Loading ...

Play interactive tourEdit tour

Windows Analysis Report Quotation for Enq # 90038355.exe

Overview

General Information

Sample Name:Quotation for Enq # 90038355.exe
Analysis ID:483892
MD5:344ba2ed272ba7e67556b82f312ea816
SHA1:e1d5527552a9879bfded79c3c76a673913e15ada
SHA256:9b4cb73e87053b62028a877f31ffba62960560bf707fa0458b3acc0899e942dd
Tags:agentteslaexe
Infos:

Most interesting Screenshot:

Detection

AgentTesla
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Multi AV Scanner detection for submitted file
Icon mismatch, binary includes an icon from a different legit application in order to fool users
Yara detected AgentTesla
Yara detected AntiVM3
Sigma detected: MSBuild connects to smtp port
Installs a global keyboard hook
Initial sample is a PE file and has a suspicious name
Writes to foreign memory regions
Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)
Tries to harvest and steal ftp login credentials
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Machine Learning detection for sample
Allocates memory in foreign processes
.NET source code contains potential unpacker
Injects a PE file into a foreign processes
.NET source code contains very large strings
Tries to steal Mail credentials (via file access)
Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)
Tries to harvest and steal browser information (history, passwords, etc)
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Antivirus or Machine Learning detection for unpacked file
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Internet Provider seen in connection with other malware
Detected potential crypto function
Yara detected Credential Stealer
Contains long sleeps (>= 3 min)
Enables debug privileges
Creates a DirectInput object (often for capturing keystrokes)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Sample file is different than original file name gathered from version info
PE file contains strange resources
Binary contains a suspicious time stamp
Creates a window with clipboard capturing capabilities
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Creates a process in suspended mode (likely to inject code)

Classification

Process Tree

  • System is w10x64
  • Quotation for Enq # 90038355.exe (PID: 5192 cmdline: 'C:\Users\user\Desktop\Quotation for Enq # 90038355.exe' MD5: 344BA2ED272BA7E67556B82F312EA816)
    • MSBuild.exe (PID: 1848 cmdline: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe MD5: D621FD77BD585874F9686D3A76462EF1)
  • cleanup

Malware Configuration

Threatname: Agenttesla

{"Exfil Mode": "SMTP", "Username": "share@phoenixfinance.com.bd", "Password": "Pfil*786", "Host": "mail.phoenixfinance.com.bd"}

Yara Overview

Memory Dumps

SourceRuleDescriptionAuthorStrings
00000002.00000002.931030895.0000000000402000.00000040.00000001.sdmpJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
    00000002.00000002.931030895.0000000000402000.00000040.00000001.sdmpJoeSecurity_AgentTesla_2Yara detected AgentTeslaJoe Security
      00000000.00000002.669711456.0000000003141000.00000004.00000001.sdmpJoeSecurity_AntiVM_3Yara detected AntiVM_3Joe Security
        00000000.00000002.670463877.00000000043B4000.00000004.00000001.sdmpJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
          00000000.00000002.670463877.00000000043B4000.00000004.00000001.sdmpJoeSecurity_AgentTesla_2Yara detected AgentTeslaJoe Security
            Click to see the 8 entries

            Unpacked PEs

            SourceRuleDescriptionAuthorStrings
            0.2.Quotation for Enq # 90038355.exe.420acc8.1.unpackJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
              0.2.Quotation for Enq # 90038355.exe.420acc8.1.unpackJoeSecurity_AgentTesla_2Yara detected AgentTeslaJoe Security
                2.2.MSBuild.exe.400000.0.unpackJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
                  2.2.MSBuild.exe.400000.0.unpackJoeSecurity_AgentTesla_2Yara detected AgentTeslaJoe Security
                    0.2.Quotation for Enq # 90038355.exe.420acc8.1.raw.unpackJoeSecurity_AgentTesla_1Yara detected AgentTeslaJoe Security
                      Click to see the 1 entries

                      Sigma Overview

                      Networking:

                      barindex
                      Sigma detected: MSBuild connects to smtp portShow sources
                      Source: Network ConnectionAuthor: Joe Security: Data: DestinationIp: 192.185.108.208, DestinationIsIpv6: false, DestinationPort: 587, EventID: 3, Image: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe, Initiated: true, ProcessId: 1848, Protocol: tcp, SourceIp: 192.168.2.4, SourceIsIpv6: false, SourcePort: 49832

                      System Summary:

                      barindex
                      Sigma detected: Possible Applocker BypassShow sources
                      Source: Process startedAuthor: juju4: Data: Command: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe, CommandLine: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe, CommandLine|base64offset|contains: , Image: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe, NewProcessName: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe, OriginalFileName: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe, ParentCommandLine: 'C:\Users\user\Desktop\Quotation for Enq # 90038355.exe' , ParentImage: C:\Users\user\Desktop\Quotation for Enq # 90038355.exe, ParentProcessId: 5192, ProcessCommandLine: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe, ProcessId: 1848

                      Jbx Signature Overview

                      Click to jump to signature section

                      Show All Signature Results

                      AV Detection:

                      barindex
                      Found malware configurationShow sources
                      Source: 0.2.Quotation for Enq # 90038355.exe.420acc8.1.unpackMalware Configuration Extractor: Agenttesla {"Exfil Mode": "SMTP", "Username": "share@phoenixfinance.com.bd", "Password": "Pfil*786", "Host": "mail.phoenixfinance.com.bd"}
                      Multi AV Scanner detection for submitted fileShow sources
                      Source: Quotation for Enq # 90038355.exeVirustotal: Detection: 32%Perma Link
                      Source: Quotation for Enq # 90038355.exeReversingLabs: Detection: 26%
                      Machine Learning detection for sampleShow sources
                      Source: Quotation for Enq # 90038355.exeJoe Sandbox ML: detected
                      Source: 2.2.MSBuild.exe.400000.0.unpackAvira: Label: TR/Spy.Gen8
                      Source: Quotation for Enq # 90038355.exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
                      Source: Quotation for Enq # 90038355.exeStatic PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT

                      Networking:

                      barindex
                      Source: Joe Sandbox ViewASN Name: UNIFIEDLAYER-AS-1US UNIFIEDLAYER-AS-1US
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49743
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49695 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49743 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49699
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49698
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49697
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49696
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49695
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49694
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49693
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49692
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49690
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49681 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49724
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50120 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49688
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50119
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49681
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49688 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 50119 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50120
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49703
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49724 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49705 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
                      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: unknownTCP traffic detected without corresponding DNS query: 92.122.145.220
                      Source: MSBuild.exe, 00000002.00000002.933029235.0000000003351000.00000004.00000001.sdmpString found in binary or memory: http://127.0.0.1:HTTP/1.1
                      Source: MSBuild.exe, 00000002.00000002.933029235.0000000003351000.00000004.00000001.sdmpString found in binary or memory: http://DynDns.comDynDNS
                      Source: MSBuild.exe, 00000002.00000002.935633413.00000000064A0000.00000004.00000001.sdmpString found in binary or memory: http://apps.identrust.com/roots/dstrootcax3.p7c0
                      Source: MSBuild.exe, 00000002.00000002.933029235.0000000003351000.00000004.00000001.sdmpString found in binary or memory: http://bJvmVK.com
                      Source: MSBuild.exe, 00000002.00000002.935633413.00000000064A0000.00000004.00000001.sdmpString found in binary or memory: http://cps.letsencrypt.org0
                      Source: MSBuild.exe, 00000002.00000002.935578751.000000000648B000.00000004.00000001.sdmpString found in binary or memory: http://cps.root-x1.letsenc
                      Source: MSBuild.exe, 00000002.00000002.935633413.00000000064A0000.00000004.00000001.sdmpString found in binary or memory: http://cps.root-x1.letsencrypt.org0
                      Source: MSBuild.exe, 00000002.00000002.935633413.00000000064A0000.00000004.00000001.sdmpString found in binary or memory: http://crl.identrust.com/DSTROOTCAX3CRL.crl0
                      Source: MSBuild.exe, 00000002.00000002.934081784.0000000003706000.00000004.00000001.sdmpString found in binary or memory: http://mail.phoenixfinance.com.bd
                      Source: MSBuild.exe, 00000002.00000002.935633413.00000000064A0000.00000004.00000001.sdmpString found in binary or memory: http://r3.i.lencr.org/0v
                      Source: MSBuild.exe, 00000002.00000002.935633413.00000000064A0000.00000004.00000001.sdmpString found in binary or memory: http://r3.o.lencr.org0
                      Source: MSBuild.exe, 00000002.00000002.935633413.00000000064A0000.00000004.00000001.sdmpString found in binary or memory: http://x1.c.lencr.org/0
                      Source: MSBuild.exe, 00000002.00000002.935633413.00000000064A0000.00000004.00000001.sdmpString found in binary or memory: http://x1.i.lencr.org/0
                      Source: MSBuild.exe, 00000002.00000002.933029235.0000000003351000.00000004.00000001.sdmpString found in binary or memory: https://YWRIJujMGl.org
                      Source: MSBuild.exe, 00000002.00000002.933029235.0000000003351000.00000004.00000001.sdmpString found in binary or memory: https://YWRIJujMGl.orgD0=
                      Source: MSBuild.exe, 00000002.00000002.933029235.0000000003351000.00000004.00000001.sdmpString found in binary or memory: https://api.ipify.org%
                      Source: MSBuild.exe, 00000002.00000002.933029235.0000000003351000.00000004.00000001.sdmpString found in binary or memory: https://api.ipify.org%GETMozilla/5.0
                      Source: Quotation for Enq # 90038355.exe, 00000000.00000002.670463877.00000000043B4000.00000004.00000001.sdmp, MSBuild.exe, 00000002.00000002.931030895.0000000000402000.00000040.00000001.sdmpString found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip
                      Source: MSBuild.exe, 00000002.00000002.933029235.0000000003351000.00000004.00000001.sdmpString found in binary or memory: https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha
                      Source: unknownDNS traffic detected: queries for: mail.phoenixfinance.com.bd

                      Key, Mouse, Clipboard, Microphone and Screen Capturing:

                      barindex
                      Installs a global keyboard hookShow sources
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWindows user hook set: 0 keyboard low level C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeJump to behavior
                      Source: Quotation for Enq # 90038355.exe, 00000000.00000002.669555775.00000000015AB000.00000004.00000020.sdmpBinary or memory string: <HOOK MODULE="DDRAW.DLL" FUNCTION="DirectDrawCreateEx"/>
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWindow created: window name: CLIPBRDWNDCLASSJump to behavior

                      System Summary:

                      barindex
                      Initial sample is a PE file and has a suspicious nameShow sources
                      Source: initial sampleStatic PE information: Filename: Quotation for Enq # 90038355.exe
                      .NET source code contains very large stringsShow sources
                      Source: Quotation for Enq # 90038355.exe, Forms/mainForm.csLong String: Length: 38272
                      Source: 0.0.Quotation for Enq # 90038355.exe.e60000.0.unpack, Forms/mainForm.csLong String: Length: 38272
                      Source: 0.2.Quotation for Enq # 90038355.exe.e60000.0.unpack, Forms/mainForm.csLong String: Length: 38272
                      Source: Quotation for Enq # 90038355.exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeCode function: 0_2_0159C1240_2_0159C124
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeCode function: 0_2_0159E5700_2_0159E570
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeCode function: 0_2_0159E5630_2_0159E563
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeCode function: 0_2_051432750_2_05143275
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeCode function: 0_2_05142E900_2_05142E90
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeCode function: 0_2_05143B480_2_05143B48
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeCode function: 0_2_05146BB80_2_05146BB8
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeCode function: 0_2_051414780_2_05141478
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeCode function: 0_2_051414680_2_05141468
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeCode function: 0_2_051434A80_2_051434A8
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeCode function: 0_2_051437B00_2_051437B0
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeCode function: 0_2_051437C00_2_051437C0
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeCode function: 0_2_05143D410_2_05143D41
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeCode function: 0_2_05140D780_2_05140D78
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeCode function: 0_2_05140D670_2_05140D67
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeCode function: 0_2_05142E800_2_05142E80
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeCode function: 0_2_05143B390_2_05143B39
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 2_2_05E2B6CC2_2_05E2B6CC
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 2_2_05E2D1582_2_05E2D158
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 2_2_05E213602_2_05E21360
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 2_2_05E2D8682_2_05E2D868
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 2_2_066DD65F2_2_066DD65F
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 2_2_066D9F942_2_066D9F94
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 2_2_066D5D782_2_066D5D78
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 2_2_066DDAB82_2_066DDAB8
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 2_2_066DBBC12_2_066DBBC1
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 2_2_066D00862_2_066D0086
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 2_2_066D6E682_2_066D6E68
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 2_2_066D6E5C2_2_066D6E5C
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 2_2_066D8D702_2_066D8D70
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 2_2_07172C582_2_07172C58
                      Source: Quotation for Enq # 90038355.exeBinary or memory string: OriginalFilename vs Quotation for Enq # 90038355.exe
                      Source: Quotation for Enq # 90038355.exe, 00000000.00000000.661886892.0000000000E62000.00000002.00020000.sdmpBinary or memory string: OriginalFilenameEVENTFILTERDESCRIPT.exe4 vs Quotation for Enq # 90038355.exe
                      Source: Quotation for Enq # 90038355.exe, 00000000.00000002.669711456.0000000003141000.00000004.00000001.sdmpBinary or memory string: OriginalFilenamejsUtdMNBeuhbNnokaRBAyEynyJeXUAQH.exe4 vs Quotation for Enq # 90038355.exe
                      Source: Quotation for Enq # 90038355.exe, 00000000.00000002.670396850.0000000004311000.00000004.00000001.sdmpBinary or memory string: OriginalFilenameCF_Secretaria.dll< vs Quotation for Enq # 90038355.exe
                      Source: Quotation for Enq # 90038355.exe, 00000000.00000002.669555775.00000000015AB000.00000004.00000020.sdmpBinary or memory string: OriginalFilenameclr.dllT vs Quotation for Enq # 90038355.exe
                      Source: Quotation for Enq # 90038355.exeBinary or memory string: OriginalFilenameEVENTFILTERDESCRIPT.exe4 vs Quotation for Enq # 90038355.exe
                      Source: Quotation for Enq # 90038355.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
                      Source: Quotation for Enq # 90038355.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
                      Source: Quotation for Enq # 90038355.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
                      Source: Quotation for Enq # 90038355.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                      Source: Quotation for Enq # 90038355.exeVirustotal: Detection: 32%
                      Source: Quotation for Enq # 90038355.exeReversingLabs: Detection: 26%
                      Source: Quotation for Enq # 90038355.exeStatic PE information: Section: .text IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                      Source: unknownProcess created: C:\Users\user\Desktop\Quotation for Enq # 90038355.exe 'C:\Users\user\Desktop\Quotation for Enq # 90038355.exe'
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{172BDDF8-CEEA-11D1-8B05-00600806D9B6}\InProcServer32Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeFile created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Quotation for Enq # 90038355.exe.logJump to behavior
                      Source: classification engineClassification label: mal100.spre.troj.spyw.evad.winEXE@3/2@2/1
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\a152fe02a317a77aeee36903305e8ba6\mscorlib.ni.dllJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeMutant created: \Sessions\1\BaseNamedObjects\NFGbaNkhdbYRiBBEDhHWGl
                      Source: Quotation for Enq # 90038355.exe, Forms/mainForm.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
                      Source: 0.0.Quotation for Enq # 90038355.exe.e60000.0.unpack, Forms/mainForm.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
                      Source: 0.2.Quotation for Enq # 90038355.exe.e60000.0.unpack, Forms/mainForm.csCryptographic APIs: 'TransformFinalBlock', 'CreateDecryptor'
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Office\15.0\Outlook\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
                      Source: Quotation for Enq # 90038355.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
                      Source: Quotation for Enq # 90038355.exeStatic PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
                      Source: Quotation for Enq # 90038355.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG

                      Data Obfuscation:

                      barindex
                      .NET source code contains potential unpackerShow sources
                      Source: Quotation for Enq # 90038355.exe, Forms/mainForm.cs.Net Code: _X_X0FT_FT2 System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
                      Source: 0.0.Quotation for Enq # 90038355.exe.e60000.0.unpack, Forms/mainForm.cs.Net Code: _X_X0FT_FT2 System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
                      Source: 0.2.Quotation for Enq # 90038355.exe.e60000.0.unpack, Forms/mainForm.cs.Net Code: _X_X0FT_FT2 System.Reflection.Assembly System.Reflection.Assembly::Load(System.Byte[])
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeCode function: 0_2_0159B5D1 pushad ; retf 0_2_0159B5ED
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeCode function: 0_2_0159F933 push esp; iretd 0_2_0159F939
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeCode function: 0_2_0514289F push edx; retf 0_2_051428A0
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeCode function: 0_2_05142898 push edx; retf 0_2_05142899
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 2_2_05E20BCE push ss; iretd 2_2_05E20BD6
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 2_2_066D3C2B push 0000001Ah; iretd 2_2_066D3C2D
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 2_2_066D3DB5 push es; ret 2_2_066D3E10
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 2_2_066D9A5F push ss; iretd 2_2_066D9A65
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 2_2_066D5BE8 push ss; iretd 2_2_066D5BEF
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeCode function: 2_2_066D41E1 push es; ret 2_2_066D41F4
                      Source: Quotation for Enq # 90038355.exeStatic PE information: 0xC4BE8666 [Mon Aug 6 22:36:22 2074 UTC]
                      Source: initial sampleStatic PE information: section name: .text entropy: 7.22138751359

                      Hooking and other Techniques for Hiding and Protection:

                      barindex
                      Icon mismatch, binary includes an icon from a different legit application in order to fool usersShow sources
                      Source: initial sampleIcon embedded in binary file: icon matches a legit application icon: icon2083.png
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeRegistry key monitored for changes: HKEY_CURRENT_USER_ClassesJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

                      Malware Analysis System Evasion:

                      barindex
                      Yara detected AntiVM3Show sources
                      Source: Yara matchFile source: 00000000.00000002.669711456.0000000003141000.00000004.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: Quotation for Enq # 90038355.exe PID: 5192, type: MEMORYSTR
                      Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)Show sources
                      Source: Quotation for Enq # 90038355.exe, 00000000.00000002.669711456.0000000003141000.00000004.00000001.sdmpBinary or memory string: WINE_GET_UNIX_FILE_NAME
                      Source: Quotation for Enq # 90038355.exe, 00000000.00000002.669711456.0000000003141000.00000004.00000001.sdmpBinary or memory string: SBIEDLL.DLL
                      Queries sensitive network adapter information (via WMI, Win32_NetworkAdapter, often done to detect virtual machines)Show sources
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_NetworkAdapterConfiguration
                      Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)Show sources
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_BaseBoard
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exe TID: 5416Thread sleep time: -39332s >= -30000sJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exe TID: 3112Thread sleep time: -922337203685477s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 6092Thread sleep time: -14757395258967632s >= -30000sJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 5688Thread sleep count: 9535 > 30Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe TID: 5688Thread sleep count: 315 > 30Jump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeThread delayed: delay time: 922337203685477Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 922337203685477Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWindow / User API: threadDelayed 9535Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\cimv2 : Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess information queried: ProcessInformationJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeThread delayed: delay time: 39332Jump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeThread delayed: delay time: 922337203685477Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeThread delayed: delay time: 922337203685477Jump to behavior
                      Source: Quotation for Enq # 90038355.exe, 00000000.00000002.669711456.0000000003141000.00000004.00000001.sdmpBinary or memory string: vmware
                      Source: Quotation for Enq # 90038355.exe, 00000000.00000002.669711456.0000000003141000.00000004.00000001.sdmpBinary or memory string: C:\PROGRAM FILES\VMWARE\VMWARE TOOLS\
                      Source: Quotation for Enq # 90038355.exe, 00000000.00000002.669711456.0000000003141000.00000004.00000001.sdmpBinary or memory string: SOFTWARE\VMware, Inc.\VMware Tools
                      Source: Quotation for Enq # 90038355.exe, 00000000.00000002.669711456.0000000003141000.00000004.00000001.sdmpBinary or memory string: VMWARE
                      Source: Quotation for Enq # 90038355.exe, 00000000.00000002.669711456.0000000003141000.00000004.00000001.sdmpBinary or memory string: InstallPath%C:\PROGRAM FILES\VMWARE\VMWARE TOOLS\
                      Source: Quotation for Enq # 90038355.exe, 00000000.00000002.669711456.0000000003141000.00000004.00000001.sdmpBinary or memory string: VMWARE"SOFTWARE\VMware, Inc.\VMware ToolsLHARDWARE\DEVICEMAP\Scsi\Scsi Port 1\Scsi Bus 0\Target Id 0\Logical Unit Id 0LHARDWARE\DEVICEMAP\Scsi\Scsi Port 2\Scsi Bus 0\Target Id 0\Logical Unit Id 0'SYSTEM\ControlSet001\Services\Disk\Enum
                      Source: Quotation for Enq # 90038355.exe, 00000000.00000002.669711456.0000000003141000.00000004.00000001.sdmpBinary or memory string: VMware SVGA II
                      Source: Quotation for Enq # 90038355.exe, 00000000.00000002.669711456.0000000003141000.00000004.00000001.sdmpBinary or memory string: vmwareNSYSTEM\ControlSet001\Control\Class\{4D36E968-E325-11CE-BFC1-08002BE10318}\0000
                      Source: MSBuild.exe, 00000002.00000002.935518873.000000000647B000.00000004.00000001.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess token adjusted: DebugJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeProcess token adjusted: DebugJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeMemory allocated: page read and write | page guardJump to behavior

                      HIPS / PFW / Operating System Protection Evasion:

                      barindex
                      Writes to foreign memory regionsShow sources
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 400000Jump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 402000Jump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 438000Jump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 43A000Jump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 10F6008Jump to behavior
                      Allocates memory in foreign processesShow sources
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeMemory allocated: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 400000 protect: page execute and read and writeJump to behavior
                      Injects a PE file into a foreign processesShow sources
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe base: 400000 value starts with: 4D5AJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeJump to behavior
                      Source: MSBuild.exe, 00000002.00000002.932796844.0000000001D40000.00000002.00020000.sdmpBinary or memory string: Program Manager
                      Source: MSBuild.exe, 00000002.00000002.932796844.0000000001D40000.00000002.00020000.sdmpBinary or memory string: Shell_TrayWnd
                      Source: MSBuild.exe, 00000002.00000002.932796844.0000000001D40000.00000002.00020000.sdmpBinary or memory string: Progman
                      Source: MSBuild.exe, 00000002.00000002.932796844.0000000001D40000.00000002.00020000.sdmpBinary or memory string: Progmanlock
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeQueries volume information: C:\Users\user\Desktop\Quotation for Enq # 90038355.exe VolumeInformationJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe VolumeInformationJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformationJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformationJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\CustomMarshalers\v4.0_4.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll VolumeInformationJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformationJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
                      Source: C:\Users\user\Desktop\Quotation for Enq # 90038355.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

                      Stealing of Sensitive Information:

                      barindex
                      Yara detected AgentTeslaShow sources
                      Source: Yara matchFile source: 0.2.Quotation for Enq # 90038355.exe.420acc8.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 2.2.MSBuild.exe.400000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.Quotation for Enq # 90038355.exe.420acc8.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000002.00000002.931030895.0000000000402000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.670463877.00000000043B4000.00000004.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.670112007.0000000004149000.00000004.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000002.00000002.933029235.0000000003351000.00000004.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: Quotation for Enq # 90038355.exe PID: 5192, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: MSBuild.exe PID: 1848, type: MEMORYSTR
                      Tries to harvest and steal Putty / WinSCP information (sessions, passwords, etc)Show sources
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Martin Prikryl\WinSCP 2\SessionsJump to behavior
                      Tries to harvest and steal ftp login credentialsShow sources
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\FileZilla\recentservers.xmlJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\SmartFTP\Client 2.0\Favorites\Quick Connect\Jump to behavior
                      Tries to steal Mail credentials (via file access)Show sources
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.iniJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\Thunderbird\profiles.iniJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeKey opened: HKEY_CURRENT_USER\Software\IncrediMail\IdentitiesJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeKey opened: HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\9375CFF0413111d3B88A00104B2A6676Jump to behavior
                      Tries to harvest and steal browser information (history, passwords, etc)Show sources
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\CookiesJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exeFile opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.iniJump to behavior
                      Source: Yara matchFile source: 00000002.00000002.933029235.0000000003351000.00000004.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: MSBuild.exe PID: 1848, type: MEMORYSTR

                      Remote Access Functionality:

                      barindex
                      Yara detected AgentTeslaShow sources
                      Source: Yara matchFile source: 0.2.Quotation for Enq # 90038355.exe.420acc8.1.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 2.2.MSBuild.exe.400000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.Quotation for Enq # 90038355.exe.420acc8.1.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000002.00000002.931030895.0000000000402000.00000040.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.670463877.00000000043B4000.00000004.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.670112007.0000000004149000.00000004.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000002.00000002.933029235.0000000003351000.00000004.00000001.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: Quotation for Enq # 90038355.exe PID: 5192, type: MEMORYSTR
                      Source: Yara matchFile source: Process Memory Space: MSBuild.exe PID: 1848, type: MEMORYSTR

                      Mitre Att&ck Matrix

                      Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
                      Valid AccountsWindows Management Instrumentation211Path InterceptionProcess Injection312Disable or Modify Tools1OS Credential Dumping2System Information Discovery114Remote ServicesArchive Collected Data11Exfiltration Over Other Network MediumEncrypted Channel12Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
                      Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsDeobfuscate/Decode Files or Information1Input Capture111Query Registry1Remote Desktop ProtocolData from Local System2Exfiltration Over BluetoothNon-Application Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
                      Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or Information2Credentials in Registry1Security Software Discovery211SMB/Windows Admin SharesEmail Collection1Automated ExfiltrationApplication Layer Protocol2Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
                      Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Software Packing13NTDSProcess Discovery2Distributed Component Object ModelInput Capture111Scheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
                      Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptTimestomp1LSA SecretsVirtualization/Sandbox Evasion131SSHClipboard Data1Data Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
                      Replication Through Removable MediaLaunchdRc.commonRc.commonMasquerading11Cached Domain CredentialsApplication Window Discovery1VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
                      External Remote ServicesScheduled TaskStartup ItemsStartup ItemsVirtualization/Sandbox Evasion131DCSyncRemote System Discovery1Windows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
                      Drive-by CompromiseCommand and Scripting InterpreterScheduled Task/JobScheduled Task/JobProcess Injection312Proc FilesystemNetwork Service ScanningShared WebrootCredential API HookingExfiltration Over Symmetric Encrypted Non-C2 ProtocolApplication Layer ProtocolDowngrade to Insecure ProtocolsGenerate Fraudulent Advertising Revenue

                      Behavior Graph

                      Screenshots

                      Thumbnails

                      This section contains all screenshots as thumbnails, including those not shown in the slideshow.

                      windows-stand

                      Antivirus, Machine Learning and Genetic Malware Detection

                      Initial Sample

                      SourceDetectionScannerLabelLink
                      Quotation for Enq # 90038355.exe33%VirustotalBrowse
                      Quotation for Enq # 90038355.exe27%ReversingLabsByteCode-MSIL.Trojan.AgentTesla
                      Quotation for Enq # 90038355.exe100%Joe Sandbox ML

                      Dropped Files

                      No Antivirus matches

                      Unpacked PE Files

                      SourceDetectionScannerLabelLinkDownload
                      2.2.MSBuild.exe.400000.0.unpack100%AviraTR/Spy.Gen8Download File

                      Domains

                      SourceDetectionScannerLabelLink
                      mail.phoenixfinance.com.bd0%VirustotalBrowse

                      URLs

                      SourceDetectionScannerLabelLink
                      http://127.0.0.1:HTTP/1.10%Avira URL Cloudsafe
                      http://DynDns.comDynDNS0%URL Reputationsafe
                      http://cps.root-x1.letsenc0%Avira URL Cloudsafe
                      http://cps.letsencrypt.org00%URL Reputationsafe
                      https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%ha0%URL Reputationsafe
                      http://x1.c.lencr.org/00%URL Reputationsafe
                      http://x1.i.lencr.org/00%URL Reputationsafe
                      http://mail.phoenixfinance.com.bd0%VirustotalBrowse
                      http://mail.phoenixfinance.com.bd0%Avira URL Cloudsafe
                      https://YWRIJujMGl.org0%Avira URL Cloudsafe
                      http://r3.i.lencr.org/0v0%Avira URL Cloudsafe
                      http://r3.o.lencr.org00%URL Reputationsafe
                      http://bJvmVK.com0%Avira URL Cloudsafe
                      https://api.ipify.org%GETMozilla/5.00%URL Reputationsafe
                      https://api.ipify.org%0%URL Reputationsafe
                      https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip0%URL Reputationsafe
                      https://YWRIJujMGl.orgD0=0%Avira URL Cloudsafe
                      http://cps.root-x1.letsencrypt.org00%URL Reputationsafe

                      Domains and IPs

                      Contacted Domains

                      NameIPActiveMaliciousAntivirus DetectionReputation
                      mail.phoenixfinance.com.bd
                      192.185.108.208
                      truetrueunknown

                      URLs from Memory and Binaries

                      NameSourceMaliciousAntivirus DetectionReputation
                      http://127.0.0.1:HTTP/1.1MSBuild.exe, 00000002.00000002.933029235.0000000003351000.00000004.00000001.sdmpfalse
                      • Avira URL Cloud: safe
                      low
                      http://DynDns.comDynDNSMSBuild.exe, 00000002.00000002.933029235.0000000003351000.00000004.00000001.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://cps.root-x1.letsencMSBuild.exe, 00000002.00000002.935578751.000000000648B000.00000004.00000001.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://cps.letsencrypt.org0MSBuild.exe, 00000002.00000002.935633413.00000000064A0000.00000004.00000001.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%haMSBuild.exe, 00000002.00000002.933029235.0000000003351000.00000004.00000001.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://x1.c.lencr.org/0MSBuild.exe, 00000002.00000002.935633413.00000000064A0000.00000004.00000001.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://x1.i.lencr.org/0MSBuild.exe, 00000002.00000002.935633413.00000000064A0000.00000004.00000001.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://mail.phoenixfinance.com.bdMSBuild.exe, 00000002.00000002.934081784.0000000003706000.00000004.00000001.sdmpfalse
                      • 0%, Virustotal, Browse
                      • Avira URL Cloud: safe
                      unknown
                      https://YWRIJujMGl.orgMSBuild.exe, 00000002.00000002.933029235.0000000003351000.00000004.00000001.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://r3.i.lencr.org/0vMSBuild.exe, 00000002.00000002.935633413.00000000064A0000.00000004.00000001.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      http://r3.o.lencr.org0MSBuild.exe, 00000002.00000002.935633413.00000000064A0000.00000004.00000001.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      http://bJvmVK.comMSBuild.exe, 00000002.00000002.933029235.0000000003351000.00000004.00000001.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://api.ipify.org%GETMozilla/5.0MSBuild.exe, 00000002.00000002.933029235.0000000003351000.00000004.00000001.sdmpfalse
                      • URL Reputation: safe
                      low
                      https://api.ipify.org%MSBuild.exe, 00000002.00000002.933029235.0000000003351000.00000004.00000001.sdmpfalse
                      • URL Reputation: safe
                      low
                      https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zipQuotation for Enq # 90038355.exe, 00000000.00000002.670463877.00000000043B4000.00000004.00000001.sdmp, MSBuild.exe, 00000002.00000002.931030895.0000000000402000.00000040.00000001.sdmpfalse
                      • URL Reputation: safe
                      unknown
                      https://YWRIJujMGl.orgD0=MSBuild.exe, 00000002.00000002.933029235.0000000003351000.00000004.00000001.sdmpfalse
                      • Avira URL Cloud: safe
                      low
                      http://cps.root-x1.letsencrypt.org0MSBuild.exe, 00000002.00000002.935633413.00000000064A0000.00000004.00000001.sdmpfalse
                      • URL Reputation: safe
                      unknown

                      Contacted IPs

                      • No. of IPs < 25%
                      • 25% < No. of IPs < 50%
                      • 50% < No. of IPs < 75%
                      • 75% < No. of IPs

                      Public

                      IPDomainCountryFlagASNASN NameMalicious
                      192.185.108.208
                      mail.phoenixfinance.com.bdUnited States
                      46606UNIFIEDLAYER-AS-1UStrue

                      General Information

                      Joe Sandbox Version:33.0.0 White Diamond
                      Analysis ID:483892
                      Start date:15.09.2021
                      Start time:15:48:07
                      Joe Sandbox Product:CloudBasic
                      Overall analysis duration:0h 7m 51s
                      Hypervisor based Inspection enabled:false
                      Report type:full
                      Sample file name:Quotation for Enq # 90038355.exe
                      Cookbook file name:default.jbs
                      Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                      Number of analysed new started processes analysed:13
                      Number of new started drivers analysed:0
                      Number of existing processes analysed:0
                      Number of existing drivers analysed:0
                      Number of injected processes analysed:0
                      Technologies:
                      • HCA enabled
                      • EGA enabled
                      • HDC enabled
                      • AMSI enabled
                      Analysis Mode:default
                      Analysis stop reason:Timeout
                      Detection:MAL
                      Classification:mal100.spre.troj.spyw.evad.winEXE@3/2@2/1
                      EGA Information:Failed
                      HDC Information:Failed
                      HCA Information:
                      • Successful, ratio: 100%
                      • Number of executed functions: 46
                      • Number of non-executed functions: 9
                      Cookbook Comments:
                      • Adjust boot time
                      • Enable AMSI
                      • Found application associated with file extension: .exe
                      Warnings:
                      Show All
                      • Exclude process from analysis (whitelisted): BackgroundTransferHost.exe, backgroundTaskHost.exe, svchost.exe, wuapihost.exe
                      • Excluded IPs from analysis (whitelisted): 20.82.209.183, 20.54.110.249, 40.112.88.60, 8.248.133.254, 67.26.137.254, 8.253.95.249, 67.26.73.254, 8.248.145.254, 23.216.77.208, 23.216.77.209, 20.82.210.154
                      • Excluded domains from analysis (whitelisted): iris-de-prod-azsc-neu.northeurope.cloudapp.azure.com, fg.download.windowsupdate.com.c.footprint.net, displaycatalog-rp-europe.md.mp.microsoft.com.akadns.net, neu-displaycatalogrp.frontdoor.bigcatalog.commerce.microsoft.com, ris-prod.trafficmanager.net, wu-shim.trafficmanager.net, asf-ris-prod-neu.northeurope.cloudapp.azure.com, ctldl.windowsupdate.com, iris-de-prod-azsc-neu-b.northeurope.cloudapp.azure.com, a1449.dscg2.akamai.net, arc.msn.com, ris.api.iris.microsoft.com, consumer-displaycatalogrp-aks2aks-europe.md.mp.microsoft.com.akadns.net, arc.trafficmanager.net, displaycatalog.mp.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, displaycatalog-rp.md.mp.microsoft.com.akadns.net
                      • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                      • Report size getting too big, too many NtOpenKeyEx calls found.
                      • Report size getting too big, too many NtProtectVirtualMemory calls found.
                      • Report size getting too big, too many NtQueryValueKey calls found.

                      Simulations

                      Behavior and APIs

                      TimeTypeDescription
                      15:49:05API Interceptor1x Sleep call for process: Quotation for Enq # 90038355.exe modified
                      15:49:19API Interceptor815x Sleep call for process: MSBuild.exe modified

                      Joe Sandbox View / Context

                      IPs

                      MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                      192.185.108.208Required Items.exeGet hashmaliciousBrowse

                        Domains

                        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                        mail.phoenixfinance.com.bdRequired Items.exeGet hashmaliciousBrowse
                        • 192.185.108.208

                        ASN

                        MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                        UNIFIEDLAYER-AS-1USHolidays_2018.docGet hashmaliciousBrowse
                        • 192.185.73.57
                        Remittance_Advice_details001009142021.xlsxGet hashmaliciousBrowse
                        • 50.87.248.20
                        Unpaid invoice.exeGet hashmaliciousBrowse
                        • 50.87.144.47
                        SOA for V.R at USD.exeGet hashmaliciousBrowse
                        • 192.185.90.36
                        re2.arm7Get hashmaliciousBrowse
                        • 69.195.102.115
                        PO. 2100002_pdf____________________________________.exeGet hashmaliciousBrowse
                        • 108.167.140.157
                        6522TrkXwt.exeGet hashmaliciousBrowse
                        • 67.20.76.71
                        SecuriteInfo.com.Variant.Barys.5541.5151.exeGet hashmaliciousBrowse
                        • 192.185.171.219
                        EM2scqNkrv.exeGet hashmaliciousBrowse
                        • 192.185.84.191
                        opZ766Gf7j.exeGet hashmaliciousBrowse
                        • 192.185.171.144
                        diagram-129.docGet hashmaliciousBrowse
                        • 192.185.17.114
                        diagram-129.docGet hashmaliciousBrowse
                        • 192.185.17.114
                        diagram-129.docGet hashmaliciousBrowse
                        • 192.185.17.114
                        vREfw6lnNC.exeGet hashmaliciousBrowse
                        • 192.185.84.191
                        vbc.exeGet hashmaliciousBrowse
                        • 50.87.144.47
                        diagram-477.docGet hashmaliciousBrowse
                        • 192.185.17.114
                        diagram-477.docGet hashmaliciousBrowse
                        • 192.185.17.114
                        diagram-477.docGet hashmaliciousBrowse
                        • 192.185.17.114
                        8765998RQF.docGet hashmaliciousBrowse
                        • 192.185.171.144
                        Quotation Required PO3652.docGet hashmaliciousBrowse
                        • 192.185.84.191

                        JA3 Fingerprints

                        No context

                        Dropped Files

                        No context

                        Created / dropped Files

                        C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Quotation for Enq # 90038355.exe.log
                        Process:C:\Users\user\Desktop\Quotation for Enq # 90038355.exe
                        File Type:ASCII text, with CRLF line terminators
                        Category:dropped
                        Size (bytes):1216
                        Entropy (8bit):5.355304211458859
                        Encrypted:false
                        SSDEEP:24:MLUE4K5E4Ks2E1qE4qXKDE4KhK3VZ9pKhPKIE4oKFKHKoZAE4Kzr7FE4x84j:MIHK5HKXE1qHiYHKhQnoPtHoxHhAHKzr
                        MD5:FED34146BF2F2FA59DCF8702FCC8232E
                        SHA1:B03BFEA175989D989850CF06FE5E7BBF56EAA00A
                        SHA-256:123BE4E3590609A008E85501243AF5BC53FA0C26C82A92881B8879524F8C0D5C
                        SHA-512:1CC89F2ED1DBD70628FA1DC41A32BA0BFA3E81EAE1A1CF3C5F6A48F2DA0BF1F21A5001B8A18B04043C5B8FE4FBE663068D86AA8C4BD8E17933F75687C3178FF6
                        Malicious:true
                        Reputation:high, very likely benign file
                        Preview: 1,"fusion","GAC",0..1,"WinRT","NotApp",1..2,"System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089",0..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\4f0a7eefa3cd3e0ba98b5ebddbbc72e6\System.ni.dll",0..2,"System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\f1d8480152e0da9a60ad49c6d16a3b6d\System.Core.ni.dll",0..3,"System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\8d67d92724ba494b6c7fd089d6f25b48\System.Configuration.ni.dll",0..3,"System.Xml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\b219d4630d26b88041b59c21
                        C:\Users\user\AppData\Roaming\0vddojdc.nzw\Chrome\Default\Cookies
                        Process:C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                        File Type:SQLite 3.x database, last written using SQLite version 3032001
                        Category:dropped
                        Size (bytes):20480
                        Entropy (8bit):0.7006690334145785
                        Encrypted:false
                        SSDEEP:24:TLbJLbXaFpEO5bNmISHn06UwcQPx5fBoe9H6pf1H1oNQ:T5LLOpEO5J/Kn7U1uBobfvoNQ
                        MD5:A7FE10DA330AD03BF22DC9AC76BBB3E4
                        SHA1:1805CB7A2208BAEFF71DCB3FE32DB0CC935CF803
                        SHA-256:8D6B84A96429B5C672838BF431A47EC59655E561EBFBB4E63B46351D10A7AAD8
                        SHA-512:1DBE27AED6E1E98E9F82AC1F5B774ACB6F3A773BEB17B66C2FB7B89D12AC87A6D5B716EF844678A5417F30EE8855224A8686A135876AB4C0561B3C6059E635C7
                        Malicious:false
                        Reputation:high, very likely benign file
                        Preview: SQLite format 3......@ ..........................................................................C....... ..g... .8....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................

                        Static File Info

                        General

                        File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                        Entropy (8bit):7.232670452918804
                        TrID:
                        • Win32 Executable (generic) Net Framework (10011505/4) 49.83%
                        • Win32 Executable (generic) a (10002005/4) 49.78%
                        • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
                        • Generic Win/DOS Executable (2004/3) 0.01%
                        • DOS Executable Generic (2002/1) 0.01%
                        File name:Quotation for Enq # 90038355.exe
                        File size:638976
                        MD5:344ba2ed272ba7e67556b82f312ea816
                        SHA1:e1d5527552a9879bfded79c3c76a673913e15ada
                        SHA256:9b4cb73e87053b62028a877f31ffba62960560bf707fa0458b3acc0899e942dd
                        SHA512:d28d70b52a61a6b7ef821a6569675aff50f367122d892630b1d0c46df74263c8614f894a5671425fcbc4abfe4057cb6bb492ba44a80f26845300a02f1509ab3c
                        SSDEEP:12288:B7u7777K7qWHCM2K4CsQQpOEpAKKeOwDS31yPdzusCDk9dWI2Pv1f3eQU7:B7u7777K7G3CsYEpDKeus6esPdeZ
                        File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...f.................0.............z.... ........@.. ....................... ............@................................

                        File Icon

                        Icon Hash:e4e2aa8aa4b4bcb4

                        Static PE Info

                        General

                        Entrypoint:0x48d47a
                        Entrypoint Section:.text
                        Digitally signed:false
                        Imagebase:0x400000
                        Subsystem:windows gui
                        Image File Characteristics:32BIT_MACHINE, EXECUTABLE_IMAGE
                        DLL Characteristics:NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
                        Time Stamp:0xC4BE8666 [Mon Aug 6 22:36:22 2074 UTC]
                        TLS Callbacks:
                        CLR (.Net) Version:v4.0.30319
                        OS Version Major:4
                        OS Version Minor:0
                        File Version Major:4
                        File Version Minor:0
                        Subsystem Version Major:4
                        Subsystem Version Minor:0
                        Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744

                        Entrypoint Preview

                        Instruction
                        jmp dword ptr [00402000h]
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al
                        add byte ptr [eax], al

                        Data Directories

                        NameVirtual AddressVirtual Size Is in Section
                        IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                        IMAGE_DIRECTORY_ENTRY_IMPORT0x8d4280x4f.text
                        IMAGE_DIRECTORY_ENTRY_RESOURCE0x8e0000x105a4.rsrc
                        IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                        IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                        IMAGE_DIRECTORY_ENTRY_BASERELOC0xa00000xc.reloc
                        IMAGE_DIRECTORY_ENTRY_DEBUG0x8d40c0x1c.text
                        IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                        IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                        IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                        IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                        IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                        IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
                        IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                        IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
                        IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0

                        Sections

                        NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                        .text0x20000x8b4800x8b600False0.767732272982data7.22138751359IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ
                        .rsrc0x8e0000x105a40x10600False0.795160424618data7.29487316941IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                        .reloc0xa00000xc0x200False0.044921875data0.101910425663IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ

                        Resources

                        NameRVASizeTypeLanguageCountry
                        RT_ICON0x8e2b00x2e8dBase IV DBT of @.DBF, block length 512, next free block index 40, next free block 4294967295, next used block 8912767
                        RT_ICON0x8e5980x128GLS_BINARY_LSB_FIRST
                        RT_ICON0x8e6c00xea8data
                        RT_ICON0x8f5680x8a8dBase IV DBT of @.DBF, block length 1024, next free block index 40, next free block 0, next used block 0
                        RT_ICON0x8fe100x568GLS_BINARY_LSB_FIRST
                        RT_ICON0x903780xa1bePNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
                        RT_ICON0x9a5380x25a8data
                        RT_ICON0x9cae00x10a8data
                        RT_ICON0x9db880x468GLS_BINARY_LSB_FIRST
                        RT_GROUP_ICON0x9dff00x84data
                        RT_VERSION0x9e0740x344data
                        RT_MANIFEST0x9e3b80x1eaXML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

                        Imports

                        DLLImport
                        mscoree.dll_CorExeMain

                        Version Infos

                        DescriptionData
                        Translation0x0000 0x04b0
                        LegalCopyrightCopyright 2019
                        Assembly Version1.0.0.0
                        InternalNameEVENTFILTERDESCRIPT.exe
                        FileVersion1.0.0.0
                        CompanyName
                        LegalTrademarks
                        Comments
                        ProductNameDisciples
                        ProductVersion1.0.0.0
                        FileDescriptionDisciples
                        OriginalFilenameEVENTFILTERDESCRIPT.exe

                        Network Behavior

                        Network Port Distribution

                        TCP Packets

                        TimestampSource PortDest PortSource IPDest IP
                        Sep 15, 2021 15:48:57.287492990 CEST49725443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:57.287550926 CEST4434972592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:57.287982941 CEST49725443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:57.288674116 CEST49723443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:57.288913012 CEST4434972392.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:57.288965940 CEST49725443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:57.288990974 CEST4434972592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:57.289015055 CEST49723443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:57.321923971 CEST4434972492.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:57.321974039 CEST4434972492.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:57.322097063 CEST49724443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:57.322129011 CEST4434972492.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:57.322150946 CEST49724443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:57.322192907 CEST49724443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:57.354331970 CEST4434972592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:57.354444027 CEST49725443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:57.354917049 CEST49725443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:57.354931116 CEST4434972592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:57.356491089 CEST49725443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:57.356503963 CEST4434972592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:57.420245886 CEST4434972592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:57.420299053 CEST4434972592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:57.420475960 CEST49725443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:57.420552015 CEST4434972592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:57.420738935 CEST49725443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:57.520199060 CEST4434972492.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:57.520916939 CEST49724443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:57.526238918 CEST49725443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:57.526475906 CEST4434972592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:57.526613951 CEST49725443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:57.533370972 CEST49724443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:57.533411980 CEST4434972492.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:57.896029949 CEST49726443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:57.896070004 CEST4434972692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:57.896205902 CEST49726443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:57.899234056 CEST49726443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:57.899344921 CEST4434972692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:57.977660894 CEST4434972692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:57.977799892 CEST49726443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:57.978212118 CEST49726443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:57.978230000 CEST4434972692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:57.979213953 CEST49726443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:57.979234934 CEST4434972692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.055659056 CEST4434972692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.055731058 CEST4434972692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.055816889 CEST49726443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.055845976 CEST4434972692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.055879116 CEST49726443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.055896997 CEST49726443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.059037924 CEST49726443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.059308052 CEST4434972692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.059401035 CEST49726443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.061192036 CEST49727443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.061252117 CEST4434972792.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.061355114 CEST49727443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.061563969 CEST49727443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.061578989 CEST4434972792.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.118693113 CEST49728443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.118752956 CEST4434972892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.118912935 CEST49728443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.119136095 CEST49728443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.119148970 CEST4434972892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.126696110 CEST4434972792.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.126818895 CEST49727443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.127615929 CEST49727443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.127629995 CEST4434972792.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.133393049 CEST49727443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.133554935 CEST4434972792.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.178601980 CEST49729443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.178646088 CEST4434972992.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.179754972 CEST49729443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.179828882 CEST49729443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.179838896 CEST4434972992.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.196059942 CEST4434972792.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.196096897 CEST4434972792.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.196167946 CEST49727443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.196216106 CEST4434972792.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.196243048 CEST49727443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.196269035 CEST49727443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.199928045 CEST49727443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.200052977 CEST4434972792.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.200134039 CEST49727443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.204236984 CEST4434972892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.204338074 CEST49728443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.204526901 CEST49730443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.204576015 CEST4434973092.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.204668999 CEST49730443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.205002069 CEST49728443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.205022097 CEST4434972892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.205507040 CEST49730443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.205543041 CEST4434973092.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.205895901 CEST49728443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.205914021 CEST4434972892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.218622923 CEST49731443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.218678951 CEST4434973192.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.218777895 CEST49731443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.218964100 CEST49731443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.218974113 CEST4434973192.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.259402990 CEST4434972992.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.259536982 CEST49729443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.259872913 CEST49729443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.259882927 CEST4434972992.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.260848045 CEST49729443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.260914087 CEST4434972992.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.269032955 CEST49732443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.269087076 CEST4434973292.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.269177914 CEST49732443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.269368887 CEST49732443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.269393921 CEST4434973292.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.282159090 CEST4434972892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.282186985 CEST4434972892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.282284975 CEST49728443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.282314062 CEST4434972892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.282330036 CEST49728443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.282392025 CEST49728443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.283920050 CEST4434973092.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.284044981 CEST49730443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.284892082 CEST49730443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.284912109 CEST4434973092.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.286195993 CEST49730443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.286209106 CEST4434973092.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.288053989 CEST49728443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.288302898 CEST4434972892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.289519072 CEST49728443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.298247099 CEST4434973192.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.298455000 CEST49731443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.298724890 CEST49731443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.298732996 CEST4434973192.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.299581051 CEST49731443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.299607038 CEST4434973192.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.329107046 CEST4434973292.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.329210043 CEST49732443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.332184076 CEST49732443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.332201958 CEST4434973292.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.333009005 CEST49732443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.333041906 CEST4434973292.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.336774111 CEST4434972992.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.336833000 CEST4434972992.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.336956024 CEST49729443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.336966991 CEST4434972992.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.336993933 CEST49729443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.337035894 CEST49729443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.339658022 CEST49729443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.339819908 CEST4434972992.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.339903116 CEST49729443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.346908092 CEST49733443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.346949100 CEST4434973392.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.347060919 CEST49733443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.347275019 CEST49733443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.347289085 CEST4434973392.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.374855042 CEST4434973192.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.374923944 CEST4434973192.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.375086069 CEST49731443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.375123024 CEST4434973192.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.375138044 CEST49731443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.375194073 CEST49731443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.376130104 CEST4434973092.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.376164913 CEST4434973092.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.376204967 CEST4434973092.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.376256943 CEST49730443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.376276016 CEST49730443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.376286983 CEST4434973092.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.376317978 CEST49730443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.376363039 CEST49730443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.380676031 CEST49731443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.380841970 CEST4434973192.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.380939007 CEST49731443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.393062115 CEST4434973292.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.393141985 CEST4434973292.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.393213987 CEST49732443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.393237114 CEST4434973292.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.393268108 CEST49732443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.393280983 CEST49732443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.395701885 CEST49732443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.395857096 CEST4434973292.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.395950079 CEST49732443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.415222883 CEST4434973092.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.415457010 CEST49730443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.415473938 CEST4434973092.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.415508986 CEST49730443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.415569067 CEST49730443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.419743061 CEST4434973392.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.419905901 CEST49733443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.420269012 CEST49733443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.420296907 CEST4434973392.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.421355963 CEST49733443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.421379089 CEST4434973392.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.434084892 CEST49734443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.434156895 CEST4434973492.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.434272051 CEST49734443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.434516907 CEST49734443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.434556007 CEST4434973492.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.492961884 CEST4434973392.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.492993116 CEST4434973392.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.493170977 CEST49733443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.493190050 CEST4434973392.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.493335962 CEST49733443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.506918907 CEST4434973492.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.507041931 CEST49734443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.517180920 CEST49733443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.517369986 CEST4434973392.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.517458916 CEST49733443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.517827034 CEST49734443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.517847061 CEST4434973492.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.519567966 CEST49734443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.519581079 CEST4434973492.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.577066898 CEST4434973492.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.577119112 CEST4434973492.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.577285051 CEST49734443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.577327013 CEST4434973492.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.577383995 CEST49734443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.577394009 CEST49734443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.581337929 CEST49734443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.581489086 CEST4434973492.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.581640959 CEST49734443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.721321106 CEST49735443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.721369028 CEST4434973592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.721472979 CEST49735443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.721712112 CEST49735443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.721724033 CEST4434973592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.752473116 CEST49736443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.752511024 CEST4434973692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.752626896 CEST49736443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.752928972 CEST49736443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.752953053 CEST4434973692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.785650969 CEST49737443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.785703897 CEST4434973792.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.785797119 CEST49737443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.786071062 CEST49737443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.786091089 CEST4434973792.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.788009882 CEST4434973592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.788247108 CEST49735443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.789118052 CEST49735443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.789128065 CEST4434973592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.790122986 CEST49735443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.790134907 CEST4434973592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.803603888 CEST49738443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.803648949 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.803736925 CEST49738443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.803945065 CEST49738443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.803956032 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.816245079 CEST49739443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.816309929 CEST4434973992.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.816397905 CEST49739443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.819233894 CEST49739443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.819263935 CEST4434973992.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.821497917 CEST4434973692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.821616888 CEST49736443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.821942091 CEST49736443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.821955919 CEST4434973692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.822881937 CEST49736443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.822897911 CEST4434973692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.827794075 CEST49740443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.827840090 CEST4434974092.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.827960014 CEST49740443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.828128099 CEST49740443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.828161955 CEST4434974092.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.853418112 CEST4434973592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.853467941 CEST4434973592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.853512049 CEST4434973592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.853648901 CEST49735443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.853667021 CEST4434973592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.853760004 CEST49735443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.866437912 CEST4434973792.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.866688967 CEST49737443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.867343903 CEST49737443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.867358923 CEST4434973792.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.868813992 CEST49737443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.868829012 CEST4434973792.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.870296001 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.870438099 CEST49738443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.870997906 CEST49738443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.871033907 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.872169971 CEST49738443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.872189045 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.879909039 CEST4434973992.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.880161047 CEST49739443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.881002903 CEST49739443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.881015062 CEST4434973992.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.882333994 CEST49739443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.882349968 CEST4434973992.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.884990931 CEST4434973592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.885122061 CEST49735443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.885144949 CEST4434973592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.885221958 CEST49735443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.887820005 CEST4434974092.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.887940884 CEST4434973592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.887995005 CEST49740443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.888070107 CEST49735443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.888086081 CEST4434973592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.888163090 CEST49735443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.888284922 CEST49735443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.888303995 CEST49735443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.888799906 CEST49740443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.888820887 CEST4434974092.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.890660048 CEST4434973692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.890702009 CEST4434973692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.890743017 CEST4434973692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.890839100 CEST49736443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.890862942 CEST4434973692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.890928984 CEST49736443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.891177893 CEST49740443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.891196966 CEST4434974092.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.891325951 CEST49736443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.896102905 CEST49736443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.896251917 CEST4434973692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.896349907 CEST49736443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.935280085 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.935309887 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.935359001 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.935516119 CEST49738443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.935547113 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.935597897 CEST49738443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.935699940 CEST49738443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.937844992 CEST4434973992.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.937947035 CEST4434973992.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.938056946 CEST49739443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.938081980 CEST4434973992.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.938193083 CEST49739443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.943613052 CEST4434973792.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.943639994 CEST4434973792.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.943684101 CEST4434973792.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.943782091 CEST49737443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.943799973 CEST4434973792.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.943865061 CEST49737443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.944740057 CEST4434974092.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.944777012 CEST4434974092.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.944957018 CEST49740443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.944979906 CEST4434974092.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.945085049 CEST49740443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.971615076 CEST49740443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.971775055 CEST4434974092.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.971849918 CEST49740443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.972872972 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.972904921 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.973138094 CEST49738443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.973157883 CEST49738443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.973175049 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.973244905 CEST49738443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.974280119 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.974402905 CEST49738443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.978792906 CEST49739443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.978918076 CEST4434973992.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.979000092 CEST49739443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.982394934 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.982419968 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.982543945 CEST49738443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.982573986 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.982642889 CEST49738443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.994424105 CEST49737443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:58.994560957 CEST4434973792.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:58.994645119 CEST49737443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.000493050 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.000566006 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.000709057 CEST49738443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.000726938 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.000740051 CEST49738443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.000780106 CEST49738443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.008040905 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.008074999 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.008193016 CEST49738443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.008205891 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.008265018 CEST49738443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.013523102 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.013587952 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.013648033 CEST49738443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.013660908 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.013698101 CEST49738443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.013706923 CEST49738443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.014559984 CEST49738443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.015897036 CEST4434973892.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.015997887 CEST49738443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.272841930 CEST49741443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.272890091 CEST4434974192.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.273013115 CEST49741443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.275150061 CEST49741443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.275170088 CEST4434974192.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.302844048 CEST49742443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.302913904 CEST4434974292.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.303180933 CEST49742443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.303272963 CEST49742443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.303286076 CEST4434974292.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.324963093 CEST49743443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.325012922 CEST4434974392.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.325108051 CEST49743443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.327056885 CEST49743443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.327080965 CEST4434974392.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.342138052 CEST49744443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.342180967 CEST4434974492.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.342303991 CEST49744443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.342612028 CEST49744443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.342631102 CEST4434974492.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.346662045 CEST4434974192.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.346846104 CEST49741443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.347892046 CEST49741443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.347914934 CEST4434974192.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.349539995 CEST49741443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.349555969 CEST4434974192.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.355272055 CEST49745443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.355320930 CEST4434974592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.355499029 CEST49745443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.355614901 CEST49745443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.355631113 CEST4434974592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.361942053 CEST4434974292.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.362447023 CEST49742443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.362464905 CEST49742443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.362474918 CEST4434974292.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.363322020 CEST49742443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.363344908 CEST4434974292.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.365839005 CEST49746443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.365891933 CEST4434974692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.365976095 CEST49746443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.366152048 CEST49746443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.366162062 CEST4434974692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.405596972 CEST4434974392.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.405980110 CEST49743443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.406673908 CEST49743443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.406693935 CEST4434974392.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.409326077 CEST49743443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.409348011 CEST4434974392.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.413904905 CEST4434974492.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.414026022 CEST49744443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.414832115 CEST49744443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.414855003 CEST4434974492.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.416896105 CEST49744443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.416922092 CEST4434974492.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.418719053 CEST4434974292.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.418950081 CEST49742443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.419029951 CEST4434974292.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.419148922 CEST49742443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.419161081 CEST4434974292.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.419246912 CEST49742443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.421880960 CEST4434974192.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.421910048 CEST4434974192.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.421932936 CEST4434974192.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.422060966 CEST49741443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.422074080 CEST4434974192.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.422177076 CEST49741443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.422816992 CEST4434974192.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.423018932 CEST49741443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.423038960 CEST4434974192.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.423154116 CEST49741443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.426661015 CEST49742443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.426842928 CEST4434974292.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.426937103 CEST49742443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.429532051 CEST49741443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.429687023 CEST4434974192.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.430054903 CEST49741443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.433979988 CEST4434974592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.434066057 CEST49745443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.434537888 CEST49745443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.434552908 CEST4434974592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.436110973 CEST49745443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.436125994 CEST4434974592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.439410925 CEST4434974692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.439479113 CEST49746443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.442996979 CEST49746443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.443013906 CEST4434974692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.445291042 CEST49746443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.445312977 CEST4434974692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.448620081 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:48:59.448765039 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:48:59.448812962 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:48:59.448839903 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:48:59.448867083 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:48:59.448894024 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:48:59.448901892 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:48:59.448985100 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:48:59.449004889 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:48:59.449018955 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:48:59.449042082 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:48:59.449054956 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:48:59.479080915 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:48:59.479253054 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:48:59.479271889 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:48:59.479410887 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:48:59.479451895 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:48:59.479563951 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:48:59.479711056 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:48:59.479744911 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:48:59.479796886 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:48:59.479829073 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:48:59.479855061 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:48:59.479895115 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:48:59.484282970 CEST4434974492.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.484306097 CEST4434974492.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.484369993 CEST4434974492.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.484430075 CEST49744443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.484446049 CEST4434974492.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.484476089 CEST49744443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.484487057 CEST49744443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.488714933 CEST4434974392.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.488749027 CEST4434974392.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.488810062 CEST49743443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.488822937 CEST4434974392.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.488857985 CEST49743443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.488893986 CEST49743443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.505619049 CEST49743443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.505805969 CEST4434974392.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.505852938 CEST49744443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.505932093 CEST4434974492.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.505903959 CEST49743443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.505983114 CEST49744443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.509809017 CEST4434974692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.509891033 CEST4434974692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.510018110 CEST49746443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.510039091 CEST4434974692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.510052919 CEST49746443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.510066032 CEST4434974692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.510113955 CEST49746443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.510130882 CEST4434974692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.510150909 CEST49746443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.510179043 CEST49746443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.510185957 CEST4434974692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.510245085 CEST49746443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.510263920 CEST4434974692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.510317087 CEST49746443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.510812998 CEST4434974592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.510839939 CEST4434974592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.510890961 CEST49745443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.510901928 CEST4434974592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.510910988 CEST49745443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.510948896 CEST49745443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.512470007 CEST49746443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.512578011 CEST4434974692.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.512829065 CEST49746443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.513143063 CEST49745443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.513257980 CEST4434974592.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.513329029 CEST49745443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.562899113 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:48:59.563086987 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:48:59.852160931 CEST49747443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.852214098 CEST4434974792.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.852442026 CEST49747443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.866152048 CEST49747443192.168.2.492.122.145.220
                        Sep 15, 2021 15:48:59.866182089 CEST4434974792.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.924319029 CEST4434974792.122.145.220192.168.2.4
                        Sep 15, 2021 15:48:59.925240993 CEST49747443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.031735897 CEST49747443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.031760931 CEST4434974792.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.113363981 CEST49748443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.113480091 CEST4434974892.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.114572048 CEST49748443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.114639997 CEST49748443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.114650011 CEST49750443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.114660978 CEST4434974892.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.114720106 CEST4434975092.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.114830017 CEST49747443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.114856005 CEST4434974792.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.114882946 CEST49749443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.114919901 CEST4434974992.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.114940882 CEST49750443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.114983082 CEST49749443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.115093946 CEST49750443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.115133047 CEST4434975092.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.115559101 CEST49749443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.115606070 CEST4434974992.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.117543936 CEST49751443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.117592096 CEST4434975192.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.117707968 CEST49751443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.117842913 CEST49751443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.117858887 CEST4434975192.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.132936001 CEST49752443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.132985115 CEST4434975292.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.133070946 CEST49752443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.133465052 CEST49752443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.133480072 CEST4434975292.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.150278091 CEST4434974792.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.150311947 CEST4434974792.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.150329113 CEST4434974792.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.150413036 CEST49747443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.150429964 CEST4434974792.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.150454998 CEST49747443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.150460005 CEST4434974792.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.150543928 CEST49747443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.150552034 CEST49747443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.150553942 CEST49747443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.150558949 CEST4434974792.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.150635958 CEST49747443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.155057907 CEST49747443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.155203104 CEST4434974792.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.155368090 CEST49747443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.177625895 CEST4434974992.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.177779913 CEST49749443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.178342104 CEST4434975092.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.178406000 CEST49750443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.178901911 CEST49749443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.178915024 CEST4434974992.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.186201096 CEST4434975192.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.186305046 CEST49751443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.197530985 CEST4434974892.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.198103905 CEST49748443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.198379040 CEST4434975292.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.198533058 CEST49752443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.212408066 CEST49752443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.212423086 CEST4434975292.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.213506937 CEST49749443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.213519096 CEST4434974992.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.216342926 CEST49752443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.216366053 CEST4434975292.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.221684933 CEST49751443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.221710920 CEST4434975192.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.222239971 CEST49748443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.222259045 CEST4434974892.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.223439932 CEST49750443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.223459005 CEST4434975092.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.224803925 CEST49748443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.224817038 CEST4434974892.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.228018999 CEST49751443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.228040934 CEST4434975192.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.228224039 CEST49750443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.228249073 CEST4434975092.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.244194984 CEST4434974992.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.244220972 CEST4434974992.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.244247913 CEST4434974992.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.244318008 CEST49749443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.244330883 CEST4434974992.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.244338989 CEST49749443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.244535923 CEST49749443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.261768103 CEST49749443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.261898041 CEST4434974992.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.262042999 CEST49749443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.263174057 CEST4434975092.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.263206005 CEST4434975092.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.263516903 CEST49750443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.263550997 CEST4434975192.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.263569117 CEST4434975092.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.263583899 CEST4434975192.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.263585091 CEST49750443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.263621092 CEST4434975192.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.263693094 CEST4434975292.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.263694048 CEST49750443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.263715982 CEST4434975292.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.263767958 CEST4434975292.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.263890028 CEST49752443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.263912916 CEST4434975292.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.263935089 CEST49751443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.263945103 CEST49752443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.263952017 CEST4434975192.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.263952017 CEST49751443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.263962984 CEST49752443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.264009953 CEST49751443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.275650978 CEST4434974892.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.275681019 CEST4434974892.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.275753975 CEST4434974892.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.275774956 CEST49748443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.275790930 CEST4434974892.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.275836945 CEST49748443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.275871992 CEST49748443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.289885044 CEST49750443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.290004015 CEST4434975092.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.290406942 CEST49750443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.292416096 CEST49752443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.292536020 CEST4434975292.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.292599916 CEST49752443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.296355963 CEST4434975192.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.296439886 CEST49751443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.296461105 CEST4434975192.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.296508074 CEST49751443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.302134991 CEST4434975192.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.302177906 CEST4434975192.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.302222013 CEST49751443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.302239895 CEST4434975192.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.302253008 CEST49751443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.302289009 CEST49751443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.303308010 CEST49751443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.303461075 CEST4434975192.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.303515911 CEST49751443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.314692020 CEST4434974892.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.314866066 CEST49748443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.314891100 CEST4434974892.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.314971924 CEST49748443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.324244976 CEST4434974892.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.324296951 CEST4434974892.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.324385881 CEST49748443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.324404001 CEST4434974892.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.324415922 CEST49748443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.324462891 CEST49748443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.326317072 CEST49748443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.327980995 CEST4434974892.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.329474926 CEST49748443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.662734985 CEST49753443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.662777901 CEST4434975392.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.663003922 CEST49753443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.663160086 CEST49753443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.663182020 CEST4434975392.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.675409079 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.675451994 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.675556898 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.675762892 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.675777912 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.692440033 CEST49755443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.692545891 CEST4434975592.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.692637920 CEST49755443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.692872047 CEST49755443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.692883015 CEST4434975592.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.708041906 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.708084106 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.708168983 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.708472967 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.708483934 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.718686104 CEST49757443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.718766928 CEST4434975792.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.718902111 CEST49757443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.719192982 CEST49757443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.719244003 CEST4434975792.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.728080034 CEST4434975392.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.728461981 CEST49753443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.728804111 CEST49753443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.728816032 CEST4434975392.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.730319023 CEST49753443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.730349064 CEST4434975392.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.734930038 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.735044003 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.735683918 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.735693932 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.736780882 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.736792088 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.757831097 CEST4434975592.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.757925034 CEST49755443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.758780956 CEST49755443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.758791924 CEST4434975592.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.760910988 CEST49755443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.760925055 CEST4434975592.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.768332005 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.768465996 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.769323111 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.769335985 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.771492958 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.771512032 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.786619902 CEST4434975792.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.787420034 CEST49757443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.787606001 CEST49757443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.787657022 CEST4434975792.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.789760113 CEST49757443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.789782047 CEST4434975792.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.793370962 CEST4434975392.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.793405056 CEST4434975392.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.793436050 CEST4434975392.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.794426918 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.794459105 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.794467926 CEST49753443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.794485092 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.794491053 CEST4434975392.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.794656992 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.794677973 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.794828892 CEST49753443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.794828892 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.822052956 CEST4434975592.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.822091103 CEST4434975592.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.822115898 CEST4434975592.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.822173119 CEST49755443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.822334051 CEST49755443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.822357893 CEST4434975592.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.822451115 CEST49755443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.828227043 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.828253031 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.828319073 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.828329086 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.828366041 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.828373909 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.828455925 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.830600977 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.830631018 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.830766916 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.830782890 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.830882072 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.831768990 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.831865072 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.833322048 CEST4434975392.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.833354950 CEST4434975392.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.833450079 CEST49753443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.833463907 CEST4434975392.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.833642006 CEST49753443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.834580898 CEST4434975392.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.834897995 CEST49753443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.838957071 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.838996887 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.839070082 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.839090109 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.839133024 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.839157104 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.843031883 CEST4434975392.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.843070030 CEST4434975392.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.843504906 CEST49753443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.843524933 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.843528986 CEST4434975392.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.843590021 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.843631029 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.843647003 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.843672991 CEST49753443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.843672991 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.843699932 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.858761072 CEST4434975592.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.858936071 CEST49755443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.858958960 CEST4434975592.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.859502077 CEST49755443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.859946012 CEST4434975392.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.860013962 CEST4434975392.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.860066891 CEST49753443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.860089064 CEST4434975392.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.860101938 CEST49753443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.860286951 CEST4434975792.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.860316992 CEST4434975792.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.860338926 CEST4434975792.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.860358953 CEST49757443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.860373974 CEST4434975792.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.860389948 CEST49757443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.860403061 CEST49757443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.860438108 CEST49753443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.860443115 CEST49757443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.860827923 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.860914946 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.860954046 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.861042023 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.861536980 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.861572027 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.861639977 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.861659050 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.861687899 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.861717939 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.862024069 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.862070084 CEST4434975592.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.862088919 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.862107038 CEST4434975592.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.862138987 CEST49755443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.862158060 CEST49755443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.862164974 CEST4434975592.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.862260103 CEST49755443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.862265110 CEST49755443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.864739895 CEST4434975592.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.864895105 CEST49755443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.864911079 CEST4434975592.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.864964962 CEST49755443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.867748976 CEST49755443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.868170977 CEST4434975592.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.868273973 CEST49755443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.869771957 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.869775057 CEST4434975392.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.869805098 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.869808912 CEST4434975392.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.869812012 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.869836092 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.869896889 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.869921923 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.869944096 CEST49753443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.870031118 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.870043993 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.870053053 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.870057106 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.870064974 CEST49753443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.870074987 CEST4434975392.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.870120049 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.871649027 CEST49753443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.872646093 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.872700930 CEST49753443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.872750044 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.872824907 CEST4434975392.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.873049021 CEST49753443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.874510050 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.874618053 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.874640942 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.874701977 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.879468918 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.879509926 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.879600048 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.879627943 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.879683018 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.882611990 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.882728100 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.888135910 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.888221025 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.888348103 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.888371944 CEST4434975492.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.888381004 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.891141891 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.891159058 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.891462088 CEST49754443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.892985106 CEST4434975792.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.893049002 CEST4434975792.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.893106937 CEST49757443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.893132925 CEST4434975792.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.893145084 CEST49757443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.895548105 CEST49757443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.895680904 CEST49757443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.895705938 CEST49757443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.896863937 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.896892071 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.896962881 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.896979094 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.897002935 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.897022009 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.902721882 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.902749062 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.902929068 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.902947903 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.902961016 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.904757977 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.906049967 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.906227112 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.913873911 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.913918018 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.914009094 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.914030075 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.914074898 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.914108038 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.915010929 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.915132046 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.917201042 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.917293072 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.917315960 CEST4434975692.122.145.220192.168.2.4
                        Sep 15, 2021 15:49:00.917356014 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:00.917386055 CEST49756443192.168.2.492.122.145.220
                        Sep 15, 2021 15:49:09.791944027 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:09.792154074 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:09.792359114 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:09.792452097 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:09.792534113 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:09.792789936 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:09.792999029 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:09.793078899 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:09.793159008 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:09.816999912 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817023039 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817038059 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817054987 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817065954 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817076921 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817164898 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817182064 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817333937 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817352057 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817363024 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817378998 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817389965 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817405939 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817423105 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817460060 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817475080 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817485094 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817498922 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817516088 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817528963 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817539930 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817548990 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817559958 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817569971 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817579985 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817589045 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817600012 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817616940 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817630053 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817643881 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817661047 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817720890 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817737103 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817753077 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817766905 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817780972 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817800999 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817816973 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817832947 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817847013 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817862034 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817878962 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817893028 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817908049 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817929029 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817944050 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817960024 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.817974091 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.818078041 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.818095922 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.818156004 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.818171024 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.818227053 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.818244934 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.818262100 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.818448067 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.818702936 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.818892002 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.818923950 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.818938017 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.819125891 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:09.907079935 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:09.907354116 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:14.950917959 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:14.951143980 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:14.951195002 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:14.951225996 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:14.951252937 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:14.951286077 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:14.951298952 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:14.951314926 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:14.951318026 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:14.952917099 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:14.953186035 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:14.953211069 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:14.976075888 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976104021 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976116896 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976131916 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976146936 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976161003 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976174116 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976187944 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976202011 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976337910 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976353884 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976368904 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976382971 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976423025 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976443052 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976457119 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976490021 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976510048 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976524115 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976537943 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976686001 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976701975 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976728916 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976785898 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976803064 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976810932 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976833105 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976982117 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.976999998 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.977009058 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.977026939 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.977039099 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.977052927 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.977062941 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.977077961 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.977087021 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.977101088 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.977176905 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:14.977224112 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.977418900 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.977508068 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:14.977771044 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:14.978189945 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:15.020163059 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:15.020381927 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:15.042711020 CEST44349695131.253.33.200192.168.2.4
                        Sep 15, 2021 15:49:15.042908907 CEST49695443192.168.2.4131.253.33.200
                        Sep 15, 2021 15:49:49.333854914 CEST4968680192.168.2.423.55.161.169
                        Sep 15, 2021 15:49:49.352406025 CEST804968623.55.161.169192.168.2.4
                        Sep 15, 2021 15:49:49.352675915 CEST4968680192.168.2.423.55.161.169
                        Sep 15, 2021 15:49:49.952965975 CEST804968493.184.220.29192.168.2.4
                        Sep 15, 2021 15:49:49.953123093 CEST4968480192.168.2.493.184.220.29
                        Sep 15, 2021 15:49:51.164277077 CEST49705443192.168.2.423.35.237.194
                        Sep 15, 2021 15:49:51.164573908 CEST4970680192.168.2.493.184.220.29
                        Sep 15, 2021 15:49:51.624032974 CEST804970193.184.220.29192.168.2.4
                        Sep 15, 2021 15:49:51.624125004 CEST4970180192.168.2.493.184.220.29
                        Sep 15, 2021 15:50:31.276164055 CEST44350119172.67.38.66192.168.2.4
                        Sep 15, 2021 15:50:31.276195049 CEST44350119172.67.38.66192.168.2.4
                        Sep 15, 2021 15:50:31.276207924 CEST44350119172.67.38.66192.168.2.4
                        Sep 15, 2021 15:50:31.276403904 CEST50119443192.168.2.4172.67.38.66
                        Sep 15, 2021 15:50:31.276439905 CEST50119443192.168.2.4172.67.38.66
                        Sep 15, 2021 15:50:31.276443005 CEST50119443192.168.2.4172.67.38.66
                        Sep 15, 2021 15:50:31.354096889 CEST44350120104.22.25.131192.168.2.4
                        Sep 15, 2021 15:50:31.354123116 CEST44350120104.22.25.131192.168.2.4
                        Sep 15, 2021 15:50:31.354150057 CEST44350120104.22.25.131192.168.2.4
                        Sep 15, 2021 15:50:31.354286909 CEST50120443192.168.2.4104.22.25.131
                        Sep 15, 2021 15:50:31.354316950 CEST50120443192.168.2.4104.22.25.131
                        Sep 15, 2021 15:50:31.354322910 CEST50120443192.168.2.4104.22.25.131
                        Sep 15, 2021 15:50:38.853665113 CEST49688443192.168.2.420.190.160.132
                        Sep 15, 2021 15:50:38.853737116 CEST49681443192.168.2.420.190.160.132
                        Sep 15, 2021 15:50:38.869203091 CEST4968480192.168.2.493.184.220.29
                        Sep 15, 2021 15:50:38.869245052 CEST4968380192.168.2.423.55.161.167
                        Sep 15, 2021 15:50:38.880218983 CEST4434968820.190.160.132192.168.2.4
                        Sep 15, 2021 15:50:38.880256891 CEST4434968120.190.160.132192.168.2.4
                        Sep 15, 2021 15:50:38.880351067 CEST49688443192.168.2.420.190.160.132
                        Sep 15, 2021 15:50:38.880383968 CEST49681443192.168.2.420.190.160.132
                        Sep 15, 2021 15:50:38.886014938 CEST804968493.184.220.29192.168.2.4
                        Sep 15, 2021 15:50:38.886112928 CEST4968480192.168.2.493.184.220.29
                        Sep 15, 2021 15:50:38.887828112 CEST804968323.55.161.167192.168.2.4
                        Sep 15, 2021 15:50:38.887923956 CEST4968380192.168.2.423.55.161.167
                        Sep 15, 2021 15:50:41.918363094 CEST49708443192.168.2.420.190.160.8
                        Sep 15, 2021 15:50:41.918415070 CEST49713443192.168.2.420.190.160.8
                        Sep 15, 2021 15:50:41.918433905 CEST49711443192.168.2.420.190.160.8
                        Sep 15, 2021 15:50:41.943706036 CEST4434971320.190.160.8192.168.2.4
                        Sep 15, 2021 15:50:41.943727970 CEST4434971120.190.160.8192.168.2.4
                        Sep 15, 2021 15:50:41.943742037 CEST4434970820.190.160.8192.168.2.4
                        Sep 15, 2021 15:50:41.943798065 CEST49713443192.168.2.420.190.160.8
                        Sep 15, 2021 15:50:41.943821907 CEST49711443192.168.2.420.190.160.8
                        Sep 15, 2021 15:50:41.943849087 CEST49708443192.168.2.420.190.160.8
                        Sep 15, 2021 15:50:51.719696999 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:51.855798006 CEST44349692131.253.33.200192.168.2.4
                        Sep 15, 2021 15:50:51.865890980 CEST58749832192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:51.866039038 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:52.065447092 CEST58749832192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:52.089365959 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:52.235933065 CEST58749832192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:52.236485004 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:52.385957003 CEST58749832192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:52.432398081 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:52.493547916 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:52.637162924 CEST4434970213.107.42.16192.168.2.4
                        Sep 15, 2021 15:50:52.649302959 CEST58749832192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:52.649333000 CEST58749832192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:52.649353981 CEST58749832192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:52.649369955 CEST58749832192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:52.649604082 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:52.649641991 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:52.651067972 CEST58749832192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:52.664349079 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:52.812242985 CEST58749832192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:52.854121923 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:53.326853037 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:53.473231077 CEST58749832192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:53.474586010 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:53.543992996 CEST804970193.184.220.29192.168.2.4
                        Sep 15, 2021 15:50:53.544154882 CEST4970180192.168.2.493.184.220.29
                        Sep 15, 2021 15:50:53.621131897 CEST58749832192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:53.622065067 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:53.770723104 CEST58749832192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:53.773041010 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:53.877031088 CEST44349696131.253.33.200192.168.2.4
                        Sep 15, 2021 15:50:53.919239998 CEST58749832192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:53.925508976 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:54.073389053 CEST58749832192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:54.073940992 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:54.220046043 CEST58749832192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:54.222383976 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:54.222565889 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:54.223540068 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:54.223689079 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:54.223787069 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:54.223867893 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:54.223944902 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:54.369213104 CEST58749832192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:54.369239092 CEST58749832192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:54.369426012 CEST58749832192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:54.369854927 CEST58749832192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:54.369901896 CEST58749832192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:54.370098114 CEST58749832192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:54.370114088 CEST58749832192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:54.370471001 CEST58749832192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:54.410264015 CEST44349694131.253.33.200192.168.2.4
                        Sep 15, 2021 15:50:54.416760921 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:54.804305077 CEST44349707204.79.197.222192.168.2.4
                        Sep 15, 2021 15:50:54.947556019 CEST44349698131.253.33.200192.168.2.4
                        Sep 15, 2021 15:50:55.408463955 CEST4434971813.107.3.254192.168.2.4
                        Sep 15, 2021 15:50:55.762470961 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:55.911722898 CEST58749832192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:55.912015915 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:56.037334919 CEST4434970313.107.5.88192.168.2.4
                        Sep 15, 2021 15:50:56.061767101 CEST49832587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:56.062545061 CEST44349699131.253.33.200192.168.2.4
                        Sep 15, 2021 15:50:56.235284090 CEST44349690131.253.33.200192.168.2.4
                        Sep 15, 2021 15:50:56.533281088 CEST4434970413.107.5.88192.168.2.4
                        Sep 15, 2021 15:50:56.577440023 CEST49833587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:56.724070072 CEST58749833192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:56.724253893 CEST49833587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:56.875197887 CEST58749833192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:56.875521898 CEST49833587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:57.022568941 CEST58749833192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:57.023036003 CEST49833587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:57.174768925 CEST58749833192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:57.175456047 CEST49833587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:57.338808060 CEST58749833192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:57.338862896 CEST58749833192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:57.338901043 CEST58749833192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:57.338928938 CEST58749833192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:57.338963032 CEST49833587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:57.338992119 CEST49833587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:57.341516972 CEST58749833192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:57.345752001 CEST49833587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:57.423259974 CEST44349693131.253.33.200192.168.2.4
                        Sep 15, 2021 15:50:57.493226051 CEST58749833192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:57.496113062 CEST49833587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:57.643407106 CEST58749833192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:57.644011974 CEST49833587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:57.791415930 CEST58749833192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:57.792634010 CEST49833587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:57.940751076 CEST58749833192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:57.941282034 CEST49833587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:58.087886095 CEST58749833192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:58.090287924 CEST49833587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:58.092180014 CEST44349697131.253.33.200192.168.2.4
                        Sep 15, 2021 15:50:58.239321947 CEST58749833192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:58.240066051 CEST49833587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:58.386744022 CEST58749833192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:58.387375116 CEST49833587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:58.387520075 CEST49833587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:58.387718916 CEST49833587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:58.387799978 CEST49833587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:58.388020039 CEST49833587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:58.388216972 CEST49833587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:58.388261080 CEST49833587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:58.388346910 CEST49833587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:50:58.534204960 CEST58749833192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:58.534270048 CEST58749833192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:58.534310102 CEST58749833192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:58.534516096 CEST58749833192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:58.534670115 CEST58749833192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:58.534708977 CEST58749833192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:58.534745932 CEST58749833192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:58.535315037 CEST58749833192.185.108.208192.168.2.4
                        Sep 15, 2021 15:50:58.589040041 CEST49833587192.168.2.4192.185.108.208
                        Sep 15, 2021 15:51:01.623631001 CEST4434971713.107.253.254192.168.2.4
                        Sep 15, 2021 15:51:06.955280066 CEST804970193.184.220.29192.168.2.4
                        Sep 15, 2021 15:51:06.955476999 CEST4970180192.168.2.493.184.220.29

                        UDP Packets

                        TimestampSource PortDest PortSource IPDest IP
                        Sep 15, 2021 15:49:27.664176941 CEST6238953192.168.2.48.8.8.8
                        Sep 15, 2021 15:49:27.707792997 CEST53623898.8.8.8192.168.2.4
                        Sep 15, 2021 15:49:46.827135086 CEST4991053192.168.2.48.8.8.8
                        Sep 15, 2021 15:49:46.861912012 CEST53499108.8.8.8192.168.2.4
                        Sep 15, 2021 15:49:47.550666094 CEST5585453192.168.2.48.8.8.8
                        Sep 15, 2021 15:49:47.577120066 CEST53558548.8.8.8192.168.2.4
                        Sep 15, 2021 15:49:48.271703005 CEST6454953192.168.2.48.8.8.8
                        Sep 15, 2021 15:49:48.285703897 CEST6315353192.168.2.48.8.8.8
                        Sep 15, 2021 15:49:48.300607920 CEST53645498.8.8.8192.168.2.4
                        Sep 15, 2021 15:49:48.343003035 CEST53631538.8.8.8192.168.2.4
                        Sep 15, 2021 15:49:48.741718054 CEST5299153192.168.2.48.8.8.8
                        Sep 15, 2021 15:49:48.775227070 CEST53529918.8.8.8192.168.2.4
                        Sep 15, 2021 15:49:49.535907030 CEST5370053192.168.2.48.8.8.8
                        Sep 15, 2021 15:49:49.561094999 CEST53537008.8.8.8192.168.2.4
                        Sep 15, 2021 15:49:49.564037085 CEST5172653192.168.2.48.8.8.8
                        Sep 15, 2021 15:49:49.593941927 CEST53517268.8.8.8192.168.2.4
                        Sep 15, 2021 15:49:51.593064070 CEST5679453192.168.2.48.8.8.8
                        Sep 15, 2021 15:49:51.621278048 CEST53567948.8.8.8192.168.2.4
                        Sep 15, 2021 15:49:52.150434971 CEST5653453192.168.2.48.8.8.8
                        Sep 15, 2021 15:49:52.183383942 CEST53565348.8.8.8192.168.2.4
                        Sep 15, 2021 15:49:52.955502033 CEST5662753192.168.2.48.8.8.8
                        Sep 15, 2021 15:49:52.997867107 CEST53566278.8.8.8192.168.2.4
                        Sep 15, 2021 15:49:53.758229971 CEST5662153192.168.2.48.8.8.8
                        Sep 15, 2021 15:49:53.818658113 CEST53566218.8.8.8192.168.2.4
                        Sep 15, 2021 15:49:54.224062920 CEST6311653192.168.2.48.8.8.8
                        Sep 15, 2021 15:49:54.250859976 CEST53631168.8.8.8192.168.2.4
                        Sep 15, 2021 15:50:05.937798023 CEST6407853192.168.2.48.8.8.8
                        Sep 15, 2021 15:50:05.968036890 CEST53640788.8.8.8192.168.2.4
                        Sep 15, 2021 15:50:36.153079033 CEST6480153192.168.2.48.8.8.8
                        Sep 15, 2021 15:50:36.179893017 CEST53648018.8.8.8192.168.2.4
                        Sep 15, 2021 15:50:38.222614050 CEST6172153192.168.2.48.8.8.8
                        Sep 15, 2021 15:50:38.255414009 CEST53617218.8.8.8192.168.2.4
                        Sep 15, 2021 15:50:51.529833078 CEST5125553192.168.2.48.8.8.8
                        Sep 15, 2021 15:50:51.575917006 CEST53512558.8.8.8192.168.2.4
                        Sep 15, 2021 15:50:56.501589060 CEST6152253192.168.2.48.8.8.8
                        Sep 15, 2021 15:50:56.575808048 CEST53615228.8.8.8192.168.2.4

                        DNS Queries

                        TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                        Sep 15, 2021 15:50:51.529833078 CEST192.168.2.48.8.8.80x30cfStandard query (0)mail.phoenixfinance.com.bdA (IP address)IN (0x0001)
                        Sep 15, 2021 15:50:56.501589060 CEST192.168.2.48.8.8.80x6619Standard query (0)mail.phoenixfinance.com.bdA (IP address)IN (0x0001)

                        DNS Answers

                        TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                        Sep 15, 2021 15:50:51.575917006 CEST8.8.8.8192.168.2.40x30cfNo error (0)mail.phoenixfinance.com.bd192.185.108.208A (IP address)IN (0x0001)
                        Sep 15, 2021 15:50:56.575808048 CEST8.8.8.8192.168.2.40x6619No error (0)mail.phoenixfinance.com.bd192.185.108.208A (IP address)IN (0x0001)

                        SMTP Packets

                        TimestampSource PortDest PortSource IPDest IPCommands
                        Sep 15, 2021 15:50:52.065447092 CEST58749832192.185.108.208192.168.2.4220-ascender.websitewelcome.com ESMTP Exim 4.94.2 #2 Wed, 15 Sep 2021 08:50:51 -0500
                        220-We do not authorize the use of this system to transport unsolicited,
                        220 and/or bulk e-mail.
                        Sep 15, 2021 15:50:52.089365959 CEST49832587192.168.2.4192.185.108.208EHLO 019635
                        Sep 15, 2021 15:50:52.235933065 CEST58749832192.185.108.208192.168.2.4250-ascender.websitewelcome.com Hello 019635 [84.17.52.51]
                        250-SIZE 52428800
                        250-8BITMIME
                        250-PIPELINING
                        250-PIPE_CONNECT
                        250-AUTH PLAIN LOGIN
                        250-STARTTLS
                        250 HELP
                        Sep 15, 2021 15:50:52.236485004 CEST49832587192.168.2.4192.185.108.208STARTTLS
                        Sep 15, 2021 15:50:52.385957003 CEST58749832192.185.108.208192.168.2.4220 TLS go ahead
                        Sep 15, 2021 15:50:56.875197887 CEST58749833192.185.108.208192.168.2.4220-ascender.websitewelcome.com ESMTP Exim 4.94.2 #2 Wed, 15 Sep 2021 08:50:56 -0500
                        220-We do not authorize the use of this system to transport unsolicited,
                        220 and/or bulk e-mail.
                        Sep 15, 2021 15:50:56.875521898 CEST49833587192.168.2.4192.185.108.208EHLO 019635
                        Sep 15, 2021 15:50:57.022568941 CEST58749833192.185.108.208192.168.2.4250-ascender.websitewelcome.com Hello 019635 [84.17.52.51]
                        250-SIZE 52428800
                        250-8BITMIME
                        250-PIPELINING
                        250-PIPE_CONNECT
                        250-AUTH PLAIN LOGIN
                        250-STARTTLS
                        250 HELP
                        Sep 15, 2021 15:50:57.023036003 CEST49833587192.168.2.4192.185.108.208STARTTLS
                        Sep 15, 2021 15:50:57.174768925 CEST58749833192.185.108.208192.168.2.4220 TLS go ahead

                        Code Manipulations

                        Statistics

                        CPU Usage

                        Click to jump to process

                        Memory Usage

                        Click to jump to process

                        High Level Behavior Distribution

                        Click to dive into process behavior distribution

                        Behavior

                        Click to jump to process

                        System Behavior

                        General

                        Start time:15:49:03
                        Start date:15/09/2021
                        Path:C:\Users\user\Desktop\Quotation for Enq # 90038355.exe
                        Wow64 process (32bit):true
                        Commandline:'C:\Users\user\Desktop\Quotation for Enq # 90038355.exe'
                        Imagebase:0xe60000
                        File size:638976 bytes
                        MD5 hash:344BA2ED272BA7E67556B82F312EA816
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:.Net C# or VB.NET
                        Yara matches:
                        • Rule: JoeSecurity_AntiVM_3, Description: Yara detected AntiVM_3, Source: 00000000.00000002.669711456.0000000003141000.00000004.00000001.sdmp, Author: Joe Security
                        • Rule: JoeSecurity_AgentTesla_1, Description: Yara detected AgentTesla, Source: 00000000.00000002.670463877.00000000043B4000.00000004.00000001.sdmp, Author: Joe Security
                        • Rule: JoeSecurity_AgentTesla_2, Description: Yara detected AgentTesla, Source: 00000000.00000002.670463877.00000000043B4000.00000004.00000001.sdmp, Author: Joe Security
                        • Rule: JoeSecurity_AgentTesla_1, Description: Yara detected AgentTesla, Source: 00000000.00000002.670112007.0000000004149000.00000004.00000001.sdmp, Author: Joe Security
                        • Rule: JoeSecurity_AgentTesla_2, Description: Yara detected AgentTesla, Source: 00000000.00000002.670112007.0000000004149000.00000004.00000001.sdmp, Author: Joe Security
                        Reputation:low

                        General

                        Start time:15:49:06
                        Start date:15/09/2021
                        Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                        Wow64 process (32bit):true
                        Commandline:C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
                        Imagebase:0xe40000
                        File size:261728 bytes
                        MD5 hash:D621FD77BD585874F9686D3A76462EF1
                        Has elevated privileges:true
                        Has administrator privileges:true
                        Programmed in:.Net C# or VB.NET
                        Yara matches:
                        • Rule: JoeSecurity_AgentTesla_1, Description: Yara detected AgentTesla, Source: 00000002.00000002.931030895.0000000000402000.00000040.00000001.sdmp, Author: Joe Security
                        • Rule: JoeSecurity_AgentTesla_2, Description: Yara detected AgentTesla, Source: 00000002.00000002.931030895.0000000000402000.00000040.00000001.sdmp, Author: Joe Security
                        • Rule: JoeSecurity_AgentTesla_1, Description: Yara detected AgentTesla, Source: 00000002.00000002.933029235.0000000003351000.00000004.00000001.sdmp, Author: Joe Security
                        • Rule: JoeSecurity_CredentialStealer, Description: Yara detected Credential Stealer, Source: 00000002.00000002.933029235.0000000003351000.00000004.00000001.sdmp, Author: Joe Security
                        Reputation:high

                        Disassembly

                        Code Analysis

                        Reset < >

                          Executed Functions

                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID:
                          • String ID: mT$mT
                          • API String ID: 0-1076960343
                          • Opcode ID: b5001037668e406cf5598a0345305ccc414d8e75d25619be9f7bcf51ffb4087b
                          • Instruction ID: 1f28f80c0646bcbc4a226746d16ca8ae5f2bfdd4f38cc2fd6cc6126d0fceea71
                          • Opcode Fuzzy Hash: b5001037668e406cf5598a0345305ccc414d8e75d25619be9f7bcf51ffb4087b
                          • Instruction Fuzzy Hash: 5A315C78E152199BDF08CFA5D9455DDFBF2FF8D200F14A42AE416B7258DB3498818F24
                          Uniqueness

                          Uniqueness Score: -1.00%

                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID:
                          • String ID: mT$mT
                          • API String ID: 0-1076960343
                          • Opcode ID: f74fd00ec9b3b8ddfd041970a11af047eae4efb1d13c686a909cab0c50f2917f
                          • Instruction ID: 554b8478f8f7f761b4faf0f3441b335af34930c770dde1a319b5830a4181f406
                          • Opcode Fuzzy Hash: f74fd00ec9b3b8ddfd041970a11af047eae4efb1d13c686a909cab0c50f2917f
                          • Instruction Fuzzy Hash: 92318D78E15219CBCB08CFA5D8455DDFBF6FF8D200F10A42AE41AB7254DB3498818F24
                          Uniqueness

                          Uniqueness Score: -1.00%

                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID:
                          • String ID: }H_[
                          • API String ID: 0-117617346
                          • Opcode ID: 314a9be3bc7dea157ea7c9bb4921941effa7f32ee4a0b404d0c6e47ab49985e2
                          • Instruction ID: dba49e0934e2459166446ed79a29a7bf7c030c75f1615fe9b972e43a7881286c
                          • Opcode Fuzzy Hash: 314a9be3bc7dea157ea7c9bb4921941effa7f32ee4a0b404d0c6e47ab49985e2
                          • Instruction Fuzzy Hash: 4FC17D74E19209DFCB18CFA5D5816ADFBF2FF89310F20A82AD015AB258D7349982CF14
                          Uniqueness

                          Uniqueness Score: -1.00%

                          Strings
                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID:
                          • String ID: }H_[
                          • API String ID: 0-117617346
                          • Opcode ID: cb85ff14cc4ba083f10d49234770e130d515081812fc1c9df719bd45dd184754
                          • Instruction ID: 6de07ba79dbdf3ac284c16a6450ee3fc4be1a35b33ca390ec5547c6f0c2b11b8
                          • Opcode Fuzzy Hash: cb85ff14cc4ba083f10d49234770e130d515081812fc1c9df719bd45dd184754
                          • Instruction Fuzzy Hash: E4418F74E15249DFCF68CFA4D1815ADFBF2EF89211F20682AE015BB248D734A9828F14
                          Uniqueness

                          Uniqueness Score: -1.00%

                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 744335635b046f452b2b6540ac00ccb63fcadfcd509f0af21d59659681d7a347
                          • Instruction ID: f91bb853ed65c575261dd05d9499fb2477ea102c3bd080be320f909bece23c62
                          • Opcode Fuzzy Hash: 744335635b046f452b2b6540ac00ccb63fcadfcd509f0af21d59659681d7a347
                          • Instruction Fuzzy Hash: D4D1FC707013068FDB29DB75C420BAEB7F6BF8A604F14886DD186DB690DB35E902CB52
                          Uniqueness

                          Uniqueness Score: -1.00%

                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: c0fa197173b3e05b02d34391784295e6c135a17d7ea94838a85ba0bcb8e62016
                          • Instruction ID: f16ee651cb5ee4965c7190efa380c7e7b6a7810431e7e86b7cf64c787f5ec0f4
                          • Opcode Fuzzy Hash: c0fa197173b3e05b02d34391784295e6c135a17d7ea94838a85ba0bcb8e62016
                          • Instruction Fuzzy Hash: F7614A75E05629CBDB28CF66C8447A9F7B6BFC9200F10E5EAD40DA7214EB705AC58F40
                          Uniqueness

                          Uniqueness Score: -1.00%

                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: df780924e2b630e0c4d3a76945fc906812b3261d55bb90f7c96c6dc55c0e9878
                          • Instruction ID: ecb4e73c55bac8113caf7a9366e257b153c33646c36e7ddb7ef702becc812c0a
                          • Opcode Fuzzy Hash: df780924e2b630e0c4d3a76945fc906812b3261d55bb90f7c96c6dc55c0e9878
                          • Instruction Fuzzy Hash: 5F612A75E1161ACBDB28CF66C844B99BBB2FFC9300F14D5EAD409A7254EB705AC58F40
                          Uniqueness

                          Uniqueness Score: -1.00%

                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 3bbb12bb5e7bd0592fa4e642d1aa98a2ea2abfbc380044f629abd9691aed46fe
                          • Instruction ID: 9d053181a7d7f09b83e3fc732d705edf1475e99970e4b84fc5658c922813df5c
                          • Opcode Fuzzy Hash: 3bbb12bb5e7bd0592fa4e642d1aa98a2ea2abfbc380044f629abd9691aed46fe
                          • Instruction Fuzzy Hash: 7B513B74D1122ACADB64CF65C884B9DB7B2FF99300F10A9E6D01AB3240EB709AD5CF44
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • CreateProcessA.KERNELBASE(?,?,?,?,?,?,?,?,?,?), ref: 05142046
                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID: CreateProcess
                          • String ID:
                          • API String ID: 963392458-0
                          • Opcode ID: fa2642b1434d444a1f5b48967929602f733fe159338fea51b895542a6d6084ca
                          • Instruction ID: 161ba3d440184a4603d8c1ff32a0a1907f8fb1a1daedb89079aa6b8f01b632e5
                          • Opcode Fuzzy Hash: fa2642b1434d444a1f5b48967929602f733fe159338fea51b895542a6d6084ca
                          • Instruction Fuzzy Hash: 71A15F75D002199FDF20CFA4C884BEEBBB2BF48314F148569E859A7240DB7499C5CF91
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • CreateProcessA.KERNELBASE(?,?,?,?,?,?,?,?,?,?), ref: 05142046
                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID: CreateProcess
                          • String ID:
                          • API String ID: 963392458-0
                          • Opcode ID: 0027307184c96ce51c1a95175a2487a36efe095933ef7c9db8c47e818287f95b
                          • Instruction ID: c6b08656910708bed74a708bb532b12e4be37dfb5cf7e1f34aabc3b5a288c212
                          • Opcode Fuzzy Hash: 0027307184c96ce51c1a95175a2487a36efe095933ef7c9db8c47e818287f95b
                          • Instruction Fuzzy Hash: 0E915E75D002199FDF20CFA8C884BEEBBB2BF49314F148569E819A7280DB7499C5CF91
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • CreateWindowExW.USER32(?,?,?,?,?,?,0000000C,?,?,?,?,?), ref: 0159FE0A
                          Memory Dump Source
                          • Source File: 00000000.00000002.669531707.0000000001590000.00000040.00000001.sdmp, Offset: 01590000, based on PE: false
                          Similarity
                          • API ID: CreateWindow
                          • String ID:
                          • API String ID: 716092398-0
                          • Opcode ID: 55bdc6c92617057a10728787c0086b084da6fed6ae7f6ba7572b676ccf281fca
                          • Instruction ID: 9913dc0d408f4ab8fdfe5ad9b5dc09d2e22e503d7a726cd3e2d1a67cdf75a410
                          • Opcode Fuzzy Hash: 55bdc6c92617057a10728787c0086b084da6fed6ae7f6ba7572b676ccf281fca
                          • Instruction Fuzzy Hash: 8151BEB1D003099FDF14CF99C884ADEBFB5BF48314F24852AE819AB250D7749985CF91
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • CreateWindowExW.USER32(?,?,?,?,?,?,0000000C,?,?,?,?,?), ref: 0159FE0A
                          Memory Dump Source
                          • Source File: 00000000.00000002.669531707.0000000001590000.00000040.00000001.sdmp, Offset: 01590000, based on PE: false
                          Similarity
                          • API ID: CreateWindow
                          • String ID:
                          • API String ID: 716092398-0
                          • Opcode ID: 22c79da17efac8da6e470a8446d7f0e121302979bc0369a07c1607a13ed6420c
                          • Instruction ID: d73f6cc7eec774cb75d98e394c9f6c328bfe343dc0ced239d3266b19587e5029
                          • Opcode Fuzzy Hash: 22c79da17efac8da6e470a8446d7f0e121302979bc0369a07c1607a13ed6420c
                          • Instruction Fuzzy Hash: 0751BEB1D003099FDF14CF99C884ADEBFB5BF48714F24852AE819AB250D7749985CF91
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • CreateActCtxA.KERNEL32(?), ref: 01595421
                          Memory Dump Source
                          • Source File: 00000000.00000002.669531707.0000000001590000.00000040.00000001.sdmp, Offset: 01590000, based on PE: false
                          Similarity
                          • API ID: Create
                          • String ID:
                          • API String ID: 2289755597-0
                          • Opcode ID: 983e307d48c8196212153debc5e0bca1a5af5bf6b159ed755cd15b7b62bb78f1
                          • Instruction ID: a1e6a4633bbc2d76fe4b05d82cf7ac81d39b59259179ca6dcc5486bd906f9d2e
                          • Opcode Fuzzy Hash: 983e307d48c8196212153debc5e0bca1a5af5bf6b159ed755cd15b7b62bb78f1
                          • Instruction Fuzzy Hash: E441F1B1D10218CBDF24CFA9C8847CEBBB5BF48318F20846AD508AB251E7B5594ACF91
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • CreateActCtxA.KERNEL32(?), ref: 01595421
                          Memory Dump Source
                          • Source File: 00000000.00000002.669531707.0000000001590000.00000040.00000001.sdmp, Offset: 01590000, based on PE: false
                          Similarity
                          • API ID: Create
                          • String ID:
                          • API String ID: 2289755597-0
                          • Opcode ID: 47a38e894fd73c2682efb92c52afab2a4dad28b5d5fc20205b47061c343d38ef
                          • Instruction ID: d036abdf95c83f903e5c948a0f34dc93932e1a5c39df350d4e47ae05e3d1899a
                          • Opcode Fuzzy Hash: 47a38e894fd73c2682efb92c52afab2a4dad28b5d5fc20205b47061c343d38ef
                          • Instruction Fuzzy Hash: 9041E270D1061CCBDF24CFA9C884BCEBBB5BF48308F20846AD508AB251D7B55945DF91
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • SetWindowLongW.USER32(?,?,?,?,?,?,?,?,0159FF28,?,?,?,?), ref: 0159FF9D
                          Memory Dump Source
                          • Source File: 00000000.00000002.669531707.0000000001590000.00000040.00000001.sdmp, Offset: 01590000, based on PE: false
                          Similarity
                          • API ID: LongWindow
                          • String ID:
                          • API String ID: 1378638983-0
                          • Opcode ID: 6868a660ebf2df2f25aac6d9f643b7fe7097842b69501453f691f1066560f2c1
                          • Instruction ID: 1fad16b4d8aa8657406e0b0df2c48aafc0f290a6e8c7a8856a1b09a5322e3ff8
                          • Opcode Fuzzy Hash: 6868a660ebf2df2f25aac6d9f643b7fe7097842b69501453f691f1066560f2c1
                          • Instruction Fuzzy Hash: 87319A72800209DFCF11DFA4E844A9ABFF8FF49310F15845AE955AB251D332A914CFA2
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • CreateActCtxA.KERNEL32(?), ref: 01595421
                          Memory Dump Source
                          • Source File: 00000000.00000002.669531707.0000000001590000.00000040.00000001.sdmp, Offset: 01590000, based on PE: false
                          Similarity
                          • API ID: Create
                          • String ID:
                          • API String ID: 2289755597-0
                          • Opcode ID: f1c55a0d96a2a0f91555aa558312868ff670bfd5d7a9c86911469e5e0bfb2ff1
                          • Instruction ID: 8ebcf3064cae1ad5d31719889a244c64919f8fb312d15af9fb03e175cc9d1e7c
                          • Opcode Fuzzy Hash: f1c55a0d96a2a0f91555aa558312868ff670bfd5d7a9c86911469e5e0bfb2ff1
                          • Instruction Fuzzy Hash: C741E0B1D10618CFDF24CFA9C8847CEBBB6BF48308F20856AD508AB251DB75594ADF91
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • SetThreadContext.KERNELBASE(?,00000000), ref: 0514141E
                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID: ContextThread
                          • String ID:
                          • API String ID: 1591575202-0
                          • Opcode ID: 768b421156a1051233d7a68b00a3ab333c7b873cd125e1a2cc1f1e26ae4727fa
                          • Instruction ID: ca446d96048ea1a84938e3276db021bc278ae789bca3bf3ceaa36b796c8bd926
                          • Opcode Fuzzy Hash: 768b421156a1051233d7a68b00a3ab333c7b873cd125e1a2cc1f1e26ae4727fa
                          • Instruction Fuzzy Hash: 9C319F758003489FDB10CFA9C4857EEBFF4EB49364F588429D945A7241DB78AA85CFA0
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • VirtualAllocEx.KERNELBASE(?,?,?,?,?), ref: 05141B36
                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID: AllocVirtual
                          • String ID:
                          • API String ID: 4275171209-0
                          • Opcode ID: c28f35b733dee90e550a36b977314bad51e845b80485a9e78bdc1fa4de211801
                          • Instruction ID: 20d0390380e545226164d17b342a9cd6ecc999d61048ef87019afdb49038b230
                          • Opcode Fuzzy Hash: c28f35b733dee90e550a36b977314bad51e845b80485a9e78bdc1fa4de211801
                          • Instruction Fuzzy Hash: CD31F2768043889FCB01CFA9C8847DEBFB5FF4A324F19846AD545A7241D7385986CFA1
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • WriteProcessMemory.KERNELBASE(?,?,00000000,?,?), ref: 05141C18
                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID: MemoryProcessWrite
                          • String ID:
                          • API String ID: 3559483778-0
                          • Opcode ID: f58e2b6e43a6efe8867269a1d12b829a468da2efa965b5ce1ecf7b1f6572cf2d
                          • Instruction ID: 47363023bcbafa703f58fc1f0dc82cdc94c467021be00dbe007469018f8b912c
                          • Opcode Fuzzy Hash: f58e2b6e43a6efe8867269a1d12b829a468da2efa965b5ce1ecf7b1f6572cf2d
                          • Instruction Fuzzy Hash: D02137759003099FCF00CFA9C884BDEBBF5FB48324F10882AE919A7240D7789985DFA0
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • PostMessageW.USER32(?,?,?,?), ref: 051454AD
                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID: MessagePost
                          • String ID:
                          • API String ID: 410705778-0
                          • Opcode ID: 1e4fb70bb43516c3fdc9f16e22ec5d69392d226b857d10255875870279dcdab4
                          • Instruction ID: d45f767dfd2dca74b545f2cad117b32f06e9a814e196478547ca9e14e055aa74
                          • Opcode Fuzzy Hash: 1e4fb70bb43516c3fdc9f16e22ec5d69392d226b857d10255875870279dcdab4
                          • Instruction Fuzzy Hash: BD21D071D042588BDF20CFA5D809BEEBBF6BB84314F158419C445BB240D7745D40DFA0
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • WriteProcessMemory.KERNELBASE(?,?,00000000,?,?), ref: 05141C18
                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID: MemoryProcessWrite
                          • String ID:
                          • API String ID: 3559483778-0
                          • Opcode ID: fec223c6a1c3ad93cbffee453a6c90ac82397b94f25ec15833ab71c2dd625cc2
                          • Instruction ID: 3443c83625c37d5102d8aa4256004aeae0cc37a6fe2d669c7d1bb8d7ea503a1b
                          • Opcode Fuzzy Hash: fec223c6a1c3ad93cbffee453a6c90ac82397b94f25ec15833ab71c2dd625cc2
                          • Instruction Fuzzy Hash: 702115759003499FCB00CFA9C884BDEBBF5FB48324F10882AE919A7240D7789985DFA0
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?,?,?,?,0159B87E,?,?,?,?,?), ref: 0159B93F
                          Memory Dump Source
                          • Source File: 00000000.00000002.669531707.0000000001590000.00000040.00000001.sdmp, Offset: 01590000, based on PE: false
                          Similarity
                          • API ID: DuplicateHandle
                          • String ID:
                          • API String ID: 3793708945-0
                          • Opcode ID: d4e87378793a33aed3827bbd5f19247e1814549cec2d8061dc6e98c9bb1d01a7
                          • Instruction ID: db9adf91fb00e71bd22ffbc617c767674aa7f9edb04c56924ebc9c39c6fb35c7
                          • Opcode Fuzzy Hash: d4e87378793a33aed3827bbd5f19247e1814549cec2d8061dc6e98c9bb1d01a7
                          • Instruction Fuzzy Hash: 622122B58002489FDB10CFA9D884AEEBFF8FB09324F14845AE914A7251D378A944DFA1
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • ReadProcessMemory.KERNELBASE(?,?,?,?,?), ref: 05141CF8
                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID: MemoryProcessRead
                          • String ID:
                          • API String ID: 1726664587-0
                          • Opcode ID: 5677a2524d60aa58108f71672ccb6e993c2ac87fc9dfe9829d0eeb4183aa7670
                          • Instruction ID: 8c2fa74e19ebef8193ee3e12956baf1c717c8c86292c6911d86b0b014c7094fb
                          • Opcode Fuzzy Hash: 5677a2524d60aa58108f71672ccb6e993c2ac87fc9dfe9829d0eeb4183aa7670
                          • Instruction Fuzzy Hash: 1B2119B59003499FCF10CFA9C884BEEBBF5FF48324F54882AE919A7240C7749945DBA1
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?,?,?,?,0159B87E,?,?,?,?,?), ref: 0159B93F
                          Memory Dump Source
                          • Source File: 00000000.00000002.669531707.0000000001590000.00000040.00000001.sdmp, Offset: 01590000, based on PE: false
                          Similarity
                          • API ID: DuplicateHandle
                          • String ID:
                          • API String ID: 3793708945-0
                          • Opcode ID: 7223fd3aee567261adaa78bc76812089d11f36702b84fa6b115e831f7e8f1a91
                          • Instruction ID: cbd48e1da6e3007dd27b5ef00ad6954cf8b3c3d1dc74ea80eef9b7120b4f7953
                          • Opcode Fuzzy Hash: 7223fd3aee567261adaa78bc76812089d11f36702b84fa6b115e831f7e8f1a91
                          • Instruction Fuzzy Hash: 5121E3B59002189FDB10CFA9D484ADEBBF8FB48324F14842AE914B7350D374A955DFA1
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • ReadProcessMemory.KERNELBASE(?,?,?,?,?), ref: 05141CF8
                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID: MemoryProcessRead
                          • String ID:
                          • API String ID: 1726664587-0
                          • Opcode ID: 701fa860d386ee68c53424a131f2ba5438a41df36efea94c4a354beda2c09487
                          • Instruction ID: de7b30751280c6d70e095f89dfdf808a9691ce24e243478d37f8a641ad52e1fd
                          • Opcode Fuzzy Hash: 701fa860d386ee68c53424a131f2ba5438a41df36efea94c4a354beda2c09487
                          • Instruction Fuzzy Hash: 172119B59002499FCB00CFA9C8846DEBBF5FF48314F508429E519A7240C7749945DBA0
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • SetThreadContext.KERNELBASE(?,00000000), ref: 0514141E
                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID: ContextThread
                          • String ID:
                          • API String ID: 1591575202-0
                          • Opcode ID: 462cf7f509d38f682d030e8fc66a31b42336618b3526178ce58994925c7a2a72
                          • Instruction ID: 539b602cc11aa3462c5a0a0fedfc2a44ad646f27a518c97159982311ff55ef8c
                          • Opcode Fuzzy Hash: 462cf7f509d38f682d030e8fc66a31b42336618b3526178ce58994925c7a2a72
                          • Instruction Fuzzy Hash: 98214971D003089FCB10CFA9C4847EEBBF5EF48368F54842AD559A7240CB78A985CFA0
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?,?,?,?,0159B87E,?,?,?,?,?), ref: 0159B93F
                          Memory Dump Source
                          • Source File: 00000000.00000002.669531707.0000000001590000.00000040.00000001.sdmp, Offset: 01590000, based on PE: false
                          Similarity
                          • API ID: DuplicateHandle
                          • String ID:
                          • API String ID: 3793708945-0
                          • Opcode ID: f624abbc57a32a3a0558c03fb591dce845062cb0a194fecaac5280fb374ffcd3
                          • Instruction ID: 101223d40f1aed41ca102da43f1ed7f3d184030f7438765a976e58db2a18a047
                          • Opcode Fuzzy Hash: f624abbc57a32a3a0558c03fb591dce845062cb0a194fecaac5280fb374ffcd3
                          • Instruction Fuzzy Hash: CC21B3B59002199FDB10CF99D884ADEBFF8FB48324F14841AE954A7350D374A954DFA1
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • LoadLibraryExW.KERNELBASE(00000000,00000000,?,?,?,?,00000000,?,01599951,00000800,00000000,00000000), ref: 01599B62
                          Memory Dump Source
                          • Source File: 00000000.00000002.669531707.0000000001590000.00000040.00000001.sdmp, Offset: 01590000, based on PE: false
                          Similarity
                          • API ID: LibraryLoad
                          • String ID:
                          • API String ID: 1029625771-0
                          • Opcode ID: 8ce967dd9d476ea924f107a5481adb304ee3f1030c8499df79b4684cedd88242
                          • Instruction ID: 00ae8cdf9926db6c57397f42ed8b39e45e96dd470df545886dcd83a02b875328
                          • Opcode Fuzzy Hash: 8ce967dd9d476ea924f107a5481adb304ee3f1030c8499df79b4684cedd88242
                          • Instruction Fuzzy Hash: 1B1106B69002098FDB10CF9AC484ADEFBF5EB48324F54842ED515A7200C3B8A545CFA1
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • VirtualAllocEx.KERNELBASE(?,?,?,?,?), ref: 05141B36
                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID: AllocVirtual
                          • String ID:
                          • API String ID: 4275171209-0
                          • Opcode ID: 5dd364c48a983d602cd8557d1c44f448ae89e490aeac39a3c6c034f4e734caef
                          • Instruction ID: 88dae0cbb8cf11dd788ce08bec48dc1f07a69ee348ab9f2d89c05ce4a397404b
                          • Opcode Fuzzy Hash: 5dd364c48a983d602cd8557d1c44f448ae89e490aeac39a3c6c034f4e734caef
                          • Instruction Fuzzy Hash: 8E1126759002089FCF10DFA9C844BDFBBF9AB88324F148819E515A7250C775A955DFA1
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • LoadLibraryExW.KERNELBASE(00000000,00000000,?,?,?,?,00000000,?,01599951,00000800,00000000,00000000), ref: 01599B62
                          Memory Dump Source
                          • Source File: 00000000.00000002.669531707.0000000001590000.00000040.00000001.sdmp, Offset: 01590000, based on PE: false
                          Similarity
                          • API ID: LibraryLoad
                          • String ID:
                          • API String ID: 1029625771-0
                          • Opcode ID: e68fa6052ff4725148474131c73c251a424cbb8171495c33e167589834ec2f06
                          • Instruction ID: 3825b743cfb802235c4a63de3c395cf5b7daa6ce63c64e4e137ab5d48884805c
                          • Opcode Fuzzy Hash: e68fa6052ff4725148474131c73c251a424cbb8171495c33e167589834ec2f06
                          • Instruction Fuzzy Hash: 8C1114B68002088FDB10CF9AC484BDEFBF9FB48324F14842ED915A7600C378A545CFA1
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID: ResumeThread
                          • String ID:
                          • API String ID: 947044025-0
                          • Opcode ID: 6f61dd58e53927152e5ff07ba702f920e7b73ba294ec63969ed5a0e231c33a45
                          • Instruction ID: af281c3593f4337355e4050360496a934ab95772d368ee17a849874736a0d8d8
                          • Opcode Fuzzy Hash: 6f61dd58e53927152e5ff07ba702f920e7b73ba294ec63969ed5a0e231c33a45
                          • Instruction Fuzzy Hash: 1E1128799002088FDB10DFAAC4887DFBBF9AB48228F14882AD519B7240C775A945CFA0
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • GetModuleHandleW.KERNELBASE(00000000,?,?,?,?,?,?,?,0159929B), ref: 015998D6
                          Memory Dump Source
                          • Source File: 00000000.00000002.669531707.0000000001590000.00000040.00000001.sdmp, Offset: 01590000, based on PE: false
                          Similarity
                          • API ID: HandleModule
                          • String ID:
                          • API String ID: 4139908857-0
                          • Opcode ID: 9ce6dc3c03d400cc3868679340b168550c34fdeb50d3b06858789f433e6ff738
                          • Instruction ID: e77e51437113ed5771d242428c7dfe9ee3af5f9d4cf55e213d79a332f6590a50
                          • Opcode Fuzzy Hash: 9ce6dc3c03d400cc3868679340b168550c34fdeb50d3b06858789f433e6ff738
                          • Instruction Fuzzy Hash: 3F11E2B5C006498BDB10DF9AC444BDEBBF4EB49224F14842ED919BB200C375A546CFA1
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • GetModuleHandleW.KERNELBASE(00000000,?,?,?,?,?,?,?,0159929B), ref: 015998D6
                          Memory Dump Source
                          • Source File: 00000000.00000002.669531707.0000000001590000.00000040.00000001.sdmp, Offset: 01590000, based on PE: false
                          Similarity
                          • API ID: HandleModule
                          • String ID:
                          • API String ID: 4139908857-0
                          • Opcode ID: bbe0d292246bf5b51ca6a0b9ddb88a6674cccf3681660c89c27ed10a723e811b
                          • Instruction ID: 99a4d7875b190c7c993b5d89628ee8c70f724c42aa1c237c1472d81d6ca64c11
                          • Opcode Fuzzy Hash: bbe0d292246bf5b51ca6a0b9ddb88a6674cccf3681660c89c27ed10a723e811b
                          • Instruction Fuzzy Hash: 7311E2B5C002499FDB10CF9AD444ADEBBF8EB49324F14842ED429BB600D375A546CFA1
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID: ResumeThread
                          • String ID:
                          • API String ID: 947044025-0
                          • Opcode ID: 1c785969e807d8facfdd1e4857a1febd38d56fb77a1842ab16c459b7c5e9cbda
                          • Instruction ID: 20c6b32e76854196e05da98ed7e2c264d18cbfa94fa399478d0f82fbd247aed8
                          • Opcode Fuzzy Hash: 1c785969e807d8facfdd1e4857a1febd38d56fb77a1842ab16c459b7c5e9cbda
                          • Instruction Fuzzy Hash: C0110A759003488FDB14DFAAC4487DFFBF9AB48224F148829D519B7240C775A945CFA5
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • FindCloseChangeNotification.KERNELBASE(?), ref: 05145E88
                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID: ChangeCloseFindNotification
                          • String ID:
                          • API String ID: 2591292051-0
                          • Opcode ID: e725a6086afae32ddd0d166787db37be9fa02dc89c9c59a343754b30bd154849
                          • Instruction ID: 8e7cb1051078901f1c87d01b6bcdc5cf64fa8c5eb632177a8fb2e00e24545d13
                          • Opcode Fuzzy Hash: e725a6086afae32ddd0d166787db37be9fa02dc89c9c59a343754b30bd154849
                          • Instruction Fuzzy Hash: C71103B68006098FCB10DF99C585BDEFBF4EB48324F14842AD959B7340D778A685DFA1
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • FindCloseChangeNotification.KERNELBASE(?), ref: 05145E88
                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID: ChangeCloseFindNotification
                          • String ID:
                          • API String ID: 2591292051-0
                          • Opcode ID: 4f6d38fa4ea56364ed75a6e079ae50b6e2678f009644389557e15987b6cc7cc4
                          • Instruction ID: d5ab845d244d92f8632f270024264bbb9d6e5bf227723e2ec1e30cd70facb60c
                          • Opcode Fuzzy Hash: 4f6d38fa4ea56364ed75a6e079ae50b6e2678f009644389557e15987b6cc7cc4
                          • Instruction Fuzzy Hash: C01103B58006098FCB10DF99C584BDEBBF4EB48324F14842AD959B7240D778A685DFA1
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • SetWindowLongW.USER32(?,?,?,?,?,?,?,?,0159FF28,?,?,?,?), ref: 0159FF9D
                          Memory Dump Source
                          • Source File: 00000000.00000002.669531707.0000000001590000.00000040.00000001.sdmp, Offset: 01590000, based on PE: false
                          Similarity
                          • API ID: LongWindow
                          • String ID:
                          • API String ID: 1378638983-0
                          • Opcode ID: 6de2f22c92ff7170dec2281be044efef46725d3509a5e3c431b54b6d5c8a0373
                          • Instruction ID: 2849729ee8936d27db100fc3bea4950916bfd6b7bca3d8a4fa1d4303bfdc55d4
                          • Opcode Fuzzy Hash: 6de2f22c92ff7170dec2281be044efef46725d3509a5e3c431b54b6d5c8a0373
                          • Instruction Fuzzy Hash: FF11F2B58002089FDB10DF99D488BDEBBF8EB49324F10845AE969A7240C3B4A944CFA1
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • PostMessageW.USER32(?,?,?,?), ref: 051454AD
                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID: MessagePost
                          • String ID:
                          • API String ID: 410705778-0
                          • Opcode ID: 47585becf83c64677d63129be9db9dff2b7ea2d23cce6a7cf485d3d76c145e61
                          • Instruction ID: 69734e5945a0dc7d9d6c7e2fc5ee38002181ec89e6602c0702e9b143d2c2e65f
                          • Opcode Fuzzy Hash: 47585becf83c64677d63129be9db9dff2b7ea2d23cce6a7cf485d3d76c145e61
                          • Instruction Fuzzy Hash: 1F11D6B58003499FDB10DF99D485BDEBBF8EB48324F14841AE555B7240D375A944CFA1
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • PostMessageW.USER32(?,?,?,?), ref: 051454AD
                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID: MessagePost
                          • String ID:
                          • API String ID: 410705778-0
                          • Opcode ID: 0e8a6ff31448396318016094cff51218aa5c53676848273c0006f1f394542c76
                          • Instruction ID: 0eddb0599b500be4250e086108d96251663b597af8bd06d09b6e9f21e851af31
                          • Opcode Fuzzy Hash: 0e8a6ff31448396318016094cff51218aa5c53676848273c0006f1f394542c76
                          • Instruction Fuzzy Hash: 0D11E5B58003499FDB10DF99D484BDEBBF8FB48324F14841AE559B7240D3B5A984CFA1
                          Uniqueness

                          Uniqueness Score: -1.00%

                          Non-executed Functions

                          Memory Dump Source
                          • Source File: 00000000.00000002.669531707.0000000001590000.00000040.00000001.sdmp, Offset: 01590000, based on PE: false
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 6f3c25f43db00cb9b45e4f62ea8eed5f292a55fb633bb3093e1bfe911f7c8f0e
                          • Instruction ID: 676e72de51d046798648a87cd0ea4b56d24f92ffb8b291995c7cb9905b3beb9c
                          • Opcode Fuzzy Hash: 6f3c25f43db00cb9b45e4f62ea8eed5f292a55fb633bb3093e1bfe911f7c8f0e
                          • Instruction Fuzzy Hash: CC1286F142374A8AE310CF69E99B18D3FA1B76532CB906209E2631FAD1DFB4154ACF54
                          Uniqueness

                          Uniqueness Score: -1.00%

                          Memory Dump Source
                          • Source File: 00000000.00000002.669531707.0000000001590000.00000040.00000001.sdmp, Offset: 01590000, based on PE: false
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: db5c68cb566173833964e166f2c2ad96fb74725391fbf03a0f18984ec67fa601
                          • Instruction ID: a371a5981022dac7d8e85da6bccf946ba9ee2fbe08324732623ec3388092c8c0
                          • Opcode Fuzzy Hash: db5c68cb566173833964e166f2c2ad96fb74725391fbf03a0f18984ec67fa601
                          • Instruction Fuzzy Hash: 40A16D32E0021A8FCF05DFA9C8445DEBBB2FF85300B15856AE905BF261EB71A955CF81
                          Uniqueness

                          Uniqueness Score: -1.00%

                          Memory Dump Source
                          • Source File: 00000000.00000002.669531707.0000000001590000.00000040.00000001.sdmp, Offset: 01590000, based on PE: false
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: c79688801d826609d35b9948ef56679d5ec71e89cd6dd7a3410a37d8215015a1
                          • Instruction ID: ea246d72137707d2a0c38750efc0858d33dcb288c41124036ddc2f80fafae095
                          • Opcode Fuzzy Hash: c79688801d826609d35b9948ef56679d5ec71e89cd6dd7a3410a37d8215015a1
                          • Instruction Fuzzy Hash: 03C10BB142274A8AD710CF69E99B28D3FA1BB6532CF516309E2632F6D1DFB41486CF44
                          Uniqueness

                          Uniqueness Score: -1.00%

                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: f7a7e36b43e50088fdcae1b748ec2387ba14cdd38611e3ec8e0c2e3d5c45ebc1
                          • Instruction ID: 3c928df65041eb8bb180474bf121bf743f389e97105b0e14e73c816a2a6d1a9d
                          • Opcode Fuzzy Hash: f7a7e36b43e50088fdcae1b748ec2387ba14cdd38611e3ec8e0c2e3d5c45ebc1
                          • Instruction Fuzzy Hash: 2F611B74E1620A8FCF18CFA9D5415AEFBB2EF89310F10A42AD426F7354D7345A418F95
                          Uniqueness

                          Uniqueness Score: -1.00%

                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 89b08ad01cd102e891ab9e7ead7405269541f4e804f7902e74c1cfe62ea506a3
                          • Instruction ID: 3972d4a2a2e1640cf13218299d374526b0c0f3d008d906705452017e313fb1b7
                          • Opcode Fuzzy Hash: 89b08ad01cd102e891ab9e7ead7405269541f4e804f7902e74c1cfe62ea506a3
                          • Instruction Fuzzy Hash: 73612A74E1620A8FCF18CFA9D5415AEFBB2EF89310F10A42AD826F7354D7345A428F95
                          Uniqueness

                          Uniqueness Score: -1.00%

                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 184929216613b5a1b5351cfd7936a3bb18a87d697d7c025be82206940a423c8e
                          • Instruction ID: 1ec6059de3fde81974f391a0eb3342e4824247f5f0909db6dec763c5d97cdd47
                          • Opcode Fuzzy Hash: 184929216613b5a1b5351cfd7936a3bb18a87d697d7c025be82206940a423c8e
                          • Instruction Fuzzy Hash: 9C41E674E156199FDB58CF6AD884AAEBBF3FF88200F10D0AAD509B7214DB305A85CF51
                          Uniqueness

                          Uniqueness Score: -1.00%

                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: ba80261a40ce1b13e9db957b68a2d19bc50dc54b44b6f5ee3d6e0b399ebe1748
                          • Instruction ID: 739e59e9606f292102deac7958d690d20d835e9a0c707e30b69097ec05d1f000
                          • Opcode Fuzzy Hash: ba80261a40ce1b13e9db957b68a2d19bc50dc54b44b6f5ee3d6e0b399ebe1748
                          • Instruction Fuzzy Hash: 40411A74E116189FDB58CF6AD984BAEBBF3BF88200F14D0AAD409A7220DB305985CF51
                          Uniqueness

                          Uniqueness Score: -1.00%

                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 6733b7e305a526e5735887982d07b17ecd1c0dafe7063db806f7e5fac9f2b118
                          • Instruction ID: e46c6392b3abb663e4f3c3395b88a72d74da482f0a064284e5f16dfb0042a771
                          • Opcode Fuzzy Hash: 6733b7e305a526e5735887982d07b17ecd1c0dafe7063db806f7e5fac9f2b118
                          • Instruction Fuzzy Hash: AE112671E116199BEB18CFABE9416EEFBF7BBC8200F14C43AD408A7214DB305A418F91
                          Uniqueness

                          Uniqueness Score: -1.00%

                          Memory Dump Source
                          • Source File: 00000000.00000002.670497998.0000000005140000.00000040.00000001.sdmp, Offset: 05140000, based on PE: false
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: c51a2867f550ce3e0f531a44fa30bdc101aa799d85af68dedaaf242d359aba12
                          • Instruction ID: db224c2ab870af5cd4c331b9ff52d6f6d548e6ad902b3b69f7cc8159b33bcd3a
                          • Opcode Fuzzy Hash: c51a2867f550ce3e0f531a44fa30bdc101aa799d85af68dedaaf242d359aba12
                          • Instruction Fuzzy Hash: D7116771E116089BEB18CFAAD9417AEFAF7BBC8200F14C03AD408A7214DB305A428F90
                          Uniqueness

                          Uniqueness Score: -1.00%

                          Executed Functions

                          APIs
                          • DrawStateW.USER32(00000001,00000000,00000000,00000000,00000000,00000000), ref: 066DDCCC
                          Memory Dump Source
                          • Source File: 00000002.00000002.935821582.00000000066D0000.00000040.00000001.sdmp, Offset: 066D0000, based on PE: false
                          Similarity
                          • API ID: DrawState
                          • String ID:
                          • API String ID: 345284738-0
                          • Opcode ID: d79040ad523eb1606b06274497db421a41f824e2b12ddb0f67197d9aab4eb126
                          • Instruction ID: 861d64d813be8613c508282b7f93f73d1fa1aa6b742c4f82fdc1a5f7e0199b86
                          • Opcode Fuzzy Hash: d79040ad523eb1606b06274497db421a41f824e2b12ddb0f67197d9aab4eb126
                          • Instruction Fuzzy Hash: AF621330F002059FDBA4ABA8C854BAEB6A7AFC5710F148469E406EF3D5DB75DC42C792
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • DrawStateW.USER32(00000001,00000000,00000000,00000000,?,00000000), ref: 066DA2CA
                          Memory Dump Source
                          • Source File: 00000002.00000002.935821582.00000000066D0000.00000040.00000001.sdmp, Offset: 066D0000, based on PE: false
                          Similarity
                          • API ID: DrawState
                          • String ID:
                          • API String ID: 345284738-0
                          • Opcode ID: 6545fc91f08284f04bbbbb84deece0f3361c086d89d7875b59ecf8932fc1c96d
                          • Instruction ID: 5bf02f9e585ddafd2531ee81fa193a2a822c716915cac1c11e8dd5fe3c0a57aa
                          • Opcode Fuzzy Hash: 6545fc91f08284f04bbbbb84deece0f3361c086d89d7875b59ecf8932fc1c96d
                          • Instruction Fuzzy Hash: 3D42CE70E082489FEB60DBE8C494BADBBB2AF85304F14856ED409AF395DB74D885CB51
                          Uniqueness

                          Uniqueness Score: -1.00%

                          APIs
                          • GetWindowRgnBox.USER32(?), ref: 066D68CD
                          Memory Dump Source
                          • Source File: 00000002.00000002.935821582.00000000066D0000.00000040.00000001.sdmp, Offset: 066D0000, based on PE: false
                          Similarity
                          • API ID: Window
                          • String ID:
                          • API String ID: 2353593579-0
                          • Opcode ID: a8d41a436e22ecb396265cafd859532ae9a17e9e4f3c0fdf6384aeb1f0481bee
                          • Instruction ID: b10b13a2105be00d8271d78270c486128f32e62d80452a88dbdfac4c4944234f
                          • Opcode Fuzzy Hash: a8d41a436e22ecb396265cafd859532ae9a17e9e4f3c0fdf6384aeb1f0481bee
                          • Instruction Fuzzy Hash: 69712A34F002468FDB64DF29C884A6A7BF5AF49750F1540AAE916CB371DB74EC41CBA1
                          Uniqueness

                          Uniqueness Score: -1.00%

                          Memory Dump Source
                          • Source File: 00000002.00000002.931789715.000000000143D000.00000040.00000001.sdmp, Offset: 0143D000, based on PE: false
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: cc447630a318f3be913170efadc9188119b8f909ff368b661e2f9d50338673b7
                          • Instruction ID: e159164eea0fb71eaeb30a3e752a80ed1c3d52559740629107e34593d53df21b
                          • Opcode Fuzzy Hash: cc447630a318f3be913170efadc9188119b8f909ff368b661e2f9d50338673b7
                          • Instruction Fuzzy Hash: 0D213671900244DFDB01DF94C8C0B17BF65FBC8328F60856AE8094B296C336D456CAA1
                          Uniqueness

                          Uniqueness Score: -1.00%

                          Memory Dump Source
                          • Source File: 00000002.00000002.931827101.000000000144D000.00000040.00000001.sdmp, Offset: 0144D000, based on PE: false
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: a1bc5f531af9b867458fc6c4f53d7eff37881773e8bd5ca57e274b96953c29ac
                          • Instruction ID: 457d3f1ae8ea16e0576938b1ebea5b4f935398e0dbc6a402dc008db55079bfdb
                          • Opcode Fuzzy Hash: a1bc5f531af9b867458fc6c4f53d7eff37881773e8bd5ca57e274b96953c29ac
                          • Instruction Fuzzy Hash: BA2137B1904244DFEB15CFA4D8C4B17BB65FB94358F20C96ED8094B356C336D847CA61
                          Uniqueness

                          Uniqueness Score: -1.00%

                          Memory Dump Source
                          • Source File: 00000002.00000002.931827101.000000000144D000.00000040.00000001.sdmp, Offset: 0144D000, based on PE: false
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: 2173fa48d1b24fce45cd4c6838caae820742f3f4214b2a7a654d2eeee65a3460
                          • Instruction ID: 4fdddae3f0dbc3fd8c85f6f9fdc30c57ca980db609b1c136bbe1f0e8ce37b05b
                          • Opcode Fuzzy Hash: 2173fa48d1b24fce45cd4c6838caae820742f3f4214b2a7a654d2eeee65a3460
                          • Instruction Fuzzy Hash: B22180755093C08FDB12CF64D594B16BF71EB46214F28C5DBD8498B667C33A980ACB62
                          Uniqueness

                          Uniqueness Score: -1.00%

                          Memory Dump Source
                          • Source File: 00000002.00000002.931789715.000000000143D000.00000040.00000001.sdmp, Offset: 0143D000, based on PE: false
                          Similarity
                          • API ID:
                          • String ID:
                          • API String ID:
                          • Opcode ID: f695eed339961eed004f4f78b14fba75fcb2e3654d3ef5a3d5d17d5512e929ac
                          • Instruction ID: ca8e9320d0c082ae5128c2cdd162a489cb4eda6c47a757e2e94bf48a890e8723
                          • Opcode Fuzzy Hash: f695eed339961eed004f4f78b14fba75fcb2e3654d3ef5a3d5d17d5512e929ac
                          • Instruction Fuzzy Hash: F111D376804280DFCB06CF54D9C4B56BF72FB88324F24C6AAD8494B766C336D55ACBA1
                          Uniqueness

                          Uniqueness Score: -1.00%

                          Non-executed Functions