Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
tKBxw8eOIV.exe

Overview

General Information

Sample name:tKBxw8eOIV.exe
renamed because original name is a hash value
Original sample name:51f4cfbe1c4f38beb7d4185086720317.exe
Analysis ID:1628986
MD5:51f4cfbe1c4f38beb7d4185086720317
SHA1:759e7e67ecc0b034d706125d6e2602c6051d2f63
SHA256:9e485a81d02dcd866ff2b63734bd9e5331319d6c6bd8c2aac53ef9e366556fcb
Tags:exeSocks5Systemzuser-abuse_ch
Infos:

Detection

Socks5Systemz
Score:84
Range:0 - 100
Confidence:100%

Signatures

Detected unpacking (changes PE section rights)
Detected unpacking (overwrites its own PE header)
Multi AV Scanner detection for submitted file
Yara detected Socks5Systemz
Contains functionality to infect the boot sector
Joe Sandbox ML detected suspicious sample
PE file has a writeable .text section
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to communicate with device drivers
Contains functionality to dynamically determine API calls
Contains functionality to launch a program with higher privileges
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to query network adapater information
Contains functionality to shutdown / reboot the system
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Drops PE files
Drops PE files to the application program directory (C:\ProgramData)
Extensive use of GetProcAddress (often used to hide API calls)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found evasive API chain (date check)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains executable resources (Code or Archives)
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries disk information (often used to detect virtual machines)
Sample file is different than original file name gathered from version info
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • tKBxw8eOIV.exe (PID: 900 cmdline: "C:\Users\user\Desktop\tKBxw8eOIV.exe" MD5: 51F4CFBE1C4F38BEB7D4185086720317)
    • tKBxw8eOIV.tmp (PID: 964 cmdline: "C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp" /SL5="$303F4,3471488,56832,C:\Users\user\Desktop\tKBxw8eOIV.exe" MD5: A68E919AA98AF0107E6C6C200955EF9C)
      • smartfiledefrag13.exe (PID: 1036 cmdline: "C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe" -i MD5: 483573178F49D6667013866FB10AB1CB)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
00000003.00000002.2660443759.0000000002D01000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_Socks5SystemzYara detected Socks5SystemzJoe Security
    00000003.00000002.2660125834.000000000270F000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_Socks5SystemzYara detected Socks5SystemzJoe Security
      Process Memory Space: smartfiledefrag13.exe PID: 1036JoeSecurity_Socks5SystemzYara detected Socks5SystemzJoe Security
        No Sigma rule has matched
        TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
        2025-03-04T10:30:05.030020+010020287653Unknown Traffic192.168.2.849710176.113.115.96443TCP
        2025-03-04T10:30:06.284270+010020287653Unknown Traffic192.168.2.849711176.113.115.96443TCP
        2025-03-04T10:30:10.200169+010020287653Unknown Traffic192.168.2.849713176.113.115.96443TCP
        2025-03-04T10:30:12.549702+010020287653Unknown Traffic192.168.2.849714176.113.115.96443TCP
        2025-03-04T10:30:13.927136+010020287653Unknown Traffic192.168.2.849715176.113.115.96443TCP
        2025-03-04T10:30:15.315018+010020287653Unknown Traffic192.168.2.849716176.113.115.96443TCP
        2025-03-04T10:30:16.601375+010020287653Unknown Traffic192.168.2.849717176.113.115.96443TCP
        2025-03-04T10:30:17.856979+010020287653Unknown Traffic192.168.2.849718176.113.115.96443TCP
        2025-03-04T10:30:19.124246+010020287653Unknown Traffic192.168.2.849719176.113.115.96443TCP
        2025-03-04T10:30:20.408843+010020287653Unknown Traffic192.168.2.849720176.113.115.96443TCP
        2025-03-04T10:30:21.658199+010020287653Unknown Traffic192.168.2.849721176.113.115.96443TCP
        2025-03-04T10:30:23.039131+010020287653Unknown Traffic192.168.2.849722176.113.115.96443TCP
        2025-03-04T10:30:24.309567+010020287653Unknown Traffic192.168.2.849723176.113.115.96443TCP
        2025-03-04T10:30:25.643708+010020287653Unknown Traffic192.168.2.849724176.113.115.96443TCP
        2025-03-04T10:30:26.922461+010020287653Unknown Traffic192.168.2.849725176.113.115.96443TCP
        2025-03-04T10:30:28.193220+010020287653Unknown Traffic192.168.2.849727176.113.115.96443TCP
        2025-03-04T10:30:29.466055+010020287653Unknown Traffic192.168.2.849729176.113.115.96443TCP
        2025-03-04T10:30:30.759513+010020287653Unknown Traffic192.168.2.849730176.113.115.96443TCP
        2025-03-04T10:30:32.035508+010020287653Unknown Traffic192.168.2.849731176.113.115.96443TCP
        2025-03-04T10:30:33.325478+010020287653Unknown Traffic192.168.2.849732176.113.115.96443TCP
        2025-03-04T10:30:34.598318+010020287653Unknown Traffic192.168.2.849733176.113.115.96443TCP
        2025-03-04T10:30:35.908417+010020287653Unknown Traffic192.168.2.849734176.113.115.96443TCP
        2025-03-04T10:30:37.278858+010020287653Unknown Traffic192.168.2.849735176.113.115.96443TCP
        2025-03-04T10:30:38.551235+010020287653Unknown Traffic192.168.2.849736176.113.115.96443TCP
        2025-03-04T10:30:39.912406+010020287653Unknown Traffic192.168.2.849737176.113.115.96443TCP
        2025-03-04T10:30:41.255044+010020287653Unknown Traffic192.168.2.849738176.113.115.96443TCP
        2025-03-04T10:30:42.512518+010020287653Unknown Traffic192.168.2.849739176.113.115.96443TCP
        2025-03-04T10:30:43.841979+010020287653Unknown Traffic192.168.2.849740176.113.115.96443TCP
        2025-03-04T10:30:45.092525+010020287653Unknown Traffic192.168.2.849741176.113.115.96443TCP
        2025-03-04T10:30:46.337587+010020287653Unknown Traffic192.168.2.849742176.113.115.96443TCP
        2025-03-04T10:30:47.601092+010020287653Unknown Traffic192.168.2.849743176.113.115.96443TCP
        2025-03-04T10:30:48.897300+010020287653Unknown Traffic192.168.2.849744176.113.115.96443TCP
        2025-03-04T10:30:50.280964+010020287653Unknown Traffic192.168.2.849745176.113.115.96443TCP
        2025-03-04T10:30:51.555679+010020287653Unknown Traffic192.168.2.849746176.113.115.96443TCP
        2025-03-04T10:30:52.928382+010020287653Unknown Traffic192.168.2.849747176.113.115.96443TCP
        2025-03-04T10:30:54.295965+010020287653Unknown Traffic192.168.2.849748176.113.115.96443TCP
        2025-03-04T10:30:55.591278+010020287653Unknown Traffic192.168.2.849749176.113.115.96443TCP
        2025-03-04T10:30:56.896884+010020287653Unknown Traffic192.168.2.849750176.113.115.96443TCP
        2025-03-04T10:30:58.175814+010020287653Unknown Traffic192.168.2.849751176.113.115.96443TCP
        2025-03-04T10:30:59.458729+010020287653Unknown Traffic192.168.2.849752176.113.115.96443TCP
        2025-03-04T10:31:00.722863+010020287653Unknown Traffic192.168.2.849753176.113.115.96443TCP
        2025-03-04T10:31:02.080124+010020287653Unknown Traffic192.168.2.849754176.113.115.96443TCP
        2025-03-04T10:31:03.376540+010020287653Unknown Traffic192.168.2.849755176.113.115.96443TCP
        2025-03-04T10:31:04.653359+010020287653Unknown Traffic192.168.2.849756176.113.115.96443TCP
        2025-03-04T10:31:05.912100+010020287653Unknown Traffic192.168.2.849757176.113.115.96443TCP
        2025-03-04T10:31:07.262374+010020287653Unknown Traffic192.168.2.849758176.113.115.96443TCP
        2025-03-04T10:31:08.531856+010020287653Unknown Traffic192.168.2.849759176.113.115.96443TCP
        2025-03-04T10:31:09.817187+010020287653Unknown Traffic192.168.2.849760176.113.115.96443TCP
        2025-03-04T10:31:11.107188+010020287653Unknown Traffic192.168.2.849761176.113.115.96443TCP
        2025-03-04T10:31:12.418691+010020287653Unknown Traffic192.168.2.849762176.113.115.96443TCP
        2025-03-04T10:31:13.860535+010020287653Unknown Traffic192.168.2.849763176.113.115.96443TCP
        TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
        2025-03-04T10:30:05.456970+010028032742Potentially Bad Traffic192.168.2.849710176.113.115.96443TCP
        2025-03-04T10:30:06.717890+010028032742Potentially Bad Traffic192.168.2.849711176.113.115.96443TCP
        2025-03-04T10:30:10.692395+010028032742Potentially Bad Traffic192.168.2.849713176.113.115.96443TCP
        2025-03-04T10:30:12.991333+010028032742Potentially Bad Traffic192.168.2.849714176.113.115.96443TCP
        2025-03-04T10:30:14.374037+010028032742Potentially Bad Traffic192.168.2.849715176.113.115.96443TCP
        2025-03-04T10:30:15.751130+010028032742Potentially Bad Traffic192.168.2.849716176.113.115.96443TCP
        2025-03-04T10:30:17.038613+010028032742Potentially Bad Traffic192.168.2.849717176.113.115.96443TCP
        2025-03-04T10:30:18.293076+010028032742Potentially Bad Traffic192.168.2.849718176.113.115.96443TCP
        2025-03-04T10:30:19.560252+010028032742Potentially Bad Traffic192.168.2.849719176.113.115.96443TCP
        2025-03-04T10:30:20.837105+010028032742Potentially Bad Traffic192.168.2.849720176.113.115.96443TCP
        2025-03-04T10:30:22.095643+010028032742Potentially Bad Traffic192.168.2.849721176.113.115.96443TCP
        2025-03-04T10:30:23.480643+010028032742Potentially Bad Traffic192.168.2.849722176.113.115.96443TCP
        2025-03-04T10:30:24.747204+010028032742Potentially Bad Traffic192.168.2.849723176.113.115.96443TCP
        2025-03-04T10:30:26.081049+010028032742Potentially Bad Traffic192.168.2.849724176.113.115.96443TCP
        2025-03-04T10:30:27.356667+010028032742Potentially Bad Traffic192.168.2.849725176.113.115.96443TCP
        2025-03-04T10:30:28.631268+010028032742Potentially Bad Traffic192.168.2.849727176.113.115.96443TCP
        2025-03-04T10:30:29.911607+010028032742Potentially Bad Traffic192.168.2.849729176.113.115.96443TCP
        2025-03-04T10:30:31.198876+010028032742Potentially Bad Traffic192.168.2.849730176.113.115.96443TCP
        2025-03-04T10:30:32.475430+010028032742Potentially Bad Traffic192.168.2.849731176.113.115.96443TCP
        2025-03-04T10:30:33.767940+010028032742Potentially Bad Traffic192.168.2.849732176.113.115.96443TCP
        2025-03-04T10:30:35.026216+010028032742Potentially Bad Traffic192.168.2.849733176.113.115.96443TCP
        2025-03-04T10:30:36.349707+010028032742Potentially Bad Traffic192.168.2.849734176.113.115.96443TCP
        2025-03-04T10:30:37.720963+010028032742Potentially Bad Traffic192.168.2.849735176.113.115.96443TCP
        2025-03-04T10:30:38.990225+010028032742Potentially Bad Traffic192.168.2.849736176.113.115.96443TCP
        2025-03-04T10:30:40.351779+010028032742Potentially Bad Traffic192.168.2.849737176.113.115.96443TCP
        2025-03-04T10:30:41.689579+010028032742Potentially Bad Traffic192.168.2.849738176.113.115.96443TCP
        2025-03-04T10:30:42.948019+010028032742Potentially Bad Traffic192.168.2.849739176.113.115.96443TCP
        2025-03-04T10:30:44.269861+010028032742Potentially Bad Traffic192.168.2.849740176.113.115.96443TCP
        2025-03-04T10:30:45.521264+010028032742Potentially Bad Traffic192.168.2.849741176.113.115.96443TCP
        2025-03-04T10:30:46.773960+010028032742Potentially Bad Traffic192.168.2.849742176.113.115.96443TCP
        2025-03-04T10:30:48.041247+010028032742Potentially Bad Traffic192.168.2.849743176.113.115.96443TCP
        2025-03-04T10:30:49.339973+010028032742Potentially Bad Traffic192.168.2.849744176.113.115.96443TCP
        2025-03-04T10:30:50.719189+010028032742Potentially Bad Traffic192.168.2.849745176.113.115.96443TCP
        2025-03-04T10:30:51.992736+010028032742Potentially Bad Traffic192.168.2.849746176.113.115.96443TCP
        2025-03-04T10:30:53.358885+010028032742Potentially Bad Traffic192.168.2.849747176.113.115.96443TCP
        2025-03-04T10:30:54.733421+010028032742Potentially Bad Traffic192.168.2.849748176.113.115.96443TCP
        2025-03-04T10:30:56.042857+010028032742Potentially Bad Traffic192.168.2.849749176.113.115.96443TCP
        2025-03-04T10:30:57.343273+010028032742Potentially Bad Traffic192.168.2.849750176.113.115.96443TCP
        2025-03-04T10:30:58.618742+010028032742Potentially Bad Traffic192.168.2.849751176.113.115.96443TCP
        2025-03-04T10:30:59.892971+010028032742Potentially Bad Traffic192.168.2.849752176.113.115.96443TCP
        2025-03-04T10:31:01.161025+010028032742Potentially Bad Traffic192.168.2.849753176.113.115.96443TCP
        2025-03-04T10:31:02.519624+010028032742Potentially Bad Traffic192.168.2.849754176.113.115.96443TCP
        2025-03-04T10:31:03.820617+010028032742Potentially Bad Traffic192.168.2.849755176.113.115.96443TCP
        2025-03-04T10:31:05.084415+010028032742Potentially Bad Traffic192.168.2.849756176.113.115.96443TCP
        2025-03-04T10:31:06.348483+010028032742Potentially Bad Traffic192.168.2.849757176.113.115.96443TCP
        2025-03-04T10:31:07.700982+010028032742Potentially Bad Traffic192.168.2.849758176.113.115.96443TCP
        2025-03-04T10:31:08.964139+010028032742Potentially Bad Traffic192.168.2.849759176.113.115.96443TCP
        2025-03-04T10:31:10.249501+010028032742Potentially Bad Traffic192.168.2.849760176.113.115.96443TCP
        2025-03-04T10:31:11.553451+010028032742Potentially Bad Traffic192.168.2.849761176.113.115.96443TCP
        2025-03-04T10:31:12.913028+010028032742Potentially Bad Traffic192.168.2.849762176.113.115.96443TCP
        2025-03-04T10:31:14.292530+010028032742Potentially Bad Traffic192.168.2.849763176.113.115.96443TCP

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: tKBxw8eOIV.exeVirustotal: Detection: 19%Perma Link
        Source: Submited SampleIntegrated Neural Analysis Model: Matched 99.9% probability
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0045D230 GetProcAddress,GetProcAddress,GetProcAddress,ISCryptGetVersion,1_2_0045D230
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0045D2E4 ArcFourCrypt,1_2_0045D2E4
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0045D2FC ArcFourCrypt,1_2_0045D2FC
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_10001000 ISCryptGetVersion,1_2_10001000
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_10001130 ArcFourCrypt,1_2_10001130

        Compliance

        barindex
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeUnpacked PE file: 3.2.smartfiledefrag13.exe.400000.0.unpack
        Source: tKBxw8eOIV.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpRegistry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smart File Defrag_is1Jump to behavior
        Source: unknownHTTPS traffic detected: 176.113.115.96:443 -> 192.168.2.8:49710 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 176.113.115.96:443 -> 192.168.2.8:49715 version: TLS 1.2
        Source: tKBxw8eOIV.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
        Source: Binary string: msvcr100.i386.pdb source: is-9L7QC.tmp.1.dr
        Source: Binary string: msvcp100.i386.pdb source: is-PTS9U.tmp.1.dr
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00452AD4 FindFirstFileA,GetLastError,1_2_00452AD4
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00475798 FindFirstFileA,FindNextFileA,FindClose,1_2_00475798
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0046417C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose,SetErrorMode,1_2_0046417C
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_004645F8 SetErrorMode,FindFirstFileA,FindNextFileA,FindClose,SetErrorMode,1_2_004645F8
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00462BF0 FindFirstFileA,FindNextFileA,FindClose,1_2_00462BF0
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00498FDC FindFirstFileA,SetFileAttributesA,FindNextFileA,FindClose,1_2_00498FDC
        Source: global trafficTCP traffic: 192.168.2.8:49712 -> 193.176.153.180:2024
        Source: Joe Sandbox ViewIP Address: 176.113.115.96 176.113.115.96
        Source: Joe Sandbox ViewIP Address: 193.176.153.180 193.176.153.180
        Source: Joe Sandbox ViewJA3 fingerprint: 51c64c77e60f3980eea90869b68c58a8
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49721 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49715 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49714 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49713 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49724 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49711 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49722 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49742 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49743 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49749 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49733 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49735 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49716 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49727 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49710 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49732 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49757 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49741 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49720 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49734 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49747 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49751 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49746 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49740 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49750 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49718 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49753 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49723 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49748 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49755 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49738 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49717 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49754 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49731 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49719 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49730 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49745 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49725 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49752 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49761 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49729 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49763 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49736 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49758 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49737 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49760 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49759 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49762 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49739 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49756 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2028765 - Severity 3 - ET JA3 Hash - [Abuse.ch] Possible Dridex : 192.168.2.8:49744 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49746 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49729 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49742 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49710 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49720 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49718 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49713 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49733 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49725 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49719 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49723 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49724 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49731 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49753 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49732 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49745 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49744 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49734 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49748 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49763 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49714 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49715 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49730 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49750 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49722 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49736 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49759 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49721 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49716 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49747 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49740 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49711 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49738 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49739 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49755 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49762 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49758 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49727 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49754 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49717 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49749 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49752 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49737 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49741 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49743 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49757 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49760 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49735 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49761 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49751 -> 176.113.115.96:443
        Source: Network trafficSuricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.8:49756 -> 176.113.115.96:443
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f926d19fe6595cd66946851e91fcd85241ab258d81729326be8ee43a8f51f8a95b5ca212a91f953c588fb52d6db9f51a9a0a29d5954cad713479a672918d4348dd4da945b49c8 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c926d19fe6595cd66946851e91fcd85241ab258d81729326be8ee43a8f51f8a95b5ca212a91f953c588fb52d6db9f51a9a0a29d5954cad713479a672918d4348dd4da945b49c8 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38b926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb388926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb389926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb386926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb387926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f842a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f852a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f862a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f872a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f802a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f812a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f822a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f832a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f8c2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f8d2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c842a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c852a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c862a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c872a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c802a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c812a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c822a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c832a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c8c2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c8d2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d842a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d852a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d862a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d872a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d802a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d812a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d822a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d832a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d8c2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d8d2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a842a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a852a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a862a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a872a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a802a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a812a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a822a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a832a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a8c2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a8d2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38b842a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38b852a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 193.176.153.180
        Source: unknownTCP traffic detected without corresponding DNS query: 193.176.153.180
        Source: unknownTCP traffic detected without corresponding DNS query: 193.176.153.180
        Source: unknownTCP traffic detected without corresponding DNS query: 193.176.153.180
        Source: unknownTCP traffic detected without corresponding DNS query: 193.176.153.180
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: unknownTCP traffic detected without corresponding DNS query: 176.113.115.96
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_02D02B95 WSASetLastError,WSARecv,WSASetLastError,select,3_2_02D02B95
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f926d19fe6595cd66946851e91fcd85241ab258d81729326be8ee43a8f51f8a95b5ca212a91f953c588fb52d6db9f51a9a0a29d5954cad713479a672918d4348dd4da945b49c8 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c926d19fe6595cd66946851e91fcd85241ab258d81729326be8ee43a8f51f8a95b5ca212a91f953c588fb52d6db9f51a9a0a29d5954cad713479a672918d4348dd4da945b49c8 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38b926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb388926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb389926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb386926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb387926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f842a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f852a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f862a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f872a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f802a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f812a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f822a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f832a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f8c2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f8d2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c842a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c852a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c862a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c872a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c802a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c812a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c822a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c832a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c8c2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c8d2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d842a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d852a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d862a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d872a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d802a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d812a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d822a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d832a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d8c2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d8d2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a842a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a852a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a862a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a872a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a802a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a812a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a822a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a832a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a8c2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a8d2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38b842a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: global trafficHTTP traffic detected: GET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38b852a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)Host: 176.113.115.96
        Source: is-5ELJT.tmp.1.dr, is-PSA15.tmp.1.drString found in binary or memory: http://icu-project.org
        Source: tKBxw8eOIV.tmp, 00000001.00000002.2659689071.0000000005C9A000.00000004.00001000.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000000.1423149968.000000000065C000.00000002.00000001.01000000.00000009.sdmp, smartfiledefrag13.exe, 00000003.00000003.1424200199.0000000002689000.00000004.00000020.00020000.00000000.sdmp, SmartFileDefrag.exe.3.dr, is-TVCIJ.tmp.1.dr, smartfiledefrag13.exe.1.drString found in binary or memory: http://www.countnow.ru
        Source: tKBxw8eOIV.tmp, tKBxw8eOIV.tmp, 00000001.00000002.2658067655.0000000000401000.00000020.00000001.01000000.00000004.sdmp, tKBxw8eOIV.tmp.0.dr, is-4UKIG.tmp.1.drString found in binary or memory: http://www.innosetup.com/
        Source: tKBxw8eOIV.exeString found in binary or memory: http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdline
        Source: tKBxw8eOIV.exeString found in binary or memory: http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU
        Source: tKBxw8eOIV.exe, 00000000.00000003.1410591558.0000000002370000.00000004.00001000.00020000.00000000.sdmp, tKBxw8eOIV.exe, 00000000.00000003.1410736592.0000000002148000.00000004.00001000.00020000.00000000.sdmp, tKBxw8eOIV.tmp, tKBxw8eOIV.tmp, 00000001.00000002.2658067655.0000000000401000.00000020.00000001.01000000.00000004.sdmp, tKBxw8eOIV.tmp.0.dr, is-4UKIG.tmp.1.drString found in binary or memory: http://www.remobjects.com/ps
        Source: tKBxw8eOIV.exe, 00000000.00000003.1410591558.0000000002370000.00000004.00001000.00020000.00000000.sdmp, tKBxw8eOIV.exe, 00000000.00000003.1410736592.0000000002148000.00000004.00001000.00020000.00000000.sdmp, tKBxw8eOIV.tmp, 00000001.00000002.2658067655.0000000000401000.00000020.00000001.01000000.00000004.sdmp, tKBxw8eOIV.tmp.0.dr, is-4UKIG.tmp.1.drString found in binary or memory: http://www.remobjects.com/psU
        Source: smartfiledefrag13.exe, 00000003.00000002.2661508814.00000000033F4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/
        Source: smartfiledefrag13.exe, 00000003.00000002.2661508814.00000000033F4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/H
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000336F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb386926d19fe6595cd66946951e91fcd85250
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003365000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb387926d19fe6595cd66946951e91fcd85250
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003321000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb388926d19fe6595cd66946951e91fcd85250
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003323000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb389926d19fe6595cd66946951e91fcd85250
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a802a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a812a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2661508814.00000000033F4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a822a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2661508814.00000000033F4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a832a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a842a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a852a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2658796792.0000000000978000.00000004.00000020.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a862a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2658796792.0000000000978000.00000004.00000020.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a872a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2661508814.00000000033F4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a8c2a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2661508814.00000000033F4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a8d2a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003328000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a926d19fe6595cd66946951e91fcd85250
        Source: smartfiledefrag13.exe, 00000003.00000002.2661508814.00000000033F4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38b842a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2661508814.00000000033F4000.00000004.00000020.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000002.2658796792.0000000000A33000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38b852a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000331E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38b926d19fe6595cd66946951e91fcd85250
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c802a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c812a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c822a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c832a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003371000.00000004.00000020.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c842a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c852a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c862a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c872a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003371000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c8c2a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c8d2a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2658796792.0000000000A51000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c926d19fe6595cd66946851e91fcd85241
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d802a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d812a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d822a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d832a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d842a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d852a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d862a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d872a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d8c2a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d8d2a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003328000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d926d19fe6595cd66946951e91fcd85250
        Source: smartfiledefrag13.exe, 00000003.00000002.2658796792.0000000000A33000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f802a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2658796792.0000000000A33000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f812a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2658796792.0000000000A33000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f822a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003328000.00000004.00000020.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003371000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f832a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003365000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f842a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003369000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f852a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000336B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f862a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003371000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f872a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003371000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f8c2a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003371000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f8d2a1cec7a86d87bdb6546ad12dac0290
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003310000.00000004.00000020.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000002.2658796792.0000000000A65000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f926d19fe6595cd66946851e91fcd85241
        Source: smartfiledefrag13.exe, 00000003.00000002.2658796792.0000000000A51000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/en-GB
        Source: smartfiledefrag13.exe, 00000003.00000002.2658796792.0000000000A51000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/en-US
        Source: smartfiledefrag13.exe, 00000003.00000002.2658796792.0000000000A51000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/mCertificates
        Source: smartfiledefrag13.exe, 00000003.00000002.2658796792.0000000000A65000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/ography
        Source: smartfiledefrag13.exe, 00000003.00000002.2661508814.00000000033F4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/r
        Source: smartfiledefrag13.exe, 00000003.00000002.2658796792.0000000000A65000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://176.113.115.96/rosoft
        Source: tKBxw8eOIV.exe, 00000000.00000003.1410283097.0000000002141000.00000004.00001000.00020000.00000000.sdmp, tKBxw8eOIV.exe, 00000000.00000002.2659067659.0000000002141000.00000004.00001000.00020000.00000000.sdmp, tKBxw8eOIV.exe, 00000000.00000003.1410213366.0000000002370000.00000004.00001000.00020000.00000000.sdmp, tKBxw8eOIV.tmp, 00000001.00000002.2658704788.0000000000734000.00000004.00000020.00020000.00000000.sdmp, tKBxw8eOIV.tmp, 00000001.00000003.1412236817.00000000030F0000.00000004.00001000.00020000.00000000.sdmp, tKBxw8eOIV.tmp, 00000001.00000003.1412307068.0000000002098000.00000004.00001000.00020000.00000000.sdmp, tKBxw8eOIV.tmp, 00000001.00000002.2659005353.0000000002098000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.easycutstudio.com/support.html
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
        Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
        Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
        Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49763 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
        Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
        Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
        Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
        Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
        Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
        Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
        Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49762 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
        Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
        Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
        Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
        Source: unknownNetwork traffic detected: HTTP traffic on port 49761 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
        Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
        Source: unknownHTTPS traffic detected: 176.113.115.96:443 -> 192.168.2.8:49710 version: TLS 1.2
        Source: unknownHTTPS traffic detected: 176.113.115.96:443 -> 192.168.2.8:49715 version: TLS 1.2

        System Summary

        barindex
        Source: smartfiledefrag13.exe.1.drStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
        Source: SmartFileDefrag.exe.3.drStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0042F594 NtdllDefWindowProc_A,1_2_0042F594
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00423B94 NtdllDefWindowProc_A,1_2_00423B94
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_004125E8 NtdllDefWindowProc_A,1_2_004125E8
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00479380 NtdllDefWindowProc_A,1_2_00479380
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0045763C PostMessageA,PostMessageA,SetForegroundWindow,NtdllDefWindowProc_A,1_2_0045763C
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0042E944: CreateFileA,DeviceIoControl,GetLastError,CloseHandle,SetLastError,1_2_0042E944
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeCode function: 0_2_00409448 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,GetLastError,ExitWindowsEx,0_2_00409448
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0045568C GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,GetLastError,ExitWindowsEx,1_2_0045568C
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeCode function: 0_2_0040840C0_2_0040840C
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00470C741_2_00470C74
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0043533C1_2_0043533C
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_004813C41_2_004813C4
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_004678481_2_00467848
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_004303D01_2_004303D0
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0044453C1_2_0044453C
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_004885E01_2_004885E0
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_004346381_2_00434638
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00444AE41_2_00444AE4
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0048ED0C1_2_0048ED0C
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00430F5C1_2_00430F5C
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0045F16C1_2_0045F16C
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_004451DC1_2_004451DC
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0045B21C1_2_0045B21C
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_004455E81_2_004455E8
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_004876801_2_00487680
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0046989C1_2_0046989C
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00451A301_2_00451A30
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0043DDC41_2_0043DDC4
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_004010003_2_00401000
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_004067B73_2_004067B7
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_609660FA3_2_609660FA
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6092114F3_2_6092114F
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6091F2C93_2_6091F2C9
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6096923E3_2_6096923E
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6093323D3_2_6093323D
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6095C3143_2_6095C314
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_609503123_2_60950312
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6094D33B3_2_6094D33B
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6093B3683_2_6093B368
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6096748C3_2_6096748C
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6093F42E3_2_6093F42E
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_609544703_2_60954470
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_609615FA3_2_609615FA
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6096A5EE3_2_6096A5EE
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6096D6A43_2_6096D6A4
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_609606A83_2_609606A8
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_609326543_2_60932654
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_609556653_2_60955665
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6094B7DB3_2_6094B7DB
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6092F74D3_2_6092F74D
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_609648073_2_60964807
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6094E9BC3_2_6094E9BC
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_609379293_2_60937929
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6093FAD63_2_6093FAD6
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6096DAE83_2_6096DAE8
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6094DA3A3_2_6094DA3A
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_60936B273_2_60936B27
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_60954CF63_2_60954CF6
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_60950C6B3_2_60950C6B
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_60966DF13_2_60966DF1
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_60963D353_2_60963D35
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_60909E9C3_2_60909E9C
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_60951E863_2_60951E86
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_60912E0B3_2_60912E0B
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_60954FF83_2_60954FF8
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_02D1BAFD3_2_02D1BAFD
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_02D22A803_2_02D22A80
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_02D1D32F3_2_02D1D32F
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_02D170C03_2_02D170C0
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_02D0E0893_2_02D0E089
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_02D2267D3_2_02D2267D
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_02D1B6093_2_02D1B609
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_02D1874A3_2_02D1874A
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_02D1BF153_2_02D1BF15
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_02D20DB43_2_02D20DB4
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: String function: 00408C1C appears 45 times
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: String function: 00406AD4 appears 45 times
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: String function: 0040596C appears 117 times
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: String function: 00407904 appears 43 times
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: String function: 00403400 appears 60 times
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: String function: 00445E48 appears 45 times
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: String function: 00457FC4 appears 77 times
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: String function: 00457DB8 appears 102 times
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: String function: 00434550 appears 32 times
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: String function: 00403494 appears 85 times
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: String function: 004533B8 appears 98 times
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: String function: 00446118 appears 58 times
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: String function: 00403684 appears 229 times
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: String function: 02D17760 appears 32 times
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: String function: 02D22A10 appears 135 times
        Source: tKBxw8eOIV.tmp.0.drStatic PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
        Source: tKBxw8eOIV.tmp.0.drStatic PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
        Source: tKBxw8eOIV.tmp.0.drStatic PE information: Resource name: RT_VERSION type: 370 sysV pure executable not stripped
        Source: is-4UKIG.tmp.1.drStatic PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
        Source: is-4UKIG.tmp.1.drStatic PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
        Source: is-4UKIG.tmp.1.drStatic PE information: Resource name: RT_VERSION type: 370 sysV pure executable not stripped
        Source: sqlite3.dll.3.drStatic PE information: Number of sections : 19 > 10
        Source: is-8A6NR.tmp.1.drStatic PE information: Number of sections : 19 > 10
        Source: tKBxw8eOIV.exe, 00000000.00000003.1410591558.0000000002370000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenameshfolder.dll~/ vs tKBxw8eOIV.exe
        Source: tKBxw8eOIV.exe, 00000000.00000003.1410736592.0000000002148000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenameshfolder.dll~/ vs tKBxw8eOIV.exe
        Source: tKBxw8eOIV.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
        Source: classification engineClassification label: mal84.troj.evad.winEXE@5/32@0/2
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_02D0F8D0 _memset,FormatMessageA,GetLastError,FormatMessageA,GetLastError,3_2_02D0F8D0
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeCode function: 0_2_00409448 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,GetLastError,ExitWindowsEx,0_2_00409448
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0045568C GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,GetLastError,ExitWindowsEx,1_2_0045568C
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00455EB4 GetModuleHandleA,GetProcAddress,GetDiskFreeSpaceA,1_2_00455EB4
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: CreateServiceA,CloseServiceHandle,CloseServiceHandle,3_2_00401EEF
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0046E5B8 GetVersion,CoCreateInstance,1_2_0046E5B8
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeCode function: 0_2_00409C34 FindResourceA,SizeofResource,LoadResource,LockResource,0_2_00409C34
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_0040D94D StartServiceCtrlDispatcherA,3_2_0040D94D
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_0040D94D StartServiceCtrlDispatcherA,3_2_0040D94D
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile created: C:\Users\user\AppData\Local\ProgramsJump to behavior
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeFile created: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile read: C:\Windows\win.iniJump to behavior
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganizationJump to behavior
        Source: smartfiledefrag13.exe, smartfiledefrag13.exe, 00000003.00000002.2663443123.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, sqlite3.dll.3.dr, is-8A6NR.tmp.1.drBinary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name=='sqlite_sequence';
        Source: smartfiledefrag13.exe, 00000003.00000002.2663443123.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, sqlite3.dll.3.dr, is-8A6NR.tmp.1.drBinary or memory string: INSERT INTO %Q.%s VALUES('index',%Q,%Q,#%d,%Q);
        Source: smartfiledefrag13.exe, smartfiledefrag13.exe, 00000003.00000002.2663443123.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, sqlite3.dll.3.dr, is-8A6NR.tmp.1.drBinary or memory string: SELECT 'INSERT INTO vacuum_db.' || quote(name) || ' SELECT * FROM main.' || quote(name) || ';'FROM main.sqlite_master WHERE type = 'table' AND name!='sqlite_sequence' AND coalesce(rootpage,1)>0
        Source: smartfiledefrag13.exe, 00000003.00000002.2663443123.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, sqlite3.dll.3.dr, is-8A6NR.tmp.1.drBinary or memory string: CREATE TABLE "%w"."%w_node"(nodeno INTEGER PRIMARY KEY, data BLOB);CREATE TABLE "%w"."%w_rowid"(rowid INTEGER PRIMARY KEY, nodeno INTEGER);CREATE TABLE "%w"."%w_parent"(nodeno INTEGER PRIMARY KEY, parentnode INTEGER);INSERT INTO '%q'.'%q_node' VALUES(1, zeroblob(%d))
        Source: smartfiledefrag13.exe, 00000003.00000002.2663443123.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, sqlite3.dll.3.dr, is-8A6NR.tmp.1.drBinary or memory string: CREATE TABLE %Q.'%q_docsize'(docid INTEGER PRIMARY KEY, size BLOB);
        Source: smartfiledefrag13.exe, 00000003.00000002.2663443123.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, sqlite3.dll.3.dr, is-8A6NR.tmp.1.drBinary or memory string: CREATE TABLE IF NOT EXISTS %Q.'%q_stat'(id INTEGER PRIMARY KEY, value BLOB);
        Source: smartfiledefrag13.exe, 00000003.00000002.2663443123.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, sqlite3.dll.3.dr, is-8A6NR.tmp.1.drBinary or memory string: CREATE TABLE %Q.'%q_segdir'(level INTEGER,idx INTEGER,start_block INTEGER,leaves_end_block INTEGER,end_block INTEGER,root BLOB,PRIMARY KEY(level, idx));
        Source: smartfiledefrag13.exe, 00000003.00000002.2663443123.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, sqlite3.dll.3.dr, is-8A6NR.tmp.1.drBinary or memory string: UPDATE "%w".%s SET sql = sqlite_rename_parent(sql, %Q, %Q) WHERE %s;
        Source: smartfiledefrag13.exe, 00000003.00000002.2663443123.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, sqlite3.dll.3.dr, is-8A6NR.tmp.1.drBinary or memory string: UPDATE sqlite_temp_master SET sql = sqlite_rename_trigger(sql, %Q), tbl_name = %Q WHERE %s;
        Source: smartfiledefrag13.exe, 00000003.00000002.2663443123.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, sqlite3.dll.3.dr, is-8A6NR.tmp.1.drBinary or memory string: CREATE TABLE %Q.'%q_segments'(blockid INTEGER PRIMARY KEY, block BLOB);
        Source: smartfiledefrag13.exe, 00000003.00000002.2663443123.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, sqlite3.dll.3.dr, is-8A6NR.tmp.1.drBinary or memory string: UPDATE %Q.%s SET sql = CASE WHEN type = 'trigger' THEN sqlite_rename_trigger(sql, %Q)ELSE sqlite_rename_table(sql, %Q) END, tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqlite_autoindex%%' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
        Source: smartfiledefrag13.exe, smartfiledefrag13.exe, 00000003.00000002.2663443123.000000006096F000.00000002.00000001.01000000.0000000A.sdmp, sqlite3.dll.3.dr, is-8A6NR.tmp.1.drBinary or memory string: SELECT 'DELETE FROM vacuum_db.' || quote(name) || ';' FROM vacuum_db.sqlite_master WHERE name='sqlite_sequence'
        Source: tKBxw8eOIV.exeVirustotal: Detection: 19%
        Source: tKBxw8eOIV.exeString found in binary or memory: need to be updated. /RESTARTAPPLICATIONS Instructs Setup to restart applications. /NORESTARTAPPLICATIONS Prevents Setup from restarting applications. /LOADINF="filename" Instructs Setup to load the settings from the specified file after having checked t
        Source: tKBxw8eOIV.exeString found in binary or memory: /LOADINF="filename"
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeFile read: C:\Users\user\Desktop\tKBxw8eOIV.exeJump to behavior
        Source: unknownProcess created: C:\Users\user\Desktop\tKBxw8eOIV.exe "C:\Users\user\Desktop\tKBxw8eOIV.exe"
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeProcess created: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp "C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp" /SL5="$303F4,3471488,56832,C:\Users\user\Desktop\tKBxw8eOIV.exe"
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpProcess created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe "C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe" -i
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeProcess created: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp "C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp" /SL5="$303F4,3471488,56832,C:\Users\user\Desktop\tKBxw8eOIV.exe" Jump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpProcess created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe "C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe" -iJump to behavior
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeSection loaded: uxtheme.dllJump to behavior
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeSection loaded: apphelp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: mpr.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: version.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: msimg32.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: uxtheme.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: kernel.appcore.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: textinputframework.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: coreuicomponents.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: coremessaging.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: ntmarta.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: coremessaging.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: wintypes.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: wintypes.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: wintypes.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: windows.storage.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: wldp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: profapi.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: shfolder.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: rstrtmgr.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: ncrypt.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: ntasn1.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: msacm32.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: winmmbase.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: winmmbase.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: textshaping.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: riched20.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: usp10.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: msls31.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: sspicli.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: explorerframe.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: sfc.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: sfc_os.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpSection loaded: apphelp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: sqlite3.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: mpr.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: version.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: appxsip.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: opcservices.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: ntmarta.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: wininet.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: iphlpapi.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: dhcpcsvc.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: windows.storage.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: wldp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: profapi.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: iertutil.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: sspicli.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: kernel.appcore.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: winhttp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: mswsock.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: winnsi.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: urlmon.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: srvcli.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: netutils.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: schannel.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: mskeyprotect.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: ntasn1.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: msasn1.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: dpapi.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: cryptsp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: rsaenh.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: cryptbase.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: gpapi.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: ncrypt.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeSection loaded: ncryptsslp.dllJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00BB2765-6A77-11D0-A535-00C04FD7D062}\InProcServer32Jump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwnerJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpWindow found: window name: TMainFormJump to behavior
        Source: Window RecorderWindow detected: More than 3 window changes detected
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpRegistry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Smart File Defrag_is1Jump to behavior
        Source: tKBxw8eOIV.exeStatic file information: File size 3722172 > 1048576
        Source: tKBxw8eOIV.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
        Source: Binary string: msvcr100.i386.pdb source: is-9L7QC.tmp.1.dr
        Source: Binary string: msvcp100.i386.pdb source: is-PTS9U.tmp.1.dr

        Data Obfuscation

        barindex
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeUnpacked PE file: 3.2.smartfiledefrag13.exe.400000.0.unpack .text:EW;.rdata:R;.data:W;.rsrc:R; vs .text:ER;.rdata:R;.data:W;.vmp0:ER;.rsrc:R;
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeUnpacked PE file: 3.2.smartfiledefrag13.exe.400000.0.unpack
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00450334 GetVersion,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,1_2_00450334
        Source: is-8A6NR.tmp.1.drStatic PE information: section name: /4
        Source: is-8A6NR.tmp.1.drStatic PE information: section name: /19
        Source: is-8A6NR.tmp.1.drStatic PE information: section name: /35
        Source: is-8A6NR.tmp.1.drStatic PE information: section name: /51
        Source: is-8A6NR.tmp.1.drStatic PE information: section name: /63
        Source: is-8A6NR.tmp.1.drStatic PE information: section name: /77
        Source: is-8A6NR.tmp.1.drStatic PE information: section name: /89
        Source: is-8A6NR.tmp.1.drStatic PE information: section name: /102
        Source: is-8A6NR.tmp.1.drStatic PE information: section name: /113
        Source: is-8A6NR.tmp.1.drStatic PE information: section name: /124
        Source: sqlite3.dll.3.drStatic PE information: section name: /4
        Source: sqlite3.dll.3.drStatic PE information: section name: /19
        Source: sqlite3.dll.3.drStatic PE information: section name: /35
        Source: sqlite3.dll.3.drStatic PE information: section name: /51
        Source: sqlite3.dll.3.drStatic PE information: section name: /63
        Source: sqlite3.dll.3.drStatic PE information: section name: /77
        Source: sqlite3.dll.3.drStatic PE information: section name: /89
        Source: sqlite3.dll.3.drStatic PE information: section name: /102
        Source: sqlite3.dll.3.drStatic PE information: section name: /113
        Source: sqlite3.dll.3.drStatic PE information: section name: /124
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeCode function: 0_2_004065C8 push 00406605h; ret 0_2_004065FD
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeCode function: 0_2_004040B5 push eax; ret 0_2_004040F1
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeCode function: 0_2_00408104 push ecx; mov dword ptr [esp], eax0_2_00408109
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeCode function: 0_2_00404185 push 00404391h; ret 0_2_00404389
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeCode function: 0_2_00404206 push 00404391h; ret 0_2_00404389
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeCode function: 0_2_0040C218 push eax; ret 0_2_0040C219
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeCode function: 0_2_004042E8 push 00404391h; ret 0_2_00404389
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeCode function: 0_2_00404283 push 00404391h; ret 0_2_00404389
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeCode function: 0_2_00408F38 push 00408F6Bh; ret 0_2_00408F63
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_004849F4 push 00484B02h; ret 1_2_00484AFA
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0040995C push 00409999h; ret 1_2_00409991
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00458060 push 00458098h; ret 1_2_00458090
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_004860E4 push ecx; mov dword ptr [esp], ecx1_2_004860E9
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_004062C4 push ecx; mov dword ptr [esp], eax1_2_004062C5
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_004783C8 push ecx; mov dword ptr [esp], edx1_2_004783C9
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_004104F0 push ecx; mov dword ptr [esp], edx1_2_004104F5
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00412938 push 0041299Bh; ret 1_2_00412993
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0049AD44 pushad ; retf 1_2_0049AD53
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0040CE48 push ecx; mov dword ptr [esp], edx1_2_0040CE4A
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00459378 push 004593BCh; ret 1_2_004593B4
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0040F3A8 push ecx; mov dword ptr [esp], edx1_2_0040F3AA
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0040546D push eax; ret 1_2_004054A9
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_004434B4 push ecx; mov dword ptr [esp], ecx1_2_004434B8
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0040553D push 00405749h; ret 1_2_00405741
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_004055BE push 00405749h; ret 1_2_00405741
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0040563B push 00405749h; ret 1_2_00405741
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_004056A0 push 00405749h; ret 1_2_00405741
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0045186C push 0045189Fh; ret 1_2_00451897
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00451A30 push ecx; mov dword ptr [esp], eax1_2_00451A35
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00495BE4 push ecx; mov dword ptr [esp], ecx1_2_00495BE9
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00419C38 push ecx; mov dword ptr [esp], ecx1_2_00419C3D
        Source: is-9L7QC.tmp.1.drStatic PE information: section name: .text entropy: 6.90903234258047

        Persistence and Installation Behavior

        barindex
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: CreateFileA,DeviceIoControl,GetLastError,CloseHandle, \\.\PhysicalDrive03_2_02D0E8B2
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\libEGL.dll (copy)Jump to dropped file
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeFile created: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\Qt5Concurrent.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-PSA15.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-1SCM6.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeFile created: C:\ProgramData\SmartFileDefrag\SmartFileDefrag.exeJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\uninstall\is-4UKIG.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\Qt5PrintSupport.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\libGLESv2.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-8A6NR.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile created: C:\Users\user\AppData\Local\Temp\is-2BJC2.tmp\_isetup\_shfoldr.dllJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\msvcp100.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-NEI73.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\sqlite3.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-9L7QC.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile created: C:\Users\user\AppData\Local\Temp\is-2BJC2.tmp\_isetup\_setup64.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-PTS9U.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\uninstall\unins000.exe (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-5ELJT.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-J242P.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\icuuc51.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\icuin51.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\msvcr100.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeFile created: C:\ProgramData\SmartFileDefrag\sqlite3.dllJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile created: C:\Users\user\AppData\Local\Temp\is-2BJC2.tmp\_isetup\_iscrypt.dllJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpFile created: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-M743B.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeFile created: C:\ProgramData\SmartFileDefrag\SmartFileDefrag.exeJump to dropped file
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeFile created: C:\ProgramData\SmartFileDefrag\sqlite3.dllJump to dropped file

        Boot Survival

        barindex
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: CreateFileA,DeviceIoControl,GetLastError,CloseHandle, \\.\PhysicalDrive03_2_02D0E8B2
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_0040D94D StartServiceCtrlDispatcherA,3_2_0040D94D
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00423C1C IsIconic,PostMessageA,PostMessageA,PostMessageA,SendMessageA,IsWindowEnabled,IsWindowEnabled,IsWindowVisible,GetFocus,SetFocus,SetFocus,IsIconic,GetFocus,SetFocus,1_2_00423C1C
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00423C1C IsIconic,PostMessageA,PostMessageA,PostMessageA,SendMessageA,IsWindowEnabled,IsWindowEnabled,IsWindowVisible,GetFocus,SetFocus,SetFocus,IsIconic,GetFocus,SetFocus,1_2_00423C1C
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_004241EC IsIconic,SetActiveWindow,SetFocus,1_2_004241EC
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_004241A4 IsIconic,SetActiveWindow,1_2_004241A4
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00418394 IsIconic,GetWindowPlacement,GetWindowRect,GetWindowLongA,GetWindowLongA,ScreenToClient,ScreenToClient,1_2_00418394
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_004843A8 IsIconic,GetWindowLongA,ShowWindow,ShowWindow,1_2_004843A8
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0042286C SendMessageA,ShowWindow,ShowWindow,CallWindowProcA,SendMessageA,ShowWindow,SetWindowPos,GetActiveWindow,IsIconic,SetWindowPos,SetActiveWindow,ShowWindow,1_2_0042286C
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0042F2F0 IsIconic,GetWindowLongA,GetWindowLongA,GetActiveWindow,MessageBoxA,SetActiveWindow,GetActiveWindow,MessageBoxA,SetActiveWindow,1_2_0042F2F0
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_004175A8 IsIconic,GetCapture,1_2_004175A8
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00417CDE IsIconic,SetWindowPos,1_2_00417CDE
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00417CE0 IsIconic,SetWindowPos,GetWindowPlacement,SetWindowPlacement,1_2_00417CE0
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0041F128 GetVersion,SetErrorMode,LoadLibraryA,SetErrorMode,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,1_2_0041F128
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdateJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: LoadLibraryA,GetProcAddress,GetAdaptersInfo,FreeLibrary,3_2_02D0E9B6
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeWindow / User API: threadDelayed 9755Jump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\libGLESv2.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\libEGL.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-8A6NR.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-2BJC2.tmp\_isetup\_shfoldr.dllJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\msvcp100.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-NEI73.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\Qt5Concurrent.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-9L7QC.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-PSA15.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-1SCM6.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-2BJC2.tmp\_isetup\_setup64.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-PTS9U.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\uninstall\unins000.exe (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-J242P.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-5ELJT.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\icuuc51.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\icuin51.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\msvcr100.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-2BJC2.tmp\_isetup\_iscrypt.dllJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-M743B.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\uninstall\is-4UKIG.tmpJump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\Qt5PrintSupport.dll (copy)Jump to dropped file
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeEvasive API call chain: GetSystemTime,DecisionNodesgraph_0-5981
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeAPI coverage: 4.9 %
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe TID: 1296Thread sleep count: 139 > 30Jump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe TID: 1296Thread sleep time: -278000s >= -30000sJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe TID: 6860Thread sleep count: 37 > 30Jump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe TID: 6860Thread sleep time: -2220000s >= -30000sJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe TID: 1296Thread sleep count: 9755 > 30Jump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe TID: 1296Thread sleep time: -19510000s >= -30000sJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeFile opened: PhysicalDrive0Jump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00452AD4 FindFirstFileA,GetLastError,1_2_00452AD4
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00475798 FindFirstFileA,FindNextFileA,FindClose,1_2_00475798
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0046417C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose,SetErrorMode,1_2_0046417C
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_004645F8 SetErrorMode,FindFirstFileA,FindNextFileA,FindClose,SetErrorMode,1_2_004645F8
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00462BF0 FindFirstFileA,FindNextFileA,FindClose,1_2_00462BF0
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00498FDC FindFirstFileA,SetFileAttributesA,FindNextFileA,FindClose,1_2_00498FDC
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeCode function: 0_2_00409B78 GetSystemInfo,VirtualQuery,VirtualProtect,VirtualProtect,VirtualQuery,0_2_00409B78
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeThread delayed: delay time: 60000Jump to behavior
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003314000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWtp.
        Source: smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003314000.00000004.00000020.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000002.2658796792.0000000000978000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
        Source: smartfiledefrag13.exe.1.drBinary or memory string: vmCi[j
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeAPI call chain: ExitProcess graph end nodegraph_0-6778
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeAPI call chain: ExitProcess graph end nodegraph_3-61906
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpProcess information queried: ProcessInformationJump to behavior
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_00401E47 LdrInitializeThunk,3_2_00401E47
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_02D13A08 _memset,IsDebuggerPresent,3_2_02D13A08
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_02D1E6BE RtlEncodePointer,RtlEncodePointer,___crtIsPackagedApp,LoadLibraryExW,GetLastError,LoadLibraryExW,GetProcAddress,RtlEncodePointer,GetProcAddress,RtlEncodePointer,GetProcAddress,RtlEncodePointer,GetProcAddress,RtlEncodePointer,GetProcAddress,RtlEncodePointer,IsDebuggerPresent,OutputDebugStringW,LdrInitializeThunk,RtlDecodePointer,RtlDecodePointer,RtlDecodePointer,RtlDecodePointer,RtlDecodePointer,RtlDecodePointer,RtlDecodePointer,3_2_02D1E6BE
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00450334 GetVersion,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,1_2_00450334
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_02D05E59 RtlInitializeCriticalSection,GetModuleHandleA,GetModuleHandleA,GetProcAddress,GetProcAddress,GetModuleHandleA,GetProcAddress,GetTickCount,GetVersionExA,_memset,_malloc,_malloc,_malloc,_malloc,_malloc,_malloc,_malloc,LdrInitializeThunk,_malloc,GetProcessHeap,GetProcessHeap,RtlAllocateHeap,RtlAllocateHeap,GetProcessHeap,RtlAllocateHeap,GetProcessHeap,RtlAllocateHeap,_memset,_memset,_memset,RtlEnterCriticalSection,RtlLeaveCriticalSection,_malloc,_malloc,_malloc,_malloc,QueryPerformanceCounter,Sleep,_malloc,_malloc,_memset,_memset,Sleep,RtlEnterCriticalSection,RtlLeaveCriticalSection,3_2_02D05E59
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_02D180E8 SetUnhandledExceptionFilter,UnhandledExceptionFilter,3_2_02D180E8
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00478DC4 ShellExecuteEx,GetLastError,MsgWaitForMultipleObjects,GetExitCodeProcess,CloseHandle,1_2_00478DC4
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0042EE28 InitializeSecurityDescriptor,SetSecurityDescriptorDacl,CreateMutexA,1_2_0042EE28
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_0042E0AC AllocateAndInitializeSid,GetVersion,GetModuleHandleA,GetProcAddress,CheckTokenMembership,GetCurrentThread,OpenThreadToken,GetLastError,GetCurrentProcess,OpenProcessToken,GetTokenInformation,GetLastError,GetTokenInformation,EqualSid,CloseHandle,FreeSid,1_2_0042E0AC
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_02D0E86A cpuid 3_2_02D0E86A
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeCode function: GetLocaleInfoA,0_2_0040520C
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeCode function: GetLocaleInfoA,0_2_00405258
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: GetLocaleInfoA,1_2_00408578
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: GetLocaleInfoA,1_2_004085C4
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00458670 GetTickCount,QueryPerformanceCounter,GetSystemTimeAsFileTime,GetCurrentProcessId,CreateNamedPipeA,GetLastError,CreateFileA,SetNamedPipeHandleState,CreateProcessA,CloseHandle,CloseHandle,1_2_00458670
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeCode function: 0_2_004026C4 GetSystemTime,0_2_004026C4
        Source: C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmpCode function: 1_2_00455644 GetUserNameA,1_2_00455644
        Source: C:\Users\user\Desktop\tKBxw8eOIV.exeCode function: 0_2_00405CF4 GetVersionExA,0_2_00405CF4

        Stealing of Sensitive Information

        barindex
        Source: Yara matchFile source: 00000003.00000002.2660443759.0000000002D01000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000003.00000002.2660125834.000000000270F000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: smartfiledefrag13.exe PID: 1036, type: MEMORYSTR

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: 00000003.00000002.2660443759.0000000002D01000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: 00000003.00000002.2660125834.000000000270F000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
        Source: Yara matchFile source: Process Memory Space: smartfiledefrag13.exe PID: 1036, type: MEMORYSTR
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_609660FA sqlite3_finalize,sqlite3_free,sqlite3_value_numeric_type,sqlite3_value_numeric_type,sqlite3_value_text,sqlite3_value_int,memcmp,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_strnicmp,sqlite3_mprintf,sqlite3_mprintf,sqlite3_malloc,sqlite3_free,sqlite3_mprintf,sqlite3_prepare_v2,sqlite3_free,sqlite3_bind_value,3_2_609660FA
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6090C1D6 sqlite3_clear_bindings,sqlite3_mutex_enter,sqlite3_mutex_leave,3_2_6090C1D6
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_60963143 sqlite3_stricmp,sqlite3_bind_int64,sqlite3_mutex_leave,3_2_60963143
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6096A2BD sqlite3_bind_int64,sqlite3_step,sqlite3_column_int,sqlite3_reset,3_2_6096A2BD
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6096923E sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_column_int64,sqlite3_reset,sqlite3_malloc,sqlite3_malloc,sqlite3_step,sqlite3_column_int64,sqlite3_reset,sqlite3_realloc,sqlite3_realloc,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_free,sqlite3_free,sqlite3_free,3_2_6096923E
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6096A38C sqlite3_bind_int,sqlite3_column_int,sqlite3_step,sqlite3_reset,3_2_6096A38C
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6096748C sqlite3_malloc,sqlite3_bind_int,sqlite3_step,sqlite3_column_blob,sqlite3_column_bytes,sqlite3_reset,sqlite3_bind_int,sqlite3_step,sqlite3_column_int64,sqlite3_reset,sqlite3_malloc,sqlite3_bind_int64,sqlite3_column_bytes,sqlite3_column_blob,sqlite3_column_int64,sqlite3_column_int64,sqlite3_column_int64,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_step,sqlite3_column_int,sqlite3_reset,sqlite3_bind_int64,sqlite3_bind_int,sqlite3_step,sqlite3_column_int64,sqlite3_column_int64,sqlite3_column_int64,sqlite3_column_bytes,sqlite3_column_blob,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_reset,memcmp,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_reset,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_column_int,sqlite3_reset,sqlite3_step,sqlite3_column_int64,sqlite3_reset,sqlite3_bind_int64,sqlite3_realloc,sqlite3_column_int,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_bind_int,sqlite3_bind_int,sqlite3_step,sqlite3_reset,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_free,sqlite3_bind_int,sqlite3_bind_blob,sqlite3_step,sqlite3_reset,sqlite3_free,sqlite3_free,3_2_6096748C
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_609254B1 sqlite3_bind_zeroblob,sqlite3_mutex_leave,3_2_609254B1
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6094B407 sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,3_2_6094B407
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6090F435 sqlite3_bind_parameter_index,3_2_6090F435
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_609255D4 sqlite3_mutex_leave,sqlite3_bind_text16,3_2_609255D4
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_609255FF sqlite3_bind_text,3_2_609255FF
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6096A5EE sqlite3_value_text,sqlite3_value_bytes,sqlite3_strnicmp,sqlite3_strnicmp,sqlite3_mprintf,sqlite3_prepare_v2,sqlite3_free,sqlite3_malloc,LdrInitializeThunk,sqlite3_column_int,sqlite3_column_int64,sqlite3_column_text,sqlite3_column_bytes,sqlite3_finalize,sqlite3_step,sqlite3_free,sqlite3_finalize,sqlite3_strnicmp,sqlite3_bind_int,sqlite3_column_int,sqlite3_step,sqlite3_reset,sqlite3_mprintf,sqlite3_prepare_v2,sqlite3_free,sqlite3_column_int64,sqlite3_column_int,sqlite3_column_text,sqlite3_column_bytes,sqlite3_step,sqlite3_finalize,sqlite3_strnicmp,sqlite3_strnicmp,sqlite3_bind_int,sqlite3_bind_int,sqlite3_step,sqlite3_reset,sqlite3_value_int,sqlite3_malloc,sqlite3_bind_null,sqlite3_step,sqlite3_reset,sqlite3_value_int,sqlite3_value_text,sqlite3_value_bytes,sqlite3_free,3_2_6096A5EE
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6094B54C sqlite3_bind_int64,sqlite3_step,sqlite3_column_int64,sqlite3_reset,memmove,3_2_6094B54C
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_60925686 sqlite3_bind_int64,sqlite3_mutex_leave,3_2_60925686
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6094A6C5 sqlite3_bind_int64,sqlite3_step,sqlite3_column_blob,sqlite3_column_bytes,sqlite3_malloc,sqlite3_reset,sqlite3_free,3_2_6094A6C5
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_609256E5 sqlite3_bind_int,sqlite3_bind_int64,3_2_609256E5
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6094B6ED sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,3_2_6094B6ED
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6092562A sqlite3_bind_blob,3_2_6092562A
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_60925655 sqlite3_bind_null,sqlite3_mutex_leave,3_2_60925655
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6094C64A sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_free,3_2_6094C64A
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_609687A7 sqlite3_bind_int64,sqlite3_bind_int,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_bind_int,sqlite3_step,sqlite3_column_blob,sqlite3_column_bytes,sqlite3_column_int64,sqlite3_reset,sqlite3_free,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_bind_int64,sqlite3_bind_blob,sqlite3_bind_int64,sqlite3_bind_int,sqlite3_step,sqlite3_reset,sqlite3_free,sqlite3_free,3_2_609687A7
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6095F7F7 sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,3_2_6095F7F7
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6092570B sqlite3_bind_double,sqlite3_mutex_leave,3_2_6092570B
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6095F772 sqlite3_bind_int64,sqlite3_bind_blob,sqlite3_step,sqlite3_reset,3_2_6095F772
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_60925778 sqlite3_bind_value,sqlite3_bind_int64,sqlite3_bind_double,sqlite3_bind_blob,3_2_60925778
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6090577D sqlite3_bind_parameter_name,3_2_6090577D
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6094B764 sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_step,3_2_6094B764
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6090576B sqlite3_bind_parameter_count,3_2_6090576B
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6094A894 sqlite3_bind_int64,sqlite3_step,sqlite3_column_int64,sqlite3_reset,3_2_6094A894
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6095F883 sqlite3_bind_int64,sqlite3_bind_int,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_bind_blob,sqlite3_step,sqlite3_reset,3_2_6095F883
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6094C8C2 sqlite3_value_int,sqlite3_value_int,sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_bind_null,sqlite3_bind_null,sqlite3_step,sqlite3_reset,3_2_6094C8C2
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6096281E sqlite3_mprintf,sqlite3_vtab_config,sqlite3_malloc,sqlite3_mprintf,sqlite3_mprintf,sqlite3_errmsg,sqlite3_mprintf,sqlite3_free,sqlite3_mprintf,sqlite3_exec,sqlite3_free,sqlite3_prepare_v2,sqlite3_bind_text,sqlite3_step,sqlite3_column_int64,sqlite3_finalize,sqlite3_mprintf,sqlite3_prepare_v2,sqlite3_free,sqlite3_errmsg,sqlite3_mprintf,sqlite3_mprintf,sqlite3_mprintf,sqlite3_free,sqlite3_mprintf,sqlite3_free,sqlite3_declare_vtab,sqlite3_errmsg,sqlite3_mprintf,sqlite3_free,3_2_6096281E
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6096583A memcmp,sqlite3_realloc,qsort,sqlite3_malloc,sqlite3_free,sqlite3_bind_int64,sqlite3_bind_int64,sqlite3_column_int64,sqlite3_column_int64,sqlite3_column_int64,sqlite3_column_bytes,sqlite3_column_blob,sqlite3_step,sqlite3_reset,3_2_6096583A
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6095F9AD sqlite3_bind_int,sqlite3_step,sqlite3_column_type,sqlite3_reset,3_2_6095F9AD
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6094A92B sqlite3_bind_int64,sqlite3_bind_null,sqlite3_bind_blob,sqlite3_step,sqlite3_reset,3_2_6094A92B
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6090EAE5 sqlite3_transfer_bindings,3_2_6090EAE5
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6095FB98 sqlite3_value_int,sqlite3_bind_int,sqlite3_bind_value,sqlite3_step,sqlite3_reset,3_2_6095FB98
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6095ECA6 sqlite3_mprintf,sqlite3_mprintf,sqlite3_mprintf,sqlite3_prepare_v2,sqlite3_free,sqlite3_bind_value,3_2_6095ECA6
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6095FCCE sqlite3_malloc,sqlite3_free,sqlite3_bind_int64,sqlite3_bind_blob,sqlite3_step,sqlite3_reset,3_2_6095FCCE
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6095FDAE sqlite3_malloc,sqlite3_bind_int,sqlite3_step,sqlite3_column_bytes,sqlite3_column_blob,sqlite3_reset,sqlite3_free,sqlite3_free,sqlite3_bind_int,sqlite3_bind_blob,sqlite3_step,sqlite3_reset,sqlite3_free,3_2_6095FDAE
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_60966DF1 sqlite3_value_text,sqlite3_mprintf,sqlite3_free,strcmp,sqlite3_free,sqlite3_malloc,sqlite3_bind_int64,sqlite3_step,sqlite3_column_type,sqlite3_reset,sqlite3_column_blob,sqlite3_reset,sqlite3_malloc,sqlite3_free,sqlite3_reset,sqlite3_result_error_code,sqlite3_result_blob,3_2_60966DF1
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_60969D75 sqlite3_bind_int,sqlite3_step,sqlite3_column_int,sqlite3_reset,3_2_60969D75
        Source: C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exeCode function: 3_2_6095FFB2 sqlite3_bind_int64,sqlite3_step,sqlite3_reset,sqlite3_result_error_code,3_2_6095FFB2
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
        Native API
        1
        DLL Side-Loading
        1
        Exploitation for Privilege Escalation
        1
        Deobfuscate/Decode Files or Information
        OS Credential Dumping1
        System Time Discovery
        Remote Services1
        Archive Collected Data
        2
        Ingress Tool Transfer
        Exfiltration Over Other Network Medium1
        System Shutdown/Reboot
        CredentialsDomainsDefault Accounts2
        Command and Scripting Interpreter
        5
        Windows Service
        1
        DLL Side-Loading
        3
        Obfuscated Files or Information
        LSASS Memory1
        Account Discovery
        Remote Desktop ProtocolData from Removable Media21
        Encrypted Channel
        Exfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain Accounts2
        Service Execution
        1
        Bootkit
        1
        Access Token Manipulation
        21
        Software Packing
        Security Account Manager2
        File and Directory Discovery
        SMB/Windows Admin SharesData from Network Shared Drive1
        Non-Standard Port
        Automated ExfiltrationData Encrypted for Impact
        Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook5
        Windows Service
        1
        DLL Side-Loading
        NTDS35
        System Information Discovery
        Distributed Component Object ModelInput Capture1
        Non-Application Layer Protocol
        Traffic DuplicationData Destruction
        Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon Script2
        Process Injection
        1
        Masquerading
        LSA Secrets1
        Query Registry
        SSHKeylogging12
        Application Layer Protocol
        Scheduled TransferData Encrypted for Impact
        Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts21
        Virtualization/Sandbox Evasion
        Cached Domain Credentials41
        Security Software Discovery
        VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
        DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
        Access Token Manipulation
        DCSync1
        Process Discovery
        Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
        Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job2
        Process Injection
        Proc Filesystem21
        Virtualization/Sandbox Evasion
        Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
        Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAt1
        Bootkit
        /etc/passwd and /etc/shadow11
        Application Window Discovery
        Direct Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
        IP AddressesCompromise InfrastructureSupply Chain CompromisePowerShellCronCronDynamic API ResolutionNetwork Sniffing3
        System Owner/User Discovery
        Shared WebrootLocal Data StagingFile Transfer ProtocolsExfiltration Over Asymmetric Encrypted Non-C2 ProtocolExternal Defacement
        Network Security AppliancesDomainsCompromise Software Dependencies and Development ToolsAppleScriptLaunchdLaunchdStripped PayloadsInput Capture1
        System Network Configuration Discovery
        Software Deployment ToolsRemote Data StagingMail ProtocolsExfiltration Over Unencrypted Non-C2 ProtocolFirmware Corruption
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Is Windows Process
        • Number of created Registry Values
        • Number of created Files
        • Visual Basic
        • Delphi
        • Java
        • .Net C# or VB.NET
        • C, C++ or other language
        • Is malicious
        • Internet

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        SourceDetectionScannerLabelLink
        tKBxw8eOIV.exe19%VirustotalBrowse
        tKBxw8eOIV.exe8%ReversingLabs
        SourceDetectionScannerLabelLink
        C:\ProgramData\SmartFileDefrag\sqlite3.dll0%ReversingLabs
        C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\Qt5Concurrent.dll (copy)4%ReversingLabs
        C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\Qt5PrintSupport.dll (copy)4%ReversingLabs
        C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\icuin51.dll (copy)2%ReversingLabs
        C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\icuuc51.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-1SCM6.tmp4%ReversingLabs
        C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-5ELJT.tmp2%ReversingLabs
        C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-8A6NR.tmp0%ReversingLabs
        C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-9L7QC.tmp0%ReversingLabs
        C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-J242P.tmp0%ReversingLabs
        C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-M743B.tmp4%ReversingLabs
        C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-NEI73.tmp0%ReversingLabs
        C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-PSA15.tmp0%ReversingLabs
        C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\is-PTS9U.tmp0%ReversingLabs
        C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\libEGL.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\libGLESv2.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\msvcp100.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\msvcr100.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\sqlite3.dll (copy)0%ReversingLabs
        C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\uninstall\is-4UKIG.tmp3%ReversingLabs
        C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\uninstall\unins000.exe (copy)3%ReversingLabs
        C:\Users\user\AppData\Local\Temp\is-2BJC2.tmp\_isetup\_iscrypt.dll0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\is-2BJC2.tmp\_isetup\_setup64.tmp0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\is-2BJC2.tmp\_isetup\_shfoldr.dll0%ReversingLabs
        C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp3%ReversingLabs
        No Antivirus matches
        No Antivirus matches
        SourceDetectionScannerLabelLink
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f832a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c842a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38b842a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f822a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a842a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a8c2a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f872a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d842a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f862a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f842a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d8c2a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f852a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f842a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a812a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f802a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c812a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c8c2a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f812a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f812a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d812a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c926d19fe6595cd66946851e91fcd85241ab258d81729326be8ee43a8f51f8a95b5ca212a91f953c588fb52d6db9f51a9a0a29d5954cad713479a672918d4348dd4da945b49c80%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f8c2a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        http://www.countnow.ru0%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f8c2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb386926d19fe6595cd66946951e91fcd852500%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f8d2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb388926d19fe6595cd66946951e91fcd852500%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c926d19fe6595cd66946851e91fcd852410%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d872a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f872a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a926d19fe6595cd66946951e91fcd852500%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a872a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c802a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a832a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c8d2a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a862a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a852a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f802a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38b926d19fe6595cd66946951e91fcd852500%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a812a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a842a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f8d2a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc0%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a822a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a802a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38b852a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a852a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f852a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc0%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38b926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc0%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d8d2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb389926d19fe6595cd66946951e91fcd852500%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a862a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d8c2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d842a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d852a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f822a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d862a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d872a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d802a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d812a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a8c2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a8d2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d832a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d822a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f832a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/en-US0%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a872a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c812a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/mCertificates0%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb389926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc0%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb388926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc0%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c872a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb387926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc0%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb386926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc0%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c862a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/H0%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c852a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c842a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c832a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c822a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c802a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c822a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38b842a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38b852a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a822a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f926d19fe6595cd66946851e91fcd85241ab258d81729326be8ee43a8f51f8a95b5ca212a91f953c588fb52d6db9f51a9a0a29d5954cad713479a672918d4348dd4da945b49c80%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d862a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a832a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f862a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c832a1cec7a86d87bdb6546ad12dac02900%Avira URL Cloudsafe
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c8c2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc070%Avira URL Cloudsafe
        No contacted domains info
        NameMaliciousAntivirus DetectionReputation
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f872a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f862a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f832a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f822a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f852a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f842a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f812a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f802a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c926d19fe6595cd66946851e91fcd85241ab258d81729326be8ee43a8f51f8a95b5ca212a91f953c588fb52d6db9f51a9a0a29d5954cad713479a672918d4348dd4da945b49c8false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f8c2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f8d2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a872a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a852a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a862a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a832a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a842a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a812a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a822a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a802a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dcfalse
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38b926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dcfalse
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dcfalse
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d8d2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d8c2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d842a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d852a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d862a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d872a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d802a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d812a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d822a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d832a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a8d2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a8c2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c812a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb389926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dcfalse
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb386926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dcfalse
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb388926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dcfalse
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb387926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dcfalse
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c872a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c862a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c852a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c842a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c832a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c822a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c802a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38b852a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38b842a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f926d19fe6595cd66946851e91fcd85241ab258d81729326be8ee43a8f51f8a95b5ca212a91f953c588fb52d6db9f51a9a0a29d5954cad713479a672918d4348dd4da945b49c8false
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c8c2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07false
        • Avira URL Cloud: safe
        unknown
        NameSourceMaliciousAntivirus DetectionReputation
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a842a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c842a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003371000.00000004.00000020.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38b842a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2661508814.00000000033F4000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f842a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003365000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d842a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a8c2a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2661508814.00000000033F4000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d8c2a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a812a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c8c2a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003371000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f812a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2658796792.0000000000A33000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c812a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d812a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        http://www.countnow.rutKBxw8eOIV.tmp, 00000001.00000002.2659689071.0000000005C9A000.00000004.00001000.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000000.1423149968.000000000065C000.00000002.00000001.01000000.00000009.sdmp, smartfiledefrag13.exe, 00000003.00000003.1424200199.0000000002689000.00000004.00000020.00020000.00000000.sdmp, SmartFileDefrag.exe.3.dr, is-TVCIJ.tmp.1.dr, smartfiledefrag13.exe.1.drfalse
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f8c2a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003371000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb386926d19fe6595cd66946951e91fcd85250smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000336F000.00000004.00000020.00020000.00000000.sdmpfalse
        • Avira URL Cloud: safe
        unknown
        https://176.113.115.96/en-GBsmartfiledefrag13.exe, 00000003.00000002.2658796792.0000000000A51000.00000004.00000020.00020000.00000000.sdmpfalse
          high
          https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb388926d19fe6595cd66946951e91fcd85250smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003321000.00000004.00000020.00020000.00000000.sdmpfalse
          • Avira URL Cloud: safe
          unknown
          https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c926d19fe6595cd66946851e91fcd85241smartfiledefrag13.exe, 00000003.00000002.2658796792.0000000000A51000.00000004.00000020.00020000.00000000.sdmpfalse
          • Avira URL Cloud: safe
          unknown
          https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d872a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpfalse
          • Avira URL Cloud: safe
          unknown
          https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f872a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003371000.00000004.00000020.00020000.00000000.sdmpfalse
          • Avira URL Cloud: safe
          unknown
          http://www.innosetup.com/tKBxw8eOIV.tmp, tKBxw8eOIV.tmp, 00000001.00000002.2658067655.0000000000401000.00000020.00000001.01000000.00000004.sdmp, tKBxw8eOIV.tmp.0.dr, is-4UKIG.tmp.1.drfalse
            high
            https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a926d19fe6595cd66946951e91fcd85250smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003328000.00000004.00000020.00020000.00000000.sdmpfalse
            • Avira URL Cloud: safe
            unknown
            https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c802a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpfalse
            • Avira URL Cloud: safe
            unknown
            https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38b926d19fe6595cd66946951e91fcd85250smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000331E000.00000004.00000020.00020000.00000000.sdmpfalse
            • Avira URL Cloud: safe
            unknown
            https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c8d2a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpfalse
            • Avira URL Cloud: safe
            unknown
            https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f802a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2658796792.0000000000A33000.00000004.00000020.00020000.00000000.sdmpfalse
            • Avira URL Cloud: safe
            unknown
            https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f8d2a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003371000.00000004.00000020.00020000.00000000.sdmpfalse
            • Avira URL Cloud: safe
            unknown
            http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdlinetKBxw8eOIV.exefalse
              high
              https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a852a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38b852a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2661508814.00000000033F4000.00000004.00000020.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000002.2658796792.0000000000A33000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f852a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003369000.00000004.00000020.00020000.00000000.sdmpfalse
              • Avira URL Cloud: safe
              unknown
              http://icu-project.orgis-5ELJT.tmp.1.dr, is-PSA15.tmp.1.drfalse
                high
                https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb389926d19fe6595cd66946951e91fcd85250smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003323000.00000004.00000020.00020000.00000000.sdmpfalse
                • Avira URL Cloud: safe
                unknown
                https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a862a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2658796792.0000000000978000.00000004.00000020.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpfalse
                • Avira URL Cloud: safe
                unknown
                https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f822a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2658796792.0000000000A33000.00000004.00000020.00020000.00000000.sdmpfalse
                • Avira URL Cloud: safe
                unknown
                https://www.easycutstudio.com/support.htmltKBxw8eOIV.exe, 00000000.00000003.1410283097.0000000002141000.00000004.00001000.00020000.00000000.sdmp, tKBxw8eOIV.exe, 00000000.00000002.2659067659.0000000002141000.00000004.00001000.00020000.00000000.sdmp, tKBxw8eOIV.exe, 00000000.00000003.1410213366.0000000002370000.00000004.00001000.00020000.00000000.sdmp, tKBxw8eOIV.tmp, 00000001.00000002.2658704788.0000000000734000.00000004.00000020.00020000.00000000.sdmp, tKBxw8eOIV.tmp, 00000001.00000003.1412236817.00000000030F0000.00000004.00001000.00020000.00000000.sdmp, tKBxw8eOIV.tmp, 00000001.00000003.1412307068.0000000002098000.00000004.00001000.00020000.00000000.sdmp, tKBxw8eOIV.tmp, 00000001.00000002.2659005353.0000000002098000.00000004.00001000.00020000.00000000.sdmpfalse
                  high
                  https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a872a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2658796792.0000000000978000.00000004.00000020.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: safe
                  unknown
                  https://176.113.115.96/ographysmartfiledefrag13.exe, 00000003.00000002.2658796792.0000000000A65000.00000004.00000020.00020000.00000000.sdmpfalse
                    high
                    https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f832a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003328000.00000004.00000020.00020000.00000000.sdmp, smartfiledefrag13.exe, 00000003.00000002.2660962056.0000000003371000.00000004.00000020.00020000.00000000.sdmpfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://176.113.115.96/en-USsmartfiledefrag13.exe, 00000003.00000002.2658796792.0000000000A51000.00000004.00000020.00020000.00000000.sdmpfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://176.113.115.96/mCertificatessmartfiledefrag13.exe, 00000003.00000002.2658796792.0000000000A51000.00000004.00000020.00020000.00000000.sdmpfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://176.113.115.96/smartfiledefrag13.exe, 00000003.00000002.2661508814.00000000033F4000.00000004.00000020.00020000.00000000.sdmpfalse
                      high
                      http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupUtKBxw8eOIV.exefalse
                        high
                        https://176.113.115.96/Hsmartfiledefrag13.exe, 00000003.00000002.2661508814.00000000033F4000.00000004.00000020.00020000.00000000.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a822a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2661508814.00000000033F4000.00000004.00000020.00020000.00000000.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c822a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d862a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f862a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000336B000.00000004.00000020.00020000.00000000.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a832a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2661508814.00000000033F4000.00000004.00000020.00020000.00000000.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://176.113.115.96/ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c832a1cec7a86d87bdb6546ad12dac0290smartfiledefrag13.exe, 00000003.00000002.2660962056.000000000339C000.00000004.00000020.00020000.00000000.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        • No. of IPs < 25%
                        • 25% < No. of IPs < 50%
                        • 50% < No. of IPs < 75%
                        • 75% < No. of IPs
                        IPDomainCountryFlagASNASN NameMalicious
                        176.113.115.96
                        unknownRussian Federation
                        49505SELECTELRUfalse
                        193.176.153.180
                        unknownunknown
                        207451AGROSVITUAfalse
                        Joe Sandbox version:42.0.0 Malachite
                        Analysis ID:1628986
                        Start date and time:2025-03-04 10:28:13 +01:00
                        Joe Sandbox product:CloudBasic
                        Overall analysis duration:0h 6m 18s
                        Hypervisor based Inspection enabled:false
                        Report type:full
                        Cookbook file name:default.jbs
                        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                        Number of analysed new started processes analysed:9
                        Number of new started drivers analysed:0
                        Number of existing processes analysed:0
                        Number of existing drivers analysed:0
                        Number of injected processes analysed:0
                        Technologies:
                        • HCA enabled
                        • EGA enabled
                        • AMSI enabled
                        Analysis Mode:default
                        Analysis stop reason:Timeout
                        Sample name:tKBxw8eOIV.exe
                        renamed because original name is a hash value
                        Original Sample Name:51f4cfbe1c4f38beb7d4185086720317.exe
                        Detection:MAL
                        Classification:mal84.troj.evad.winEXE@5/32@0/2
                        EGA Information:
                        • Successful, ratio: 100%
                        HCA Information:
                        • Successful, ratio: 92%
                        • Number of executed functions: 205
                        • Number of non-executed functions: 304
                        Cookbook Comments:
                        • Found application associated with file extension: .exe
                        • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
                        • Excluded IPs from analysis (whitelisted): 172.202.163.200
                        • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                        • Not all processes where analyzed, report is missing behavior information
                        • Report size exceeded maximum capacity and may have missing disassembly code.
                        • Report size getting too big, too many NtOpenKeyEx calls found.
                        • Report size getting too big, too many NtQueryValueKey calls found.
                        TimeTypeDescription
                        04:29:45API Interceptor439388x Sleep call for process: smartfiledefrag13.exe modified
                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                        176.113.115.96soft.exeGet hashmaliciousGCleaner, LummaC Stealer, Socks5SystemzBrowse
                          9uWGaRcOv8.exeGet hashmaliciousSocks5SystemzBrowse
                            9uWGaRcOv8.exeGet hashmaliciousSocks5SystemzBrowse
                              file.exeGet hashmaliciousSocks5SystemzBrowse
                                file.exeGet hashmaliciousSocks5SystemzBrowse
                                  silk.exeGet hashmaliciousSocks5SystemzBrowse
                                    silk.exeGet hashmaliciousSocks5SystemzBrowse
                                      random.exeGet hashmaliciousGCleaner, LummaC Stealer, Socks5SystemzBrowse
                                        mix.exeGet hashmaliciousSocks5SystemzBrowse
                                          mix.exeGet hashmaliciousSocks5SystemzBrowse
                                            193.176.153.1809uWGaRcOv8.exeGet hashmaliciousSocks5SystemzBrowse
                                              file.exeGet hashmaliciousSocks5SystemzBrowse
                                                silk.exeGet hashmaliciousSocks5SystemzBrowse
                                                  mix.exeGet hashmaliciousSocks5SystemzBrowse
                                                    mix.exeGet hashmaliciousSocks5SystemzBrowse
                                                      KFkv0LwVHW.exeGet hashmaliciousAmadey, Credential Flusher, Cryptbot, GCleaner, LummaC Stealer, PureLog Stealer, RedLineBrowse
                                                        random.exeGet hashmaliciousAmadey, Cryptbot, Socks5SystemzBrowse
                                                          random.exeGet hashmaliciousSocks5SystemzBrowse
                                                            AApUa7VQiy.exeGet hashmaliciousLummaC, Amadey, LummaC Stealer, Socks5Systemz, Stealc, VidarBrowse
                                                              LMl9NtTiV19n.exeGet hashmaliciousSocks5SystemzBrowse
                                                                No context
                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                AGROSVITUA9uWGaRcOv8.exeGet hashmaliciousSocks5SystemzBrowse
                                                                • 193.176.153.180
                                                                file.exeGet hashmaliciousSocks5SystemzBrowse
                                                                • 193.176.153.180
                                                                silk.exeGet hashmaliciousSocks5SystemzBrowse
                                                                • 193.176.153.180
                                                                mix.exeGet hashmaliciousSocks5SystemzBrowse
                                                                • 193.176.153.180
                                                                mix.exeGet hashmaliciousSocks5SystemzBrowse
                                                                • 193.176.153.180
                                                                KFkv0LwVHW.exeGet hashmaliciousAmadey, Credential Flusher, Cryptbot, GCleaner, LummaC Stealer, PureLog Stealer, RedLineBrowse
                                                                • 193.176.153.180
                                                                random.exeGet hashmaliciousAmadey, Cryptbot, Socks5SystemzBrowse
                                                                • 193.176.153.180
                                                                random.exeGet hashmaliciousSocks5SystemzBrowse
                                                                • 193.176.153.180
                                                                AApUa7VQiy.exeGet hashmaliciousLummaC, Amadey, LummaC Stealer, Socks5Systemz, Stealc, VidarBrowse
                                                                • 193.176.153.180
                                                                LMl9NtTiV19n.exeGet hashmaliciousSocks5SystemzBrowse
                                                                • 193.176.153.180
                                                                SELECTELRUrhsvjqRoEV.exeGet hashmaliciousAmadey, LummaC Stealer, PureLog Stealer, XWormBrowse
                                                                • 176.113.115.6
                                                                S2W2ftXM2b.exeGet hashmaliciousAmadey, LummaC Stealer, PureLog Stealer, XWormBrowse
                                                                • 176.113.115.6
                                                                pGOrhjLXy3.exeGet hashmaliciousAmadey, LummaC Stealer, StealcBrowse
                                                                • 176.113.115.6
                                                                cbr.x86.elfGet hashmaliciousMiraiBrowse
                                                                • 45.146.169.54
                                                                random.exeGet hashmaliciousAmadey, Credential Flusher, GCleaner, LummaC Stealer, StealcBrowse
                                                                • 176.113.115.6
                                                                random.exeGet hashmaliciousAmadey, LummaC StealerBrowse
                                                                • 176.113.115.6
                                                                soft.exeGet hashmaliciousGCleaner, LummaC Stealer, Socks5SystemzBrowse
                                                                • 176.113.115.96
                                                                9uWGaRcOv8.exeGet hashmaliciousSocks5SystemzBrowse
                                                                • 176.113.115.96
                                                                9uWGaRcOv8.exeGet hashmaliciousSocks5SystemzBrowse
                                                                • 176.113.115.96
                                                                W7W3IFQljT.exeGet hashmaliciousAmadey, LummaC Stealer, PureLog Stealer, Tofsee, zgRATBrowse
                                                                • 176.113.115.6
                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                51c64c77e60f3980eea90869b68c58a8xn3nGSFdRn.exeGet hashmaliciousVidarBrowse
                                                                • 176.113.115.96
                                                                soft.exeGet hashmaliciousGCleaner, LummaC Stealer, Socks5SystemzBrowse
                                                                • 176.113.115.96
                                                                9uWGaRcOv8.exeGet hashmaliciousSocks5SystemzBrowse
                                                                • 176.113.115.96
                                                                9uWGaRcOv8.exeGet hashmaliciousSocks5SystemzBrowse
                                                                • 176.113.115.96
                                                                file.exeGet hashmaliciousSocks5SystemzBrowse
                                                                • 176.113.115.96
                                                                file.exeGet hashmaliciousSocks5SystemzBrowse
                                                                • 176.113.115.96
                                                                yMwA2Hcj3Q.dllGet hashmaliciousCobaltStrike, MetasploitBrowse
                                                                • 176.113.115.96
                                                                server.exeGet hashmaliciousUrsnifBrowse
                                                                • 176.113.115.96
                                                                silk.exeGet hashmaliciousSocks5SystemzBrowse
                                                                • 176.113.115.96
                                                                silk.exeGet hashmaliciousSocks5SystemzBrowse
                                                                • 176.113.115.96
                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                C:\ProgramData\SmartFileDefrag\sqlite3.dllsoft.exeGet hashmaliciousGCleaner, LummaC Stealer, Socks5SystemzBrowse
                                                                  9uWGaRcOv8.exeGet hashmaliciousSocks5SystemzBrowse
                                                                    9uWGaRcOv8.exeGet hashmaliciousSocks5SystemzBrowse
                                                                      file.exeGet hashmaliciousSocks5SystemzBrowse
                                                                        file.exeGet hashmaliciousSocks5SystemzBrowse
                                                                          silk.exeGet hashmaliciousSocks5SystemzBrowse
                                                                            silk.exeGet hashmaliciousSocks5SystemzBrowse
                                                                              1w5RpHuliE.exeGet hashmaliciousAmadey, GCleaner, LummaC Stealer, PureLog Stealer, RedLine, SmokeLoader, VidarBrowse
                                                                                random.exeGet hashmaliciousGCleaner, LummaC Stealer, Socks5SystemzBrowse
                                                                                  mix.exeGet hashmaliciousSocks5SystemzBrowse
                                                                                    Process:C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):3036672
                                                                                    Entropy (8bit):6.676551488534372
                                                                                    Encrypted:false
                                                                                    SSDEEP:49152:Gewe1eae/lefseluTQep6eMiXMiyq9fMmkmBtla/9WdyplLnDesOJvA:yecSoii86fMmkmBra/9WdyplaJ
                                                                                    MD5:483573178F49D6667013866FB10AB1CB
                                                                                    SHA1:927E913247E5458925813BC6747AE9882BC03FD6
                                                                                    SHA-256:4E43B32BCA5224D444D61A366E6949A33DF1526C2AD209A1EC49221D9972A323
                                                                                    SHA-512:0404AC48831B71A1EB78EEE6BB7F4C39FF6543E0809A511198151152283A4D39574328345E6136A19E4DAE46D6B0AAB9175A6611769BD3E0E1F97E2453BEEA08
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......................PE..L....P.g..................#..........?#.......#...@........................................................................D.#......P$.0[............................................................................#.p............................text...*.#.......#.................`....rdata...?....#..@....#.............@..@.data....c....#..0....#.............@....rsrc....\...P$..\....#.............@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):645592
                                                                                    Entropy (8bit):6.50414583238337
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:i0zrcH2F3OfwjtWvuFEmhx0Cj37670jwX+E7tFKm0qTYh:iJUOfwh8u9hx0D70NE7tFTYh
                                                                                    MD5:E477A96C8F2B18D6B5C27BDE49C990BF
                                                                                    SHA1:E980C9BF41330D1E5BD04556DB4646A0210F7409
                                                                                    SHA-256:16574F51785B0E2FC29C2C61477EB47BB39F714829999511DC8952B43AB17660
                                                                                    SHA-512:335A86268E7C0E568B1C30981EC644E6CD332E66F96D2551B58A82515316693C1859D87B4F4B7310CF1AC386CEE671580FDD999C3BCB23ACF2C2282C01C8798C
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Joe Sandbox View:
                                                                                    • Filename: soft.exe, Detection: malicious, Browse
                                                                                    • Filename: 9uWGaRcOv8.exe, Detection: malicious, Browse
                                                                                    • Filename: 9uWGaRcOv8.exe, Detection: malicious, Browse
                                                                                    • Filename: file.exe, Detection: malicious, Browse
                                                                                    • Filename: file.exe, Detection: malicious, Browse
                                                                                    • Filename: silk.exe, Detection: malicious, Browse
                                                                                    • Filename: silk.exe, Detection: malicious, Browse
                                                                                    • Filename: 1w5RpHuliE.exe, Detection: malicious, Browse
                                                                                    • Filename: random.exe, Detection: malicious, Browse
                                                                                    • Filename: mix.exe, Detection: malicious, Browse
                                                                                    Reputation:moderate, very likely benign file
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S.v..?......!................X..............`......................... ......8......... .................................L................................'......................................................p............................text...............................`.0`.data...............................@.@..rdata..$...........................@.@@.bss..................................@..edata..............................@.0@.idata..L...........................@.0..CRT................................@.0..tls.... ...........................@.0..reloc...'.......(..................@.0B/4......`....0......................@.@B/19..........@......................@..B/35.....M....P......................@..B/51.....`C...`...D..................@..B/63..................8..............@..B/77..................F..............@..B/89..................R..
                                                                                    Process:C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    File Type:ISO-8859 text, with no line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):8
                                                                                    Entropy (8bit):2.0
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:X/:X/
                                                                                    MD5:83212A9F8E435B456F775DF90EAF0BE3
                                                                                    SHA1:64C1988F7A0F93C17B5D5F590D2111C9E3C6DDFB
                                                                                    SHA-256:E6B4175889EAE0DB8A49E2E096FF6229388A7E5EE75153C60DB6C1876265983B
                                                                                    SHA-512:439FEE3974B2352C5267FCDE61325BCC43EB168968C600F6B3DD8C6936F34E31E8BA1D5A8A60C5410921488D4B99120F464801434C1705911D4A8F4E9B375F81
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    Preview:#..g....
                                                                                    Process:C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    File Type:data
                                                                                    Category:dropped
                                                                                    Size (bytes):4
                                                                                    Entropy (8bit):0.8112781244591328
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:vln:9
                                                                                    MD5:533F1EADB15135CA6266579F2678CD73
                                                                                    SHA1:B8CB6B3DE866F2FD1F17996FEE01CEC4748A03E8
                                                                                    SHA-256:85DD751867E3155C7F2E23E8446546906F5BF617D4D985ED474822613764D69E
                                                                                    SHA-512:CFB56B2C754E7D51DB64D746ECB76EB4969EEBB5F4CDA9CE933E4CACA5A0A4344CC240B5B2B7887836CF78E8756C32F261F1BA1307D1956FAEBB288E0FA9CB74
                                                                                    Malicious:false
                                                                                    Reputation:low
                                                                                    Preview:2...
                                                                                    Process:C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    File Type:ASCII text, with no line terminators
                                                                                    Category:dropped
                                                                                    Size (bytes):128
                                                                                    Entropy (8bit):2.951914235012335
                                                                                    Encrypted:false
                                                                                    SSDEEP:3:ZoeGqdhHzXDBdUBWetxt:kq3HzX3UFx
                                                                                    MD5:DD1ADC2BD780F3D8A4D52C8F148CCC77
                                                                                    SHA1:E1920FE88E516FEEE3573E21D3914784A6367AE9
                                                                                    SHA-256:5D08D3AC6C11A03519DCBD53D0FFBCAC8FD0099A8FB525760FDEB5DE11BEC463
                                                                                    SHA-512:D4E83054B8033D52B42352BA425DE086A22119A854DB1A35C51433E392FDC10082AFB8675958CF897E27F06862865DCE861FAC1175B90DDF51AEAF94C368943F
                                                                                    Malicious:false
                                                                                    Reputation:moderate, very likely benign file
                                                                                    Preview:1eb2b8720110dff756582a45e74bb62f518d3799011c89eb7c719048e83fac56................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):18432
                                                                                    Entropy (8bit):5.996483336647155
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:lLKSmUAPRD6PA/GKge44+4yif7DOnFPV5kzaOCSSZ:IVH/D4z4yG7DOnFdKaO6Z
                                                                                    MD5:C5735F75847667E33A6B2D5E50D19C6F
                                                                                    SHA1:D2C5952138FA5A246EC5900C9E680E7AEAF099AF
                                                                                    SHA-256:32B0ACDF551507B4A8B9BD0467BEFDC2539C776E3F48221F0B577499F6EAE616
                                                                                    SHA-512:DA961258A682C732F0A480EE7220D74B4511FA5313FB3BF0ACAF07AA42FA7410F3EE1A83C221C995854C2919286676F346A45CD278E1D1929E0164155F6D98F5
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 4%
                                                                                    Reputation:moderate, very likely benign file
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$....................^....v.U......S......g......Q..............f......V......W......P....Rich...........................PE..L......Q...........!..... ...$.......(.......0.....f.................................$....@..........................?......L6..P....`..,....................p......................................x1..@............0...............................text............ .................. ..`.rdata.......0.......$..............@..@.data........P.......<..............@....rsrc...,....`.......>..............@..@.reloc.......p.......D..............@..B........................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):226304
                                                                                    Entropy (8bit):6.833378525054972
                                                                                    Encrypted:false
                                                                                    SSDEEP:6144:dN8sMIcF8WExUx855gVPXQj5zxXhvRrxVEYnRWmgZvgiLMOnf:dNL9e8W4UMiV
                                                                                    MD5:0E2C47A16BC8ED754E810FEAEFF64E0D
                                                                                    SHA1:7C23F3C5DD8E613DB1B426FAE98D0FDC0226068E
                                                                                    SHA-256:FF6507A53076A9C33D7AE07CDE0E876E1AD5B81A2DA18EBDC24608E79B4BBF0E
                                                                                    SHA-512:9A2D9EDF5C3959E0D463161D9DB0C7457741785F7FE4E76097D13D24F6E566D50CCC3DC1BCFF6872AC52577F74CFEB957A03242B5565E333C0679E6D79D5A07B
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 4%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........j...j...j...$*..j....,..j.......j.......j....!..j...j...i.......j....)..j....(..j..../..j..Rich.j..........PE..L......Q...........!.....V..........&^.......p......................................4.....@.............................&S..\P.......`..0....................p...(...................................:..@............p..0............................text...;U.......V.................. ..`.rdata..&....p.......Z..............@..@.data...|....P.......2..............@....rsrc...0....`.......<..............@..@.reloc...0...p...2...B..............@..B........................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):1767424
                                                                                    Entropy (8bit):6.502501235310596
                                                                                    Encrypted:false
                                                                                    SSDEEP:24576:7GWPHUAzlcNk0BjXxOKWf8e4VY/+AnattjtpKFJ/t:FPHUGOkIxOKW5OXlKHV
                                                                                    MD5:A7F201C0B9AC05E950ECC55D4403EC16
                                                                                    SHA1:20B5B9AEFD27B11BD129AF6BF362D11DFFAFA5E5
                                                                                    SHA-256:173092C4E256958B100683A6AB2CE0D1C9895EC63F222198F9DE485E61C728CA
                                                                                    SHA-512:0D3B3A3F2D5C39B7309943591E51587C1DB4BFC70EA5B0FD4A9016AACF0CA9DFA69040E6D74E1B9424FD8E41B3B3E22AB5D7C5352AF6C216E491EDEC78C612D7
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 2%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......J:...[...[...[...#...[.......[..a-...[..a-...[...[..!X..a-6..[..a-7..[..a-...[..a-...[..a-...[..Rich.[..................PE..L....VuQ...........!.....4..........6L.......P.....J.........................P............@.............................#...$'..d.... ..X....................0..<....................................4..@............P...............................text....2.......4.................. ..`.rdata...s...P...t...8..............@..@.data....K.......*..................@....rsrc...X.... ......................@..@.reloc..B....0......................@..B................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):1295872
                                                                                    Entropy (8bit):6.469213828080914
                                                                                    Encrypted:false
                                                                                    SSDEEP:24576:DCYW9S/7mMcs50Mf+Av1gQp3Y6ZBGB6riFv9Kk2HPmOh:DCw/8s0IaQp3Y6ZBj+Kf
                                                                                    MD5:DAE4100039A943128C34BA3E05F6CD02
                                                                                    SHA1:22B25C997C8204CA104CB72D98BC7FE57EA02B48
                                                                                    SHA-256:2357806CA24C9D3152D54D34270810DA9D9CA943462EBF7291AE06A10E5CB8BA
                                                                                    SHA-512:5155B812AFECDDFCC904AD403D04DD060D284A2E9A9A0B26CCC96FB593801176BE2BA69FFD2FA2A6F246A84F6DC824F042ADACA7E8C1D3D57AAE3FC62C2C24E1
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......tN6.0/X.0/X.0/X.a..1/X._Y..9/X.9W..4/X._Y..5/X.0/Y.U/X._Y..s/X._Y..L/X._Y..1/X._Y..1/X._Y..1/X.Rich0/X.........PE..L....VuQ...........!.....4..........^........P.....J.........................0............@..........................r.......i..d.......X........................[......................................@............P...............................text....2.......4.................. ..`.rdata..i....P.......8..............@..@.data....;...p.......J..............@....rsrc...X............Z..............@..@.reloc..4d.......f...`..............@..B........................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):226304
                                                                                    Entropy (8bit):6.833378525054972
                                                                                    Encrypted:false
                                                                                    SSDEEP:6144:dN8sMIcF8WExUx855gVPXQj5zxXhvRrxVEYnRWmgZvgiLMOnf:dNL9e8W4UMiV
                                                                                    MD5:0E2C47A16BC8ED754E810FEAEFF64E0D
                                                                                    SHA1:7C23F3C5DD8E613DB1B426FAE98D0FDC0226068E
                                                                                    SHA-256:FF6507A53076A9C33D7AE07CDE0E876E1AD5B81A2DA18EBDC24608E79B4BBF0E
                                                                                    SHA-512:9A2D9EDF5C3959E0D463161D9DB0C7457741785F7FE4E76097D13D24F6E566D50CCC3DC1BCFF6872AC52577F74CFEB957A03242B5565E333C0679E6D79D5A07B
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 4%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........j...j...j...$*..j....,..j.......j.......j....!..j...j...i.......j....)..j....(..j..../..j..Rich.j..........PE..L......Q...........!.....V..........&^.......p......................................4.....@.............................&S..\P.......`..0....................p...(...................................:..@............p..0............................text...;U.......V.................. ..`.rdata..&....p.......Z..............@..@.data...|....P.......2..............@....rsrc...0....`.......<..............@..@.reloc...0...p...2...B..............@..B........................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):1767424
                                                                                    Entropy (8bit):6.502501235310596
                                                                                    Encrypted:false
                                                                                    SSDEEP:24576:7GWPHUAzlcNk0BjXxOKWf8e4VY/+AnattjtpKFJ/t:FPHUGOkIxOKW5OXlKHV
                                                                                    MD5:A7F201C0B9AC05E950ECC55D4403EC16
                                                                                    SHA1:20B5B9AEFD27B11BD129AF6BF362D11DFFAFA5E5
                                                                                    SHA-256:173092C4E256958B100683A6AB2CE0D1C9895EC63F222198F9DE485E61C728CA
                                                                                    SHA-512:0D3B3A3F2D5C39B7309943591E51587C1DB4BFC70EA5B0FD4A9016AACF0CA9DFA69040E6D74E1B9424FD8E41B3B3E22AB5D7C5352AF6C216E491EDEC78C612D7
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 2%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......J:...[...[...[...#...[.......[..a-...[..a-...[...[..!X..a-6..[..a-7..[..a-...[..a-...[..a-...[..Rich.[..................PE..L....VuQ...........!.....4..........6L.......P.....J.........................P............@.............................#...$'..d.... ..X....................0..<....................................4..@............P...............................text....2.......4.................. ..`.rdata...s...P...t...8..............@..@.data....K.......*..................@....rsrc...X.... ......................@..@.reloc..B....0......................@..B................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):645592
                                                                                    Entropy (8bit):6.50414583238337
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:i0zrcH2F3OfwjtWvuFEmhx0Cj37670jwX+E7tFKm0qTYh:iJUOfwh8u9hx0D70NE7tFTYh
                                                                                    MD5:E477A96C8F2B18D6B5C27BDE49C990BF
                                                                                    SHA1:E980C9BF41330D1E5BD04556DB4646A0210F7409
                                                                                    SHA-256:16574F51785B0E2FC29C2C61477EB47BB39F714829999511DC8952B43AB17660
                                                                                    SHA-512:335A86268E7C0E568B1C30981EC644E6CD332E66F96D2551B58A82515316693C1859D87B4F4B7310CF1AC386CEE671580FDD999C3BCB23ACF2C2282C01C8798C
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S.v..?......!................X..............`......................... ......8......... .................................L................................'......................................................p............................text...............................`.0`.data...............................@.@..rdata..$...........................@.@@.bss..................................@..edata..............................@.0@.idata..L...........................@.0..CRT................................@.0..tls.... ...........................@.0..reloc...'.......(..................@.0B/4......`....0......................@.@B/19..........@......................@..B/35.....M....P......................@..B/51.....`C...`...D..................@..B/63..................8..............@..B/77..................F..............@..B/89..................R..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):773968
                                                                                    Entropy (8bit):6.901569696995594
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:yMmCy3nAgPAxN9ueqix/HEmxsvGrif8ZSy+rdQw2QRAtd74/vmYK6H3BV0eAI:dmCy3KxW3ixPEmxsvGrm8Z6r+JQPzV4I
                                                                                    MD5:BF38660A9125935658CFA3E53FDC7D65
                                                                                    SHA1:0B51FB415EC89848F339F8989D323BEA722BFD70
                                                                                    SHA-256:60C06E0FA4449314DA3A0A87C1A9D9577DF99226F943637E06F61188E5862EFA
                                                                                    SHA-512:25F521FFE25A950D0F1A4DE63B04CB62E2A3B0E72E7405799586913208BF8F8FA52AA34E96A9CC6EE47AFCD41870F3AA0CD8289C53461D1B6E792D19B750C9A1
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......:.y.~...~...~...w...}...~.......eD.....eD..+...eD..J...eD......eD......eD......eD......Rich~...................PE..L..."._M.........."!.........................0.....x................................u.....@..........................H......d...(.......................P.......$L...!..8...........................hE..@............................................text...!........................... ..`.data....Z...0...N..................@....rsrc................f..............@..@.reloc..$L.......N...j..............@..B................................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):48128
                                                                                    Entropy (8bit):6.044429679961545
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:Ydp3loIiS+gbIdX9h9btywVT+0sdfLKc/IQiInhtTaQotOnKOdHGd3:YH3llRbIdth9JjTvsFec/IYhtuztOnpW
                                                                                    MD5:EAE56B896A718C3BC87A4253832A5650
                                                                                    SHA1:4987D30E08490B3C5F356F47C33061E2F7E608C9
                                                                                    SHA-256:EE1D7D8F396D627FEE7DCF2655FB5ACFE5A1EE2A5DEEDA764EF311E75B94CEA1
                                                                                    SHA-512:044335B7899189C9685C9FE1C7985EE2A985A77B1C2B59FB81884BFE353DD80973C3918A107D67550C4FA686E1838D15206519015FA58A9EB054BAFA10720551
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........+.w.x.w.x.w.x@9Ox.w.x..Ix.w.x..}x.w.x..Kx.w.x..Dx.w.x.w.x.w.x..|x.w.x..Lx.w.x..Jx.w.xRich.w.x........................PE..L......Q...........!.........2......................................................o....@.....................................x...............................\...................................p...@...............,............................text...6........................... ..`.rdata..H ......."..................@..@.data...............................@....rsrc...............................@..@.reloc..<...........................@..B................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):18432
                                                                                    Entropy (8bit):5.996483336647155
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:lLKSmUAPRD6PA/GKge44+4yif7DOnFPV5kzaOCSSZ:IVH/D4z4yG7DOnFdKaO6Z
                                                                                    MD5:C5735F75847667E33A6B2D5E50D19C6F
                                                                                    SHA1:D2C5952138FA5A246EC5900C9E680E7AEAF099AF
                                                                                    SHA-256:32B0ACDF551507B4A8B9BD0467BEFDC2539C776E3F48221F0B577499F6EAE616
                                                                                    SHA-512:DA961258A682C732F0A480EE7220D74B4511FA5313FB3BF0ACAF07AA42FA7410F3EE1A83C221C995854C2919286676F346A45CD278E1D1929E0164155F6D98F5
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 4%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$....................^....v.U......S......g......Q..............f......V......W......P....Rich...........................PE..L......Q...........!..... ...$.......(.......0.....f.................................$....@..........................?......L6..P....`..,....................p......................................x1..@............0...............................text............ .................. ..`.rdata.......0.......$..............@..@.data........P.......<..............@....rsrc...,....`.......>..............@..@.reloc.......p.......D..............@..B........................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):728576
                                                                                    Entropy (8bit):6.569671392209985
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:HgCO4mFq3kAVoYQVggbGAoTbmnuNfMxJWVtrKnffO9Py0n4wj:AcmFq37JQOTbZpaffOFy0n4G
                                                                                    MD5:A73EE126B2E6D43182D4C3482899D338
                                                                                    SHA1:998F61112F911B050F7E07021F58AAB4F64C5D36
                                                                                    SHA-256:06BBE605D7B0EF044871633B496948A8D65C78661E457D0844DC434A0609F763
                                                                                    SHA-512:2E3A83421154C4B3499FCC7E66F5FA7BF95FB157002CA7EC0DB2041AE9C9A3483C7787D9E07E48C28D28B216B577B5D0972ED03F54FBA34F6E908F74137837B9
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........z.............}........z.......z.......z...............!o...............i....z.......z.......z......Rich............PE..L......Q...........!.....:...................P...............................`............@..........................n..E....Y..x................................r......................................@............P..0............................text....9.......:.................. ..`.rdata..E0...P...2...>..............@..@.data...l............p..............@....rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):1295872
                                                                                    Entropy (8bit):6.469213828080914
                                                                                    Encrypted:false
                                                                                    SSDEEP:24576:DCYW9S/7mMcs50Mf+Av1gQp3Y6ZBGB6riFv9Kk2HPmOh:DCw/8s0IaQp3Y6ZBj+Kf
                                                                                    MD5:DAE4100039A943128C34BA3E05F6CD02
                                                                                    SHA1:22B25C997C8204CA104CB72D98BC7FE57EA02B48
                                                                                    SHA-256:2357806CA24C9D3152D54D34270810DA9D9CA943462EBF7291AE06A10E5CB8BA
                                                                                    SHA-512:5155B812AFECDDFCC904AD403D04DD060D284A2E9A9A0B26CCC96FB593801176BE2BA69FFD2FA2A6F246A84F6DC824F042ADACA7E8C1D3D57AAE3FC62C2C24E1
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......tN6.0/X.0/X.0/X.a..1/X._Y..9/X.9W..4/X._Y..5/X.0/Y.U/X._Y..s/X._Y..L/X._Y..1/X._Y..1/X._Y..1/X.Rich0/X.........PE..L....VuQ...........!.....4..........^........P.....J.........................0............@..........................r.......i..d.......X........................[......................................@............P...............................text....2.......4.................. ..`.rdata..i....P.......8..............@..@.data....;...p.......J..............@....rsrc...X............Z..............@..@.reloc..4d.......f...`..............@..B........................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):421200
                                                                                    Entropy (8bit):6.595802017835318
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:zNb8zxr1aWPaHX7dGP57rhUgiW6QR7t5qv3Ooc8UHkC2ejGH:zNb8Fpa6aHX7dGP5Kv3Ooc8UHkC2eKH
                                                                                    MD5:E3C817F7FE44CC870ECDBCBC3EA36132
                                                                                    SHA1:2ADA702A0C143A7AE39B7DE16A4B5CC994D2548B
                                                                                    SHA-256:D769FAFA2B3232DE9FA7153212BA287F68E745257F1C00FAFB511E7A02DE7ADF
                                                                                    SHA-512:4FCF3FCDD27C97A714E173AA221F53DF6C152636D77DEA49E256A9788F2D3F2C2D7315DD0B4D72ECEFC553082F9149B8580779ABB39891A88907F16EC9E13CBE
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........e..d...d...d.......d.......d...d..Cd..K*...d.......d.......d.......d.......d.......d.......d.......d..Rich.d..........................PE..L...A._M.........."!.................<.............x.................................{....@.................................<...<.... ...............V..P....0..D;..p................................/..@...............p............................text...u........................... ..`.data...$:.......,..................@....rsrc........ ......................@..@.reloc...S...0...T..................@..B........................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:data
                                                                                    Category:dropped
                                                                                    Size (bytes):3036672
                                                                                    Entropy (8bit):6.676551553887878
                                                                                    Encrypted:false
                                                                                    SSDEEP:49152:Rewe1eae/lefseluTQep6eMiXMiyq9fMmkmBtla/9WdyplLnDesOJvA:1ecSoii86fMmkmBra/9WdyplaJ
                                                                                    MD5:F5D1B5D7DFEBF250F91A607903A121EC
                                                                                    SHA1:4A7B5B98BE83C51AE6237042F17B92C1E3A44995
                                                                                    SHA-256:A288996D52C56D005E71B7DAA601715058CBDE6A2DBAB5CB588D40FA0F8529BF
                                                                                    SHA-512:8AAFEB81F6315BA156F23D86CDFFA655D0BD15E004C90BC94302AD3900912BC067B5B30DC682BA7C875CA1F3D9C2BDA2F3802A4C63642370B52277C70BA090D4
                                                                                    Malicious:false
                                                                                    Preview:.Z......................@...............................................!..L.!This program cannot be run in DOS mode....$.......................PE..L....P.g..................#..........?#.......#...@........................................................................D.#......P$.0[............................................................................#.p............................text...*.#.......#.................`....rdata...?....#..@....#.............@..@.data....c....#..0....#.............@....rsrc....\...P$..\....#.............@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):48128
                                                                                    Entropy (8bit):6.044429679961545
                                                                                    Encrypted:false
                                                                                    SSDEEP:768:Ydp3loIiS+gbIdX9h9btywVT+0sdfLKc/IQiInhtTaQotOnKOdHGd3:YH3llRbIdth9JjTvsFec/IYhtuztOnpW
                                                                                    MD5:EAE56B896A718C3BC87A4253832A5650
                                                                                    SHA1:4987D30E08490B3C5F356F47C33061E2F7E608C9
                                                                                    SHA-256:EE1D7D8F396D627FEE7DCF2655FB5ACFE5A1EE2A5DEEDA764EF311E75B94CEA1
                                                                                    SHA-512:044335B7899189C9685C9FE1C7985EE2A985A77B1C2B59FB81884BFE353DD80973C3918A107D67550C4FA686E1838D15206519015FA58A9EB054BAFA10720551
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........+.w.x.w.x.w.x@9Ox.w.x..Ix.w.x..}x.w.x..Kx.w.x..Dx.w.x.w.x.w.x..|x.w.x..Lx.w.x..Jx.w.xRich.w.x........................PE..L......Q...........!.........2......................................................o....@.....................................x...............................\...................................p...@...............,............................text...6........................... ..`.rdata..H ......."..................@..@.data...............................@....rsrc...............................@..@.reloc..<...........................@..B................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):728576
                                                                                    Entropy (8bit):6.569671392209985
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:HgCO4mFq3kAVoYQVggbGAoTbmnuNfMxJWVtrKnffO9Py0n4wj:AcmFq37JQOTbZpaffOFy0n4G
                                                                                    MD5:A73EE126B2E6D43182D4C3482899D338
                                                                                    SHA1:998F61112F911B050F7E07021F58AAB4F64C5D36
                                                                                    SHA-256:06BBE605D7B0EF044871633B496948A8D65C78661E457D0844DC434A0609F763
                                                                                    SHA-512:2E3A83421154C4B3499FCC7E66F5FA7BF95FB157002CA7EC0DB2041AE9C9A3483C7787D9E07E48C28D28B216B577B5D0972ED03F54FBA34F6E908F74137837B9
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........z.............}........z.......z.......z...............!o...............i....z.......z.......z......Rich............PE..L......Q...........!.....:...................P...............................`............@..........................n..E....Y..x................................r......................................@............P..0............................text....9.......:.................. ..`.rdata..E0...P...2...>..............@..@.data...l............p..............@....rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):421200
                                                                                    Entropy (8bit):6.595802017835318
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:zNb8zxr1aWPaHX7dGP57rhUgiW6QR7t5qv3Ooc8UHkC2ejGH:zNb8Fpa6aHX7dGP5Kv3Ooc8UHkC2eKH
                                                                                    MD5:E3C817F7FE44CC870ECDBCBC3EA36132
                                                                                    SHA1:2ADA702A0C143A7AE39B7DE16A4B5CC994D2548B
                                                                                    SHA-256:D769FAFA2B3232DE9FA7153212BA287F68E745257F1C00FAFB511E7A02DE7ADF
                                                                                    SHA-512:4FCF3FCDD27C97A714E173AA221F53DF6C152636D77DEA49E256A9788F2D3F2C2D7315DD0B4D72ECEFC553082F9149B8580779ABB39891A88907F16EC9E13CBE
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........e..d...d...d.......d.......d...d..Cd..K*...d.......d.......d.......d.......d.......d.......d.......d..Rich.d..........................PE..L...A._M.........."!.................<.............x.................................{....@.................................<...<.... ...............V..P....0..D;..p................................/..@...............p............................text...u........................... ..`.data...$:.......,..................@....rsrc........ ......................@..@.reloc...S...0...T..................@..B........................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):773968
                                                                                    Entropy (8bit):6.901569696995594
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:yMmCy3nAgPAxN9ueqix/HEmxsvGrif8ZSy+rdQw2QRAtd74/vmYK6H3BV0eAI:dmCy3KxW3ixPEmxsvGrm8Z6r+JQPzV4I
                                                                                    MD5:BF38660A9125935658CFA3E53FDC7D65
                                                                                    SHA1:0B51FB415EC89848F339F8989D323BEA722BFD70
                                                                                    SHA-256:60C06E0FA4449314DA3A0A87C1A9D9577DF99226F943637E06F61188E5862EFA
                                                                                    SHA-512:25F521FFE25A950D0F1A4DE63B04CB62E2A3B0E72E7405799586913208BF8F8FA52AA34E96A9CC6EE47AFCD41870F3AA0CD8289C53461D1B6E792D19B750C9A1
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......:.y.~...~...~...w...}...~.......eD.....eD..+...eD..J...eD......eD......eD......eD......Rich~...................PE..L..."._M.........."!.........................0.....x................................u.....@..........................H......d...(.......................P.......$L...!..8...........................hE..@............................................text...!........................... ..`.data....Z...0...N..................@....rsrc................f..............@..@.reloc..$L.......N...j..............@..B................................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                    Category:modified
                                                                                    Size (bytes):3036672
                                                                                    Entropy (8bit):6.676551488534372
                                                                                    Encrypted:false
                                                                                    SSDEEP:49152:Gewe1eae/lefseluTQep6eMiXMiyq9fMmkmBtla/9WdyplLnDesOJvA:yecSoii86fMmkmBra/9WdyplaJ
                                                                                    MD5:483573178F49D6667013866FB10AB1CB
                                                                                    SHA1:927E913247E5458925813BC6747AE9882BC03FD6
                                                                                    SHA-256:4E43B32BCA5224D444D61A366E6949A33DF1526C2AD209A1EC49221D9972A323
                                                                                    SHA-512:0404AC48831B71A1EB78EEE6BB7F4C39FF6543E0809A511198151152283A4D39574328345E6136A19E4DAE46D6B0AAB9175A6611769BD3E0E1F97E2453BEEA08
                                                                                    Malicious:true
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......................PE..L....P.g..................#..........?#.......#...@........................................................................D.#......P$.0[............................................................................#.p............................text...*.#.......#.................`....rdata...?....#..@....#.............@..@.data....c....#..0....#.............@....rsrc....\...P$..\....#.............@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):645592
                                                                                    Entropy (8bit):6.50414583238337
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:i0zrcH2F3OfwjtWvuFEmhx0Cj37670jwX+E7tFKm0qTYh:iJUOfwh8u9hx0D70NE7tFTYh
                                                                                    MD5:E477A96C8F2B18D6B5C27BDE49C990BF
                                                                                    SHA1:E980C9BF41330D1E5BD04556DB4646A0210F7409
                                                                                    SHA-256:16574F51785B0E2FC29C2C61477EB47BB39F714829999511DC8952B43AB17660
                                                                                    SHA-512:335A86268E7C0E568B1C30981EC644E6CD332E66F96D2551B58A82515316693C1859D87B4F4B7310CF1AC386CEE671580FDD999C3BCB23ACF2C2282C01C8798C
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S.v..?......!................X..............`......................... ......8......... .................................L................................'......................................................p............................text...............................`.0`.data...............................@.@..rdata..$...........................@.@@.bss..................................@..edata..............................@.0@.idata..L...........................@.0..CRT................................@.0..tls.... ...........................@.0..reloc...'.......(..................@.0B/4......`....0......................@.@B/19..........@......................@..B/35.....M....P......................@..B/51.....`C...`...D..................@..B/63..................8..............@..B/77..................F..............@..B/89..................R..
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):722597
                                                                                    Entropy (8bit):6.522043548379102
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:jQ4Ch1/aLmSKrPD37zzH2A6QGgx/bsQYq9KgERkVfzrrNVyblI4cNaf/yxyRP:jQph1yLmSKrPD37zzH2A6QD/IpqggE2y
                                                                                    MD5:AAAC7D961509F2DC44974ED319205A72
                                                                                    SHA1:7DB7F5C81D13EF477D739E5E66E7406F20995566
                                                                                    SHA-256:DEF4FACD78AD9431A1357195EEFB78FB8C0201B9D6B34E0D10BD766D5E4B4FDD
                                                                                    SHA-512:F08E2847DB28C6B921B07A96F021BAFF287EA94C6FE148A7E6CA5F6032B068BDE1740B433D82BBA35B0DDEDBAEFCBFEF8DB1ACA14DB6590A595CEC3BA96EE216
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 3%
                                                                                    Preview:MZP.....................@.......................InUn....................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*..........................................@.......................................@......@...............................&........................................................... ......................................................CODE....$........................... ..`DATA.... ...........................@...BSS......................................idata...&.......(..................@....tls.....................................rdata....... ......................@..P.reloc......0......................@..P.rsrc...............................@..P.....................f..............@..P........................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:InnoSetup Log Smart File Defrag, version 0x30, 5022 bytes, 704672\user, "C:\Users\user\AppData\Local\Smart File Defrag 7.1.3"
                                                                                    Category:dropped
                                                                                    Size (bytes):5022
                                                                                    Entropy (8bit):4.7829467232870035
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:EdWi488/pAU4W9s+eOIhxa7ICSss/LnYws0i6W:EdWi480pA+HIhWICSsAns1
                                                                                    MD5:DE3B5800822D57D139196EF5FA7F5F31
                                                                                    SHA1:BA2FE0A8144E2B1EAC83A1EAD96B9B548046CC13
                                                                                    SHA-256:B7662E31AB791472EABD3D7F0B6A2C1DD1CC24BC5611CBE6DE1CC82CEE0F327A
                                                                                    SHA-512:E2204C184D1FA9D520FD3F8F7CB3381FCE2822851C40635C6FE97F98DC036389A961CE19757C0ACF6A9C33862BF71E167419330458935104D2EF48FD2B3A32FB
                                                                                    Malicious:false
                                                                                    Preview:Inno Setup Uninstall Log (b)....................................Smart File Defrag...............................................................................................................Smart File Defrag...............................................................................................................0...........%..................................................................................................................L.................V....704672.user5C:\Users\user\AppData\Local\Smart File Defrag 7.1.3.................. ............IFPS.............................................................................................................BOOLEAN..............TWIZARDFORM....TWIZARDFORM.........TPASSWORDEDIT....TPASSWORDEDIT...........................................!MAIN....-1..(...dll:kernel32.dll.CreateFileA..............$...dll:kernel32.dll.WriteFile............"...dll:kernel32.dll.CloseHandle........"...dll:kernel32.dll.ExitProcess........%...dll:
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):722597
                                                                                    Entropy (8bit):6.522043548379102
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:jQ4Ch1/aLmSKrPD37zzH2A6QGgx/bsQYq9KgERkVfzrrNVyblI4cNaf/yxyRP:jQph1yLmSKrPD37zzH2A6QD/IpqggE2y
                                                                                    MD5:AAAC7D961509F2DC44974ED319205A72
                                                                                    SHA1:7DB7F5C81D13EF477D739E5E66E7406F20995566
                                                                                    SHA-256:DEF4FACD78AD9431A1357195EEFB78FB8C0201B9D6B34E0D10BD766D5E4B4FDD
                                                                                    SHA-512:F08E2847DB28C6B921B07A96F021BAFF287EA94C6FE148A7E6CA5F6032B068BDE1740B433D82BBA35B0DDEDBAEFCBFEF8DB1ACA14DB6590A595CEC3BA96EE216
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 3%
                                                                                    Preview:MZP.....................@.......................InUn....................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*..........................................@.......................................@......@...............................&........................................................... ......................................................CODE....$........................... ..`DATA.... ...........................@...BSS......................................idata...&.......(..................@....tls.....................................rdata....... ......................@..P.reloc......0......................@..P.rsrc...............................@..P.....................f..............@..P........................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):2560
                                                                                    Entropy (8bit):2.8818118453929262
                                                                                    Encrypted:false
                                                                                    SSDEEP:24:e1GSgDIX566lIB6SXvVmMPUjvhBrDsqZ:SgDKRlVImgUNBsG
                                                                                    MD5:A69559718AB506675E907FE49DEB71E9
                                                                                    SHA1:BC8F404FFDB1960B50C12FF9413C893B56F2E36F
                                                                                    SHA-256:2F6294F9AA09F59A574B5DCD33BE54E16B39377984F3D5658CDA44950FA0F8FC
                                                                                    SHA-512:E52E0AA7FE3F79E36330C455D944653D449BA05B2F9ABEE0914A0910C3452CFA679A40441F9AC696B3CCF9445CBB85095747E86153402FC362BB30AC08249A63
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........W.c.W.c.W.c...>.T.c.W.b.V.c.R.<.V.c.R.?.V.c.R.9.V.c.RichW.c.........................PE..L....b.@...........!......................... ...............................@......................................p ..}.... ..(............................0....................................................... ...............................text............................... ..`.rdata....... ......................@..@.reloc.......0......................@..B................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):6144
                                                                                    Entropy (8bit):4.720366600008286
                                                                                    Encrypted:false
                                                                                    SSDEEP:96:sfkcXegaJ/ZAYNzcld1xaX12p+gt1sONA0:sfJEVYlvxaX12C6A0
                                                                                    MD5:E4211D6D009757C078A9FAC7FF4F03D4
                                                                                    SHA1:019CD56BA687D39D12D4B13991C9A42EA6BA03DA
                                                                                    SHA-256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
                                                                                    SHA-512:17257F15D843E88BB78ADCFB48184B8CE22109CC2C99E709432728A392AFAE7B808ED32289BA397207172DE990A354F15C2459B6797317DA8EA18B040C85787E
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......^...............l...............=\......=\......=\......Rich............................PE..d.....R..........#............................@.............................`.......,......................................................<!.......P..H....@..0.................................................................... ...............................text............................... ..`.rdata..|.... ......................@..@.data...,....0......................@....pdata..0....@......................@..@.rsrc...H....P......................@..@................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    File Type:PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):23312
                                                                                    Entropy (8bit):4.596242908851566
                                                                                    Encrypted:false
                                                                                    SSDEEP:384:+Vm08QoKkiWZ76UJuP71W55iWHHoSHigH2euwsHTGHVb+VHHmnH+aHjHqLHxmoq1:2m08QotiCjJuPGw4
                                                                                    MD5:92DC6EF532FBB4A5C3201469A5B5EB63
                                                                                    SHA1:3E89FF837147C16B4E41C30D6C796374E0B8E62C
                                                                                    SHA-256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
                                                                                    SHA-512:9908E573921D5DBC3454A1C0A6C969AB8A81CC2E8B5385391D46B1A738FB06A76AA3282E0E58D0D2FFA6F27C85668CD5178E1500B8A39B1BBAE04366AE6A86D3
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......IzJ^..$...$...$...%.".$.T87...$.[."...$...$...$.Rich..$.........................PE..L.....\;...........#..... ...4.......'.......0.....q....................................................................k...l)..<....@.../...................p..T....................................................................................text...{........ .................. ..`.data...\....0.......&..............@....rsrc..../...@...0...(..............@..@.reloc.......p.......X..............@..B................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                    Process:C:\Users\user\Desktop\tKBxw8eOIV.exe
                                                                                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                    Category:dropped
                                                                                    Size (bytes):711168
                                                                                    Entropy (8bit):6.513789679017668
                                                                                    Encrypted:false
                                                                                    SSDEEP:12288:bQ4Ch1/aLmSKrPD37zzH2A6QGgx/bsQYq9KgERkVfzrrNVyblI4cNaf/yxyR:bQph1yLmSKrPD37zzH2A6QD/IpqggE2M
                                                                                    MD5:A68E919AA98AF0107E6C6C200955EF9C
                                                                                    SHA1:C48FC16FAB8AB5F59C2619FAD6C14C676FAEE68B
                                                                                    SHA-256:8577C42C652797CE0B766CAC8E82F0C35B78C24DA42A56A0AE5E0FAB3353E3F5
                                                                                    SHA-512:183BC84D30D16A27EF509EB8FA75EE5687623825825EAD596F3DFA6B84E4EB96D1495D54707EF8894E536D0E75717D0BAADE380B3A9F9A957606D62347DE6D99
                                                                                    Malicious:false
                                                                                    Antivirus:
                                                                                    • Antivirus: ReversingLabs, Detection: 3%
                                                                                    Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*..........................................@.......................................@......@...............................&........................................................... ......................................................CODE....$........................... ..`DATA.... ...........................@...BSS......................................idata...&.......(..................@....tls.....................................rdata....... ......................@..P.reloc......0......................@..P.rsrc...............................@..P.....................f..............@..P........................................................................................................................................
                                                                                    File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                    Entropy (8bit):7.997995779792712
                                                                                    TrID:
                                                                                    • Win32 Executable (generic) a (10002005/4) 98.86%
                                                                                    • Inno Setup installer (109748/4) 1.08%
                                                                                    • Win16/32 Executable Delphi generic (2074/23) 0.02%
                                                                                    • Generic Win/DOS Executable (2004/3) 0.02%
                                                                                    • DOS Executable Generic (2002/1) 0.02%
                                                                                    File name:tKBxw8eOIV.exe
                                                                                    File size:3'722'172 bytes
                                                                                    MD5:51f4cfbe1c4f38beb7d4185086720317
                                                                                    SHA1:759e7e67ecc0b034d706125d6e2602c6051d2f63
                                                                                    SHA256:9e485a81d02dcd866ff2b63734bd9e5331319d6c6bd8c2aac53ef9e366556fcb
                                                                                    SHA512:ba0cfed8eef029049af9aabc9dbc07e4e853b42fcbf6060dc912e8fdc7378659669807507d2bf4d3074eb240c9f7f882da3466e2db241356df1ab7ab526a06d4
                                                                                    SSDEEP:98304:32j3Ueigw7UxZ+97pnu0okteY/EZaqjI6SRmBYZeIl7JS:Gjfig5iu0ok9/EZaL6SYYLl7JS
                                                                                    TLSH:810633A79EE984FBE066CEBCBF0AC1245533BF9240725006BBF966994B33DC01119797
                                                                                    File Content Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7.......................................................................................................................................
                                                                                    Icon Hash:2d2e3797b32b2b99
                                                                                    Entrypoint:0x40a5f8
                                                                                    Entrypoint Section:CODE
                                                                                    Digitally signed:false
                                                                                    Imagebase:0x400000
                                                                                    Subsystem:windows gui
                                                                                    Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
                                                                                    DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                                                                                    Time Stamp:0x2A425E19 [Fri Jun 19 22:22:17 1992 UTC]
                                                                                    TLS Callbacks:
                                                                                    CLR (.Net) Version:
                                                                                    OS Version Major:1
                                                                                    OS Version Minor:0
                                                                                    File Version Major:1
                                                                                    File Version Minor:0
                                                                                    Subsystem Version Major:1
                                                                                    Subsystem Version Minor:0
                                                                                    Import Hash:884310b1928934402ea6fec1dbd3cf5e
                                                                                    Instruction
                                                                                    push ebp
                                                                                    mov ebp, esp
                                                                                    add esp, FFFFFFC4h
                                                                                    push ebx
                                                                                    push esi
                                                                                    push edi
                                                                                    xor eax, eax
                                                                                    mov dword ptr [ebp-10h], eax
                                                                                    mov dword ptr [ebp-24h], eax
                                                                                    call 00007F76C4EA2E13h
                                                                                    call 00007F76C4EA401Ah
                                                                                    call 00007F76C4EA42A9h
                                                                                    call 00007F76C4EA434Ch
                                                                                    call 00007F76C4EA62EBh
                                                                                    call 00007F76C4EA8C56h
                                                                                    call 00007F76C4EA8DBDh
                                                                                    xor eax, eax
                                                                                    push ebp
                                                                                    push 0040ACC9h
                                                                                    push dword ptr fs:[eax]
                                                                                    mov dword ptr fs:[eax], esp
                                                                                    xor edx, edx
                                                                                    push ebp
                                                                                    push 0040AC92h
                                                                                    push dword ptr fs:[edx]
                                                                                    mov dword ptr fs:[edx], esp
                                                                                    mov eax, dword ptr [0040C014h]
                                                                                    call 00007F76C4EA986Bh
                                                                                    call 00007F76C4EA9456h
                                                                                    cmp byte ptr [0040B234h], 00000000h
                                                                                    je 00007F76C4EAA34Eh
                                                                                    call 00007F76C4EA9968h
                                                                                    xor eax, eax
                                                                                    call 00007F76C4EA3B09h
                                                                                    lea edx, dword ptr [ebp-10h]
                                                                                    xor eax, eax
                                                                                    call 00007F76C4EA68FBh
                                                                                    mov edx, dword ptr [ebp-10h]
                                                                                    mov eax, 0040CE2Ch
                                                                                    call 00007F76C4EA2EAAh
                                                                                    push 00000002h
                                                                                    push 00000000h
                                                                                    push 00000001h
                                                                                    mov ecx, dword ptr [0040CE2Ch]
                                                                                    mov dl, 01h
                                                                                    mov eax, 0040738Ch
                                                                                    call 00007F76C4EA718Ah
                                                                                    mov dword ptr [0040CE30h], eax
                                                                                    xor edx, edx
                                                                                    push ebp
                                                                                    push 0040AC4Ah
                                                                                    push dword ptr fs:[edx]
                                                                                    mov dword ptr fs:[edx], esp
                                                                                    call 00007F76C4EA98C6h
                                                                                    mov dword ptr [0040CE38h], eax
                                                                                    mov eax, dword ptr [0040CE38h]
                                                                                    cmp dword ptr [eax+0Ch], 00000000h
                                                                                    NameVirtual AddressVirtual Size Is in Section
                                                                                    IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_IMPORT0xd0000x950.idata
                                                                                    IMAGE_DIRECTORY_ENTRY_RESOURCE0x110000x2c00.rsrc
                                                                                    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_TLS0xf0000x18.rdata
                                                                                    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_IAT0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                                                    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                                    NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                                    CODE0x10000x9d300x9e00611a4d7a24dd9b18a256468a5d7453f5False0.6052956882911392data6.631747641055028IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                                                    DATA0xb0000x2500x4002f7f9f859c8b4b133abf78cebd99cc90False0.306640625data2.7547169534996403IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                    BSS0xc0000xe900x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                    .idata0xd0000x9500xa00bb5485bf968b970e5ea81292af2acdbaFalse0.414453125data4.430733069799036IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                    .tls0xe0000x80x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                    .rdata0xf0000x180x2009ba824905bf9c7922b6fc87a38b74366False0.052734375data0.2044881574398449IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_SHARED, IMAGE_SCN_MEM_READ
                                                                                    .reloc0x100000x8c40x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_SHARED, IMAGE_SCN_MEM_READ
                                                                                    .rsrc0x110000x2c000x2c0037e923072c61cee26ec74415e8f2ab5fFalse0.33149857954545453data4.5727961719482355IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_SHARED, IMAGE_SCN_MEM_READ
                                                                                    NameRVASizeTypeLanguageCountryZLIB Complexity
                                                                                    RT_ICON0x113540x128Device independent bitmap graphic, 16 x 32 x 4, image size 192DutchNetherlands0.5675675675675675
                                                                                    RT_ICON0x1147c0x568Device independent bitmap graphic, 16 x 32 x 8, image size 320DutchNetherlands0.4486994219653179
                                                                                    RT_ICON0x119e40x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 640DutchNetherlands0.4637096774193548
                                                                                    RT_ICON0x11ccc0x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 1152DutchNetherlands0.3935018050541516
                                                                                    RT_STRING0x125740x2f2data0.35543766578249336
                                                                                    RT_STRING0x128680x30cdata0.3871794871794872
                                                                                    RT_STRING0x12b740x2cedata0.42618384401114207
                                                                                    RT_STRING0x12e440x68data0.75
                                                                                    RT_STRING0x12eac0xb4data0.6277777777777778
                                                                                    RT_STRING0x12f600xaedata0.5344827586206896
                                                                                    RT_RCDATA0x130100x2cdata1.2045454545454546
                                                                                    RT_GROUP_ICON0x1303c0x3edataEnglishUnited States0.8387096774193549
                                                                                    RT_VERSION0x1307c0x4f4dataEnglishUnited States0.25946372239747634
                                                                                    RT_MANIFEST0x135700x62cXML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.4240506329113924
                                                                                    DLLImport
                                                                                    kernel32.dllDeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, VirtualFree, VirtualAlloc, LocalFree, LocalAlloc, WideCharToMultiByte, TlsSetValue, TlsGetValue, MultiByteToWideChar, GetModuleHandleA, GetLastError, GetCommandLineA, WriteFile, SetFilePointer, SetEndOfFile, RtlUnwind, ReadFile, RaiseException, GetStdHandle, GetFileSize, GetSystemTime, GetFileType, ExitProcess, CreateFileA, CloseHandle
                                                                                    user32.dllMessageBoxA
                                                                                    oleaut32.dllVariantChangeTypeEx, VariantCopyInd, VariantClear, SysStringLen, SysAllocStringLen
                                                                                    advapi32.dllRegQueryValueExA, RegOpenKeyExA, RegCloseKey, OpenProcessToken, LookupPrivilegeValueA
                                                                                    kernel32.dllWriteFile, VirtualQuery, VirtualProtect, VirtualFree, VirtualAlloc, Sleep, SizeofResource, SetLastError, SetFilePointer, SetErrorMode, SetEndOfFile, RemoveDirectoryA, ReadFile, LockResource, LoadResource, LoadLibraryA, IsDBCSLeadByte, GetWindowsDirectoryA, GetVersionExA, GetUserDefaultLangID, GetSystemInfo, GetSystemDefaultLCID, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetLastError, GetFullPathNameA, GetFileSize, GetFileAttributesA, GetExitCodeProcess, GetEnvironmentVariableA, GetCurrentProcess, GetCommandLineA, GetACP, InterlockedExchange, FormatMessageA, FindResourceA, DeleteFileA, CreateProcessA, CreateFileA, CreateDirectoryA, CloseHandle
                                                                                    user32.dllTranslateMessage, SetWindowLongA, PeekMessageA, MsgWaitForMultipleObjects, MessageBoxA, LoadStringA, ExitWindowsEx, DispatchMessageA, DestroyWindow, CreateWindowExA, CallWindowProcA, CharPrevA
                                                                                    comctl32.dllInitCommonControls
                                                                                    advapi32.dllAdjustTokenPrivileges
                                                                                    DescriptionData
                                                                                    CommentsThis installation was built with Inno Setup.
                                                                                    CompanyName
                                                                                    FileDescriptionSmart File Defrag Setup
                                                                                    FileVersion
                                                                                    LegalCopyright
                                                                                    ProductNameSmart File Defrag
                                                                                    ProductVersion
                                                                                    Translation0x0000 0x04b0
                                                                                    Language of compilation systemCountry where language is spokenMap
                                                                                    DutchNetherlands
                                                                                    EnglishUnited States
                                                                                    TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                                    2025-03-04T10:30:05.030020+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849710176.113.115.96443TCP
                                                                                    2025-03-04T10:30:05.456970+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849710176.113.115.96443TCP
                                                                                    2025-03-04T10:30:06.284270+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849711176.113.115.96443TCP
                                                                                    2025-03-04T10:30:06.717890+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849711176.113.115.96443TCP
                                                                                    2025-03-04T10:30:10.200169+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849713176.113.115.96443TCP
                                                                                    2025-03-04T10:30:10.692395+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849713176.113.115.96443TCP
                                                                                    2025-03-04T10:30:12.549702+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849714176.113.115.96443TCP
                                                                                    2025-03-04T10:30:12.991333+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849714176.113.115.96443TCP
                                                                                    2025-03-04T10:30:13.927136+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849715176.113.115.96443TCP
                                                                                    2025-03-04T10:30:14.374037+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849715176.113.115.96443TCP
                                                                                    2025-03-04T10:30:15.315018+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849716176.113.115.96443TCP
                                                                                    2025-03-04T10:30:15.751130+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849716176.113.115.96443TCP
                                                                                    2025-03-04T10:30:16.601375+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849717176.113.115.96443TCP
                                                                                    2025-03-04T10:30:17.038613+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849717176.113.115.96443TCP
                                                                                    2025-03-04T10:30:17.856979+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849718176.113.115.96443TCP
                                                                                    2025-03-04T10:30:18.293076+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849718176.113.115.96443TCP
                                                                                    2025-03-04T10:30:19.124246+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849719176.113.115.96443TCP
                                                                                    2025-03-04T10:30:19.560252+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849719176.113.115.96443TCP
                                                                                    2025-03-04T10:30:20.408843+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849720176.113.115.96443TCP
                                                                                    2025-03-04T10:30:20.837105+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849720176.113.115.96443TCP
                                                                                    2025-03-04T10:30:21.658199+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849721176.113.115.96443TCP
                                                                                    2025-03-04T10:30:22.095643+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849721176.113.115.96443TCP
                                                                                    2025-03-04T10:30:23.039131+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849722176.113.115.96443TCP
                                                                                    2025-03-04T10:30:23.480643+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849722176.113.115.96443TCP
                                                                                    2025-03-04T10:30:24.309567+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849723176.113.115.96443TCP
                                                                                    2025-03-04T10:30:24.747204+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849723176.113.115.96443TCP
                                                                                    2025-03-04T10:30:25.643708+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849724176.113.115.96443TCP
                                                                                    2025-03-04T10:30:26.081049+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849724176.113.115.96443TCP
                                                                                    2025-03-04T10:30:26.922461+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849725176.113.115.96443TCP
                                                                                    2025-03-04T10:30:27.356667+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849725176.113.115.96443TCP
                                                                                    2025-03-04T10:30:28.193220+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849727176.113.115.96443TCP
                                                                                    2025-03-04T10:30:28.631268+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849727176.113.115.96443TCP
                                                                                    2025-03-04T10:30:29.466055+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849729176.113.115.96443TCP
                                                                                    2025-03-04T10:30:29.911607+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849729176.113.115.96443TCP
                                                                                    2025-03-04T10:30:30.759513+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849730176.113.115.96443TCP
                                                                                    2025-03-04T10:30:31.198876+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849730176.113.115.96443TCP
                                                                                    2025-03-04T10:30:32.035508+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849731176.113.115.96443TCP
                                                                                    2025-03-04T10:30:32.475430+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849731176.113.115.96443TCP
                                                                                    2025-03-04T10:30:33.325478+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849732176.113.115.96443TCP
                                                                                    2025-03-04T10:30:33.767940+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849732176.113.115.96443TCP
                                                                                    2025-03-04T10:30:34.598318+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849733176.113.115.96443TCP
                                                                                    2025-03-04T10:30:35.026216+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849733176.113.115.96443TCP
                                                                                    2025-03-04T10:30:35.908417+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849734176.113.115.96443TCP
                                                                                    2025-03-04T10:30:36.349707+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849734176.113.115.96443TCP
                                                                                    2025-03-04T10:30:37.278858+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849735176.113.115.96443TCP
                                                                                    2025-03-04T10:30:37.720963+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849735176.113.115.96443TCP
                                                                                    2025-03-04T10:30:38.551235+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849736176.113.115.96443TCP
                                                                                    2025-03-04T10:30:38.990225+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849736176.113.115.96443TCP
                                                                                    2025-03-04T10:30:39.912406+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849737176.113.115.96443TCP
                                                                                    2025-03-04T10:30:40.351779+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849737176.113.115.96443TCP
                                                                                    2025-03-04T10:30:41.255044+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849738176.113.115.96443TCP
                                                                                    2025-03-04T10:30:41.689579+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849738176.113.115.96443TCP
                                                                                    2025-03-04T10:30:42.512518+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849739176.113.115.96443TCP
                                                                                    2025-03-04T10:30:42.948019+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849739176.113.115.96443TCP
                                                                                    2025-03-04T10:30:43.841979+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849740176.113.115.96443TCP
                                                                                    2025-03-04T10:30:44.269861+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849740176.113.115.96443TCP
                                                                                    2025-03-04T10:30:45.092525+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849741176.113.115.96443TCP
                                                                                    2025-03-04T10:30:45.521264+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849741176.113.115.96443TCP
                                                                                    2025-03-04T10:30:46.337587+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849742176.113.115.96443TCP
                                                                                    2025-03-04T10:30:46.773960+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849742176.113.115.96443TCP
                                                                                    2025-03-04T10:30:47.601092+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849743176.113.115.96443TCP
                                                                                    2025-03-04T10:30:48.041247+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849743176.113.115.96443TCP
                                                                                    2025-03-04T10:30:48.897300+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849744176.113.115.96443TCP
                                                                                    2025-03-04T10:30:49.339973+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849744176.113.115.96443TCP
                                                                                    2025-03-04T10:30:50.280964+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849745176.113.115.96443TCP
                                                                                    2025-03-04T10:30:50.719189+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849745176.113.115.96443TCP
                                                                                    2025-03-04T10:30:51.555679+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849746176.113.115.96443TCP
                                                                                    2025-03-04T10:30:51.992736+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849746176.113.115.96443TCP
                                                                                    2025-03-04T10:30:52.928382+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849747176.113.115.96443TCP
                                                                                    2025-03-04T10:30:53.358885+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849747176.113.115.96443TCP
                                                                                    2025-03-04T10:30:54.295965+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849748176.113.115.96443TCP
                                                                                    2025-03-04T10:30:54.733421+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849748176.113.115.96443TCP
                                                                                    2025-03-04T10:30:55.591278+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849749176.113.115.96443TCP
                                                                                    2025-03-04T10:30:56.042857+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849749176.113.115.96443TCP
                                                                                    2025-03-04T10:30:56.896884+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849750176.113.115.96443TCP
                                                                                    2025-03-04T10:30:57.343273+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849750176.113.115.96443TCP
                                                                                    2025-03-04T10:30:58.175814+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849751176.113.115.96443TCP
                                                                                    2025-03-04T10:30:58.618742+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849751176.113.115.96443TCP
                                                                                    2025-03-04T10:30:59.458729+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849752176.113.115.96443TCP
                                                                                    2025-03-04T10:30:59.892971+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849752176.113.115.96443TCP
                                                                                    2025-03-04T10:31:00.722863+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849753176.113.115.96443TCP
                                                                                    2025-03-04T10:31:01.161025+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849753176.113.115.96443TCP
                                                                                    2025-03-04T10:31:02.080124+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849754176.113.115.96443TCP
                                                                                    2025-03-04T10:31:02.519624+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849754176.113.115.96443TCP
                                                                                    2025-03-04T10:31:03.376540+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849755176.113.115.96443TCP
                                                                                    2025-03-04T10:31:03.820617+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849755176.113.115.96443TCP
                                                                                    2025-03-04T10:31:04.653359+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849756176.113.115.96443TCP
                                                                                    2025-03-04T10:31:05.084415+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849756176.113.115.96443TCP
                                                                                    2025-03-04T10:31:05.912100+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849757176.113.115.96443TCP
                                                                                    2025-03-04T10:31:06.348483+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849757176.113.115.96443TCP
                                                                                    2025-03-04T10:31:07.262374+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849758176.113.115.96443TCP
                                                                                    2025-03-04T10:31:07.700982+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849758176.113.115.96443TCP
                                                                                    2025-03-04T10:31:08.531856+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849759176.113.115.96443TCP
                                                                                    2025-03-04T10:31:08.964139+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849759176.113.115.96443TCP
                                                                                    2025-03-04T10:31:09.817187+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849760176.113.115.96443TCP
                                                                                    2025-03-04T10:31:10.249501+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849760176.113.115.96443TCP
                                                                                    2025-03-04T10:31:11.107188+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849761176.113.115.96443TCP
                                                                                    2025-03-04T10:31:11.553451+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849761176.113.115.96443TCP
                                                                                    2025-03-04T10:31:12.418691+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849762176.113.115.96443TCP
                                                                                    2025-03-04T10:31:12.913028+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849762176.113.115.96443TCP
                                                                                    2025-03-04T10:31:13.860535+01002028765ET JA3 Hash - [Abuse.ch] Possible Dridex3192.168.2.849763176.113.115.96443TCP
                                                                                    2025-03-04T10:31:14.292530+01002803274ETPRO MALWARE Common Downloader Header Pattern UH2192.168.2.849763176.113.115.96443TCP
                                                                                    TimestampSource PortDest PortSource IPDest IP
                                                                                    Mar 4, 2025 10:30:04.277339935 CET49710443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:04.277398109 CET44349710176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:04.277481079 CET49710443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:04.288914919 CET49710443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:04.288937092 CET44349710176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:05.029897928 CET44349710176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:05.030019999 CET49710443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:05.125828028 CET49710443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:05.125868082 CET44349710176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:05.127002954 CET44349710176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:05.127079964 CET49710443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:05.131335974 CET49710443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:05.179337025 CET44349710176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:05.457056046 CET44349710176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:05.457250118 CET44349710176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:05.457326889 CET49710443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:05.457406998 CET49710443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:05.459373951 CET49710443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:05.459423065 CET44349710176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:05.568784952 CET49711443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:05.568839073 CET44349711176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:05.568928957 CET49711443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:05.569324970 CET49711443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:05.569336891 CET44349711176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:06.283629894 CET44349711176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:06.284270048 CET49711443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:06.284759045 CET49711443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:06.284765959 CET44349711176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:06.285264015 CET49711443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:06.285271883 CET44349711176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:06.717936993 CET44349711176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:06.718043089 CET44349711176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:06.718139887 CET49711443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:06.718204975 CET49711443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:06.718524933 CET49711443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:06.718564987 CET44349711176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:06.720026016 CET497122024192.168.2.8193.176.153.180
                                                                                    Mar 4, 2025 10:30:06.725152969 CET202449712193.176.153.180192.168.2.8
                                                                                    Mar 4, 2025 10:30:06.725301027 CET497122024192.168.2.8193.176.153.180
                                                                                    Mar 4, 2025 10:30:06.725399971 CET497122024192.168.2.8193.176.153.180
                                                                                    Mar 4, 2025 10:30:06.730365992 CET202449712193.176.153.180192.168.2.8
                                                                                    Mar 4, 2025 10:30:06.730501890 CET497122024192.168.2.8193.176.153.180
                                                                                    Mar 4, 2025 10:30:06.737394094 CET202449712193.176.153.180192.168.2.8
                                                                                    Mar 4, 2025 10:30:07.348737955 CET202449712193.176.153.180192.168.2.8
                                                                                    Mar 4, 2025 10:30:07.394608021 CET497122024192.168.2.8193.176.153.180
                                                                                    Mar 4, 2025 10:30:09.366183996 CET49713443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:09.366234064 CET44349713176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:09.366461992 CET49713443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:09.366755009 CET49713443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:09.366767883 CET44349713176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:10.200042009 CET44349713176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:10.200169086 CET49713443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:10.200922012 CET49713443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:10.200927019 CET44349713176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:10.201149940 CET49713443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:10.201154947 CET44349713176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:10.692404032 CET44349713176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:10.692507029 CET44349713176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:10.692511082 CET49713443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:10.692584038 CET49713443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:10.692810059 CET49713443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:10.692822933 CET44349713176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:11.818669081 CET49714443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:11.818721056 CET44349714176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:11.818778038 CET49714443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:11.819089890 CET49714443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:11.819104910 CET44349714176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:12.549635887 CET44349714176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:12.549701929 CET49714443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:12.550884962 CET49714443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:12.550900936 CET44349714176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:12.551383972 CET49714443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:12.551393986 CET44349714176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:12.991333008 CET44349714176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:12.991425037 CET49714443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:12.991435051 CET44349714176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:12.991489887 CET49714443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:12.991673946 CET49714443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:12.991687059 CET44349714176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:13.099792004 CET49715443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:13.099827051 CET44349715176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:13.099898100 CET49715443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:13.100311041 CET49715443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:13.100323915 CET44349715176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:13.927037954 CET44349715176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:13.927135944 CET49715443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:13.927866936 CET49715443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:13.927872896 CET44349715176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:13.928236961 CET49715443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:13.928242922 CET44349715176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:14.374087095 CET44349715176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:14.374167919 CET49715443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:14.374169111 CET44349715176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:14.374229908 CET49715443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:14.374459982 CET49715443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:14.374473095 CET44349715176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:14.498430014 CET49716443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:14.498477936 CET44349716176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:14.498545885 CET49716443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:14.498930931 CET49716443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:14.498944998 CET44349716176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:15.314726114 CET44349716176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:15.315017939 CET49716443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:15.316436052 CET49716443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:15.316499949 CET44349716176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:15.316993952 CET49716443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:15.317001104 CET44349716176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:15.751173973 CET44349716176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:15.751269102 CET49716443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:15.751274109 CET44349716176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:15.751323938 CET49716443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:15.751733065 CET49716443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:15.751750946 CET44349716176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:15.865609884 CET49717443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:15.865731001 CET44349717176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:15.865827084 CET49717443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:15.866194010 CET49717443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:15.866231918 CET44349717176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:16.601188898 CET44349717176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:16.601375103 CET49717443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:16.601921082 CET49717443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:16.601933956 CET44349717176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:16.602163076 CET49717443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:16.602166891 CET44349717176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:17.038642883 CET44349717176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:17.038738966 CET44349717176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:17.038835049 CET49717443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:17.039153099 CET49717443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:17.039153099 CET49717443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:17.146859884 CET49718443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:17.146934032 CET44349718176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:17.147023916 CET49718443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:17.147368908 CET49718443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:17.147384882 CET44349718176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:17.347793102 CET49717443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:17.347831964 CET44349717176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:17.856731892 CET44349718176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:17.856978893 CET49718443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:17.857469082 CET49718443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:17.857477903 CET44349718176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:17.857661009 CET49718443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:17.857667923 CET44349718176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:18.293116093 CET44349718176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:18.293236017 CET44349718176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:18.293262005 CET49718443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:18.293294907 CET49718443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:18.293734074 CET49718443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:18.293757915 CET44349718176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:18.414875984 CET49719443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:18.414932013 CET44349719176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:18.415041924 CET49719443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:18.415715933 CET49719443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:18.415730000 CET44349719176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:19.124037027 CET44349719176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:19.124245882 CET49719443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:19.124892950 CET49719443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:19.124902964 CET44349719176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:19.125087976 CET49719443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:19.125093937 CET44349719176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:19.560286045 CET44349719176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:19.560354948 CET49719443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:19.560375929 CET44349719176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:19.560389042 CET44349719176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:19.560419083 CET49719443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:19.560442924 CET49719443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:19.560606003 CET49719443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:19.560621023 CET44349719176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:19.678046942 CET49720443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:19.678096056 CET44349720176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:19.678174019 CET49720443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:19.678468943 CET49720443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:19.678483963 CET44349720176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:20.408747911 CET44349720176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:20.408843040 CET49720443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:20.409320116 CET49720443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:20.409351110 CET44349720176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:20.409502029 CET49720443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:20.409514904 CET44349720176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:20.837007999 CET44349720176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:20.837095976 CET44349720176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:20.837224960 CET49720443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:20.837224960 CET49720443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:20.837492943 CET49720443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:20.837512970 CET44349720176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:20.943730116 CET49721443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:20.943840981 CET44349721176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:20.943953991 CET49721443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:20.944236994 CET49721443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:20.944277048 CET44349721176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:21.658121109 CET44349721176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:21.658199072 CET49721443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:21.658842087 CET49721443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:21.658874035 CET44349721176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:21.659059048 CET49721443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:21.659073114 CET44349721176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:22.095666885 CET44349721176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:22.095762968 CET49721443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:22.095766068 CET44349721176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:22.095813990 CET49721443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:22.096081018 CET49721443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:22.096097946 CET44349721176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:22.209141016 CET49722443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:22.209192991 CET44349722176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:22.209280968 CET49722443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:22.209589005 CET49722443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:22.209604025 CET44349722176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:23.039026022 CET44349722176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:23.039130926 CET49722443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:23.039833069 CET49722443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:23.039851904 CET44349722176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:23.039937973 CET49722443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:23.039943933 CET44349722176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:23.480695009 CET44349722176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:23.480796099 CET44349722176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:23.480808973 CET49722443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:23.480842113 CET49722443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:23.481146097 CET49722443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:23.481162071 CET44349722176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:23.600034952 CET49723443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:23.600095987 CET44349723176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:23.600203037 CET49723443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:23.600502968 CET49723443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:23.600516081 CET44349723176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:24.309478045 CET44349723176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:24.309566975 CET49723443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:24.310463905 CET49723443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:24.310473919 CET44349723176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:24.310682058 CET49723443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:24.310687065 CET44349723176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:24.747237921 CET44349723176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:24.747339010 CET44349723176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:24.747378111 CET49723443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:24.747442961 CET49723443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:24.747747898 CET49723443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:24.747788906 CET44349723176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:24.865456104 CET49724443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:24.865520000 CET44349724176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:24.865600109 CET49724443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:24.865935087 CET49724443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:24.865947962 CET44349724176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:25.643569946 CET44349724176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:25.643707991 CET49724443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:25.644387007 CET49724443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:25.644397020 CET44349724176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:25.644818068 CET49724443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:25.644823074 CET44349724176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:26.080971003 CET44349724176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:26.081060886 CET44349724176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:26.081229925 CET49724443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:26.081758022 CET49724443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:26.081782103 CET44349724176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:26.194056034 CET49725443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:26.194125891 CET44349725176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:26.194269896 CET49725443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:26.194557905 CET49725443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:26.194570065 CET44349725176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:26.922343016 CET44349725176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:26.922461033 CET49725443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:26.923129082 CET49725443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:26.923151016 CET44349725176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:26.923337936 CET49725443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:26.923345089 CET44349725176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:27.356699944 CET44349725176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:27.356791973 CET44349725176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:27.356818914 CET49725443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:27.356853962 CET49725443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:27.357187986 CET49725443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:27.357208967 CET44349725176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:27.475446939 CET49727443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:27.475493908 CET44349727176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:27.475603104 CET49727443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:27.476098061 CET49727443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:27.476109028 CET44349727176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:28.193155050 CET44349727176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:28.193219900 CET49727443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:28.194149971 CET49727443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:28.194164991 CET44349727176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:28.194423914 CET49727443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:28.194432020 CET44349727176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:28.631303072 CET44349727176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:28.631397963 CET44349727176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:28.631427050 CET49727443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:28.631587029 CET49727443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:28.631855011 CET49727443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:28.631874084 CET44349727176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:28.740938902 CET49729443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:28.741003036 CET44349729176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:28.741226912 CET49729443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:28.742263079 CET49729443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:28.742274046 CET44349729176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:29.465955019 CET44349729176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:29.466054916 CET49729443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:29.467060089 CET49729443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:29.467070103 CET44349729176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:29.473906994 CET49729443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:29.473917961 CET44349729176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:29.911623001 CET44349729176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:29.911710024 CET44349729176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:29.911861897 CET49729443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:29.912199020 CET49729443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:29.912220001 CET44349729176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:30.022078037 CET49730443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:30.022142887 CET44349730176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:30.022296906 CET49730443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:30.022583961 CET49730443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:30.022595882 CET44349730176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:30.759445906 CET44349730176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:30.759512901 CET49730443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:30.760102034 CET49730443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:30.760109901 CET44349730176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:30.760310888 CET49730443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:30.760315895 CET44349730176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:31.198894978 CET44349730176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:31.198972940 CET44349730176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:31.199037075 CET49730443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:31.199352026 CET49730443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:31.199352026 CET49730443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:31.318694115 CET49731443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:31.318766117 CET44349731176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:31.318871021 CET49731443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:31.319200993 CET49731443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:31.319211006 CET44349731176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:31.503972054 CET49730443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:31.504009008 CET44349730176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:32.035446882 CET44349731176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:32.035507917 CET49731443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:32.036092997 CET49731443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:32.036101103 CET44349731176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:32.036299944 CET49731443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:32.036304951 CET44349731176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:32.475451946 CET44349731176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:32.475528002 CET44349731176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:32.475538969 CET49731443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:32.475573063 CET49731443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:32.476804972 CET49731443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:32.476824045 CET44349731176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:32.599740982 CET49732443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:32.599795103 CET44349732176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:32.599869013 CET49732443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:32.600243092 CET49732443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:32.600251913 CET44349732176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:33.325400114 CET44349732176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:33.325478077 CET49732443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:33.326105118 CET49732443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:33.326139927 CET44349732176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:33.326365948 CET49732443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:33.326379061 CET44349732176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:33.768018961 CET44349732176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:33.768191099 CET44349732176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:33.768296957 CET49732443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:33.768534899 CET49732443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:33.768552065 CET44349732176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:33.881186008 CET49733443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:33.881314993 CET44349733176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:33.881477118 CET49733443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:33.881735086 CET49733443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:33.881772041 CET44349733176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:34.598239899 CET44349733176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:34.598318100 CET49733443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:34.599204063 CET49733443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:34.599222898 CET44349733176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:34.599455118 CET49733443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:34.599461079 CET44349733176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:35.026240110 CET44349733176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:35.026318073 CET44349733176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:35.026343107 CET49733443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:35.026386976 CET49733443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:35.027699947 CET49733443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:35.027720928 CET44349733176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:35.163556099 CET49734443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:35.163623095 CET44349734176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:35.163685083 CET49734443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:35.164216042 CET49734443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:35.164232969 CET44349734176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:35.907849073 CET44349734176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:35.908416986 CET49734443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:35.908927917 CET49734443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:35.908935070 CET44349734176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:35.909146070 CET49734443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:35.909149885 CET44349734176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:36.349783897 CET44349734176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:36.349951982 CET49734443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:36.349971056 CET44349734176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:36.350025892 CET49734443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:36.350339890 CET49734443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:36.350356102 CET44349734176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:36.459223032 CET49735443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:36.459280014 CET44349735176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:36.459356070 CET49735443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:36.459820986 CET49735443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:36.459836960 CET44349735176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:37.278665066 CET44349735176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:37.278857946 CET49735443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:37.279372931 CET49735443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:37.279405117 CET44349735176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:37.279580116 CET49735443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:37.279592991 CET44349735176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:37.720993042 CET44349735176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:37.721066952 CET44349735176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:37.721076012 CET49735443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:37.721116066 CET49735443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:37.721295118 CET49735443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:37.721316099 CET44349735176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:37.834333897 CET49736443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:37.834398985 CET44349736176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:37.834481955 CET49736443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:37.834842920 CET49736443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:37.834852934 CET44349736176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:38.551150084 CET44349736176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:38.551234961 CET49736443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:38.551875114 CET49736443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:38.551907063 CET44349736176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:38.552081108 CET49736443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:38.552093029 CET44349736176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:38.990262032 CET44349736176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:38.990343094 CET49736443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:38.990365028 CET44349736176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:38.990381956 CET44349736176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:38.990403891 CET49736443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:38.990430117 CET49736443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:38.990638018 CET49736443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:38.990649939 CET44349736176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:39.100037098 CET49737443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:39.100178003 CET44349737176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:39.100267887 CET49737443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:39.100565910 CET49737443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:39.100605011 CET44349737176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:39.912281036 CET44349737176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:39.912405968 CET49737443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:39.913017035 CET49737443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:39.913034916 CET44349737176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:39.913218975 CET49737443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:39.913228989 CET44349737176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:40.351783991 CET44349737176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:40.351871967 CET44349737176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:40.351914883 CET49737443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:40.351953030 CET49737443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:40.352283001 CET49737443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:40.352309942 CET44349737176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:40.459322929 CET49738443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:40.459391117 CET44349738176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:40.459491014 CET49738443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:40.459800005 CET49738443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:40.459814072 CET44349738176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:41.254956961 CET44349738176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:41.255043983 CET49738443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:41.255534887 CET49738443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:41.255543947 CET44349738176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:41.255740881 CET49738443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:41.255747080 CET44349738176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:41.689579964 CET44349738176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:41.689672947 CET44349738176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:41.689773083 CET49738443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:41.690015078 CET49738443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:41.690038919 CET44349738176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:41.803050995 CET49739443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:41.803165913 CET44349739176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:41.803278923 CET49739443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:41.803561926 CET49739443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:41.803599119 CET44349739176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:42.512343884 CET44349739176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:42.512517929 CET49739443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:42.513068914 CET49739443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:42.513118982 CET44349739176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:42.513283968 CET49739443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:42.513314009 CET44349739176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:42.948005915 CET44349739176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:42.948091030 CET44349739176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:42.948122025 CET49739443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:42.948153019 CET49739443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:42.948523045 CET49739443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:42.948544025 CET44349739176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:43.112483978 CET49740443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:43.112528086 CET44349740176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:43.112632036 CET49740443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:43.113068104 CET49740443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:43.113085032 CET44349740176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:43.841866016 CET44349740176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:43.841979027 CET49740443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:43.863950968 CET49740443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:43.863969088 CET44349740176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:43.867893934 CET49740443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:43.867912054 CET44349740176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:44.269851923 CET44349740176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:44.269928932 CET49740443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:44.269944906 CET44349740176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:44.269958019 CET44349740176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:44.269992113 CET49740443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:44.270025969 CET49740443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:44.270355940 CET49740443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:44.270370960 CET44349740176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:44.381027937 CET49741443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:44.381063938 CET44349741176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:44.381149054 CET49741443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:44.381505966 CET49741443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:44.381519079 CET44349741176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:45.091840029 CET44349741176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:45.092525005 CET49741443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:45.093087912 CET49741443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:45.093101978 CET44349741176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:45.093296051 CET49741443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:45.093302965 CET44349741176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:45.521294117 CET44349741176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:45.521382093 CET44349741176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:45.521523952 CET49741443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:45.521744013 CET49741443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:45.521761894 CET44349741176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:45.631237030 CET49742443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:45.631283045 CET44349742176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:45.631375074 CET49742443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:45.631716967 CET49742443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:45.631728888 CET44349742176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:46.337529898 CET44349742176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:46.337587118 CET49742443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:46.338570118 CET49742443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:46.338578939 CET44349742176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:46.339045048 CET49742443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:46.339049101 CET44349742176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:46.773947954 CET44349742176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:46.774038076 CET44349742176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:46.774137020 CET49742443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:46.774137020 CET49742443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:46.774329901 CET49742443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:46.774348021 CET44349742176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:46.881249905 CET49743443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:46.881304026 CET44349743176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:46.881416082 CET49743443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:46.881831884 CET49743443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:46.881844044 CET44349743176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:47.600990057 CET44349743176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:47.601092100 CET49743443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:47.601655006 CET49743443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:47.601661921 CET44349743176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:47.601881981 CET49743443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:47.601886988 CET44349743176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:48.041291952 CET44349743176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:48.041367054 CET44349743176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:48.041385889 CET49743443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:48.041409016 CET49743443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:48.041743040 CET49743443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:48.041760921 CET44349743176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:48.162230015 CET49744443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:48.162275076 CET44349744176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:48.162357092 CET49744443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:48.162655115 CET49744443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:48.162668943 CET44349744176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:48.897186041 CET44349744176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:48.897300005 CET49744443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:48.909821033 CET49744443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:48.909847021 CET44349744176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:48.912533045 CET49744443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:48.912554026 CET44349744176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:49.340003967 CET44349744176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:49.340097904 CET44349744176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:49.340230942 CET49744443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:49.340231895 CET49744443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:49.340490103 CET49744443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:49.340536118 CET44349744176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:49.459754944 CET49745443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:49.459799051 CET44349745176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:49.459939003 CET49745443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:49.460253000 CET49745443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:49.460264921 CET44349745176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:50.280817032 CET44349745176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:50.280963898 CET49745443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:50.281560898 CET49745443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:50.281570911 CET44349745176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:50.281822920 CET49745443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:50.281832933 CET44349745176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:50.719296932 CET44349745176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:50.719434023 CET49745443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:50.719459057 CET44349745176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:50.719511986 CET44349745176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:50.719513893 CET49745443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:50.719566107 CET49745443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:50.719857931 CET49745443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:50.719872952 CET44349745176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:50.834830046 CET49746443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:50.834891081 CET44349746176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:50.835004091 CET49746443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:50.835354090 CET49746443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:50.835391998 CET44349746176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:51.555574894 CET44349746176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:51.555679083 CET49746443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:51.556438923 CET49746443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:51.556468964 CET44349746176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:51.556911945 CET49746443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:51.556926012 CET44349746176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:51.992763996 CET44349746176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:51.992856979 CET44349746176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:51.992930889 CET49746443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:51.992930889 CET49746443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:51.993165970 CET49746443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:51.993222952 CET44349746176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:52.099894047 CET49747443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:52.099963903 CET44349747176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:52.100043058 CET49747443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:52.100420952 CET49747443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:52.100433111 CET44349747176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:52.928276062 CET44349747176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:52.928381920 CET49747443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:52.928981066 CET49747443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:52.928991079 CET44349747176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:52.929225922 CET49747443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:52.929230928 CET44349747176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:53.358939886 CET44349747176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:53.359036922 CET49747443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:53.359047890 CET44349747176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:53.359100103 CET49747443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:53.373317957 CET49747443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:53.373342991 CET44349747176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:53.490848064 CET49748443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:53.490905046 CET44349748176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:53.490971088 CET49748443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:53.491287947 CET49748443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:53.491303921 CET44349748176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:54.295770884 CET44349748176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:54.295964956 CET49748443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:54.296544075 CET49748443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:54.296555996 CET44349748176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:54.296854973 CET49748443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:54.296859980 CET44349748176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:54.733500004 CET44349748176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:54.733609915 CET49748443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:54.733628035 CET44349748176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:54.733668089 CET49748443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:54.733686924 CET44349748176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:54.733732939 CET49748443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:54.733916998 CET49748443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:54.733932972 CET44349748176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:54.850069046 CET49749443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:54.850115061 CET44349749176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:54.850199938 CET49749443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:54.850486040 CET49749443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:54.850502014 CET44349749176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:55.591213942 CET44349749176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:55.591278076 CET49749443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:55.594917059 CET49749443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:55.594923973 CET44349749176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:55.595129967 CET49749443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:55.595134974 CET44349749176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:56.042887926 CET44349749176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:56.042958975 CET49749443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:56.042984009 CET44349749176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:56.042999029 CET44349749176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:56.043032885 CET49749443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:56.043059111 CET49749443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:56.043329954 CET49749443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:56.043346882 CET44349749176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:56.165668011 CET49750443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:56.165724993 CET44349750176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:56.165810108 CET49750443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:56.166356087 CET49750443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:56.166368008 CET44349750176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:56.896807909 CET44349750176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:56.896883965 CET49750443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:56.897638083 CET49750443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:56.897638083 CET49750443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:56.897653103 CET44349750176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:56.897669077 CET44349750176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:57.343297958 CET44349750176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:57.343386889 CET44349750176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:57.343394041 CET49750443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:57.343638897 CET49750443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:57.343751907 CET49750443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:57.343775988 CET44349750176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:57.459424973 CET49751443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:57.459472895 CET44349751176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:57.459558010 CET49751443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:57.459952116 CET49751443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:57.459964991 CET44349751176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:58.175692081 CET44349751176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:58.175813913 CET49751443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:58.176476002 CET49751443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:58.176490068 CET44349751176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:58.176750898 CET49751443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:58.176755905 CET44349751176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:58.618767977 CET44349751176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:58.618870974 CET44349751176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:58.618876934 CET49751443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:58.618921041 CET49751443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:58.619164944 CET49751443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:58.619184017 CET44349751176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:58.740603924 CET49752443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:58.740652084 CET44349752176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:58.740742922 CET49752443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:58.741087914 CET49752443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:58.741100073 CET44349752176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:59.458617926 CET44349752176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:59.458729029 CET49752443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:59.459285021 CET49752443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:59.459295034 CET44349752176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:59.459506989 CET49752443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:59.459511995 CET44349752176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:59.892993927 CET44349752176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:59.893079042 CET44349752176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:30:59.893135071 CET49752443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:59.893161058 CET49752443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:59.893381119 CET49752443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:30:59.893403053 CET44349752176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:00.006125927 CET49753443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:00.006184101 CET44349753176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:00.006294966 CET49753443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:00.006584883 CET49753443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:00.006598949 CET44349753176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:00.722593069 CET44349753176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:00.722862959 CET49753443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:00.743304968 CET49753443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:00.743328094 CET44349753176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:00.743493080 CET49753443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:00.743498087 CET44349753176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:01.161036968 CET44349753176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:01.161113977 CET49753443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:01.161129951 CET44349753176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:01.161183119 CET49753443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:01.161444902 CET49753443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:01.161463022 CET44349753176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:01.273567915 CET49754443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:01.273617029 CET44349754176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:01.273700953 CET49754443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:01.274108887 CET49754443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:01.274126053 CET44349754176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:02.079977036 CET44349754176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:02.080123901 CET49754443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:02.080888033 CET49754443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:02.080897093 CET44349754176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:02.081110954 CET49754443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:02.081116915 CET44349754176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:02.519640923 CET44349754176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:02.519711971 CET44349754176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:02.519790888 CET49754443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:02.520237923 CET49754443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:02.520256996 CET44349754176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:02.631138086 CET49755443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:02.631191969 CET44349755176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:02.631269932 CET49755443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:02.631635904 CET49755443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:02.631649017 CET44349755176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:03.374653101 CET44349755176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:03.376539946 CET49755443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:03.422429085 CET49755443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:03.422451973 CET44349755176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:03.422671080 CET49755443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:03.422674894 CET44349755176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:03.820705891 CET44349755176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:03.820779085 CET49755443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:03.820808887 CET44349755176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:03.820856094 CET49755443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:03.820884943 CET44349755176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:03.820941925 CET49755443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:03.821036100 CET49755443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:03.821049929 CET44349755176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:03.928764105 CET49756443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:03.928829908 CET44349756176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:03.928898096 CET49756443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:03.929241896 CET49756443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:03.929258108 CET44349756176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:04.653218985 CET44349756176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:04.653358936 CET49756443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:04.653881073 CET49756443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:04.653911114 CET44349756176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:04.654103994 CET49756443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:04.654117107 CET44349756176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:05.084616899 CET44349756176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:05.084791899 CET44349756176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:05.084913969 CET49756443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:05.085098028 CET49756443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:05.085143089 CET44349756176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:05.193778992 CET49757443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:05.193880081 CET44349757176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:05.193979979 CET49757443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:05.194300890 CET49757443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:05.194339037 CET44349757176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:05.911863089 CET44349757176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:05.912100077 CET49757443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:05.912570953 CET49757443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:05.912585974 CET44349757176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:05.912676096 CET49757443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:05.912683964 CET44349757176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:06.348597050 CET44349757176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:06.348725080 CET49757443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:06.348800898 CET44349757176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:06.348839045 CET44349757176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:06.348874092 CET49757443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:06.348907948 CET49757443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:06.349025011 CET49757443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:06.349052906 CET44349757176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:06.459883928 CET49758443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:06.459928036 CET44349758176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:06.460000992 CET49758443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:06.460367918 CET49758443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:06.460383892 CET44349758176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:07.262295008 CET44349758176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:07.262373924 CET49758443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:07.262903929 CET49758443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:07.262917995 CET44349758176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:07.264861107 CET49758443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:07.264873981 CET44349758176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:07.700953007 CET44349758176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:07.701034069 CET49758443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:07.701041937 CET44349758176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:07.701106071 CET49758443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:07.701297998 CET49758443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:07.701343060 CET44349758176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:07.824593067 CET49759443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:07.824727058 CET44349759176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:07.824800968 CET49759443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:07.825088024 CET49759443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:07.825123072 CET44349759176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:08.531794071 CET44349759176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:08.531856060 CET49759443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:08.532453060 CET49759443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:08.532465935 CET44349759176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:08.534637928 CET49759443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:08.534657001 CET44349759176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:08.964134932 CET44349759176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:08.964222908 CET44349759176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:08.964236021 CET49759443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:08.964276075 CET49759443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:08.964549065 CET49759443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:08.964570999 CET44349759176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:09.101644039 CET49760443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:09.101730108 CET44349760176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:09.102890968 CET49760443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:09.103179932 CET49760443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:09.103202105 CET44349760176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:09.817102909 CET44349760176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:09.817187071 CET49760443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:09.817825079 CET49760443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:09.817842007 CET44349760176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:09.820461035 CET49760443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:09.820470095 CET44349760176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:10.249495983 CET44349760176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:10.249583006 CET49760443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:10.249593019 CET44349760176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:10.249650002 CET49760443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:10.250094891 CET49760443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:10.250134945 CET44349760176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:10.370069027 CET49761443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:10.370111942 CET44349761176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:10.370182991 CET49761443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:10.370608091 CET49761443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:10.370620966 CET44349761176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:11.106784105 CET44349761176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:11.107187986 CET49761443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:11.109519958 CET49761443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:11.109519958 CET49761443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:11.109533072 CET44349761176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:11.109550953 CET44349761176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:11.553455114 CET44349761176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:11.553550959 CET49761443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:11.553556919 CET44349761176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:11.553724051 CET49761443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:11.554078102 CET49761443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:11.554100990 CET44349761176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:11.680681944 CET49762443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:11.680747986 CET44349762176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:11.681035042 CET49762443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:11.681344032 CET49762443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:11.681366920 CET44349762176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:12.418622017 CET44349762176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:12.418690920 CET49762443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:12.593621016 CET49762443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:12.593651056 CET44349762176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:12.596085072 CET49762443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:12.596091986 CET44349762176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:12.913049936 CET44349762176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:12.913129091 CET44349762176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:12.913145065 CET49762443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:12.913194895 CET49762443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:12.913376093 CET49762443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:12.913402081 CET44349762176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:13.033297062 CET49763443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:13.033345938 CET44349763176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:13.033624887 CET49763443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:13.035018921 CET49763443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:13.035027027 CET44349763176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:13.860472918 CET44349763176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:13.860534906 CET49763443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:13.861227036 CET49763443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:13.861237049 CET44349763176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:13.863797903 CET49763443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:13.863802910 CET44349763176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:14.292556047 CET44349763176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:14.292640924 CET44349763176.113.115.96192.168.2.8
                                                                                    Mar 4, 2025 10:31:14.292640924 CET49763443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:14.292711020 CET49763443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:14.295928001 CET49763443192.168.2.8176.113.115.96
                                                                                    Mar 4, 2025 10:31:14.295959949 CET44349763176.113.115.96192.168.2.8
                                                                                    • 176.113.115.96
                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    0192.168.2.849710176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:05 UTC295OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f926d19fe6595cd66946851e91fcd85241ab258d81729326be8ee43a8f51f8a95b5ca212a91f953c588fb52d6db9f51a9a0a29d5954cad713479a672918d4348dd4da945b49c8 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:05 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:05 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:05 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    1192.168.2.849711176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:06 UTC295OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c926d19fe6595cd66946851e91fcd85241ab258d81729326be8ee43a8f51f8a95b5ca212a91f953c588fb52d6db9f51a9a0a29d5954cad713479a672918d4348dd4da945b49c8 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:06 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:06 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:06 UTC664INData Raw: 32 38 63 0d 0a 38 62 37 32 33 63 36 38 65 65 31 38 34 30 33 63 36 36 30 66 62 66 65 30 33 38 34 65 32 66 61 62 61 30 38 66 38 33 33 61 35 33 62 39 33 39 64 63 38 63 32 35 39 31 36 38 35 31 65 61 30 35 63 31 64 30 34 62 34 66 61 64 34 31 39 31 34 62 33 32 36 65 33 64 62 34 61 65 31 31 61 63 63 33 31 38 39 66 39 35 62 31 63 66 33 66 36 62 64 33 66 35 35 62 64 62 39 34 66 61 34 66 63 39 64 33 39 65 35 30 61 36 62 33 66 34 63 31 30 38 30 38 63 36 64 32 30 37 30 30 64 66 33 30 32 36 30 37 64 31 33 31 38 65 63 61 64 33 39 36 35 38 34 32 63 38 37 30 33 34 66 39 64 36 30 37 35 32 36 37 30 65 37 34 63 65 65 64 31 30 37 37 61 37 66 32 35 39 61 39 65 34 65 61 35 32 61 61 37 34 63 64 63 63 32 35 65 62 66 31 63 34 65 62 35 34 31 35 38 63 34 36 39 62 33 37 61 35 33 31
                                                                                    Data Ascii: 28c8b723c68ee18403c660fbfe0384e2faba08f833a53b939dc8c25916851ea05c1d04b4fad41914b326e3db4ae11acc3189f95b1cf3f6bd3f55bdb94fa4fc9d39e50a6b3f4c10808c6d20700df302607d1318ecad3965842c87034f9d60752670e74ceed1077a7f259a9e4ea52aa74cdcc25ebf1c4eb54158c469b37a531


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    2192.168.2.849713176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:10 UTC303OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:10 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:10 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:10 UTC127INData Raw: 37 34 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 30 33 33 37 37 37 34 38 62 61 65 34 36 64 34 32 32 37 61 66 62 38 39 30 38 35 33 64 34 65 61 36 33 64 64 65 39 37 33 61 39 30 36 61 34 63 62 32 34 35 39 62 38 61 32 35 30 39 66 34 31 61 64 35 31 35 32 31 36 66 32 65 65 34 65 30 35 63 66 30 62 32 34 33 64 62 39 66 61 65 63 64 33 35 36 62 64 33 66 64 35 30 66 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: 748b723663ec1303377748bae46d4227afb890853d4ea63dde973a906a4cb2459b8a2509f41ad515216f2ee4e05cf0b243db9faecd356bd3fd50f50


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    3192.168.2.849714176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:12 UTC303OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:12 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:12 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:12 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    4192.168.2.849715176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:13 UTC303OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38b926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:14 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:14 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:14 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    5192.168.2.849716176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:15 UTC303OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb388926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:15 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:15 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:15 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    6192.168.2.849717176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:16 UTC303OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb389926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:17 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:16 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:17 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    7192.168.2.849718176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:17 UTC303OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb386926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:18 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:18 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:18 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    8192.168.2.849719176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:19 UTC303OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb387926d19fe6595cd66946951e91fcd85250eed10dc05672e26e1fd09b4a144c9c4e9976278d7f7449ad5f64dd7cc9f4badbff4c50d15918a5449d3323240976481d5d5905c48c17032f8dc HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:19 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:19 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:19 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    9192.168.2.849720176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:20 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f842a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:20 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:20 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:20 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    10192.168.2.849721176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:21 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f852a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:22 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:21 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:22 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    11192.168.2.849722176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:23 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f862a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:23 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:23 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:23 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    12192.168.2.849723176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:24 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f872a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:24 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:24 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:24 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    13192.168.2.849724176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:25 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f802a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:26 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:25 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:26 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    14192.168.2.849725176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:26 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f812a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:27 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:27 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:27 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    15192.168.2.849727176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:28 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f822a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:28 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:28 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:28 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    16192.168.2.849729176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:29 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f832a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:29 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:29 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:29 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    17192.168.2.849730176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:30 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f8c2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:31 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:31 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:31 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    18192.168.2.849731176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:32 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38f8d2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:32 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:32 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:32 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    19192.168.2.849732176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:33 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c842a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:33 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:33 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:33 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    20192.168.2.849733176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:34 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c852a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:35 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:34 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:35 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    21192.168.2.849734176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:35 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c862a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:36 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:36 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:36 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    22192.168.2.849735176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:37 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c872a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:37 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:37 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:37 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    23192.168.2.849736176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:38 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c802a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:38 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:38 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:38 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    24192.168.2.849737176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:39 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c812a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:40 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:40 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:40 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    25192.168.2.849738176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:41 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c822a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:41 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:41 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:41 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    26192.168.2.849739176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:42 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c832a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:42 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:42 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:42 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    27192.168.2.849740176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:43 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c8c2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:44 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:44 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:44 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    28192.168.2.849741176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:45 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38c8d2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:45 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:45 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:45 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    29192.168.2.849742176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:46 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d842a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:46 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:46 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:46 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    30192.168.2.849743176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:47 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d852a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:48 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:47 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:48 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    31192.168.2.849744176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:48 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d862a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:49 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:49 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:49 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    32192.168.2.849745176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:50 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d872a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:50 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:50 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:50 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    33192.168.2.849746176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:51 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d802a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:51 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:51 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:51 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    34192.168.2.849747176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:52 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d812a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:53 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:53 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:53 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    35192.168.2.849748176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:54 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d822a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:54 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:54 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:54 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    36192.168.2.849749176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:55 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d832a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:56 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:55 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:56 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    37192.168.2.849750176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:56 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d8c2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:57 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:57 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:57 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    38192.168.2.849751176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:58 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38d8d2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:58 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:58 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:58 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    39192.168.2.849752176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:30:59 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a842a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:30:59 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:30:59 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:30:59 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    40192.168.2.849753176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:31:00 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a852a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:31:01 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:31:01 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:31:01 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    41192.168.2.849754176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:31:02 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a862a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:31:02 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:31:02 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:31:02 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    42192.168.2.849755176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:31:03 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a872a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:31:03 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:31:03 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:31:03 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    43192.168.2.849756176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:31:04 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a802a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:31:05 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:31:04 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:31:05 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    44192.168.2.849757176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:31:05 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a812a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:31:06 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:31:06 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:31:06 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    45192.168.2.849758176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:31:07 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a822a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:31:07 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:31:07 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:31:07 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    46192.168.2.849759176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:31:08 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a832a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:31:08 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:31:08 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:31:08 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    47192.168.2.849760176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:31:09 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a8c2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:31:10 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:31:10 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:31:10 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    48192.168.2.849761176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:31:11 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38a8d2a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:31:11 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:31:11 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:31:11 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    49192.168.2.849762176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:31:12 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38b842a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:31:12 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:31:12 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:31:12 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                    50192.168.2.849763176.113.115.964431036C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    TimestampBytes transferredDirectionData
                                                                                    2025-03-04 09:31:13 UTC305OUTGET /ai/?key=8f3f2b3ae514176a774cb0f2231678fbb38b852a1cec7a86d87bdb6546ad12dac0290de81fdd1a29366be8ef43a8ec4cda8eec906920dff151d3c9b841d6d28155b2b7fdc10c06d180594f893e250f8a74d8d9d3935949c97834ffdc07 HTTP/1.1
                                                                                    User-Agent: Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 9.0; en-US)
                                                                                    Host: 176.113.115.96
                                                                                    2025-03-04 09:31:14 UTC200INHTTP/1.1 200 OK
                                                                                    Server: nginx/1.18.0 (Ubuntu)
                                                                                    Date: Tue, 04 Mar 2025 09:31:14 GMT
                                                                                    Content-Type: text/html; charset=UTF-8
                                                                                    Transfer-Encoding: chunked
                                                                                    Connection: close
                                                                                    X-Powered-By: PHP/7.4.33
                                                                                    2025-03-04 09:31:14 UTC24INData Raw: 65 0d 0a 38 62 37 32 33 36 36 33 65 63 31 33 32 35 0d 0a 30 0d 0a 0d 0a
                                                                                    Data Ascii: e8b723663ec13250


                                                                                    Click to jump to process

                                                                                    Click to jump to process

                                                                                    Click to dive into process behavior distribution

                                                                                    Click to jump to process

                                                                                    Target ID:0
                                                                                    Start time:04:29:08
                                                                                    Start date:04/03/2025
                                                                                    Path:C:\Users\user\Desktop\tKBxw8eOIV.exe
                                                                                    Wow64 process (32bit):true
                                                                                    Commandline:"C:\Users\user\Desktop\tKBxw8eOIV.exe"
                                                                                    Imagebase:0x400000
                                                                                    File size:3'722'172 bytes
                                                                                    MD5 hash:51F4CFBE1C4F38BEB7D4185086720317
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Reputation:low
                                                                                    Has exited:false

                                                                                    Target ID:1
                                                                                    Start time:04:29:09
                                                                                    Start date:04/03/2025
                                                                                    Path:C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp
                                                                                    Wow64 process (32bit):true
                                                                                    Commandline:"C:\Users\user\AppData\Local\Temp\is-BJCEB.tmp\tKBxw8eOIV.tmp" /SL5="$303F4,3471488,56832,C:\Users\user\Desktop\tKBxw8eOIV.exe"
                                                                                    Imagebase:0x400000
                                                                                    File size:711'168 bytes
                                                                                    MD5 hash:A68E919AA98AF0107E6C6C200955EF9C
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Antivirus matches:
                                                                                    • Detection: 3%, ReversingLabs
                                                                                    Reputation:low
                                                                                    Has exited:false

                                                                                    Target ID:3
                                                                                    Start time:04:29:10
                                                                                    Start date:04/03/2025
                                                                                    Path:C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe
                                                                                    Wow64 process (32bit):true
                                                                                    Commandline:"C:\Users\user\AppData\Local\Smart File Defrag 7.1.3\smartfiledefrag13.exe" -i
                                                                                    Imagebase:0x400000
                                                                                    File size:3'036'672 bytes
                                                                                    MD5 hash:483573178F49D6667013866FB10AB1CB
                                                                                    Has elevated privileges:true
                                                                                    Has administrator privileges:true
                                                                                    Programmed in:C, C++ or other language
                                                                                    Yara matches:
                                                                                    • Rule: JoeSecurity_Socks5Systemz, Description: Yara detected Socks5Systemz, Source: 00000003.00000002.2660443759.0000000002D01000.00000040.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                                                    • Rule: JoeSecurity_Socks5Systemz, Description: Yara detected Socks5Systemz, Source: 00000003.00000002.2660125834.000000000270F000.00000004.00000020.00020000.00000000.sdmp, Author: Joe Security
                                                                                    Reputation:low
                                                                                    Has exited:false

                                                                                    Reset < >