Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
uxeS0sMmqM.exe

Overview

General Information

Sample name:uxeS0sMmqM.exe
renamed because original name is a hash value
Original sample name:a5dd6d6c37a74355e33fe789b28a52a27f9a441169c5f4aab047a09c9d58e467.exe
Analysis ID:1631794
MD5:653ac46acc92bc606b888e35e44f912a
SHA1:c451f9ec5de81877919a7c312c72e10c3e6b1a0b
SHA256:a5dd6d6c37a74355e33fe789b28a52a27f9a441169c5f4aab047a09c9d58e467
Tags:exeuser-adrian__luca
Infos:

Detection

GuLoader
Score:76
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
Yara detected GuLoader
Joe Sandbox ML detected suspicious sample
Switches to a custom stack to bypass stack traces
Tries to detect virtualization through RDTSC time measurements
Abnormal high CPU Usage
Contains functionality for read data from the clipboard
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to dynamically determine API calls
Contains functionality to shutdown / reboot the system
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Found dropped PE file which has not been started or loaded
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Sample execution stops while process was sleeping (likely an evasion)
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files
Uses a known web browser user agent for HTTP communication

Classification

  • System is w10x64
  • uxeS0sMmqM.exe (PID: 7748 cmdline: "C:\Users\user\Desktop\uxeS0sMmqM.exe" MD5: 653AC46ACC92BC606B888E35E44F912A)
    • uxeS0sMmqM.exe (PID: 640 cmdline: "C:\Users\user\Desktop\uxeS0sMmqM.exe" MD5: 653AC46ACC92BC606B888E35E44F912A)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
CloudEyE, GuLoaderCloudEyE (initially named GuLoader) is a small VB5/6 downloader. It typically downloads RATs/Stealers, such as Agent Tesla, Arkei/Vidar, Formbook, Lokibot, Netwire and Remcos, often but not always from Google Drive. The downloaded payload is xored.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.cloudeye
No configs have been found
SourceRuleDescriptionAuthorStrings
0000000B.00000002.3745667715.0000000002BD7000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_GuLoader_2Yara detected GuLoaderJoe Security
    00000001.00000002.2767667629.00000000061E7000.00000040.00001000.00020000.00000000.sdmpJoeSecurity_GuLoader_2Yara detected GuLoaderJoe Security
      No Sigma rule has matched
      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
      2025-03-07T16:00:40.204610+010028032702Potentially Bad Traffic192.168.2.549694142.250.74.206443TCP

      Click to jump to signature section

      Show All Signature Results

      AV Detection

      barindex
      Source: uxeS0sMmqM.exeAvira: detected
      Source: uxeS0sMmqM.exeVirustotal: Detection: 68%Perma Link
      Source: uxeS0sMmqM.exeReversingLabs: Detection: 55%
      Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
      Source: uxeS0sMmqM.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
      Source: unknownHTTPS traffic detected: 142.250.74.206:443 -> 192.168.2.5:49694 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 142.250.186.33:443 -> 192.168.2.5:49695 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 142.250.186.33:443 -> 192.168.2.5:49701 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 142.250.74.206:443 -> 192.168.2.5:49702 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 142.250.186.33:443 -> 192.168.2.5:49705 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 142.250.186.33:443 -> 192.168.2.5:49707 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 142.250.186.33:443 -> 192.168.2.5:49709 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 142.250.186.33:443 -> 192.168.2.5:49711 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 142.250.186.33:443 -> 192.168.2.5:49715 version: TLS 1.2
      Source: uxeS0sMmqM.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
      Source: Binary string: mshtml.pdb source: uxeS0sMmqM.exe, 0000000B.00000001.2766160188.0000000000649000.00000020.00000001.01000000.00000009.sdmp
      Source: Binary string: mshtml.pdbUGP source: uxeS0sMmqM.exe, 0000000B.00000001.2766160188.0000000000649000.00000020.00000001.01000000.00000009.sdmp
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeCode function: 1_2_00405A19 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose,1_2_00405A19
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeCode function: 1_2_004065CE FindFirstFileA,FindClose,1_2_004065CE
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeCode function: 1_2_004027AA FindFirstFileA,1_2_004027AA
      Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
      Source: Network trafficSuricata IDS: 2803270 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UHCa : 192.168.2.5:49694 -> 142.250.74.206:443
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cache
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-Alive
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cache
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-Alive
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-AliveCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficHTTP traffic detected: GET /uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:134.0) Gecko/20100101 Firefox/134.0Host: drive.google.comCache-Control: no-cacheCookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ
      Source: global trafficDNS traffic detected: DNS query: drive.google.com
      Source: global trafficDNS traffic detected: DNS query: drive.usercontent.google.com
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundX-GUploader-UploadID: AKDAyIvJwrrqX5e4slm5DkhDziRbpGhtzLLWnAmawzC0UakoR7goUKLjBwrhRk3g4uzyal7hContent-Type: text/html; charset=utf-8Cache-Control: no-cache, no-store, max-age=0, must-revalidatePragma: no-cacheExpires: Mon, 01 Jan 1990 00:00:00 GMTDate: Fri, 07 Mar 2025 15:00:42 GMTP3P: CP="This is not a P3P policy! See g.co/p3phelp for more info."Content-Security-Policy: script-src 'nonce-mGldqglPdqZ9h9qwvJ8FuQ' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/DriveUntrustedContentHttp/cspreport;worker-src 'self'Content-Security-Policy: script-src 'unsafe-inline' 'unsafe-eval' blob: data: 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/DriveUntrustedContentHttp/cspreport/allowlistContent-Security-Policy: require-trusted-types-for 'script';report-uri /_/DriveUntrustedContentHttp/cspreportAccept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-VersionCross-Origin-Opener-Policy: same-originPermissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*Content-Length: 1652Server: UploadServerSet-Cookie: NID=522=5ETNAlfdoX0RyLwSDDZncie7i6-IZDhpjDhkN5_HyxoG2tRXCY7UnF43FKB6CaKFOJ97ucE1aahF_LzoSNZSVpZdueYiz67tgx6Eb8ePoHlU-jJNRdGIlrvIhhEcIBSZrKOSGKulgkRFR7mJb_EDeOG_ZlR86aBOJ4L1zn4rfS_Kgtw8a48lFBxB_UmvbJH8aQ; expires=Sat, 06-Sep-2025 15:00:42 GMT; path=/; domain=.google.com; Secure; HttpOnly; SameSite=noneAlt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000Content-Security-Policy: sandbox allow-scriptsConnection: close
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundX-GUploader-UploadID: AKDAyIvz52mBF_oLenNU37_noogVOuYUPHhyhWjD8D5MAP6XzMlJvRBBKhPN9sH-aJEaAq0rDe4hD0YContent-Type: text/html; charset=utf-8Cache-Control: no-cache, no-store, max-age=0, must-revalidatePragma: no-cacheExpires: Mon, 01 Jan 1990 00:00:00 GMTDate: Fri, 07 Mar 2025 15:00:48 GMTAccept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-VersionCross-Origin-Opener-Policy: same-originContent-Security-Policy: require-trusted-types-for 'script';report-uri /_/DriveUntrustedContentHttp/cspreportContent-Security-Policy: script-src 'nonce-3uq08PSEDR3mcoxNCxOEWg' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/DriveUntrustedContentHttp/cspreport;worker-src 'self'Content-Security-Policy: script-src 'unsafe-inline' 'unsafe-eval' blob: data: 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/DriveUntrustedContentHttp/cspreport/allowlistPermissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*Content-Length: 1652Server: UploadServerAlt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000Content-Security-Policy: sandbox allow-scriptsConnection: close
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundX-GUploader-UploadID: AKDAyItiHmGHuV4wKxSKHR99HBs6UR8Qxuv13vusXRdZQpitZdDX_KwUl5Ad-YGlTITu5kOJContent-Type: text/html; charset=utf-8Cache-Control: no-cache, no-store, max-age=0, must-revalidatePragma: no-cacheExpires: Mon, 01 Jan 1990 00:00:00 GMTDate: Fri, 07 Mar 2025 15:00:54 GMTContent-Security-Policy: require-trusted-types-for 'script';report-uri /_/DriveUntrustedContentHttp/cspreportContent-Security-Policy: script-src 'nonce-M6ajZ-Ip08Z0sXgXAjFo1Q' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/DriveUntrustedContentHttp/cspreport;worker-src 'self'Content-Security-Policy: script-src 'unsafe-inline' 'unsafe-eval' blob: data: 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/DriveUntrustedContentHttp/cspreport/allowlistCross-Origin-Opener-Policy: same-originAccept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-VersionPermissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*Content-Length: 1652Server: UploadServerAlt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000Content-Security-Policy: sandbox allow-scriptsConnection: close
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundX-GUploader-UploadID: AKDAyIucp1XYVduC4u4WwbLKlHf3B8ZWIJR4p2ybRpST3g4d0Oqha-yhSyPZT9wymteGtSb-Content-Type: text/html; charset=utf-8Cache-Control: no-cache, no-store, max-age=0, must-revalidatePragma: no-cacheExpires: Mon, 01 Jan 1990 00:00:00 GMTDate: Fri, 07 Mar 2025 15:00:59 GMTAccept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-VersionCross-Origin-Opener-Policy: same-originContent-Security-Policy: require-trusted-types-for 'script';report-uri /_/DriveUntrustedContentHttp/cspreportContent-Security-Policy: script-src 'nonce-6NKcQyoD566LS_WuxXmqjA' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/DriveUntrustedContentHttp/cspreport;worker-src 'self'Content-Security-Policy: script-src 'unsafe-inline' 'unsafe-eval' blob: data: 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/DriveUntrustedContentHttp/cspreport/allowlistPermissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*Content-Length: 1652Server: UploadServerAlt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000Content-Security-Policy: sandbox allow-scriptsConnection: close
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundX-GUploader-UploadID: AKDAyIuNFb8u2qO_KkiC9RcqXncPNa99qkZLYEU7pA4btk3kbFH4nbAV4bDpXF_3GTqC0MZ6Content-Type: text/html; charset=utf-8Cache-Control: no-cache, no-store, max-age=0, must-revalidatePragma: no-cacheExpires: Mon, 01 Jan 1990 00:00:00 GMTDate: Fri, 07 Mar 2025 15:01:05 GMTContent-Security-Policy: require-trusted-types-for 'script';report-uri /_/DriveUntrustedContentHttp/cspreportContent-Security-Policy: script-src 'nonce-pupBCyBdnWWj9lgqPptd9Q' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/DriveUntrustedContentHttp/cspreport;worker-src 'self'Content-Security-Policy: script-src 'unsafe-inline' 'unsafe-eval' blob: data: 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/DriveUntrustedContentHttp/cspreport/allowlistCross-Origin-Opener-Policy: same-originPermissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-VersionContent-Length: 1652Server: UploadServerAlt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000Content-Security-Policy: sandbox allow-scriptsConnection: close
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundX-GUploader-UploadID: AKDAyIsafnM_U0AWbegpXCtHGTaGKhcQQ3nIoLquVDouvp-B2Vzvd6GZWsV5v0-zoKX1GxhHContent-Type: text/html; charset=utf-8Cache-Control: no-cache, no-store, max-age=0, must-revalidatePragma: no-cacheExpires: Mon, 01 Jan 1990 00:00:00 GMTDate: Fri, 07 Mar 2025 15:01:11 GMTCross-Origin-Opener-Policy: same-originContent-Security-Policy: require-trusted-types-for 'script';report-uri /_/DriveUntrustedContentHttp/cspreportContent-Security-Policy: script-src 'nonce-JQhYwQjI-CKsvD4Nw-SpGw' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/DriveUntrustedContentHttp/cspreport;worker-src 'self'Content-Security-Policy: script-src 'unsafe-inline' 'unsafe-eval' blob: data: 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/DriveUntrustedContentHttp/cspreport/allowlistAccept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-VersionPermissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*Content-Length: 1652Server: UploadServerAlt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000Content-Security-Policy: sandbox allow-scriptsConnection: close
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundX-GUploader-UploadID: AKDAyIttKOppM7HPinWkT0Dz51mbpgxJUONPeN0_hDnalehXS5qye0fF6TR7cXegPFgi9PD_-fslV78Content-Type: text/html; charset=utf-8Cache-Control: no-cache, no-store, max-age=0, must-revalidatePragma: no-cacheExpires: Mon, 01 Jan 1990 00:00:00 GMTDate: Fri, 07 Mar 2025 15:01:17 GMTContent-Security-Policy: script-src 'nonce-1J2r19azwV2iOcmX6ktFoQ' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/DriveUntrustedContentHttp/cspreport;worker-src 'self'Content-Security-Policy: script-src 'unsafe-inline' 'unsafe-eval' blob: data: 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/DriveUntrustedContentHttp/cspreport/allowlistContent-Security-Policy: require-trusted-types-for 'script';report-uri /_/DriveUntrustedContentHttp/cspreportCross-Origin-Opener-Policy: same-originAccept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-VersionPermissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*Content-Length: 1652Server: UploadServerAlt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000Content-Security-Policy: sandbox allow-scriptsConnection: close
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundX-GUploader-UploadID: AKDAyIvb8ALh9LPw18xobMPwojZMRFZFWNj8UDBKwGmzdMoPeBMwQUp017e3_2v1wiccBw4WContent-Type: text/html; charset=utf-8Cache-Control: no-cache, no-store, max-age=0, must-revalidatePragma: no-cacheExpires: Mon, 01 Jan 1990 00:00:00 GMTDate: Fri, 07 Mar 2025 15:01:22 GMTContent-Security-Policy: script-src 'nonce-NcncYCN77hzZy1_5NT4cMA' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/DriveUntrustedContentHttp/cspreport;worker-src 'self'Content-Security-Policy: script-src 'unsafe-inline' 'unsafe-eval' blob: data: 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/DriveUntrustedContentHttp/cspreport/allowlistContent-Security-Policy: require-trusted-types-for 'script';report-uri /_/DriveUntrustedContentHttp/cspreportCross-Origin-Opener-Policy: same-originAccept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-VersionPermissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*Content-Length: 1652Server: UploadServerAlt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000Content-Security-Policy: sandbox allow-scriptsConnection: close
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundX-GUploader-UploadID: AKDAyIsvaKNuweFiYUua285q5_zAfHdebnIbb83rzA3Ma3Z1Zmwbe_SUX9d4CLo-LdQFKZMDContent-Type: text/html; charset=utf-8Cache-Control: no-cache, no-store, max-age=0, must-revalidatePragma: no-cacheExpires: Mon, 01 Jan 1990 00:00:00 GMTDate: Fri, 07 Mar 2025 15:01:28 GMTContent-Security-Policy: script-src 'nonce-9F0RNDFodHXe7nxsN7sFjw' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/DriveUntrustedContentHttp/cspreport;worker-src 'self'Content-Security-Policy: script-src 'unsafe-inline' 'unsafe-eval' blob: data: 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/DriveUntrustedContentHttp/cspreport/allowlistContent-Security-Policy: require-trusted-types-for 'script';report-uri /_/DriveUntrustedContentHttp/cspreportCross-Origin-Opener-Policy: same-originAccept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-VersionPermissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*Content-Length: 1652Server: UploadServerAlt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000Content-Security-Policy: sandbox allow-scriptsConnection: close
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundX-GUploader-UploadID: AKDAyIs6Ob9kIDDSsdctjjyuNBUZ1YFsER8AIj0qNt-GplgxQDzOQWU9X2RE77jrT0-j5DjU17KRxFwContent-Type: text/html; charset=utf-8Cache-Control: no-cache, no-store, max-age=0, must-revalidatePragma: no-cacheExpires: Mon, 01 Jan 1990 00:00:00 GMTDate: Fri, 07 Mar 2025 15:01:33 GMTCross-Origin-Opener-Policy: same-originContent-Security-Policy: require-trusted-types-for 'script';report-uri /_/DriveUntrustedContentHttp/cspreportContent-Security-Policy: script-src 'nonce-w_PrZO9cSbhWi1ur5xJs8Q' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/DriveUntrustedContentHttp/cspreport;worker-src 'self'Content-Security-Policy: script-src 'unsafe-inline' 'unsafe-eval' blob: data: 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/DriveUntrustedContentHttp/cspreport/allowlistAccept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-VersionPermissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*Content-Length: 1652Server: UploadServerAlt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000Content-Security-Policy: sandbox allow-scriptsConnection: close
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundX-GUploader-UploadID: AKDAyIswlmFpklLFWLPTnIQOTlgJmvt2B254CKwCS7zqQhSvvdLeXewkROjPG9KNscJ8sZaYContent-Type: text/html; charset=utf-8Cache-Control: no-cache, no-store, max-age=0, must-revalidatePragma: no-cacheExpires: Mon, 01 Jan 1990 00:00:00 GMTDate: Fri, 07 Mar 2025 15:01:38 GMTCross-Origin-Opener-Policy: same-originContent-Security-Policy: require-trusted-types-for 'script';report-uri /_/DriveUntrustedContentHttp/cspreportContent-Security-Policy: script-src 'nonce-u_Vt73BIAckK5CF7C8f_og' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/DriveUntrustedContentHttp/cspreport;worker-src 'self'Content-Security-Policy: script-src 'unsafe-inline' 'unsafe-eval' blob: data: 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/DriveUntrustedContentHttp/cspreport/allowlistAccept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-VersionPermissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*Content-Length: 1652Server: UploadServerAlt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000Content-Security-Policy: sandbox allow-scriptsConnection: close
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundX-GUploader-UploadID: AKDAyIvpFlT08spLJE4tlwPMnD-TzcSJe8bS88gpmMCIdkUXPcwhLqf9_1VZEnWdhAxKFMo0bPkUuUIContent-Type: text/html; charset=utf-8Cache-Control: no-cache, no-store, max-age=0, must-revalidatePragma: no-cacheExpires: Mon, 01 Jan 1990 00:00:00 GMTDate: Fri, 07 Mar 2025 15:01:44 GMTCross-Origin-Opener-Policy: same-originContent-Security-Policy: require-trusted-types-for 'script';report-uri /_/DriveUntrustedContentHttp/cspreportContent-Security-Policy: script-src 'nonce-gVMJP8u9cdWJmihN5RTjBg' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/DriveUntrustedContentHttp/cspreport;worker-src 'self'Content-Security-Policy: script-src 'unsafe-inline' 'unsafe-eval' blob: data: 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/DriveUntrustedContentHttp/cspreport/allowlistAccept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-VersionPermissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*Content-Length: 1652Server: UploadServerAlt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000Content-Security-Policy: sandbox allow-scriptsConnection: close
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundX-GUploader-UploadID: AKDAyIsgZv3SGP6sdd05Zj82EDFTU47hUpp0JRkZPRt39mQCuIRsTlwOTxLVknDMuKkdpNk8Content-Type: text/html; charset=utf-8Cache-Control: no-cache, no-store, max-age=0, must-revalidatePragma: no-cacheExpires: Mon, 01 Jan 1990 00:00:00 GMTDate: Fri, 07 Mar 2025 15:01:50 GMTContent-Security-Policy: require-trusted-types-for 'script';report-uri /_/DriveUntrustedContentHttp/cspreportContent-Security-Policy: script-src 'nonce-lRGY75OC07qSM-WkeI04bQ' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/DriveUntrustedContentHttp/cspreport;worker-src 'self'Content-Security-Policy: script-src 'unsafe-inline' 'unsafe-eval' blob: data: 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/DriveUntrustedContentHttp/cspreport/allowlistCross-Origin-Opener-Policy: same-originAccept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-VersionPermissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*Content-Length: 1652Server: UploadServerAlt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000Content-Security-Policy: sandbox allow-scriptsConnection: close
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundX-GUploader-UploadID: AKDAyIueINZW47NCeUMM1gH6V5tf5UXt7UEV1AYG8q2qpyQHbCtM3oOUA56XK7Yhr0rxutISContent-Type: text/html; charset=utf-8Cache-Control: no-cache, no-store, max-age=0, must-revalidatePragma: no-cacheExpires: Mon, 01 Jan 1990 00:00:00 GMTDate: Fri, 07 Mar 2025 15:01:56 GMTContent-Security-Policy: require-trusted-types-for 'script';report-uri /_/DriveUntrustedContentHttp/cspreportContent-Security-Policy: script-src 'nonce-ehXrjCgOcSBZxHVK9QiQIg' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/DriveUntrustedContentHttp/cspreport;worker-src 'self'Content-Security-Policy: script-src 'unsafe-inline' 'unsafe-eval' blob: data: 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/DriveUntrustedContentHttp/cspreport/allowlistPermissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*Accept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-VersionCross-Origin-Opener-Policy: same-originContent-Length: 1652Server: UploadServerAlt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000Content-Security-Policy: sandbox allow-scriptsConnection: close
      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundX-GUploader-UploadID: AKDAyIsKR5nfu-jxVBtoREjwbKk7uOswFguLAao0tOk4SjxXNAMDy6CMdJ-yyk9GcySjKTFVContent-Type: text/html; charset=utf-8Cache-Control: no-cache, no-store, max-age=0, must-revalidatePragma: no-cacheExpires: Mon, 01 Jan 1990 00:00:00 GMTDate: Fri, 07 Mar 2025 15:02:01 GMTCross-Origin-Opener-Policy: same-originContent-Security-Policy: script-src 'nonce-xS9oETHaSXV8JqxCretoLA' 'unsafe-inline';object-src 'none';base-uri 'self';report-uri /_/DriveUntrustedContentHttp/cspreport;worker-src 'self'Content-Security-Policy: script-src 'unsafe-inline' 'unsafe-eval' blob: data: 'self' https://apis.google.com https://ssl.gstatic.com https://www.google.com https://www.googletagmanager.com https://www.gstatic.com https://www.google-analytics.com;report-uri /_/DriveUntrustedContentHttp/cspreport/allowlistContent-Security-Policy: require-trusted-types-for 'script';report-uri /_/DriveUntrustedContentHttp/cspreportAccept-CH: Sec-CH-UA-Arch, Sec-CH-UA-Bitness, Sec-CH-UA-Full-Version, Sec-CH-UA-Full-Version-List, Sec-CH-UA-Model, Sec-CH-UA-WoW64, Sec-CH-UA-Form-Factors, Sec-CH-UA-Platform, Sec-CH-UA-Platform-VersionPermissions-Policy: ch-ua-arch=*, ch-ua-bitness=*, ch-ua-full-version=*, ch-ua-full-version-list=*, ch-ua-model=*, ch-ua-wow64=*, ch-ua-form-factors=*, ch-ua-platform=*, ch-ua-platform-version=*Content-Length: 1652Server: UploadServerAlt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000Content-Security-Policy: sandbox allow-scriptsConnection: close
      Source: uxeS0sMmqM.exeString found in binary or memory: http://nsis.sf.net/NSIS_Error
      Source: uxeS0sMmqM.exeString found in binary or memory: http://nsis.sf.net/NSIS_ErrorError
      Source: uxeS0sMmqM.exe, 0000000B.00000001.2766160188.0000000000649000.00000020.00000001.01000000.00000009.sdmpString found in binary or memory: http://www.ftp.ftp://ftp.gopher.
      Source: uxeS0sMmqM.exe, 0000000B.00000001.2766160188.00000000005F2000.00000020.00000001.01000000.00000009.sdmpString found in binary or memory: http://www.w3c.org/TR/1999/REC-html401-19991224/frameset.dtd
      Source: uxeS0sMmqM.exe, 0000000B.00000001.2766160188.00000000005F2000.00000020.00000001.01000000.00000009.sdmpString found in binary or memory: http://www.w3c.org/TR/1999/REC-html401-19991224/loose.dtd
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3640746268.0000000004A1C000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3253615886.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3099666813.0000000004A1C000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3047154144.0000000004A12000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2966587927.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3100063186.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3099775262.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3189892989.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2993556576.00000000049D2000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2905966380.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3225610075.00000000049BE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://apis.google.com
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3640746268.0000000004A1C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dhttps://drive.usercontent.google.com/download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=d
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3728422467.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3281574919.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3553134870.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3668212007.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2934862157.0000000004A1C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/
      Source: uxeS0sMmqM.exe, 0000000B.00000002.3749063193.0000000004A1C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/0
      Source: uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049A6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download
      Source: uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049A6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=downloade
      Source: uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049A6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/_1
      Source: uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049A6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/crosoft
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3440734205.00000000049E4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/n
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3099666813.0000000004A1C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/ns
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3047122421.0000000004A1C000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3099666813.0000000004A1C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/orkspace.usercontent.google.com0
      Source: uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049A6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/q
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3640746268.0000000004A1C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/rcontent.google.com/download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=do
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3099666813.0000000004A1C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/tu
      Source: uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000002.3749063193.0000000004968000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3640762328.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000002.3748998662.00000000048C0000.00000004.00001000.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3611818558.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3697370560.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049A6000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3728422467.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3668212007.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000002.3748756806.00000000045EB000.00000004.00000010.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz
      Source: uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3640762328.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3525250793.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3499743809.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3611818558.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3583595491.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3697370560.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3728422467.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3553134870.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3668212007.00000000049E4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz0306150042Z
      Source: uxeS0sMmqM.exe, 0000000B.00000002.3749063193.0000000004968000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz?
      Source: uxeS0sMmqM.exe, 0000000B.00000002.3749063193.0000000004968000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6LzA
      Source: uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049A6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6LzM
      Source: uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049A6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6LzP
      Source: uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049BE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lzgoogletagservices-cn
      Source: uxeS0sMmqM.exe, 0000000B.00000002.3749063193.0000000004968000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lzs
      Source: uxeS0sMmqM.exe, 0000000B.00000002.3749063193.0000000004968000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lzu
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3640762328.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3611818558.00000000049E4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/uc?export=download&id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6LzubA8qPS6c1eA6Lz:4
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3020132804.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3072794698.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3047154144.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3414376639.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3386769508.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2993556576.00000000049E4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.google.com/v
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3668212007.00000000049E4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3020132804.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3307498568.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3189806040.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3072794698.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3047154144.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3360105480.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3160698154.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3468879495.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3440734205.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3640762328.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3334409291.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3414376639.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3525250793.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3386769508.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3132775079.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3499743809.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3611818558.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3583595491.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3221987961.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2934898485.00000000049E4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/G
      Source: uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049E4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/X
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3668212007.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3225610075.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3160698154.00000000049D2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3020132804.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3189806040.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3471861880.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3072794698.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3360105480.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3160698154.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3468879495.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3440734205.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3640762328.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3414376639.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2967157291.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3414431197.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3525250793.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3386769508.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3386853569.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3132775079.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3499743809.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3611818558.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3583595491.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3440861834.0000000004A11000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download$
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3099666813.0000000004A1C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download.c
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3020132804.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3307498568.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3189806040.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3471861880.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3072794698.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3360105480.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3160698154.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3468879495.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3440734205.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3640762328.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3334409291.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3414376639.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2967157291.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3414431197.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3525250793.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3386769508.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3386853569.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3132775079.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3499743809.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3611818558.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3583595491.00000000049E4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download2
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3047122421.0000000004A1C000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3020028052.0000000004A1C000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3099666813.0000000004A1C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=downloadE
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3697344840.0000000004A1C000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000002.3749063193.0000000004A1C000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3640746268.0000000004A1C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=downloadJ
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3307498568.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3189806040.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3471861880.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3072794698.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3360105480.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3160698154.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3468879495.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3440734205.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3640762328.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3334409291.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3414376639.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3414431197.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3525250793.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3386769508.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3386853569.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3132775079.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3499743809.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3611818558.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3583595491.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3221987961.00000000049E4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=downloadL
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3020132804.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3307498568.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3471861880.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3072794698.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3360105480.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3468879495.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3440734205.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3640762328.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3334409291.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3414376639.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3414431197.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3525250793.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3386769508.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3386853569.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3499743809.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3611818558.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3583595491.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3440861834.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3253557916.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3697370560.00000000049E4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=downloadV
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3307498568.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3189806040.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3471861880.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3360105480.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3160698154.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3468879495.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3440734205.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3640762328.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3334409291.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3414376639.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3414431197.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3525250793.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3386769508.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3386853569.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3132775079.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3499743809.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3611818558.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3583595491.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3221987961.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3440861834.0000000004A11000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=downloadZ
      Source: uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049A6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=download_
      Source: uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049A6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=downloadc
      Source: uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049A6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=downloadi
      Source: uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049A6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=downloads
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3020132804.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3307498568.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3189806040.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3471861880.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3072794698.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3360105480.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3160698154.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3468879495.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3440734205.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3640762328.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3334409291.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3414376639.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2967157291.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2906095354.0000000004A10000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3414431197.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3525250793.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3386769508.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3386853569.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3132775079.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3499743809.00000000049E4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://drive.usercontent.google.com/download?id=1dw0CTI415CKRkkbfOubA8qPS6c1eA6Lz&export=downloadx
      Source: uxeS0sMmqM.exe, 0000000B.00000001.2766160188.0000000000649000.00000020.00000001.01000000.00000009.sdmpString found in binary or memory: https://inference.location.live.net/inferenceservice/v21/Pox/GetLocationUsingFingerprinte1e71f6b-214
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3640746268.0000000004A1C000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3253615886.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3099666813.0000000004A1C000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3047154144.0000000004A12000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2966587927.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3100063186.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3099775262.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3189892989.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2993556576.00000000049D2000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2905966380.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3225610075.00000000049BE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ssl.gstatic.com
      Source: uxeS0sMmqM.exe, 0000000B.00000002.3749063193.0000000004A1C000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2934898485.00000000049D4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3281634827.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3100063186.00000000049CF000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2967157291.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2906095354.0000000004A10000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3132775079.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3640746268.0000000004A1C000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3253615886.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3099666813.0000000004A1C000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2934898485.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3047154144.0000000004A12000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2966587927.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2934957372.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2993556576.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3100063186.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3099775262.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3189892989.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2993556576.00000000049D2000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2905966380.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3225610075.00000000049BE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.google-analytics.com;report-uri
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3020132804.00000000049D4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3225610075.00000000049CC000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000002.3749063193.0000000004A1C000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2934898485.00000000049D4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3281634827.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3100063186.00000000049CF000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2967157291.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2906095354.0000000004A10000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3132775079.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3640746268.0000000004A1C000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3253615886.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3099666813.0000000004A1C000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3047154144.0000000004A12000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2966587927.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3100063186.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3099775262.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3189892989.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2993556576.00000000049D2000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2905966380.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3225610075.00000000049BE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.google.com
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3583283341.0000000004A1C000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3640746268.0000000004A1C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.google.como
      Source: uxeS0sMmqM.exe, 0000000B.00000003.3020132804.00000000049D4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3225610075.00000000049CC000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000002.3749063193.0000000004A1C000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2934898485.00000000049D4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3281634827.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3100063186.00000000049CF000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2967157291.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2906095354.0000000004A10000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3132775079.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3640746268.0000000004A1C000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3253615886.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3099666813.0000000004A1C000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3047154144.0000000004A12000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2966587927.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3100063186.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3099775262.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3189892989.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2993556576.00000000049D2000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2905966380.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3225610075.00000000049BE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.googletagmanager.com
      Source: uxeS0sMmqM.exe, 0000000B.00000002.3749063193.0000000004A1C000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2934898485.00000000049D4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3281634827.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3100063186.00000000049CF000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2967157291.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2906095354.0000000004A10000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3132775079.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3640746268.0000000004A1C000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3253615886.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3099666813.0000000004A1C000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2934898485.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3047154144.0000000004A12000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2966587927.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2934957372.0000000004A11000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2993556576.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3100063186.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3099775262.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3189892989.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2993556576.00000000049D2000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.2905966380.00000000049E4000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3225610075.00000000049BE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.gstatic.com
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
      Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49699 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49695 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49720 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49697
      Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49696
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49695
      Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49694
      Source: unknownNetwork traffic detected: HTTP traffic on port 49696 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49703 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49721 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49722
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49721
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49720
      Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49697 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49722 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
      Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
      Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
      Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
      Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49694 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
      Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49705
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
      Source: unknownHTTPS traffic detected: 142.250.74.206:443 -> 192.168.2.5:49694 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 142.250.186.33:443 -> 192.168.2.5:49695 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 142.250.186.33:443 -> 192.168.2.5:49701 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 142.250.74.206:443 -> 192.168.2.5:49702 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 142.250.186.33:443 -> 192.168.2.5:49705 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 142.250.186.33:443 -> 192.168.2.5:49707 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 142.250.186.33:443 -> 192.168.2.5:49709 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 142.250.186.33:443 -> 192.168.2.5:49711 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 142.250.186.33:443 -> 192.168.2.5:49715 version: TLS 1.2
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeCode function: 1_2_004054B6 GetDlgItem,GetDlgItem,GetDlgItem,GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,ShowWindow,ShowWindow,GetDlgItem,SendMessageA,SendMessageA,SendMessageA,GetDlgItem,CreateThread,CloseHandle,ShowWindow,ShowWindow,ShowWindow,LdrInitializeThunk,SendMessageA,CreatePopupMenu,LdrInitializeThunk,AppendMenuA,GetWindowRect,TrackPopupMenu,SendMessageA,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageA,GlobalUnlock,LdrInitializeThunk,SetClipboardData,CloseClipboard,1_2_004054B6
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeProcess Stats: CPU usage > 49%
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeCode function: 1_2_004033B3 EntryPoint,SetErrorMode,GetVersionExA,GetVersionExA,GetVersionExA,lstrlenA,#17,OleInitialize,SHGetFileInfoA,GetCommandLineA,CharNextA,LdrInitializeThunk,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcatA,lstrcatA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,LdrInitializeThunk,CopyFileA,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess,1_2_004033B3
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeCode function: 1_2_0040727F1_2_0040727F
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeCode function: 1_2_00406AA81_2_00406AA8
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeCode function: 1_2_73781B281_2_73781B28
      Source: uxeS0sMmqM.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
      Source: classification engineClassification label: mal76.troj.evad.winEXE@3/20@2/2
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeCode function: 1_2_004033B3 EntryPoint,SetErrorMode,GetVersionExA,GetVersionExA,GetVersionExA,lstrlenA,#17,OleInitialize,SHGetFileInfoA,GetCommandLineA,CharNextA,LdrInitializeThunk,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcatA,lstrcatA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,LdrInitializeThunk,CopyFileA,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess,1_2_004033B3
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeCode function: 1_2_00404766 GetDlgItem,SetWindowTextA,LdrInitializeThunk,LdrInitializeThunk,SHBrowseForFolderA,CoTaskMemFree,lstrcmpiA,lstrcatA,SetDlgItemTextA,LdrInitializeThunk,GetDiskFreeSpaceA,MulDiv,SetDlgItemTextA,1_2_00404766
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeCode function: 1_2_00402173 LdrInitializeThunk,CoCreateInstance,MultiByteToWideChar,LdrInitializeThunk,1_2_00402173
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeFile created: C:\Users\user\AppData\Roaming\bekendtgrelsersJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeFile created: C:\Users\user\AppData\Local\Temp\nszAE9F.tmpJump to behavior
      Source: uxeS0sMmqM.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeFile read: C:\Users\desktop.iniJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
      Source: uxeS0sMmqM.exeVirustotal: Detection: 68%
      Source: uxeS0sMmqM.exeReversingLabs: Detection: 55%
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeFile read: C:\Users\user\Desktop\uxeS0sMmqM.exeJump to behavior
      Source: unknownProcess created: C:\Users\user\Desktop\uxeS0sMmqM.exe "C:\Users\user\Desktop\uxeS0sMmqM.exe"
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeProcess created: C:\Users\user\Desktop\uxeS0sMmqM.exe "C:\Users\user\Desktop\uxeS0sMmqM.exe"
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeProcess created: C:\Users\user\Desktop\uxeS0sMmqM.exe "C:\Users\user\Desktop\uxeS0sMmqM.exe"Jump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: uxtheme.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: userenv.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: apphelp.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: propsys.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: dwmapi.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: cryptbase.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: oleacc.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: ntmarta.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: version.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: shfolder.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: kernel.appcore.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: windows.storage.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: wldp.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: riched20.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: usp10.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: msls31.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: textinputframework.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: coreuicomponents.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: coremessaging.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: wintypes.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: wintypes.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: wintypes.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: textshaping.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: profapi.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: iertutil.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: sspicli.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: powrprof.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: winhttp.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: wkscli.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: netutils.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: umpdc.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: wininet.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: windows.storage.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: wldp.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: profapi.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: kernel.appcore.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: mswsock.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: iphlpapi.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: winnsi.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: urlmon.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: srvcli.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: dnsapi.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: rasadhlp.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: fwpuclnt.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: schannel.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: mskeyprotect.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: ntasn1.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: msasn1.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: dpapi.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: cryptsp.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: rsaenh.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: cryptbase.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: gpapi.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: ncrypt.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeSection loaded: ncryptsslp.dllJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32Jump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeFile written: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\furriery.iniJump to behavior
      Source: uxeS0sMmqM.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
      Source: Binary string: mshtml.pdb source: uxeS0sMmqM.exe, 0000000B.00000001.2766160188.0000000000649000.00000020.00000001.01000000.00000009.sdmp
      Source: Binary string: mshtml.pdbUGP source: uxeS0sMmqM.exe, 0000000B.00000001.2766160188.0000000000649000.00000020.00000001.01000000.00000009.sdmp

      Data Obfuscation

      barindex
      Source: Yara matchFile source: 0000000B.00000002.3745667715.0000000002BD7000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
      Source: Yara matchFile source: 00000001.00000002.2767667629.00000000061E7000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeCode function: 1_2_73781B28 GlobalAlloc,lstrcpyA,lstrcpyA,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GlobalFree,lstrcpyA,GetModuleHandleA,LoadLibraryA,GetProcAddress,lstrlenA,1_2_73781B28
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeFile created: C:\Users\user\AppData\Local\Temp\nsfB094.tmp\LangDLL.dllJump to dropped file
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeFile created: C:\Users\user\AppData\Local\Temp\nsfB094.tmp\System.dllJump to dropped file
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

      Malware Analysis System Evasion

      barindex
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeAPI/Special instruction interceptor: Address: 68773EB
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeAPI/Special instruction interceptor: Address: 32673EB
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeRDTSC instruction interceptor: First address: 68362C6 second address: 68362C6 instructions: 0x00000000 rdtsc 0x00000002 cmp ebx, ecx 0x00000004 jc 00007F70C8C9BA14h 0x00000006 cmp edx, 6BB88DE8h 0x0000000c inc ebp 0x0000000d inc ebx 0x0000000e rdtsc
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeRDTSC instruction interceptor: First address: 32262C6 second address: 32262C6 instructions: 0x00000000 rdtsc 0x00000002 cmp ebx, ecx 0x00000004 jc 00007F70C8747C44h 0x00000006 cmp edx, 6BB88DE8h 0x0000000c inc ebp 0x0000000d inc ebx 0x0000000e rdtsc
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsfB094.tmp\LangDLL.dllJump to dropped file
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsfB094.tmp\System.dllJump to dropped file
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exe TID: 2728Thread sleep time: -150000s >= -30000sJump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeLast function: Thread delayed
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeCode function: 1_2_00405A19 GetTempPathA,DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,FindNextFileA,FindClose,1_2_00405A19
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeCode function: 1_2_004065CE FindFirstFileA,FindClose,1_2_004065CE
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeCode function: 1_2_004027AA FindFirstFileA,1_2_004027AA
      Source: uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3281634827.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3253615886.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3100063186.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3189892989.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3225610075.00000000049BE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW5
      Source: uxeS0sMmqM.exe, 0000000B.00000002.3749063193.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3281634827.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000002.3749063193.0000000004968000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3253615886.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3100063186.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3189892989.00000000049BE000.00000004.00000020.00020000.00000000.sdmp, uxeS0sMmqM.exe, 0000000B.00000003.3225610075.00000000049BE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeAPI call chain: ExitProcess graph end nodegraph_1-4431
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeAPI call chain: ExitProcess graph end nodegraph_1-4581
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeCode function: 1_2_00401759 lstrcatA,CompareFileTime,LdrInitializeThunk,SetFileTime,CloseHandle,lstrcatA,1_2_00401759
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeCode function: 1_2_73781B28 GlobalAlloc,lstrcpyA,lstrcpyA,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GlobalFree,lstrcpyA,GetModuleHandleA,LoadLibraryA,GetProcAddress,lstrlenA,1_2_73781B28
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeProcess created: C:\Users\user\Desktop\uxeS0sMmqM.exe "C:\Users\user\Desktop\uxeS0sMmqM.exe"Jump to behavior
      Source: C:\Users\user\Desktop\uxeS0sMmqM.exeCode function: 1_2_004033B3 EntryPoint,SetErrorMode,GetVersionExA,GetVersionExA,GetVersionExA,lstrlenA,#17,OleInitialize,SHGetFileInfoA,GetCommandLineA,CharNextA,LdrInitializeThunk,GetTempPathA,GetTempPathA,GetWindowsDirectoryA,lstrcatA,GetTempPathA,lstrcatA,SetEnvironmentVariableA,SetEnvironmentVariableA,SetEnvironmentVariableA,DeleteFileA,OleUninitialize,ExitProcess,lstrcatA,lstrcatA,lstrcatA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,LdrInitializeThunk,CopyFileA,CloseHandle,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx,ExitProcess,1_2_004033B3
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
      Native API
      1
      DLL Side-Loading
      1
      Access Token Manipulation
      1
      Masquerading
      OS Credential Dumping21
      Security Software Discovery
      Remote Services1
      Archive Collected Data
      11
      Encrypted Channel
      Exfiltration Over Other Network Medium1
      System Shutdown/Reboot
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts11
      Process Injection
      1
      Virtualization/Sandbox Evasion
      LSASS Memory1
      Virtualization/Sandbox Evasion
      Remote Desktop Protocol1
      Clipboard Data
      3
      Ingress Tool Transfer
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
      DLL Side-Loading
      1
      Access Token Manipulation
      Security Account Manager3
      File and Directory Discovery
      SMB/Windows Admin SharesData from Network Shared Drive3
      Non-Application Layer Protocol
      Automated ExfiltrationData Encrypted for Impact
      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook11
      Process Injection
      NTDS23
      System Information Discovery
      Distributed Component Object ModelInput Capture14
      Application Layer Protocol
      Traffic DuplicationData Destruction
      Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
      DLL Side-Loading
      LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Is Windows Process
      • Number of created Registry Values
      • Number of created Files
      • Visual Basic
      • Delphi
      • Java
      • .Net C# or VB.NET
      • C, C++ or other language
      • Is malicious
      • Internet

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.