fs:[00000030h]3_2_014FA9D0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FA9D0 mov eax, dword ptr fs:[00000030h]3_2_014FA9D0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015229F9 mov eax, dword ptr fs:[00000030h]3_2_015229F9
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015229F9 mov eax, dword ptr fs:[00000030h]3_2_015229F9
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0157E9E0 mov eax, dword ptr fs:[00000030h]3_2_0157E9E0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F09AD mov eax, dword ptr fs:[00000030h]3_2_014F09AD
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F09AD mov eax, dword ptr fs:[00000030h]3_2_014F09AD
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015789B3 mov esi, dword ptr fs:[00000030h]3_2_015789B3
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015789B3 mov eax, dword ptr fs:[00000030h]3_2_015789B3
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015789B3 mov eax, dword ptr fs:[00000030h]3_2_015789B3
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015029A0 mov eax, dword ptr fs:[00000030h]3_2_015029A0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015029A0 mov eax, dword ptr fs:[00000030h]3_2_015029A0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015029A0 mov eax, dword ptr fs:[00000030h]3_2_015029A0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015029A0 mov eax, dword ptr fs:[00000030h]3_2_015029A0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015029A0 mov eax, dword ptr fs:[00000030h]3_2_015029A0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015029A0 mov eax, dword ptr fs:[00000030h]3_2_015029A0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015029A0 mov eax, dword ptr fs:[00000030h]3_2_015029A0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015029A0 mov eax, dword ptr fs:[00000030h]3_2_015029A0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015029A0 mov eax, dword ptr fs:[00000030h]3_2_015029A0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015029A0 mov eax, dword ptr fs:[00000030h]3_2_015029A0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015029A0 mov eax, dword ptr fs:[00000030h]3_2_015029A0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015029A0 mov eax, dword ptr fs:[00000030h]3_2_015029A0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015029A0 mov eax, dword ptr fs:[00000030h]3_2_015029A0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01520854 mov eax, dword ptr fs:[00000030h]3_2_01520854
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01502840 mov ecx, dword ptr fs:[00000030h]3_2_01502840
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F4859 mov eax, dword ptr fs:[00000030h]3_2_014F4859
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F4859 mov eax, dword ptr fs:[00000030h]3_2_014F4859
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0157E872 mov eax, dword ptr fs:[00000030h]3_2_0157E872
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0157E872 mov eax, dword ptr fs:[00000030h]3_2_0157E872
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01586870 mov eax, dword ptr fs:[00000030h]3_2_01586870
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01586870 mov eax, dword ptr fs:[00000030h]3_2_01586870
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0157C810 mov eax, dword ptr fs:[00000030h]3_2_0157C810
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152A830 mov eax, dword ptr fs:[00000030h]3_2_0152A830
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159483A mov eax, dword ptr fs:[00000030h]3_2_0159483A
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159483A mov eax, dword ptr fs:[00000030h]3_2_0159483A
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01512835 mov eax, dword ptr fs:[00000030h]3_2_01512835
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01512835 mov eax, dword ptr fs:[00000030h]3_2_01512835
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01512835 mov eax, dword ptr fs:[00000030h]3_2_01512835
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01512835 mov ecx, dword ptr fs:[00000030h]3_2_01512835
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01512835 mov eax, dword ptr fs:[00000030h]3_2_01512835
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01512835 mov eax, dword ptr fs:[00000030h]3_2_01512835
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151E8C0 mov eax, dword ptr fs:[00000030h]3_2_0151E8C0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015C08C0 mov eax, dword ptr fs:[00000030h]3_2_015C08C0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152C8F9 mov eax, dword ptr fs:[00000030h]3_2_0152C8F9
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152C8F9 mov eax, dword ptr fs:[00000030h]3_2_0152C8F9
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015BA8E4 mov eax, dword ptr fs:[00000030h]3_2_015BA8E4
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F0887 mov eax, dword ptr fs:[00000030h]3_2_014F0887
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0157C89D mov eax, dword ptr fs:[00000030h]3_2_0157C89D
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159EB50 mov eax, dword ptr fs:[00000030h]3_2_0159EB50
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015A4B4B mov eax, dword ptr fs:[00000030h]3_2_015A4B4B
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015A4B4B mov eax, dword ptr fs:[00000030h]3_2_015A4B4B
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01586B40 mov eax, dword ptr fs:[00000030h]3_2_01586B40
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01586B40 mov eax, dword ptr fs:[00000030h]3_2_01586B40
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015BAB40 mov eax, dword ptr fs:[00000030h]3_2_015BAB40
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01598B42 mov eax, dword ptr fs:[00000030h]3_2_01598B42
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014ECB7E mov eax, dword ptr fs:[00000030h]3_2_014ECB7E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0156EB1D mov eax, dword ptr fs:[00000030h]3_2_0156EB1D
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0156EB1D mov eax, dword ptr fs:[00000030h]3_2_0156EB1D
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0156EB1D mov eax, dword ptr fs:[00000030h]3_2_0156EB1D
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0156EB1D mov eax, dword ptr fs:[00000030h]3_2_0156EB1D
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0156EB1D mov eax, dword ptr fs:[00000030h]3_2_0156EB1D
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0156EB1D mov eax, dword ptr fs:[00000030h]3_2_0156EB1D
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0156EB1D mov eax, dword ptr fs:[00000030h]3_2_0156EB1D
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0156EB1D mov eax, dword ptr fs:[00000030h]3_2_0156EB1D
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0156EB1D mov eax, dword ptr fs:[00000030h]3_2_0156EB1D
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151EB20 mov eax, dword ptr fs:[00000030h]3_2_0151EB20
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151EB20 mov eax, dword ptr fs:[00000030h]3_2_0151EB20
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015B8B28 mov eax, dword ptr fs:[00000030h]3_2_015B8B28
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015B8B28 mov eax, dword ptr fs:[00000030h]3_2_015B8B28
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F0BCD mov eax, dword ptr fs:[00000030h]3_2_014F0BCD
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F0BCD mov eax, dword ptr fs:[00000030h]3_2_014F0BCD
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F0BCD mov eax, dword ptr fs:[00000030h]3_2_014F0BCD
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159EBD0 mov eax, dword ptr fs:[00000030h]3_2_0159EBD0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01510BCB mov eax, dword ptr fs:[00000030h]3_2_01510BCB
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01510BCB mov eax, dword ptr fs:[00000030h]3_2_01510BCB
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01510BCB mov eax, dword ptr fs:[00000030h]3_2_01510BCB
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0157CBF0 mov eax, dword ptr fs:[00000030h]3_2_0157CBF0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151EBFC mov eax, dword ptr fs:[00000030h]3_2_0151EBFC
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F8BF0 mov eax, dword ptr fs:[00000030h]3_2_014F8BF0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F8BF0 mov eax, dword ptr fs:[00000030h]3_2_014F8BF0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F8BF0 mov eax, dword ptr fs:[00000030h]3_2_014F8BF0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015A4BB0 mov eax, dword ptr fs:[00000030h]3_2_015A4BB0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015A4BB0 mov eax, dword ptr fs:[00000030h]3_2_015A4BB0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01500BBE mov eax, dword ptr fs:[00000030h]3_2_01500BBE
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01500BBE mov eax, dword ptr fs:[00000030h]3_2_01500BBE
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01500A5B mov eax, dword ptr fs:[00000030h]3_2_01500A5B
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01500A5B mov eax, dword ptr fs:[00000030h]3_2_01500A5B
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F6A50 mov eax, dword ptr fs:[00000030h]3_2_014F6A50
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F6A50 mov eax, dword ptr fs:[00000030h]3_2_014F6A50
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F6A50 mov eax, dword ptr fs:[00000030h]3_2_014F6A50
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F6A50 mov eax, dword ptr fs:[00000030h]3_2_014F6A50
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F6A50 mov eax, dword ptr fs:[00000030h]3_2_014F6A50
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F6A50 mov eax, dword ptr fs:[00000030h]3_2_014F6A50
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F6A50 mov eax, dword ptr fs:[00000030h]3_2_014F6A50
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0156CA72 mov eax, dword ptr fs:[00000030h]3_2_0156CA72
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0156CA72 mov eax, dword ptr fs:[00000030h]3_2_0156CA72
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0159EA60 mov eax, dword ptr fs:[00000030h]3_2_0159EA60
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152CA6F mov eax, dword ptr fs:[00000030h]3_2_0152CA6F
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152CA6F mov eax, dword ptr fs:[00000030h]3_2_0152CA6F
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152CA6F mov eax, dword ptr fs:[00000030h]3_2_0152CA6F
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0157CA11 mov eax, dword ptr fs:[00000030h]3_2_0157CA11
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01514A35 mov eax, dword ptr fs:[00000030h]3_2_01514A35
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01514A35 mov eax, dword ptr fs:[00000030h]3_2_01514A35
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152CA38 mov eax, dword ptr fs:[00000030h]3_2_0152CA38
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152CA24 mov eax, dword ptr fs:[00000030h]3_2_0152CA24
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0151EA2E mov eax, dword ptr fs:[00000030h]3_2_0151EA2E
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01524AD0 mov eax, dword ptr fs:[00000030h]3_2_01524AD0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01524AD0 mov eax, dword ptr fs:[00000030h]3_2_01524AD0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01546ACC mov eax, dword ptr fs:[00000030h]3_2_01546ACC
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01546ACC mov eax, dword ptr fs:[00000030h]3_2_01546ACC
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01546ACC mov eax, dword ptr fs:[00000030h]3_2_01546ACC
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F0AD0 mov eax, dword ptr fs:[00000030h]3_2_014F0AD0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152AAEE mov eax, dword ptr fs:[00000030h]3_2_0152AAEE
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_0152AAEE mov eax, dword ptr fs:[00000030h]3_2_0152AAEE
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01528A90 mov edx, dword ptr fs:[00000030h]3_2_01528A90
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FEA80 mov eax, dword ptr fs:[00000030h]3_2_014FEA80
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FEA80 mov eax, dword ptr fs:[00000030h]3_2_014FEA80
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FEA80 mov eax, dword ptr fs:[00000030h]3_2_014FEA80
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FEA80 mov eax, dword ptr fs:[00000030h]3_2_014FEA80
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FEA80 mov eax, dword ptr fs:[00000030h]3_2_014FEA80
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FEA80 mov eax, dword ptr fs:[00000030h]3_2_014FEA80
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FEA80 mov eax, dword ptr fs:[00000030h]3_2_014FEA80
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FEA80 mov eax, dword ptr fs:[00000030h]3_2_014FEA80
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014FEA80 mov eax, dword ptr fs:[00000030h]3_2_014FEA80
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_015C4A80 mov eax, dword ptr fs:[00000030h]3_2_015C4A80
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F8AA0 mov eax, dword ptr fs:[00000030h]3_2_014F8AA0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F8AA0 mov eax, dword ptr fs:[00000030h]3_2_014F8AA0
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_01546AA4 mov eax, dword ptr fs:[00000030h]3_2_01546AA4
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F0D59 mov eax, dword ptr fs:[00000030h]3_2_014F0D59
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F0D59 mov eax, dword ptr fs:[00000030h]3_2_014F0D59
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F0D59 mov eax, dword ptr fs:[00000030h]3_2_014F0D59
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F8D59 mov eax, dword ptr fs:[00000030h]3_2_014F8D59
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F8D59 mov eax, dword ptr fs:[00000030h]3_2_014F8D59
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeCode function: 3_2_014F8D59 mov eax, dword ptr fs:[00000030h]3_2_014F8D59
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeMemory allocated: page read and write | page guardJump to behavior

                HIPS / PFW / Operating System Protection Evasion

                barindex
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtWriteVirtualMemory: Direct from: 0x77762E3CJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtMapViewOfSection: Direct from: 0x77762D1CJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtNotifyChangeKey: Direct from: 0x77763C2CJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtCreateMutant: Direct from: 0x777635CCJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtResumeThread: Direct from: 0x777636ACJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtProtectVirtualMemory: Direct from: 0x77757B2EJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtQuerySystemInformation: Direct from: 0x77762DFCJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtAllocateVirtualMemory: Direct from: 0x77762BFCJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtReadFile: Direct from: 0x77762ADCJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtDelayExecution: Direct from: 0x77762DDCJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtWriteVirtualMemory: Direct from: 0x7776490CJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtQueryInformationProcess: Direct from: 0x77762C26Jump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtResumeThread: Direct from: 0x77762FBCJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtCreateUserProcess: Direct from: 0x7776371CJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtSetInformationThread: Direct from: 0x777563F9Jump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtAllocateVirtualMemory: Direct from: 0x77763C9CJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtSetInformationThread: Direct from: 0x77762B4CJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtQueryAttributesFile: Direct from: 0x77762E6CJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtClose: Direct from: 0x77762B6C
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtReadVirtualMemory: Direct from: 0x77762E8CJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtCreateKey: Direct from: 0x77762C6CJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtQuerySystemInformation: Direct from: 0x777648CCJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtAllocateVirtualMemory: Direct from: 0x777648ECJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtQueryVolumeInformationFile: Direct from: 0x77762F2CJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtOpenSection: Direct from: 0x77762E0CJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtDeviceIoControlFile: Direct from: 0x77762AECJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtAllocateVirtualMemory: Direct from: 0x77762BECJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtQueryInformationToken: Direct from: 0x77762CACJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtTerminateThread: Direct from: 0x77762FCCJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtCreateFile: Direct from: 0x77762FECJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtOpenFile: Direct from: 0x77762DCCJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtOpenKeyEx: Direct from: 0x77762B9CJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtSetInformationProcess: Direct from: 0x77762C5CJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtTerminateProcess: Direct from: 0x77762D5CJump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeNtProtectVirtualMemory: Direct from: 0x77762F9CJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeMemory written: C:\Users\user\Desktop\Demande de devis. Quote Request.exe base: 400000 value starts with: 4D5AJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeSection loaded: NULL target: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exe protection: execute and read and writeJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeSection loaded: NULL target: C:\Windows\SysWOW64\timeout.exe protection: execute and read and writeJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: NULL target: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exe protection: read writeJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: NULL target: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exe protection: execute and read and writeJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: NULL target: C:\Program Files\Mozilla Firefox\firefox.exe protection: read writeJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: NULL target: C:\Program Files\Mozilla Firefox\firefox.exe protection: execute and read and writeJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeThread register set: target process: 2176Jump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeThread APC queued: target process: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeProcess created: C:\Users\user\Desktop\Demande de devis. Quote Request.exe "C:\Users\user\Desktop\Demande de devis. Quote Request.exe"Jump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeProcess created: C:\Windows\SysWOW64\Magnify.exe "C:\Windows\SysWOW64\Magnify.exe"Jump to behavior
                Source: C:\Program Files (x86)\leJnGNYxUsBPuzOETbGxhgWwlshrVbErWnWKZZWKbXTDvmrN\V8sJoOh7MX.exeProcess created: C:\Windows\SysWOW64\timeout.exe "C:\Windows\SysWOW64\timeout.exe"Jump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeProcess created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\Firefox.exe"Jump to behavior
                Source: V8sJoOh7MX.exe, 00000006.00000002.3758356122.0000000001061000.00000002.00000001.00040000.00000000.sdmp, V8sJoOh7MX.exe, 00000006.00000000.1581269860.0000000001060000.00000002.00000001.00040000.00000000.sdmp, V8sJoOh7MX.exe, 00000009.00000002.3758957124.0000000000EC1000.00000002.00000001.00040000.00000000.sdmpBinary or memory string: Shell_TrayWnd
                Source: V8sJoOh7MX.exe, 00000006.00000002.3758356122.0000000001061000.00000002.00000001.00040000.00000000.sdmp, V8sJoOh7MX.exe, 00000006.00000000.1581269860.0000000001060000.00000002.00000001.00040000.00000000.sdmp, V8sJoOh7MX.exe, 00000009.00000002.3758957124.0000000000EC1000.00000002.00000001.00040000.00000000.sdmpBinary or memory string: Progman
                Source: V8sJoOh7MX.exe, 00000006.00000002.3758356122.0000000001061000.00000002.00000001.00040000.00000000.sdmp, V8sJoOh7MX.exe, 00000006.00000000.1581269860.0000000001060000.00000002.00000001.00040000.00000000.sdmp, V8sJoOh7MX.exe, 00000009.00000002.3758957124.0000000000EC1000.00000002.00000001.00040000.00000000.sdmpBinary or memory string: ?Program Manager
                Source: V8sJoOh7MX.exe, 00000006.00000002.3758356122.0000000001061000.00000002.00000001.00040000.00000000.sdmp, V8sJoOh7MX.exe, 00000006.00000000.1581269860.0000000001060000.00000002.00000001.00040000.00000000.sdmp, V8sJoOh7MX.exe, 00000009.00000002.3758957124.0000000000EC1000.00000002.00000001.00040000.00000000.sdmpBinary or memory string: Progmanlock
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeQueries volume information: C:\Users\user\Desktop\Demande de devis. Quote Request.exe VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Data.DataSetExtensions\v4.0_4.0.0.0__b77a5c561934e089\System.Data.DataSetExtensions.dll VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeQueries volume information: C:\Windows\Fonts\segoesc.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeQueries volume information: C:\Windows\Fonts\segoescb.ttf VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\Demande de devis. Quote Request.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

                Stealing of Sensitive Information

                barindex
                Source: Yara matchFile source: 3.2.Demande de devis. Quote Request.exe.400000.0.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 3.2.Demande de devis. Quote Request.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000008.00000002.3759172651.0000000004B40000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000003.00000002.1657618519.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000008.00000002.3756604386.0000000002B50000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000008.00000002.3757205678.0000000003020000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000003.00000002.1729597114.0000000005D00000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000009.00000002.3762527305.0000000004D40000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000006.00000002.3759091233.0000000005040000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000003.00000002.1659532102.0000000004110000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
                Source: C:\Windows\SysWOW64\timeout.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Network\CookiesJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web DataJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local StateJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\Local StateJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login DataJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\CookiesJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\CookiesJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\Jump to behavior

                Remote Access Functionality

                barindex
                Source: Yara matchFile source: 3.2.Demande de devis. Quote Request.exe.400000.0.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 3.2.Demande de devis. Quote Request.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000008.00000002.3759172651.0000000004B40000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000003.00000002.1657618519.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000008.00000002.3756604386.0000000002B50000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000008.00000002.3757205678.0000000003020000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000003.00000002.1729597114.0000000005D00000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000009.00000002.3762527305.0000000004D40000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000006.00000002.3759091233.0000000005040000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000003.00000002.1659532102.0000000004110000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
                ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
                DLL Side-Loading
                412
                Process Injection
                1
                Masquerading
                1
                OS Credential Dumping
                121
                Security Software Discovery
                Remote Services1
                Email Collection
                1
                Encrypted Channel
                Exfiltration Over Other Network MediumAbuse Accessibility Features
                CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
                Abuse Elevation Control Mechanism
                1
                Disable or Modify Tools
                LSASS Memory2
                Process Discovery
                Remote Desktop Protocol1
                Archive Collected Data
                3
                Ingress Tool Transfer
                Exfiltration Over BluetoothNetwork Denial of Service
                Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
                DLL Side-Loading
                41
                Virtualization/Sandbox Evasion
                Security Account Manager41
                Virtualization/Sandbox Evasion
                SMB/Windows Admin Shares1
                Data from Local System
                4
                Non-Application Layer Protocol
                Automated ExfiltrationData Encrypted for Impact
                Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook412
                Process Injection
                NTDS1
                Application Window Discovery
                Distributed Component Object ModelInput Capture4
                Application Layer Protocol
                Traffic DuplicationData Destruction
                Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
                Deobfuscate/Decode Files or Information
                LSA Secrets2
                File and Directory Discovery
                SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
                Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
                Abuse Elevation Control Mechanism
                Cached Domain Credentials113
                System Information Discovery
                VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items4
                Obfuscated Files or Information
                DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
                Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job12
                Software Packing
                Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
                Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAt1
                Timestomp
                /etc/passwd and /etc/shadowNetwork SniffingDirect Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
                IP AddressesCompromise InfrastructureSupply Chain CompromisePowerShellCronCron1
                DLL Side-Loading
                Network SniffingNetwork Service DiscoveryShared WebrootLocal Data StagingFile Transfer ProtocolsExfiltration Over Asymmetric Encrypted Non-C2 ProtocolExternal Defacement
                Hide Legend

                Legend:

                • Process
                • Signature
                • Created File
                • DNS/IP Info
                • Is Dropped
                • Is Windows Process
                • Number of created Registry Values
                • Number of created Files
                • Visual Basic
                • Delphi
                • Java
                • .Net C# or VB.NET
                • C, C++ or other language
                • Is malicious
                • Internet
                behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1612358 Sample: Demande de devis. Quote Req... Startdate: 11/02/2025 Architecture: WINDOWS Score: 100 33 www.uarsg.xyz 2->33 35 www.weilaishijie.xyz 2->35 37 16 other IPs or domains 2->37 47 Suricata IDS alerts for network traffic 2->47 49 Antivirus detection for URL or domain 2->49 51 Antivirus / Scanner detection for submitted sample 2->51 55 6 other signatures 2->55 10 Demande de devis. Quote Request.exe 3 2->10         started        signatures3 53 Performs DNS queries to domains with low reputation 35->53 process4 file5 31 Demande de devis. Quote Request.exe.log, ASCII 10->31 dropped 67 Injects a PE file into a foreign processes 10->67 14 Demande de devis. Quote Request.exe 10->14         started        signatures6 process7 signatures8 69 Maps a DLL or memory area into another process 14->69 17 V8sJoOh7MX.exe 14->17 injected process9 signatures10 45 Found direct / indirect Syscall (likely to bypass EDR) 17->45 20 timeout.exe 13 17->20         started        23 Magnify.exe 17->23         started        process11 signatures12 57 Tries to steal Mail credentials (via file / registry access) 20->57 59 Tries to harvest and steal browser information (history, passwords, etc) 20->59 61 Modifies the context of a thread in another process (thread injection) 20->61 63 3 other signatures 20->63 25 V8sJoOh7MX.exe 20->25 injected 29 firefox.exe 20->29         started        process13 dnsIp14 39 www.actionulse.live 209.74.64.58, 49991, 49992, 49993 MULTIBAND-NEWHOPEUS United States 25->39 41 tz301301.222tt.icu 23.145.136.206, 49995, 49996, 49997 HURRICANEUS Reserved 25->41 43 7 other IPs or domains 25->43 65 Found direct / indirect Syscall (likely to bypass EDR) 25->65 signatures15

                This section contains all screenshots as thumbnails, including those not shown in the slideshow.